EU's data protection supervisor recommends that personal data such as search queries and browsing history should not be used for the assessment of credit scores
The European Union's lead data protection supervisor has recommended on Thursday that personal data such as search queries … Tweets: @cubicleapril , @hypervisible , and @campuscodi Tweets: April King / @cubicleapril : Fintech companies being so shamelessly rapacious that the EU needs to say this makes me want to launch all their computers into the sun. https://therecord.media/... Hypervisible Dot Pdf / @hypervisible : This was a response to an IMF rec “which was universally panned and considered downright creepy, [but] showed, however, the underlying fear of most of the banking sector—that they are losing ground to tech companies like Amazon, Facebook, and Google.” https://therecord.media/... Catalin Cimpanu / @campuscodi : The EDPS recommendation somewhat comes as a response to that creepy IMF blog post from last year where IMF researchers argued that credit scores would be more accurate with nonfinancial data points such as browsing and search history. https://blogs.imf.org/...
Context & Ripple Effects
The European Data Protection Supervisor's advice lands after an IMF proposal to let lenders tap behavioral web data was widely panned as invasive — but, as commentators quoted in the coverage note, it exposed how much of the banking sector quietly wants exactly that capability.
It also arrives into an industry already building toward it: Equifax and FICO's Data Decision Cloud packages consumer credit data for financial firms and marketers, while critics have long questioned whether the Irish DPC, the EU's lead GDPR enforcer, will actually police dominant tech firms. A later CJEU ruling on sensitive personal data shows courts are converging on the same question of what tracking may legitimately feed.
First-order effects
- Fintech lenders and marketers experimenting with search-query or browsing-history inputs for credit decisions face supervisory guidance against the practice inside the EU, raising legal exposure under GDPR for any product already built on it.
- The EDPS has effectively staked out the supervisor-level position ahead of any formal rule change, giving national data protection authorities a citable basis to challenge behavioral credit-scoring schemes.
Second-order effects
- Scoring providers are pushed back toward traditional bureau data — a relative win for incumbents like Equifax and FICO whose offerings aggregate established credit files rather than web behavior.
- Enforcement pressure now shifts to member-state authorities such as the Irish DPC, whose willingness to act against major firms remains the open question in EU privacy oversight.
Third-order effects
- If supervisors hold this line alongside court rulings like the Lithuanian case, a durable boundary forms between behavioral web tracking and consequential financial decisions about individuals — a template other jurisdictions watching GDPR enforcement may copy.
- The episode signals that alternative-data credit products will need explicit legal foundations rather than repurposed ad-tech pipelines, reshaping which data suppliers fintech can source from at all.
The trend: European regulators are drawing a permission boundary around personal web-behavior data, barring its reuse for high-stakes decisions like credit scoring.