Every defective entry in a credit information system (CIS) — ASNEF, Badexcug and similar — is a potential claim. The Provincial Courts of Appeal (Audiencias Provinciales) have been making awards in indicative ranges of 3,000 to 10,000 euros plus costs per entry, with an indicative average award of 4,500 euros. If you register debtors every month under a defective standard contract, the mistake is not made once: it is multiplied across your whole portfolio.
The Flash Audit answers a single question: what would happen to you today if a serial claims firm went through your files? And it answers it before someone else does.
Who it is for
- CEOs, CFOs and heads of risk or debt recovery at financial institutions and credit establishments.
- Servicers and debt portfolio managers that register entries in a CIS on their own account or for third parties.
- Telecoms and utilities with a recurring volume of consumer defaults.
- Companies that finance instalment sales and report unpaid debts as a matter of routine.
If your company registers debtors in credit default registers on a regular basis, this service is for you. If you only do so occasionally, start with the Exposure Test: in a few minutes you will know whether you need the audit.
What it includes, exactly
- Review of your standard contracts: checking the information clause against Article 13 GDPR, and in particular whether it specifically identifies the CIS to which the data will be reported or whether it uses the generic wording the courts reject.
- Review of your CIS reporting protocol: when you register, what prior checks you make that the debt is certain, due and payable, and whether a prior payment demand is sent when it is required.
- Review of a sample of files: a representative selection of real files, to check whether what the protocol says is what can be proved with the documents in hand.
What problem it solves
The audit measures your practice against the three criteria you will be judged by. These are not opinions: they are the rules the Provincial Courts of Appeal apply today in claims for improper registration.
1. If your contract does not identify the specific register, the prior demand is compulsory
Generic clauses ("credit default registers", "solvency registers") do not meet Article 13 GDPR. Without specific identification of the CIS in the contract, registering without a prior payment demand is an improper registration. It is the most repeated defect and the most expensive one, because it affects every contract signed on the same template.
This allows the interpretation that a prior demand will only be necessary where the contract has not informed the data subject of the specific CIS in which the creditor participates, or of the other requirements laid down by Article 13 of Regulation (EU) 2016/679. [translation]
For the creditor to be able to enter a defaulting debtor in the CIS without first sending a payment demand informing them of the possibility of that entry, it is necessary that this was stated in the contract from which the debt arises, with specific identification of the CIS to which the information is to be reported, in compliance with the requirements of Regulation (EU) 2016/679. [translation]
2. You may only report debts that are certain, due, payable and beyond doubt
The data accuracy principle (Article 5 GDPR) excludes debts that are uncertain, in dispute or contested. Registering a debt the customer has challenged or disputed in writing is not debt recovery: it is a breach that may also infringe the right to honour. The audit reviews which filters your team applies before registering and whether they leave a documentary trail. That is the position taken, among others, in SAP Orense 629/2021, of 29 December, and SAP Orense 385/2023, of 13 June.
3. Complying is not enough: you have to be able to prove it
The accountability duty in Article 5(2) GDPR reverses your position in the proceedings: the burden of establishing lawfulness, accuracy and diligence falls on your company. A correct protocol that generates no filed evidence is worth, before a judge, exactly as much as having no protocol at all. That is why the audit does not stop at the documents: it goes down to real files.
And, under Article 5(2) GDPR, "the controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 ('accountability')". [translation]
The same decision recalls that Article 5(1)(d) GDPR requires inaccurate data to be erased or rectified without delay. A file that remains registered after payment, or after a well-founded complaint, is exposure that grows every day.
Deliverables
- Exposure report: what defects your practice has, in which documents and files they materialise and what potential cost they represent, expressed in the indicative range the courts apply (€3,000–10,000 plus costs per defective entry).
- Prioritised remediation plan: what to fix first, by financial impact and ease of execution — what requires changing the standard contract, what is solved by the prior demand process and what is pure documentary discipline.
Both documents are written for management, not for lawyers: every finding is translated into euros and into a decision.
Timescale
10 working days from receipt of the documentation (standard contracts, protocol and sample files). No site visits and no interruption to your operation: we work from document copies.
Request your Flash Audit
Tell us your sector and your approximate volume of entries and we will send you a fixed proposal on scope and fees.
Request a Flash Audit proposalStill not sure whether you need it? Take the Exposure Test first · See the 5 mistakes that are leading to adverse judgments