The expression “citizen score” sounds as though it describes a government number that judges, in general terms, whether someone is a “good” or “bad” citizen. That, however, is not what Greece has enacted. The new framework concerns creditworthiness and solvency in relation to the State: it uses financial data to estimate how likely a natural or legal person is to meet their obligations. The expression “state Teiresias” is journalistic shorthand, not the system’s legal designation.

This distinction is not a matter of wording. Credit scoring can affect real economic opportunities and requires strict rules, but it is not automatically the same as China’s Social Credit System. A proper comparison requires us to examine who assigns the score, which data are used, for what purpose, who sees the result and what rights the citizen has.

The short answer: Greece has not introduced a general “social score” that evaluates opinions, friends or online posts. It has created a public system for assessing financial creditworthiness, distinct from the Bank of Greece’s Central Credit Register. The system provides for the cross-checking of public financial data and the use of statistical methods and machine learning. This makes it an important mechanism for financial profiling, raising critical issues of transparency, accuracy, human intervention and rectification and, when the result is transmitted to a private entity, specific consent.

1. What changed in Greece in 2026

The core framework derives from Law 4972/2022 on creditworthiness assessment in relation to the State. In 2026, Law 5301/2026 transferred the relevant responsibilities from the Independent Credit Assessment Authority to the General Secretariat for the Financial Sector and Private Debt Management of the Ministry of National Economy and Finance. This organisational change matters: the competent body is no longer the independent authority originally envisaged.

In June 2026, the Ministry presented the Creditworthiness Assessment System and the Private Debt Monitoring Register. In July, Joint Ministerial Decisions 117113 EX 2026 and 117786 EX 2026 were published, specifying the methodology, rating grades, data sources, application process and technical parameters.

The existence of a complete institutional and technical framework does not mean that, without an individual application or official notification, we should assume every citizen already has an active score that is used everywhere. The sound conclusion is that a statutory mechanism exists for producing a creditworthiness score and that specific means of accessing and using it are provided for.

2. Three different systems that should not be confused

Three infrastructures operate in Greece and are often conflated in public discussion:

  • The Ministry’s Creditworthiness Assessment System primarily processes data on financial conduct toward the State and assesses solvency and creditworthiness.
  • The Bank of Greece’s Central Credit Register (CCR) collects detailed data on credit exposures, such as loans, finance leases, factoring and guarantees reported by creditors.
  • Tiresias S.A. is a private credit-information company owned by banks operating in Greece. It maintains records of financial behaviour for credit-market purposes.

The public assessment system, the CCR and Tiresias S.A. may use related concepts, but they have different operators, legal bases, data sources and access or rectification procedures. The journalistic label “state Teiresias” does not mean that the private company has become a public body or that the three systems use identical databases.

The Ministry’s official presentation also states that the first system will be able to exchange creditworthiness scores with creditworthiness assessment bodies to produce a consolidated score. This is a planned interoperability capability, not evidence that all public and private databases have already been merged or that a permanent, universal number exists for every citizen.

The CCR collects, monthly, credit exposures equal to or greater than EUR 2,000 per creditor and debtor for natural persons and sole proprietorships, and EUR 5,000 for legal persons. A debtor may request a Credit Report free of charge and dispute inaccurate data. The CCR is not the same as the public score, even if both systems contribute to a fuller picture of financial obligations.

3. Which data the public score may use

Joint Ministerial Decision 117786 EX 2026 provides for financial data to be obtained from and correlated across public sources. Data held by the Independent Authority for Public Revenue (AADE) include information from E1, E2, E3 and N tax returns, income, expenditure, assets, the unified property tax (ENFIA), assessed debts, payments, payment arrangements and enforcement measures. The framework also covers data from the Social Security Debt Collection Centre (KEAO) concerning social security debts, payments and arrangements, as well as information from the Electronic Solvency Register.

Natural persons are grouped according to basic financial characteristics, such as employees with or without business activity, pensioners, business operators, farmers, persons with income from assets and persons with no declared income. Grouping does not in itself amount to a condemnation or final decision. It is used for the statistical comparison of similar cases and the assessment of credit risk.

This is financial profiling: the processing of data to evaluate or predict aspects of a specific person’s financial position and conduct. The quality and currency of the sources, the ability to explain the result and the correction of an error are therefore not secondary technical matters.

4. What EUR 100, EUR 500 and 90 days actually mean

The decision describes a model that examines historical data and seeks to estimate the probability of default over a twelve-month horizon. To define a default event for the model, it refers to material overdue amounts of EUR 100 for natural persons and EUR 500 for legal persons where those amounts remain overdue for 90 days.

This does not mean that a debt of EUR 100 automatically leads to a particular adverse grade. The amounts and the period serve as a technical criterion for the model’s training or evaluation target. The final score is derived from additional data and rules. This distinction is critical, because an oversimplified statement can cause unwarranted fear.

At the same time, the methodology provides for annual review and, where necessary, retraining or recalibration. An algorithm should not be treated as an immutable law; it must be tested for accuracy, bias and changes in the real economy.

5. What the rating grades are and why D is separate

For natural persons, the methodology provides for five creditworthiness rating grades within bands A to C. For legal persons, it provides for nine grades, with more detailed intermediate gradations. Category D appears separately for cases involving material, currently overdue debts to the State.

The simple statement “six scores for citizens and ten for businesses” therefore does not accurately reflect the methodology. There are five or nine main rating grades, plus the special D designation. The difference matters so that a prediction is not confused with the existence of an already material overdue debt.

6. How the score is obtained and how long it remains valid

The person concerned submits an application through the designated digital service. The decision states that the result must be produced within no more than 24 hours and accompanied by the corresponding notice. The score remains valid for three months, after which a new assessment is required if an updated result is needed.

The limited period is reasonable because debts, payment arrangements, income and payments change. It is not, however, in itself a guarantee of accuracy. If the original source contains an incorrect tax identification number, a debt recorded as unpaid even though it has been settled, or a delayed update to a payment arrangement, the result may remain incorrect until the source is corrected and the score recalculated.

Subject to conditions, the framework permits access by a private entity. It does not provide for a permanent, general authorisation. Each specific request requires the person’s express, specific and separate consent, authentication through Taxisnet and the necessary waiver of tax confidentiality for that particular transmission.

Before clicking “I agree”, the citizen should be able to see clearly:

  • exactly who is requesting the score and for what purpose,
  • which data or result the requester will receive,
  • how long the requester will retain it,
  • whether refusal means that a specific contract will not be concluded,
  • how consent can be withdrawn and what happens to data already obtained.

Consent for one request must not become an open-ended permission for repeated checks. If a company requests another result, a new, specific procedure is required.

8. What a citizen can do when the data or score is wrong

The first step is to establish where the error lies. Joint Ministerial Decision 117786 EX 2026 provides an electronic request to correct or supplement the data used, accompanied by supporting evidence. If the source is, for example, AADE or KEAO, the incorrect underlying record must also be corrected with the body that maintains it; otherwise it may reappear in a later assessment.

Challenging the accuracy of the creditworthiness score itself is a different matter. Article 59 of Law 4972/2022 provides an appeal to the territorially competent Greek Administrative Court of Appeal, based on the economic-behaviour data that existed when notification of the score was issued. Joint Ministerial Decision 117786 EX 2026 clarifies that this route cannot be pursued electronically. It is therefore not a simple portal request or a generic administrative objection.

Practical rule: For a data correction, identify the inaccurate information, the period, the source body and the supporting document. For an appeal against the score itself, obtain timely case-specific Greek legal advice on jurisdiction, the applicable deadline, standing and the evidence required, and recheck the procedure in force when the action is taken.

9. Greece, China, the United States and Germany: the substantive comparison

Country / systemResponsible bodyMain data and purposePossible consequencesCore rights
GreeceMinistry / General Secretariat and, separately, the Bank of Greece for the CCRPublic debts, income, assets, payments, payment arrangements and credit exposures; assessment of financial solvencyUse in financial assessment and, with specific consent, transmission to a private entityInformation, access and rectification of data; judicial appeal against the score and GDPR rights
ChinaMultiple public authorities, courts, and local and sectoral registersFinancial, judicial and regulatory compliance across a network of registers and listsSectoral supervision, public lists and restrictions linked to specific infringements or failure to comply with decisionsProcedures for correction and credit restoration, under an institutional framework different from that of the EU
United StatesPrivate credit bureaus and scoring providers, subject to the FCRA and specific oversightCredit and payment history, credit utilisation and account age; assessment of credit riskLoans, interest rates, cards, leases and, in some cases, insurance or other contractsFree reports, the right to dispute inaccuracies and notice of adverse action
GermanyPrivate financial information companies, primarily SCHUFAData on contracts, accounts and payments; prediction of the likelihood of paymentBanking, telecommunications, energy and other contracts or their termsAccess under the GDPR, rectification and greater transparency following CJEU case law

The most substantive difference is not whether there is a number or a letter, but the scope and purpose of the assessment. Greece, the United States and Germany assess a defined financial risk. China’s Social Credit System has a broader remit: it links administrative, judicial and regulatory compliance to registers, lists and sector-specific measures.

10. How China’s system actually works and why the single-score myth is misleading

The familiar image of a single national number that rises when someone behaves “well” and falls with every social choice is misleading. China has developed a fragmented but progressively integrated ecosystem of corporate and individual credit files, administrative lists, judicial blacklists, sectoral supervision and restoration mechanisms.

The official 2025 guidelines seek uniform rules, better aggregation of credit information and protection of rights, but the system remains much broader than a bank credit score. One characteristic example is the consequences that may be linked to non-compliance with an enforceable court decision, such as restrictions on certain consumer or travel expenditure.

The accurate description, therefore, is not that “China scores every citizen with one number”. China instead uses multiple mechanisms to record creditworthiness and compliance and to enforce specific obligations; some can affect areas of life beyond access to a loan.

11. United States: a private credit score, not a government social score

In the United States, credit scoring is a mature private market. Credit bureaus collect histories of loans, cards, payments, balances and the age of accounts. Different providers and lenders may use different models; the familiar 300-to-850 range is not a government score, nor is it the only score in existence.

The score can affect whether a loan is approved, the interest rate, the credit limit and other terms. In certain states and for certain uses, credit information may also affect insurance decisions. The Fair Credit Reporting Act requires specific permissible purposes, a right of access and a right to dispute inaccuracies, as well as notice when adverse action is taken on the basis of a credit report.

Private scores have considerable practical power, but the legal model differs from the Greek State’s processing of tax and social security data. The similarity lies in the financial purpose; the difference lies in the responsible body, the sources and the oversight procedures.

12. Germany: what SCHUFA is and what changed in 2026

SCHUFA is not a government authority. It is a private financial information company that provides banks, telecommunications providers, energy companies and other contracting partners with an estimate of the likelihood of payment. On 17 March 2026, it introduced a new score ranging from 100 to 999 points, based on twelve published criteria. At launch, approximately 25% of its contracting partners used the new score, while older sector-specific scores remained in circulation.

The judgment of the Court of Justice of the European Union in the SCHUFA case, C-634/21, is crucial. An automated score may itself constitute automated decision-making under Article 22 GDPR when the entity that formally decides whether to enter into a contract gives that score a determining role. A business cannot therefore simply say that “the computer only provided advice” if, in practice, the formal decision-maker almost always follows the score.

13. What the AI Act prohibits and what it classifies as high-risk

Regulation (EU) 2024/1689 prohibits specific forms of AI social scoring where natural persons are evaluated on the basis of social behaviour or personal characteristics and the result leads to adverse treatment in an unrelated context, or to treatment that is unjustified or disproportionate to the behaviour.

Not every assessment of a person for a specific legitimate purpose is prohibited. The use of AI to assess the creditworthiness of natural persons is, however, classified among the high-risk applications in Annex III. This entails enhanced requirements for risk management, data quality, documentation, record-keeping, human oversight, accuracy and cybersecurity when the relevant provisions apply.

Following the amendment of the timetable through the AI Omnibus, the rules for the high-risk uses listed in Annex III are scheduled to apply from 2 December 2027. Prohibited practices and other obligations under the Regulation have different application dates. Any reference to the AI Act must therefore distinguish what already applies from what will apply later.

14. GDPR: when human intervention is required

Article 22 GDPR gives a person the right not to be subject to a decision based solely on automated processing, including profiling, where the decision produces legal effects concerning that person or similarly significantly affects them. Exceptions exist, but they are subject to conditions and safeguards.

In practice, the question is not only who presses the final button, but also whether there is meaningful human judgment. If an employee mechanically approves whatever the algorithm recommends, the human presence may be merely nominal. Depending on the use, the citizen must be able to request human intervention, express their point of view and contest the decision.

The rights to information, access and rectification, and, where applicable, restriction or objection, also apply. An explanation need not disclose a trade secret or the entire source code, but it must be sufficiently meaningful for the citizen to understand which data and which basic logic influenced the result.

15. Practical checks before allowing the score to be used

  1. Confirm the responsible body. The public score, a Credit Report from the CCR and a private credit report are different things.
  2. Ask for the purpose in writing. For which contract or administrative procedure is the result required?
  3. Check the source data. Debts, payments, payment arrangements, property and income must be up to date.
  4. Read the consent. It must relate to the specific entity and the specific request, not unspecified future uses.
  5. Keep the result and its date. The score is valid for three months and may change.
  6. Request an explanation. If the result materially affects a decision, ask which main factors carried adverse weight.
  7. Correct the source first. An error held by AADE or KEAO must be addressed there and substantiated.
  8. Distinguish correction from appeal. Data correction can be requested electronically. A challenge to the score under Article 59 goes to the territorially competent Greek Administrative Court of Appeal and requires a timely legal assessment.
  9. Request human review. This is especially important when the score leads to rejection or less favourable terms.

16. Frequently asked questions

Do all citizens already have a score?

It should not be taken for granted that every citizen has an active score that is used automatically in every transaction. A statutory system and a procedure for producing a result exist. Actual use must be evidenced by a specific application, notification or transmission.

Will social media, political views or friends be assessed?

The Greek framework currently in force describes financial, tax, social security and asset data. It does not provide for the scoring of political beliefs, posts or social relationships. Such an extension would constitute a different system and would raise far more serious issues under the GDPR, the AI Act and fundamental rights.

Does a debt of EUR 100 automatically mean D?

No. The EUR 100 amount, the 90-day period and the twelve-month horizon describe a technical criterion in the model for natural persons. The special D category is linked to material current overdue debts and must not be mechanically equated with every small amount.

The prescribed transmission to a private entity requires a specific procedure, express and separate consent for the particular request, and the necessary waiver of tax confidentiality. Other credit information may be governed by a different lawful framework, so ask which precise report is being used.

Where can I turn if the result is not explained or corrected?

First correct inaccurate data at source and through the prescribed electronic request. If you challenge the accuracy of the score itself, Article 59 of Law 4972/2022 provides an appeal to the territorially competent Greek Administrative Court of Appeal, not an online objection in the portal. For an infringement of personal data rights, you may contact the Hellenic Data Protection Authority. Do not let a general complaint replace a timely assessment of any judicial deadline.

17. The real question is not whether “we have become China”

The easy headline “Social Credit is coming to Greece” omits the more useful truth. The Greek system has a defined purpose: assessing financial creditworthiness. China’s Social Credit System has a broader regulatory and judicial compliance remit. The United States and Germany nevertheless show that even a purely financial score can acquire considerable practical power when it affects loans, housing, services or contractual terms.

The substantive question is: who decides what the score means, who sees it, how decisive it becomes and how easily an error can be corrected? Public oversight, transparency of the methodology, data quality and genuine human review will determine whether the tool supports responsible lending or creates a new mechanism of financial exclusion.

18. Is it ultimately good or bad?

The neutral answer is that such a system is, in itself, neither a guarantee of modernisation nor a mechanism of oppression. It can help citizens and businesses demonstrate their solvency, reduce unjustified delays, make the assessment of financial risk more consistent, and identify errors or problems of over-indebtedness at an earlier stage.

The same features can, however, cause serious injustice if the score becomes an opaque end in itself, if old or inaccurate data are repeatedly reused, if a small or temporary debt is assessed without its actual context, if consent is reduced to the formality of clicking a button, or if banks and other bodies follow the result mechanically. The score may then close doors to people who struggle to prove that the picture it presents of them is inaccurate or outdated.

Whether its application proves beneficial will be determined in practice: by data minimisation and accuracy, clear reasons, restriction of every use to the stated purpose, meaningful human review, timely rectification and objection, scrutiny of the methodology, and independent oversight. With these safeguards, it can operate as useful economic infrastructure. Without them, it can become a mechanism of financial exclusion. The final judgment should therefore be based not on the label “digital Teiresias”, but on the system’s actual data, uses and safeguards.

For citizens, the first protective measure is accurate information. They need to know what the system is and is not, which data it uses, who is requesting the score, for what specific purpose, what consent is required, and through which procedure they can request an explanation, rectification or review. Neither alarmism nor uncritical complacency is helpful; what matters is evidence-based information that enables citizens to exercise their rights in good time.

Legal notice: This article provides general information based on the framework and official information available on 30 August 2026. It does not constitute individual legal or financial advice. The exercise of rights and the application of time limits depend on the responsible body, the specific request, the source of the data and the documents in the case.

Official and institutional sources

  1. Ministry of National Economy and Finance, presentation of the Creditworthiness Assessment System, 18.06.2026.
  2. Hellenic Parliament, Law 4972/2022, particularly Article 59 on appeals against a creditworthiness assessment.
  3. Official text of Law 5301/2026, Government Gazette, Series A, 74/15.05.2026, particularly Articles 49 and 100.
  4. Joint Ministerial Decision 117786 EX 2026, Government Gazette, Series B, 4436/21.07.2026, technical procedure and creditworthiness assessment model.
  5. Joint Ministerial Decision 117113 EX 2026, Government Gazette, Series B, 4422/20.07.2026, methodology and rating grades.
  6. Bank of Greece, Central Credit Register.
  7. Bank of Greece, launch of the CCR and credit-reporting thresholds.
  8. Tiresias S.A., corporate identity and shareholding.
  9. Tiresias S.A., history and management of economic-behaviour data.
  10. Regulation (EU) 2016/679, in particular Articles 12-16, 21 and 22.
  11. Court of Justice of the European Union, Case C-634/21, SCHUFA Holding.
  12. Regulation (EU) 2024/1689 on artificial intelligence.
  13. Regulation (EU) 2026/1744, amendment to the timetable for obligations concerning high-risk AI systems.
  14. European Commission, official timetable for the application of the AI Act.
  15. State Council of China, guidelines on the social-credit system, 31.03.2025.
  16. European Parliament, study on China’s Social Credit System.
  17. Federal Trade Commission, Credit Scores.
  18. Federal Trade Commission, Fair Credit Reporting Act.
  19. USAGov, credit reports and scores.
  20. Verbraucherzentrale, new SCHUFA Score 2026.
  21. Bundeskartellamt, scoring and consumer protection.

The sources and application dates were checked on 30 August 2026.

Lead image: original composition for Nomika Epilekta. It does not depict an actual government interface or an official state score.

Update of 31 August 2026: can a citizen “hide” their data from Tiresias?

The short answer is no, if “hide” means erase or make the record disappear. There is, however, an official and free procedure through which an individual may ask Tiresias not to transmit selected economic-behaviour data and/or their credit-behaviour score to the relevant recipients.

This distinction matters. The request does not correct an inaccurate record, erase a debt, shorten a statutory retention period or make the person invisible. Once it is accepted, the relevant file displays an indication that the person does not wish their data or score to be transmitted. A bank, finance provider or business may assess that indication freely, with any consequences this may have for a credit or transaction decision.

What an individual may select

The current official form E-EK 02-7 allows one or more of the following choices:

  • non-transmission of data from the Default Obligations and Mortgages/Pre-notations file (SAU-SYP),
  • non-transmission of data from the Credit Consolidation file (SSX),
  • non-transmission of data from the Business Risk Control file (TSEK),
  • non-transmission of the credit-behaviour score, or
  • non-transmission of all the above.

For SAU-SYP, SSX or the score itself, the form states that no score will be calculated by the relevant system. The recipient sees the applicable non-transmission indication instead of the selected data or score.

What non-transmission does not cover

The form expressly says that certain information continues to be transmitted. This includes records of lost or stolen identity cards and passports, terminated business contracts, assigned claims arising from public-works contracts or certifications, company information from the Government Gazette and GEMI, and identification data held in the reference file. A specific administrative measure depriving a person of a cheque book may also continue to be transmitted.

The procedure concerns Tiresias and the recipients of its specified files. It does not bind every public or private register and does not recall information that was lawfully transmitted before the request was granted.

How to submit the request

  1. Download the official individual non-transmission form E-EK 02-7 and select carefully the files or score concerned.
  2. Complete all identification details, previous identity-card or tax numbers where applicable, address and preferred delivery method for the response.
  3. Submit the request to tiresias@tiresias.gr, in person at Tiresias or by post. For electronic submission, follow Tiresias’ instructions on a declaration through gov.gr/e-dilosi. Otherwise, a fully completed form and, where required, certified signature are necessary.
  4. Keep proof of submission and the protocol number. Tiresias says processing time depends on the request and that its average response time is ten days, always within the statutory deadline.

The request may be withdrawn at any time using the separate E-EK 02-9 form for lifting non-transmission.

Non-transmission, correction and erasure are different requests

  • Access: asks what data are held and where they came from.
  • Rectification: seeks correction of inaccurate or completion of incomplete data, supported by evidence.
  • Erasure: applies only when the conditions of Article 17 GDPR are met and no lawful exception applies.
  • Restriction or objection: operates under Articles 18 and 21 GDPR. Tiresias describes this special non-transmission mechanism as an expression of restriction of processing that continued from the earlier regulatory framework.
  • Non-transmission: does not change the record; it limits future disclosure within the selected files and displays a corresponding indication.

Rectification, erasure, restriction and objection use the separate GDPR rights form E-EK 01-25. If the problem is a debt attributed to the wrong person, an incorrect amount, a repaid obligation or another factual error, non-transmission is not a substitute for rectification and supporting documents.

This is not the state Credit Scoring System

Form E-EK 02-7 applies to the files and behaviour score operated by the private company Tiresias. It is not a general opt-out from the state Credit Scoring System and does not automatically prevent lawful processing by public bodies or by the Bank of Greece Central Credit Register.

Within the Central Credit Register, an individual debtor may request a Type A Credit Report and file an electronic challenge for correction or completion under Article 120(2) of Law 4972/2022. This is a separate Bank of Greece procedure.

Practical check before signing

  1. Request access first, so that you know which record exists and in which file.
  2. If there is an error, pursue rectification with evidence; do not use non-transmission as a replacement.
  3. If you are considering a loan application, take into account that the recipient may consider the non-transmission indication.
  4. Select only the scope you need and retain copies of the request, attachments and response.
  5. Where a solely automated decision has significant effects, the Article 22 GDPR right is exercised against the organisation making that decision, not only against Tiresias.

Bottom line: this is a real tool for controlling transmission, not a “delete me from Tiresias” button. The appropriate route depends on whether the person needs access, rectification, erasure where legally available, or specifically non-transmission to future recipients.

Official sources: Tiresias public service, Tiresias legislation and data-protection rights, and Bank of Greece Central Credit Register and personal data.