• via Alberto da Giussano, 26, 20145 Milano
  • +39 02 8295 4969
  • info@studiolegalebianucci.it
Avv. Marco Bianucci
Avv. Marco Bianucci

Damages & Compensation Lawyer

An incorrect report in credit data can immediately affect a loan application, the maintenance of a bank credit facility, or the relationship with suppliers and guarantors. The first doubt is often very concrete: does the report truly concern an existing debt, or does it report a wrong amount, delay, or classification? A second doubt concerns remedies: is it enough to request deletion, is it necessary to ask for a correction, or is it also possible to obtain compensation for damages?

I help you distinguish the Central Credit Register managed by the Bank of Italy from private credit information systems, often simply called "CRIF". We will see why a report alone does not equate to a credit denial, which data must be checked, and when the request should concern correction rather than total deletion.

Central Credit Register and private systems are not the same thing

The Central Credit Register is a public information system entrusted to the Bank of Italy, in which participating intermediaries communicate information on the debt position and guarantees of customers. Its function is to offer intermediaries an overview of credit relationships and related risk; it is not a list of persons to whom credit must be denied. The establishing source clarifies that this is a system relating to individual debt position: CICR decree on the Central Credit Register.

A private credit information system has different organizational rules. CRIF is a known name, but it does not coincide with the Bank of Italy's Central Credit Register. The same event can therefore appear in different archives, managed by different entities and fed according to non-identical assumptions. Before requesting deletion, it is necessary to identify precisely who is processing the data, which relationship is indicated, and which category of information is registered.

The presence of the data does not automatically decide creditworthiness. An intermediary can use the available information when evaluating a credit application or monitoring an already open relationship, but retains its own overall assessment. The discipline published with the twenty-first update of Circular No. 139 explicitly recalls the informative function of the Central Register and the obligations of participating intermediaries: Circular No. 139/1991, 21st update. For this reason, correcting the report and deciding on a credit facility are related issues, but they remain distinct.

When a report can be challenged

The decisive point is the accuracy of the data on the date of the report. There may be an error in the subject's identity, the amount, the relationship number, the indicated guarantee, or the very fact that justifies a certain classification. Even the omitted registration of a payment, an agreement modifying the maturity, or the closure of a relationship can make the representation incomplete.

A contested debt is not automatically false data. If you claim you do not owe a sum because the contract is void, because there are undue charges, or because the calculation is disputed, it is necessary to distinguish the dispute over the credit from the correctness of the communicated information. The report may be inaccurate if it ignores a documented and relevant fact; it does not become so simply because the debtor does not share the bank's or financial company's claim.

Deletion is not always the correct remedy. If the relationship actually existed but the amount is wrong, the coherent solution is correction. If the data concerns a different person, a non-existent relationship, or information processed without an adequate basis, deletion may instead be the main request. Indiscriminately asking to "disappear from the Central Credit Register" risks failing to identify the real problem and obtaining a generic response.

Credit classification requires concrete control

The labels used to describe risk are not interchangeable. A payment delay, an overdue exposure, a difficulty in repayment situation, and a position classified as non-performing express different situations. It is not enough to look at the category name; what matters are the contractual relationship, payments made, any agreements, communications received, and the situation known to the intermediary in the considered period.

The documentation must speak of the right date. A receipt issued after the report can prove that the debt was subsequently paid, but it does not prove by itself that the previous data was incorrect. On the contrary, a payment already made, a agreed suspension, or a relationship closure prior to detection can directly affect the correctness of the communicated information.

Access, correction, and deletion of personal data

Before challenging, it is useful to obtain a verifiable picture of the processed data. Article 15 of the GDPR recognizes the right of access: you can request confirmation of processing, a copy of personal data, and relevant information on purposes, categories of data, and recipients. This step serves to avoid disputes built on verbal communication or an imprecise formula received at the counter.

Inaccurate data must be corrected without undue delay. Article 16 of the GDPR concerns the correction of incorrect personal data and the integration of incomplete ones. Article 17 instead governs deletion, but only when its prerequisites are met: not every unwanted or unfavorable data must be eliminated. The text of the European regulation can be consulted here: Regulation (EU) 2016/679, Articles 15, 16, and 17.

The request must indicate the contested data and the requested correction. It is more effective to specify the concerned relationship, the period, the amount or classification you consider incorrect, the reason for the error, and the documents proving it. For example, if the payment has already been made, it is relevant to attach proof of payment and explain which installment or balance it refers to; if the error concerns identity, data excluding the connection with that relationship are needed.

The controller must generally respond within one month. Article 12 of the GDPR requires informing the data subject on the action taken without undue delay and, normally, within one month of receiving the request. In complex cases, the term may be extended, but the extension and reasons for the delay must be communicated within the first month. This term concerns the reply to the privacy request; it does not automatically turn the banking affair into a judicial urgency. Article 12 of the GDPR.

The revocation of a credit facility and the refusal of a loan

The revocation of a credit facility does not prove by itself the illegitimacy of the report. The bank can make credit decisions based on the contract, the trend of the relationship, guarantees, and its own risk assessment. If an inaccurate report has contributed to the decision, it is however necessary to distinguish what depends on the erroneous data from what would have happened anyway for autonomous reasons.

Data correction does not automatically oblige the granting of credit. If the intermediary eliminates or corrects a registration, the loan or credit facility renewal application can be re-examined, but it remains a credit decision. It is important not to confuse the immediate objective, namely having correct data, with a further result that also depends on income, assets, guarantees, account usage, and contractual conditions.

The temporal connection can be important evidence, but it is not enough on its own. A revocation arrived shortly after a report, a refusal motivated by specific data, or a communication recalling the archive can help reconstruct the link between error and prejudice. If instead the decision is based on multiple independent elements, it becomes essential to understand what concrete weight the contested report had.

When there may be compensation for damages

Compensation is not an automatic consequence of the error. Article 82 of the GDPR recognizes the right to compensation for material or non-material damage suffered due to a violation of the regulation. It is therefore necessary to distinguish three aspects: the violation, the damage actually suffered, and the link between that violation and the claimed prejudice. The text does not allow presuming an amount solely from the presence of a dispute.

Pecuniary loss requires demonstrable economic consequences. Depending on the facts, additional costs of a loan obtained under worse conditions, loss of a concrete business opportunity, or expenses incurred to remedy effects directly linked to inaccurate data may assume relevance. Instead, it is not enough to state in an abstract way that a report "damaged credit": facts, documents, and a reasonable link between the data and the economic consequence are needed.

Non-pecuniary loss must also be alleged in a concrete way. An injury to credit reputation or serious distress can be put forward, but the claim must explain what personal consequence occurred and why it derives from the unlawful processing. Article 82 of the GDPR and administrative and judicial remedies are governed in the European regulation; for disputes regarding the processing of personal data, including compensation provided by GDPR, Article 152 of the Privacy Code assigns jurisdiction to the ordinary judicial authority: Article 152 of the Personal Data Protection Code.

What steps to consider and what errors to avoid

The first choice is to contact the entity that processes or has communicated the data. A written request for access and correction addressed to the intermediary or the system manager allows clearly establishing the dispute and keeping proof of the request. If the problem concerns different archives, requests must reach the respective controllers: correcting data in one system does not guarantee modification in the others.

A privacy complaint is a different option from a lawsuit. Article 77 of the GDPR allows lodging a complaint with the supervisory authority when it is believed that the processing violates the regulation; Articles 78 and 79 provide for judicial remedies. The choice depends on the objective: obtaining control over the processing does not necessarily coincide with asking the judge for the urgent correction of a situation or compensation for damages already accrued.

It is not advisable to wait only for the informal response. Phone calls, verbal reassurances, and update promises can be useful, but they do not show precisely which data will be corrected, in which archive, and with what effective date. Instead, keep the credit report or communication revealing the report, contracts, bank statements, receipts, agreements, and any response from the intermediary. With my staff, I can help you sort these elements around the concrete question: correction, deletion, re-examination of a decision, or compensation.

Frequently asked questions

Can I request the deletion of every negative report?

No, deletion requires specific prerequisites. If the data is correct and necessary regarding the purpose of the processing, the sole unfavorable consequence is not enough to obtain its elimination. When the amount, date, or classification are wrong, the most suitable request is often correction. Article 17 of the GDPR does not replace the verification of data accuracy.

How long does the intermediary have to respond to my request?

As a rule, the reply must arrive within one month. The GDPR establishes this term for requests relating to data subject rights, including access, correction, and deletion. In complex cases, the controller can extend the term, but must communicate it with the reasons for the extension within the first month. Keeping proof of sending is therefore important.

Does the report in the Central Credit Register always prevent obtaining a loan?

No, it does not produce an automatic credit prohibition. The Central Credit Register is an informative tool and the intermediary makes its own assessment, also considering other elements. A correct report can negatively affect the decision; an incorrect report instead deserves a punctual dispute, but its correction does not oblige the bank to grant the financing.

Can I claim damages if my credit facility was revoked?

You can claim compensation if you prove violation, damage, and causal link. Revocation is not enough, by itself, to prove that inaccurate data caused it. It is necessary to verify the contract, the motivations communicated by the bank, the trend of the relationship, and actual economic consequences. The GDPR contemplates material and non-material damages, but does not provide for automatic compensation.

Should I contest the report to the Bank of Italy or the bank that entered it?

The dispute of data normally starts from the entity that processes or has communicated it. For the Central Credit Register, it is essential to identify the reporting intermediary and ask for clarifications or correction with precise documents. If a problem also emerges in a private information system, the relative controller must be contacted: the archives are distinct and an update does not transfer automatically from one to the other.

Institutional references

To distinguish function and discipline of the Central Credit Register, you can consult the 2012 decree on the Central Credit Register and the complete reprint of Circular No. 139/1991, 21st update.

For access, correction, deletion, complaint, appeal, and compensation, the reference is Regulation (EU) 2016/679. If you need to understand whether the report correctly describes your position and which remedies are coherent with available documents, you can contact me.