// analysis
AI is asking you to pay: what you can check

Accessing a calculated profile, understanding a decision and checking a debt: useful rights, their limits and the separate remedies in France and the EU.
AI is asking you to pay · Part 6
Read also: Part 1: decisions · Part 2: performance claims · Part 3: asking for help · Part 4: correcting the record · Part 5: contracts and accountability.
An assessment of your willingness to pay can be personal data even though you never supplied it. The Court of Justice of the European Union expressly made that point in its CRIF judgment of 4 May 2023. A request for access can therefore reach information a company has calculated about you, not just your name, address or the details you gave it. [1]
That distinction matters in automated debt collection. On its French product page, PAIR Finance says that how easily someone can be reached and how quickly they respond inform its assessment of willingness to pay. The company also describes changes to the channel, frequency and tone of communications. This description is the supplier’s own account. [2]
The two documents approach the same issue from different directions. The supplier describes how it interprets behaviour. The court explains why some interpretations generated about a person remain data that person can access. Making use of that right requires knowing what to ask for and keeping the request separate from a dispute over the debt itself.
This final instalment examines how to check a collection demand in France under the European data-protection framework. The judgments clarify these rights through disputes in other sectors; they contain no findings against the collection platforms studied here. The procedural rules below concern France.
Start with the debt
Before examining the software, it must be possible to reconstruct the amount claimed. Who says they are the creditor? Who is acting on their behalf? Which contract, service or transaction supports the claim? Which payments have already been recorded? Article 1353 of the French Civil Code places the burden of proving an obligation on the party seeking to enforce it. A person claiming to have paid must, in turn, establish payment or another ground of discharge. The account therefore needs to connect the amount claimed with the supporting records. [4]
French law also sets requirements for the collection letter. For third-party out-of-court collection within the scope of Article R124-1 of the Civil Enforcement Procedures Code, the letter must identify the collector and the creditor, explain the basis of the demand, and separate principal, interest and other amounts. Subsequent collection approaches must refer to the letter and its sending date. Professions governed by specific statutes require separate consideration: these requirements cannot simply be applied to every person seeking payment. [5] [6]
The breakdown matters when the amount increases between messages. A charge does not become payable just because it appears on a screen. Under Article L111-8, collection costs incurred without an enforceable instrument, or titre exécutoire, generally fall on the creditor. The provision includes an exception for acts the law requires the creditor to perform and allows the creditor to ask a court to allocate certain necessary costs to a debtor acting in bad faith. Specific statutory provisions must also be considered. [7]
An out-of-court demand is different from compulsory enforcement. The wording of a reminder does not give it the powers associated with an enforceable instrument. Conversely, a genuine procedural document should not be treated as an ordinary commercial notification. France’s consumer-protection authority, the DGCCRF, explains this distinction in its collection guidance. [20]
Reconciling documents and amounts also helps locate an error: an upstream failure to record a payment can affect every subsequent stage of the software’s operation.
The profile the company created
A collection company may hold information received from a creditor, exchanges with the person concerned and assessments derived from them. In CRIF, the Court adopted a definition of personal data that includes derived information about an identified or identifiable person, specifically mentioning assessments of creditworthiness or willingness to pay. A result does not fall outside the right of access merely because the company generated it. [1]
A request can cover the personal data actually being processed, including scores and assessments where they exist. Article 15 of the General Data Protection Regulation (GDPR) also covers information on purposes, the source of data not obtained from the individual, recipients and retention. [3]
The response must make the data understandable. A list of categories cannot replace the data themselves. The Court recognises that extracts or even complete documents may be essential to an intelligible copy. It does not grant unrestricted access to every company document: the right concerns personal data, with the necessary context and due regard to other people’s rights. [1] [10]
For a collection file, this calls for a distinction between facts and assessments. A receipt date records an event. A classification intended to represent willingness to pay is an interpretation. Its accuracy and its role in subsequent handling each require examination.
A focused request could cover assessments applied to the case, what they mean and when they were made where that information is retained, then ask how they were used. This approach, proposed by l0g, starts with the information actually available.
An explanation that addresses the individual case
On 27 February 2025, in Dun & Bradstreet Austria, the Court clarified the explanation required under Article 15(1)(h) of the GDPR. The case concerned an automated creditworthiness assessment used to refuse a mobile-phone contract. The actual procedure and principles must be explained in a way that lets the person understand which data were used and how. Providing a mathematical formula on its own is insufficient. [9]
A product description and an individual explanation therefore provide different kinds of information. Saying that a service uses behavioural data describes its design. Explaining which information influenced a decision about a particular case allows its relevance to be challenged. The Court notes that explaining how a change in the data could have changed the result may be appropriate. [9]
The scope matters. Article 22 concerns decisions based solely on automated processing that have legal or similarly significant effects. Profiling does not necessarily lead to such a decision. Conversely, a decision can fall within Article 22 without using a generative model. Exceptions exist, including contractual necessity, statutory authorisation with safeguards, and explicit consent. [3] [11]
Where a decision relies on contractual necessity or explicit consent, Article 22 provides at least for human intervention, an opportunity to express a view and the ability to contest the decision. Under the statutory-authorisation exception, the authorising law must provide suitable safeguards. [3]
The right to access personal data remains applicable even where Article 22’s particular conditions are not met. The right to human intervention under that article depends on the nature of the decision and the basis on which it is made. [3] [11]
Where trade secrets are invoked, the 2025 judgment requires allegedly protected information to be provided to the competent authority or court. It must balance the competing interests to determine the extent of access. [9]
What access records can reveal
Records of computer operations may contain relevant information too. In Pankki S, decided on 22 June 2023, the Court recognised a right to obtain the dates and purposes of consultations of personal data. The case concerned data consultations within a bank. [8]
There is generally no right to the names of employees who consulted the data under the controller’s authority and instructions. The Court leaves room for that information where it is essential to exercising the person’s rights, while taking employees’ rights into account. [8]
These records locate an operation in time. To examine how a complaint was handled, we propose matching the consultation date, its purpose and the resulting response. The content of that response can then be checked to see whether the relevant document was taken into account.
Knowing that the interlocutor is AI
Since 2 August 2026, Article 50 of the EU AI Act has required providers of covered systems to design and develop them so that people are informed when they interact directly with AI. The information must be clear and provided no later than the first interaction, subject notably to the exception where the artificial nature is obvious in context. The rule concerns direct interaction; automated background analysis requires a separate assessment. [12] [13]
Disclosure identifies the interlocutor. It does not necessarily explain which data are used, what the software is allowed to do or where the amount claimed came from. Data-protection duties and collection rules still need to be examined separately. [3] [5] [12]
The timetable distinguishes this transparency duty from obligations for high-risk systems. The European Commission states that high-risk requirements for Annex III systems will apply from 2 December 2027, following the revised timetable under the Digital Omnibus, which entered into force on 27 July 2026. Its FAQ retains 2 August 2026 for disclosure of an AI interaction. It gives certain pre-existing systems a specific additional period for marking generated content. [13] [14]
High-risk classification depends on the system’s intended use. Annex III covers, among other uses, evaluating individuals’ creditworthiness or establishing their credit scores, with an exception for financial-fraud detection. Use in the collection industry alone therefore does not settle that classification. [22]
Examining the response
On 30 January 2025, the digital-innovation laboratory of France’s data-protection authority, the CNIL, published an assessment of data-access journeys on ten social networks observed in 2024. It expressly stated that the study did not assess the completeness or quality of the data returned. This was not research into debt collection. It nevertheless offers a useful methodological distinction: assessing how easily someone obtains an export is different from examining what the export allows them to verify. [15]
A separate CNIL report, published on 20 January 2025, concerned actual inspections. Across eleven public and private organisations examined in 2024, the authority found examples of responses that supplied a privacy explanation without a copy of the data, or a copy without an explanation of the processing. The organisations had been selected partly because of complaints. These findings are neither a national non-compliance rate nor an investigation of AI collection. They do show why receiving a response is not the same as receiving a complete one. [23]
For collection cases, we propose comparing the response with material the person already holds. Does it include a dated exchange? Has a payment for which there is a receipt been properly recorded? Are the assessments understandable? Does the response explain which information was not found, is no longer retained or is being withheld, and why?
An omission calls for clarification: data may fall under another controller’s responsibility or no longer be retained. The CNIL states that the controller must organise its response, obtaining assistance from processors where needed, and give reasons for a refusal. Working with a supplier is part of that responsibility. [10]
Identifying the case, relevant exchanges and information sought can make the request easier to handle. The person does not need to disclose every detail of their life to make a valid request. Identity checks should be proportionate: the CNIL says that a copy of an identity document is not routinely necessary, although reasonable doubts may justify additional information. [10]
The communication channel also needs checking. For suspicious messages, Cybermalveillance.gouv.fr recommends contacting the organisation through its official details or usual channels rather than following the link received. Keeping original records in private storage and sharing only necessary material through a verified channel limits exposure of personal data. [16]
Separate requests and deadlines
An access response may reveal inaccurate data. GDPR Article 16 provides a right to rectification. Article 18 provides, subject to conditions, for restricting data use, including while disputed accuracy is checked. Article 19 governs notification of certain corrections or restrictions to recipients, with exceptions. These provisions concern data processing; they do not, on their own, extinguish a payment obligation. [3]
The desired outcome should be precise: correcting a recorded amount, challenging an assessment or having the claim’s legal basis examined. Written confirmation can then be compared with the next statement or relevant operation.
The deadlines must also be kept separate. For GDPR rights, information on the action taken should normally arrive within one month of receipt. A two-month extension is possible depending on the complexity and number of requests, with notice in the first month. Court proceedings follow their own timetable. [3]
In France, an objection to an injonction de payer, a payment order, must be made to the relevant court, normally within one month after formal service. If service was not made on the person, Article 1416 allows an objection until one month after the first document served on the person or the first enforcement measure making assets unavailable. A GDPR request or customer-service complaint does not count as that objection. [18]
The two-month period introduced in Article 1422 for orders issued from 1 September 2026 concerns the conditions under which the order becomes enforceable. The objection period under Article 1416 is a separate matter. [18]
Care is also warranted before entering a commitment concerning a disputed or old claim. Under Civil Code Article 2240, the debtor’s acknowledgment of the creditor’s right interrupts the limitation period. This does not make every message or request for information an acknowledgment. It is a reason to obtain advice on the circumstances before attempting to settle a legal uncertainty through a commitment whose consequences have not been assessed. [17]
Directing the request
The service handling the claim should be asked about its basis, the amount and payment corrections. The data controller, or its data-protection officer where one is appointed, is the contact for personal data and the exercise of data rights. CNIL guidance also explains how another person can be authorised to make an access request. The same company may handle both matters without the requests having the same purpose. [4] [5] [10]
A data issue may lead to a complaint to the CNIL under GDPR Article 77. A problem with an out-of-court collection company can be reported through SignalConso, France’s public consumer-reporting service. A dispute over the debt and any proceedings must be handled through the appropriate routes, with legal support where needed. A data-protection authority does not replace the court deciding the payment dispute. [19] [20]
This separation should not require someone to understand the supplier’s entire architecture before asking for help. Its purpose is to make the request actionable: identify the problem, the supporting document and the outcome sought, without treating one remedy as though it automatically delivered every other remedy.
From the calculated profile to the individual record
PAIR Finance and Ophelos describe an ambition to tailor communications, route certain requests and make some interactions available more quickly. A service that simplifies a task or identifies a need for help earlier can deliver a real benefit. Product descriptions alone cannot measure that benefit, the conditions under which it occurs or how it is distributed among affected people. [2] [21]
The first five instalments separated responsibilities, performance measures, support needs, error correction and contracts. Taken together, they point to a verification requirement: a general claim should be capable of comparison with what happened in an individual case. This sixth article identifies information people can already seek, the limits of access and the procedures that remain separate.
For this documentary series, we did not obtain authenticated individual files that could connect every stage. We conducted no interviews, made no access requests on behalf of affected people and tested no commercial platform. This work cannot establish a French AI-collection error rate, a rate of abusive pressure or a rate of lasting debt resolution.
The next stage of this investigation requires individual records: connecting the basis of the amount, the assessments used and the response to a request. An explanation becomes useful when someone can use it to have their case checked.
Documentary investigation closed on 25 September 2026. Findings from other sectors and court decisions are presented within their scope, not as findings against the companies discussed. The diagram compares legal deadlines; the examination criteria are proposed by l0g. This article provides general reference points, not legal advice on an individual claim.
Sources and reference points
[1] Cour de justice de l’Union européenne. C-487/21, Österreichische Datenschutzbehörde et CRIF. Judgment of 4 May 2023. Covers derived assessments about a person and a faithful, intelligible copy. It does not grant an unconditional right to every complete document.
[2] PAIR Finance. Gestion des créances avec la technologie IA. Undated product page. Describes classification and personalised communications. Corporate description of the advertised service.
[3] Union européenne / CNIL. RGPD, chapitre III : droits de la personne concernée. Regulation of 27 April 2016, applicable since 25 May 2018. Access, rectification, restriction, automated decisions and response periods; conditions and exceptions for each right.
[4] Légifrance. Code civil, article 1353. In force since 1 October 2016. Proof of the obligation and, conversely, of payment or another asserted ground of discharge.
[5] Légifrance. Code des procédures civiles d’exécution, R124-4. In force since 2 February 2013. Required letter within R124-1’s scope, not an identical formality applying indiscriminately to every creditor.
[6] Légifrance. Code des procédures civiles d’exécution, R124-1 à R124-7. Version consulted on 25 September 2026. Out-of-court collection for another party, subject to professional-status exceptions; prior creditor agreement.
[7] Légifrance. Code des procédures civiles d’exécution, L111-8. In force since 19 March 2014. Collection costs without an enforceable instrument generally fall on the creditor; statutory exceptions and a court decision must be distinguished.
[8] Cour de justice de l’Union européenne. C-579/21, Pankki S. Judgment of 22 June 2023. Access to consultation dates and purposes, not a general entitlement to employees’ names or every technical log.
[9] Cour de justice de l’Union européenne. C-203/22, Dun & Bradstreet Austria : communiqué n°22/25. Judgment of 27 February 2025. Explanation of the principles actually applied; protected information assessed by an authority or court. A creditworthiness case, not litigation against the collectors discussed here.
[10] CNIL. Professionnels : comment répondre à une demande de droit d’accès ?. Page dated 13 June 2017, version consulted in September 2026. No routine identity-document requirement; secure delivery, actual data and reasons for refusal.
[11] CNIL. Profilage et décision entièrement automatisée. Published 29 May 2018. Distinguishes profiling from solely automated decisions with legal or similarly significant effects. Read alongside Article 22 and subsequent case law.
[12] European Commission. Article 50: transparency obligations. Article 50(1) and (5), reproduced by the AI Act Service Desk. The page flags pending incorporation of some Omnibus amendments; the timetable is checked against the updated FAQ [13].
[13] Commission européenne. Transparency obligations under Article 50 of the AI Act. FAQ updated on 24 July 2026, consulted on 25 September 2026. Confirms 2 August 2026; the additional marking period does not defer chatbot disclosure. Administrative guidance read alongside the regulation.
[14] European Commission. AI Act: regulatory framework and timeline. Official overview consulted on 25 September 2026. Digital Omnibus entry into force on 27 July 2026 and application of high-risk requirements for Annex III systems on 2 December 2027.
[15] CNIL / LINC. Observatoire du droit d’accès sur les réseaux sociaux : bilan. Published 30 January 2025, based on 2024 observations of ten social networks. Completeness and quality of the data were not assessed. No result is extrapolated to debt collection.
[16] Cybermalveillance.gouv.fr. Le smishing ou hameçonnage par SMS. Published 13 June 2023, updated 21 February 2025. Verify through the organisation’s usual channels and preserve suspicious messages.
[17] Légifrance. Code civil, article 2240. In force since 19 June 2008. Acknowledging the creditor’s right interrupts limitation; whether a particular exchange constitutes acknowledgment depends on the facts.
[18] Légifrance. Code de procédure civile, procédures d’injonction. Version consulted on 25 September 2026. Court objection, the one-month period and special starting rules; the 2026 amendments do not create a two-month objection period.
[19] Union européenne / CNIL. RGPD, chapitre VIII : voies de recours. Data-protection complaints and judicial remedies. Powers of supervisory authorities and judicial routes.
[20] DGCCRF. Recouvrement amiable de créances : les règles à connaître. Published 24 October 2025. Public guidance, with the detailed rules checked against the Civil Enforcement Procedures Code.
[21] Ophelos. L’IA dans le recouvrement de créances. Undated product page. Describes functions and expected benefits; expected benefits remain the supplier’s claims.
[22] Commission européenne. AI Act Service Desk, annexe III. Annex covering, among other uses, evaluation of individuals’ creditworthiness and credit scores, except financial-fraud detection. Classification requires Article 6 and the actual intended use.
[23] CNIL. Droit d’accès : bilan des contrôles de l’action coordonnée européenne. Published on 20 January 2025. Eleven organisations across sectors, selected partly through complaints. Actual findings of partial responses, not a representative sample or an AI debt-collection study. Follow-up status is that reported at publication.
Documents consulted on 25 September 2026. Multiple references from one institution are not independent confirmations. Product pages are used to document their authors’ claims.
This analysis is not investment advice.
// cite this analysis
l0g, “AI is asking you to pay: what you can check”, l0g.fr, published September 25, 2026, updated September 25, 2026, https://l0g.fr/en/analysis/ai-debt-collection-6-data-rights/
$ cd ../analysis