The classic trap
Recital 31 illuminates Article 5(1)(c), which bans social scoring. The trap is not the obvious 'Chinese social credit' system, but the internal composite scorings that aggregate heterogeneous behavioural data (attendance, social media, purchases, geolocation, health) to produce a generic 'reliability' score used in contexts disconnected from the original collection. An insurer that prices premiums on a 'lifestyle' score built from bank data and wearables, an employer that ranks staff on an 'engagement' score combining productivity and LinkedIn activity: these are direct candidates for prohibition. The CNPD and the future Luxembourg AI authority will cross-read their respective frameworks, since GDPR Article 22 (automated decision-making) and the AI Act stack.
The 4-criteria test to qualify prohibited social scoring
To separate lawful evaluation (bank credit scoring, fraud scoring, targeted HR assessment) from prohibited social scoring, recital 31 implicitly provides 4 cumulative criteria:
- Multiple contexts: does the score aggregate data from different spheres (private life + work life + online behaviour)?
- Decontextualisation: is the score used in a context unrelated to the original collection purpose?
- Disproportionate detrimental effect: is the consequence (service denial, surcharge, exclusion) proportionate to the gravity of the assessed behaviour?
- Generalist nature: does the score assess the person globally ('trustworthiness', 'civic-mindedness', 'social risk') rather than a specific bounded risk (default on a precise credit)?
If the 4 criteria are met, the system falls under the Article 5 prohibition and exposes the operator to fines of up to EUR 35 million or 7% of worldwide turnover. Lawful evaluations (Basel III credit scoring, AML/KYC scoring, documented HR performance assessment) remain authorised provided they are specific, purposeful and proportionate.
How Luxgap automates this risk
Our Luxgap Social Scoring Detector continuously scans your AI models, data pipelines and business algorithms to automatically detect any score construction that combines heterogeneous sources and could tip into the 'prohibited social scoring' category. The tool connects to your Databricks, Azure ML, AWS SageMaker, Dataiku environments and your CRMs (Salesforce, HubSpot, Odoo) to map every feature used, its provenance and its original collection context, then automatically applies the 4-criteria test from recital 31.
- Detects any scoring model that aggregates features from more than two distinct contexts (financial + behavioural + health + social) and raises an Article 5 risk alert.
- Traces for each feature its initial collection purpose declared in your GDPR register and flags purpose mismatches between collection and scoring use.
- Automatically applies the 4-criteria test (plurality, decontextualisation, disproportion, generalisation) and produces a reasoned verdict: authorised, to document, to redesign, prohibited.
- Generates a reasoned defence file for legitimate scorings (credit, AML, targeted HR) with legal basis, specific purpose and proportionality documented, opposable to the CNPD and the future Luxembourg AI authority.
- Alerts in real time via Teams or Slack whenever a data scientist deploys a new model combining risky features, before production rollout.
- Produces a timestamped, cryptographically sealed PDF report, opposable during an inspection by the EU AI Office or the CNPD.
Available as part of a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your AI perimeter. Request a tailored quote and our teams will prepare a demonstration on your real models, with a free 48-hour blind audit to map your at-risk scorings before any engagement.