Credit Scoring In Cyprus: What The Score Is, And What It Is Not

15th September 2026
General

Following the 2026 legislative reforms, credit scoring is now operational in Cyprus. It has attracted a good deal of comment and a certain amount of misunderstanding, much of it concerning what the score actually determines, whose data sits behind it, and what a borrower can do about the data held. This note sets out the statutory position.

 

The legal basis

The framework is contained in the Business of Credit Institutions Laws of 1997 to 2026, as most recently amended by Law 84(I)/2026, which was published in the Official Gazette on 21 April 2026. The amending law replaces Articles 28D, 28E and 28F of the principal law and substantially revises the definitions in Article 2. Its stated purpose is further harmonisation with Article 21 of the Mortgage Credit Directive (Directive 2014/17/EU) and Article 8(1) and Article 9(1) of the Consumer Credit Directive (Directive 2008/48/EC), which concern creditworthiness assessment and access to credit databases.

The framework sits on top of an existing structure. The ARTEMIS data exchange mechanism has held credit behaviour data on Cyprus borrowers for years, and participating institutions have long been able to obtain a credit report on a prospective borrower. What the 2026 amendment does is restate the legal basis for the mechanism in full, widen the circle of those who supply and receive data, define whose data is held, and place credit scoring expressly within the mechanism’s statutory purpose.

What the mechanism is for

Article 28D(2) provides that the mechanism exists for the assessment of the creditworthiness of customers, expressly including the wholly or partly automated, as well as non-automated, scoring of customers’ credit standing, for the more effective management of credit facilities and of credit and related risks, with the objective of safeguarding financial stability in the Republic.

The law itself does not prescribe a scoring methodology, a scale, or the content of a scoring report. Article 28D(12) leaves all of these to directives issued by the Central Bank of Cyprus, which may regulate the creation of the scoring system, the process by which scores are produced, the form and content of the scoring report, the classification of customers on a rating scale, and measures for the protection of customers’ legitimate interests in the scoring process. Before issuing any such directive the Central Bank must consult the Commissioner for Personal Data Protection on matters concerning the processing of personal data.

Who supplies data and who receives it

The amending law introduces two defined classes. Data submitters supply customer data to the mechanism. Data recipients are entitled to receive, access, use and process it, in accordance with the law and the Central Bank’s directives.

Both classes are drawn considerably wider than the banking sector. Data recipients include licensed credit institutions, Cyprus branches of credit institutions from other member states, credit servicers and credit facility managers, leasing companies and providers of leasing services, creditors under the mortgage credit and consumer credit legislation including creditors from other member states, and servicers of securitised exposures. Data submitters comprise a corresponding list, and additionally include credit purchasers and non-credit institutions under the mortgage credit legislation.

Separately, Article 28D(10) requires three public bodies to submit to the mechanism such data as the Central Bank specifies by directive: the Registrar of Companies, the Insolvency Department, and the Registrar General and Registrars under the Civil Registry Law. Public registry data may therefore form part of the information held and processed by the mechanism, to the extent specified in directives issued by the Central Bank.

Whose data is held

This is the part of the law most likely to surprise those who assume the mechanism concerns only people who have borrowed money. The definition of customer in Article 2 extends to four categories.

The first is the prospective customer: any natural or legal person, resident or not, who has applied for or otherwise requested a facility, or who intends to provide a guarantee or security in connection with an existing or proposed facility. The second is any person who has entered into a facility agreement, expressly including judgment debtors. The third is any guarantor or provider of security for such a person, again including judgment debtors in that capacity. The fourth is any connected person of any of the foregoing, with connected persons defined by reference to the concept of a group of connected clients under the Capital Requirements Regulation and, in the case of a legal person, expressly including its beneficial owners.

The term facility is equally broad. It covers loans, overdrafts, credit card limits, factoring and stock finance agreements, leasing agreements and any other financing facility. It includes facilities that have been sold to a credit purchaser, facilities that have been terminated or are the subject of pending legal proceedings, and facilities that have been restructured, amended, replaced or assigned.

The practical consequence is that a director who has personally guaranteed a company’s facility, a shareholder who has provided security, and a beneficial owner of a borrowing company are each within the statutory definition of customer, and their data may be held and processed in the mechanism accordingly.

What the score is not

The score does not decide whether credit is granted. The law regulates the mechanism, the data it holds and who may access that data. It does not transfer the lending decision to the mechanism. The assessment of a borrower’s creditworthiness remains with the creditor: as a statutory obligation in consumer and mortgage credit, and as a matter of credit policy and prudential requirements in other lending. The directives the law harmonises with are precisely those which place that obligation on the creditor and give it access to the database as one input into the assessment.

A score is therefore neither an approval nor a refusal. A borrower who is declined has not been declined by the mechanism, and a borrower who is approved has not been approved by it. The institution remains the decision maker.

Accuracy and correction

A score is only as sound as the data underlying it. Article 28D(7) provides that where a data submitter has submitted erroneous or incomplete data, it must, on written notification from the mechanism, correct and resubmit the data immediately, or as soon as it has received sufficient evidence from its customer. Where the submitter fails to comply, the Central Bank has power to require the correction. The law expressly preserves the separate right of rectification under the General Data Protection Regulation and the Cyprus data protection law.

For individuals, the GDPR right of access to the data held about them applies to data in the mechanism as it does to any other personal data, and the law makes repeated reference to the GDPR and to the principle of data minimisation. Legal persons fall outside the GDPR, and their access to data held about them is a matter for the operator’s procedures and any applicable directives. The personal data of individuals connected with a borrowing company, including guarantors and beneficial owners, remains subject to the GDPR in the ordinary way.

Confidentiality and use of the data

Article 28D(20) provides that information obtained from the mechanism, from data recipients or from data submitters is confidential and may be used only for the purposes for which it was obtained. Article 28D(19) provides that the provision or exchange of data under the law does not constitute a breach of any duty of confidentiality or professional secrecy, and Article 28D(15) applies the banking secrecy provisions of Article 29 to every person who obtains data from the mechanism.

The law provides for transfer of data from the mechanism to other credit databases only where those databases operate exclusively within the European Economic Area, only in compliance with the GDPR, and only after a reasoned report to the Central Bank including the results of consultation with the affected data recipients and submitters.

Supervision and sanctions

The Central Bank supervises the mechanism, the data recipients and the data submitters, with powers of entry, inspection and access to systems and records. Under the amended Article 42(3), the Governor may impose an administrative fine of between EUR 1,000 and EUR 80,000 for each breach of the law or of a directive, and where a breach continues, a further fine of between EUR 100 and EUR 8,000 for each day it continues. These sanctions apply to the operator of the mechanism, to data recipients and to data submitters alike.

Practical implications

For companies with existing facilities, or contemplating new or revised ones, the information recorded in the mechanism has acquired greater practical significance following the introduction of statutory credit scoring. It is no longer confined to information appearing in a traditional credit report; it may also contribute to a score produced within a statutory framework and made available to authorised data recipients participating in the mechanism. There is a practical case for establishing what information is held before seeking new or revised credit facilities.

The same applies to directors, shareholders and beneficial owners who have given personal guarantees or provided security, since the statutory definition of customer places them within the mechanism in their own right.

Where a facility has been sold to a credit purchaser, restructured, or is the subject of proceedings, it continues, subject to the terms of the legislation and any applicable directives, to fall within the broad statutory definition of a facility and may therefore continue to form part of the information held within the mechanism.

The legislative framework establishes the legal basis for the collection, exchange and use of data. The practical operation of the scoring system, including how a score is produced and what it contains, is governed by the directives and technical requirements issued by the Central Bank of Cyprus from time to time.

Finally, the substance of the scoring regime, including the scale, the methodology and the content of the scoring report, sits in Central Bank directives rather than in the law itself. Any assessment of a particular score, of the process by which it was produced, or of the rights available to a customer in relation to that process, should be made by reference to those directives as in force at the relevant time.

Law 84(I)/2026 has restated the legal framework for the ARTEMIS data exchange mechanism and put credit scoring on a statutory footing in Cyprus. Who supplies data, who receives it, whose data is held, and what the score does not decide.

More News

Vertical Restraints In Cyprus And The Eu: Decisions And Updates.

26 FEB, 2021

Vertical restraints in Cyprus and the EU: Decis...

Read More
Covid-19 And Justice

12 OCT, 2020

How the pandemic is ushering in a new era for j...

Read More
Go to all News