GDPR breach: 300.000€ fine against bank after lack of transparency over automated rejection of credit card application

A Berlin based bank offered a credit card on their website. Using an online form, the bank requested various data about the applicant's income, occupation and personal details. Based on the information requested and additional data from external sources, the bank's algorithm rejected the customer's application without any particular justification. The algorithm is based on criteria and rules previously defined by the bank. Since the client had a good credit rating and a regular high income, he doubted the automated rejection and complained to the Berlin data protection commissioner. Even when asked by the complainant, the bank only provided blanket information about the scoring procedure, detached from the individual case. However, it refused to tell him why it assumed a poor creditworthiness in his case. The complainant was thus unable to understand which data basis and factors formed the basis of the automated rejection and on the basis of which criteria his credit car...