What's Happening?
The new EU Consumer Credit Directive (CCD2), set to apply from November 20, 2026, will significantly alter data protection and AI usage in consumer credit assessments. This directive, along with the GDPR and the AI Act, introduces stringent rules on what
data can be used for creditworthiness evaluations. Specifically, Article 18(3) CCD2 prohibits the use of special categories of data, such as health data or political opinions, and excludes social networks as external data sources. Unlike the GDPR, CCD2 offers no exceptions for processing special category data, even with consumer consent. The directive also mandates that AI systems used for credit scoring are classified as high-risk, requiring obligations related to data governance, bias examination, technical documentation, event logging, human oversight, and transparency. Furthermore, it emphasizes the need for necessity and proportionality in data collection, meaning that the data set used for a small loan should differ from that for a high-value credit. Creditors will need to prepare separate, narrower data scopes for individual products to comply.
Why It's Important?
The implementation of CCD2 will have a profound impact on the consumer credit industry, particularly for lenders utilizing automated credit decisioning and alternative data sources. The directive's strict prohibitions on certain data categories and sources, like social media activity, will necessitate a re-evaluation of existing credit scoring models. This could lead to increased operational costs for financial institutions as they adapt their systems and processes to comply with the new regulations. The classification of AI credit assessment systems as high-risk under the AI Act will also demand significant investment in data governance, bias detection, and human oversight mechanisms. For consumers, these changes aim to prevent irresponsible lending, over-indebtedness, and discriminatory practices, ensuring more transparent and fair credit assessments. However, it could also potentially limit the ability of some individuals, particularly those with thin credit files, to access credit if alternative data sources are restricted without adequate replacements. The directive also shifts the legal basis for creditworthiness assessments from legitimate interests to a mandatory statutory step, impacting how data processing activities are documented and justified.
What's Next?
Creditors, credit intermediaries, buy-now-pay-later (BNPL) providers, and crowdfunding credit service providers must prepare for the application of CCD2 by November 20, 2026. This involves building a variable inventory for every scoring and affordability model, removing special category data and social network-derived signals, and updating records of processing activities. They will also need to rebuild contracts with vendors and credit reference agencies to clarify controller roles and responsibilities under the SCHUFA judgment. A two-level explanation system and a documented human review procedure satisfying Article 18(8) CCD2 must be implemented, along with refusal notifications that include referrals to debt advisory services. Furthermore, reporting to credit registers needs to be reviewed for accuracy, correction processes, and retention periods. Member States, including Poland, are in the process of transposing the directive into national law, and creditors should monitor these developments, as the legal basis for data processing will depend on the national implementing act's entry into force.
Beyond the Headlines
The CCD2, in conjunction with the GDPR and the AI Act, represents a significant step towards a more ethical and transparent financial landscape in the EU. The emphasis on human oversight and the right to explanation in automated credit decisions addresses growing concerns about algorithmic bias and the potential for discriminatory outcomes. By prohibiting the use of certain data, such as health information or social media activity, the directive aims to protect individual privacy and ensure that credit decisions are based solely on relevant financial indicators. This could foster greater trust in financial institutions and AI-driven systems. However, it also presents a challenge for innovation, as companies that rely heavily on alternative data for credit assessment will need to find new, compliant methods. The directive's impact extends beyond credit decisions, influencing broader discussions on data ethics, AI governance, and consumer rights in the digital age, potentially setting a precedent for similar regulations globally.











