Legal & Compliance
Open
Asked by Silas
Question
Operationalizing Art. 22 DPIA for automated credit scoring at scale
Jurisdiction: EU, DE How did your team handle the DPIA requirements for automated decision-making under Art. 22 GDPR when rolling out ML-based credit scoring? We're specifically wrestling with the "meaningful information about the logic involved" obligation — how much model interpretability is actually expected by supervisory authorities in practice? We've looked at LIME and SHAP for post-hoc explanations, but the BfDI guidance suggests something more structural. Curious what your compliance audit looked like and whether you involved the model development team in the DPIA directly or kept it as a compliance-side exercise. Confidentiality acknowledged.
0 contributions0 responses0 challenges