Accept Refuse

EUR-Lex Access to European Union law

Back to EUR-Lex homepage

This document is an excerpt from the EUR-Lex website

Document 52011XX1223(01)

Opinion of the European Data Protection Supervisor on the proposal for a directive of the European Parliament and of the Council on credit agreements relating to residential property

OJ C 377, 23.12.2011, p. 5–7 (BG, ES, CS, DA, DE, ET, EL, EN, FR, IT, LV, LT, HU, MT, NL, PL, PT, RO, SK, SL, FI, SV)



Official Journal of the European Union

C 377/5

Opinion of the European Data Protection Supervisor on the proposal for a directive of the European Parliament and of the Council on credit agreements relating to residential property

2011/C 377/02


Having regard to the Treaty on the Functioning of the European Union, and in particular Article 16 thereof,

Having regard to the Charter of Fundamental Rights of the European Union, and in particular Articles 7 and 8 thereof,

Having regard to Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (1),

Having regard to Regulation (EC) No 45/2001 of the European Parliament and of the Council of 18 December 2000 on the protection of individuals with regard to the processing of personal data by the Community institutions and bodies and on the free movement of such data (2), and in particular its Article 28(2),




On 31 March 2011, the Commission adopted a proposal for a directive of the European Parliament and of the Council on credit agreements relating to residential property (hereinafter ‘the proposal’).

1.1.   Consultation with the EDPS


The proposal was sent by the Commission to the EDPS on 31 March 2011. The EDPS understands this communication as a request to advise Community institutions and bodies, as foreseen in Article 28(2) of Regulation (EC) No 45/2001 of 18 December 2000 on the protection of individuals with regard to the processing of personal data by the Community institutions and bodies and on the free movement of such data (hereinafter ‘Regulation (EC) No 45/2001’). Previously (3), before the adoption of the proposal, the EDPS was given the possibility by the Commission to provide informal comments. The EDPS welcomes the openness of the process, which has helped to improve the text from a data protection point of view at an early stage. Some of those comments have been taken into account in the proposal. The EDPS welcomes the reference to the present consultation in the preamble of the proposal.

1.2.   General background


Responsible lending is defined by the proposal as the care taken by creditors and intermediaries to lend amounts that consumers can afford and meet their needs and circumstances. The concept of responsible borrowing entails that consumers should provide relevant, complete and accurate information on their financial situation and are encouraged to make informed and sustainable decisions.


The proposal lists a range of factors that drive the decision to grant a particular mortgage credit, the borrower’s choice of mortgage product and the borrower’s ability to repay the loan. These include the economic climate, information asymmetries and conflicts of interest, regulatory gaps and inconsistencies, as well as other factors such as a borrowers’ financial literacy and mortgage financing structures. In the proposal's perspective, irresponsible behaviour by certain market actors was at the source of the financial crisis, therefore irresponsible lending and borrowing are the objectives to be addressed by the legislative inititative in order to avoid a repetition of the financial crisis.


The proposal therefore introduces prudential and supervisory requirements for lenders and obligations and rights for borrowers in order to establish a clear legal framework which should guarantee the EU mortgage market from the disruptive effects experienced during the financial crisis.

1.3.   Relationship with EU data protection regime


The proposal involves a limited number of activities, which have relevance under the EU data protection regime. These are mainly related to the consultation by creditors and credit intermediaries of the so-called ‘credit database’ with the purpose of assessing the creditworthiness of consumers and to the release of information by the consumers to the creditors or credit intermediaries.


The EDPS is pleased to note that important references to the relevant data protection rules have been included in the current text of the proposal. However, he would like to point towards the need for a few clarifications. On the one hand, the proposal should not introduce too detailed provisions on the respect of the data protection principles, which is guaranteed by the applicability to any of the processing operations of the national laws implementing Directive 95/46/EC. On the other hand, the EDPS suggests some improvements in the text with the aim of clarifying it and with the purpose of avoiding that criteria determining the access rights to the credit database are mandated to delegated legislation.


2.1.   Reference to Directive 95/46/EC and the obligation to assess a consumer's creditworthiness

Recital 30


The EDPS is pleased to note that the proposal has introduced the reference to directive 95/46/EC in the preamble to the text of the directive. Recital 30 introduces the general application of Directive 95/46/EC to the data processing activities carried out within the context of the assessment of consumers' creditworthiness.


However, in order to reflect the fact that any data processing operation must be carried out in accordance with the implementing rules and that the various national laws implementing such directive are the appropriate references, the proposal could introduce a general article as the following: ‘Any processing of personal data performed pursuant to this directive shall be carried out in conformity with the relevant national laws implementing Directive 95/46/EC’. By introducing such an article, the specific references to the Directive in Articles 15(3) and 16(4) could be removed.

Article 14


Article 14 of the proposal introduces an obligation for creditors to carry out a thorough assessment of the creditworthiness of consumers. This assessment should be based on certain criteria, such as the consumer's income, savings, debts and other financial commitments. This obligation could have a significant impact on the privacy of individuals seeking credit, as the type and amount of information that could be accessed to by the creditor is potentially very large. Therefore, the EDPS welcomes the introduction of specifications in the text as regards the limitation of the creditor's search to the ‘necessary’ information obtained by the creditor. The Article establishes in general terms that this information can only be obtained from ‘internal relevant or external sources’. The EDPS welcomes the explicit reference to the principles of necessity and proportionality enshrined in Article 6 of Directive 95/46/EC, but would however suggest specifying in a more detailed way, to the extent possible, which are the sources from which the information can be obtained.

2.2.   Consultation of the credit database


The credit database is mentioned first in recital 27, where its usefulness is highlighted in the context of the assessment of creditworthiness and during the lifetime of the loan. The recital also specifies that, pursuant to Directive 95/46/EC, consumers should be informed about the consultation of the database, and should have the right to access, rectify, block or erase the data contained in the database. Article 14 introduces specific obligations on the creditor regarding a possible rejection of the credit request, in particular when connected with the consultation of the ‘credit database’.


More general provisions establishing the ‘database access’ criteria are contained in Article 16. Article 16 is formulated in a very broad manner (‘Each Member State shall ensure non-discriminatory access for all creditors to databases used in that Member State for assessing […] creditworthiness […] and for monitoring consumers' compliance with the credit obligations […]’). The text does not specify whether the databases should be specifically designed for such creditworthiness checks, who is responsible for the database, what kind of information might be contained in the database, what the ‘monitoring’ of consumer compliance entails, etc. The EDPS understands that credit databases have different structures and are established in different legal frameworks across the various Member States and that a full harmonisation of the abovementioned criteria would go beyond the scope of the directive. The aim of the proposal would be however to introduce harmonised conditions of access to the database so that, for example, a creditor in Belgium could access the credit history of a consumer in Italy (even though the Belgian and the Italian databases might be different) at the same conditions as Italian creditors, if the consumer is asking for a mortgage in Belgium. The details of the criteria for harmonised access shall be further specified in delegated acts of the Commission (see Article 16(2)). The EDPS also notes the reference to Directive 95/46/EC in Article 16(4) (4).


The EDPS has already expressed the view that measures which have a substantive impact on the privacy of citizens should not be dealt with in delegated legislation. Certainly details can be elaborated in such legislation. The main implications for the citizens should however be clear and agreed upon in the legislation adopted on the basis of the ordinary legislative procedure. From a data protection perspective, the EDPS is particularly concerned about the apparent contradiction between the generalised possibility of consultation by (a not yet identifiable number of) credit operators to the database under Article 16 and the ‘light’ obligation inserted only in recital 27, namely that ‘consumers […] should be informed about the consultation of the database’ and ‘should have access to the information […] rectify, erase or block the personal data concerning them […]’. In the EDPS' view, the concrete possibility to exercise the data subject's rights pursuant to Directive 95/46/EC is connected to the possibility to identify the possible recipients of the personal data contained in the credit database. The effectiveness of the reference to the rights contained in Directive 95/46/EC could be therefore neutralised by the impossibility for the data subject to clearly and pre-emptively identify the natural or legal persons who can have access to the database.


The EDPS therefore suggests some modifications to the text of the directive with the purpose of addressing the shortcomings identified above. Any (5) access to the database should be subject to the following conditions, which should be introduced in the text of Article 16: (i) definition of the criteria on the basis of which creditors or credit intermediaries can have access to the database and, in particular, clarification of whether only creditors or credit intermediaries who concluded a contract with a consumer or are required by the consumer to take steps to conclude a contractual relationship with him (6) can have access to his or her data; (ii) obligation to communicate in advance to the consumer that a certain creditor or credit intermediary has the intention to access his or her personal data in the database; (iii) obligation to contemporaneously communicate to the consumer of his or her rights to access, rectify, block or erase the data contained in the database pursuant to the principles of Directive 95/46/EC.


As a result of the introduction in the text of such general criteria and obligations, the specific provision of Article 14(2)(c) and recital 29 related to the obligation to communicate to the consumer the access to the database in case of rejection of the credit request could be removed from the text.



The EDPS welcomes the specific reference in the proposal to Directive 95/46/EC. However, he suggests some minor modifications in the text in order to clarify the applicability of the data protection principles to the processing operations covered by the proposal. In particular:

in order to better reflect the fact that the national laws implementing Directive 95/46/EC are the appropriate references and to emphasise that any data processing operation must be carried, out in accordance with those implementing laws, the EDPS suggests introducing a new article with specific wording to that effect. This would also allow the removal of other references to Directive 95/46/EC in the text of the proposal,

the text of the proposal could specify in a more detailed way the sources from which information on the creditor's creditworthiness can be obtained,

the text of the proposal should include the definition of criteria for the possibility to consult the database and the obligations to communicate the data subjects' rights before any access to the database, thereby ensuring concrete and effective possibilities for data subjects to exercise their rights.

Done at Brussels, 25 July 2011.


Assistant European Data Protection Supervisor

(1)  OJ L 281, 23.11.1995, p. 31 (hereinafter ‘Directive 95/46/EC’).

(2)  OJ L 8, 12.1.2001, p. 1.

(3)  In December 2010.

(4)  The Article is ‘without prejudice to the application of Directive 95/46/EC […]’. See however paragraph 9 in which a modification of this Article is suggested.

(5)  This term should be intended as meaning access by any authorised creditor at any point in time.

(6)  See Article 7(b) of Directive 95/46/EC.