A Wrong Payment Record on Your Company File: How to Get It Corrected
Von Johanna Brecht, Redakteurin für Verbraucherfinanzen · 9.9.2026 · 9 Min. Lesezeit
There is one sentence business owners say remarkably often the first time they see their own commercial credit file: “That is not right.” Sometimes the amount is wrong. Sometimes there is a claim on the file that has been in dispute for a year and a half. Sometimes the invoice was paid long ago, just two weeks later than the supplier would have liked.
All three cases have the same root. Payment records are reported by your own suppliers, and you are never part of that step. Nobody asks you beforehand, and nobody tells you afterwards. You notice it in the terms you are offered, not in your post.
And it carries weight. Payment behaviour weighs more than any other single feature in the Bonitätsindex that Creditreform keeps on almost every German firm, the business credit index a supplier consults before granting a payment term: 25 per cent of the mark, level with the credit rating judgement, which itself leans on how you pay. One wrong report can therefore shift that mark further than your legal form, the age of the business and the size of your payroll do between them.
First, the uncomfortable legal question
Before you write a line, you need to know what you are standing on. This is the point most guides skip: the GDPR protects natural persons, not legal ones. Recital 14 says so in as many words. The regulation does not cover the processing of data relating to legal persons.
Three very different starting positions follow from that.
Sole traders and freelancers. The data held about the business is largely data about you as a private individual. Article 15 GDPR (Art. 15 DSGVO) applies in full: the copy of your data (Datenkopie) free of charge, one month to answer, no reason required. Correction runs under Article 16, erasure under Article 17. This is the strongest of the three positions by some distance.
Partnerships. A GbR, OHG or KG has no right of access of its own. You personally, though, appear in the file by name as a partner, and for those entries the right does apply. In practice you ask for both in a single letter and let the agency sort out which half it owes you.
Companies with limited liability. A GmbH, UG or AG has no enforceable right of access. You as managing director have one for your own personal data. Quite separately from that, the agencies do let a company inspect its own file, not because they are obliged to, but because a wrong file is worth nothing to them either.
In day-to-day terms the difference is smaller than it sounds. But it changes the tone of the letter. In one case you are exercising a right; in the other you are asking to see something. A GmbH that opens with Article 15 GDPR occasionally receives a formally correct refusal, and has lost a fortnight for nothing.
The rule an entry falls on
For reported outstanding claims there is one hard provision, and it is shorter than people expect. Section 31(2) BDSG (§ 31 Abs. 2 BDSG) allows the report only where one of its conditions is satisfied. In the case that comes up most often in practice, that means:
- The claim is due.
- Two reminders went out, at least four weeks apart.
- The coming report was pointed out in advance.
- The claim is not disputed.
Four conditions, all at once. As an alternative, a claim established by a court order or expressly acknowledged is enough on its own.
Point four is the most effective of them. If you objected to an invoice in writing, over defects, over a partial delivery, over a contested variation, then the claim is disputed and the report was not permitted. Point two comes a close second: two reminders four weeks apart are more than a good many creditors actually sent before they filed.
The agency does not test any of this on its own initiative. It tests when you object, and then has to go back to the reporting creditor. If that creditor cannot show the conditions were met, the entry has to come off the file.
Step by step to a correction
- Ask for the file. At the Creditreform branch office for your registered seat, at CRIF, which holds business files across all three countries, and, for the owner's data, at SCHUFA, Germany's main consumer credit agency. For anything held about you personally, the request runs under Article 15 GDPR and costs nothing.
- Work through the payment records one at a time. Amount, date, creditor. Put your own bookkeeping alongside it; discrepancies jump out immediately.
- Tick off the four conditions. For every negative entry. Did you ever see the second reminder? Did it mention the report that was coming?
- Assemble the evidence. Proof of payment, your own letter of objection, the email thread about the defect. An objection without evidence is an assertion.
- Object in writing. To the agency, citing Article 16 GDPR and Section 31(2) BDSG. Name the entry precisely: creditor, amount, date.
- Ask for processing to be restricted. Under Article 18(1)(a) GDPR for as long as the check runs. The disputed entry then stops working against you in the meantime.
- Write to the creditor in parallel. The creditor is the one who can withdraw the report. That route is frequently quicker than the agency.
- Diarise the deadline: one month. For complex enquiries it may be extended by two months, and you have to be told about that inside the first month (Article 12(3) GDPR). After that, the complaint to the supervisory authority is open (Article 77 GDPR).
- Ask who received the data. Under Article 19 GDPR the agency must notify the correction to every recipient it passed the data to. Ask for that in so many words, or the old figure stays sitting in your business partners' systems.
Point nine is the one almost everybody forgets. An erasure at the agency achieves little while your supplier's trade credit insurer is still working off the old number.
Austria and Switzerland
In Austria the same GDPR applies. The central bodies are KSV1870, the Austrian credit protection association, with its Warenkreditevidenz, a register of how firms pay their trade credit, and CRIF. Complaints go to the data protection authority, the Datenschutzbehörde in Vienna. The sequence is the same as in Germany.
Switzerland works differently. The revised Data Protection Act has covered only natural persons since 2023. The right of access is in Article 25 of the Swiss Data Protection Act (Art. 25 DSG) and is free of charge once a year as a rule. More important for a company is the Betreibungsregisterauszug, the extract from the debt enforcement register, under Article 8a SchKG, because that is the document business partners, landlords and banks ask for most often. The agencies to approach are CRIF and Intrum.
How long does an entry stay on file?
There is a distinction here that gets blurred constantly. For personal data, meaning you as owner, partner or managing director, the credit agencies' code of conduct sets out clear periods: settled claims three years; since 2024 only eighteen months where the claim was paid within a hundred days of the report and no further entries exist; enquiries twelve months, visible to third parties for ten days; six months after a discharge of residual debt (Restschuldbefreiung).
For your company's file there is no comparable published catalogue of periods. Payment records and rating features are held for as long as they are needed for the assessment, and the agency decides that under rules of its own. So anyone reading that a company entry vanishes automatically after three years is reading a rule written for private individuals.
That changes the strategy. With personal data, sitting it out can be a route, because a date is fixed. With a company file it seldom is. There the route runs through proof that the report was never permitted, or through the creditor who filed it.
The faster route: the creditor
The agency is the formally correct addressee, but not always the quickest one. It has to put the question to the creditor, wait for the answer and then decide. That takes time you may not have while a supplier is shortening your terms.
The creditor, by contrast, can withdraw the report directly, and sometimes has every interest in doing so: when the trading relationship is meant to continue, or when you both know the second reminder was never sent. A plain, factual letter that walks through the four conditions of Section 31(2) BDSG one by one and asks for the report to be withdrawn is often dealt with inside a fortnight.
Write to both, in parallel. The objection to the agency protects your position and triggers the duty to check. The letter to the creditor frequently solves the actual problem. Keep any threat out of that second letter. What you need from that person is an action, not a legal opinion.
What FIAON takes on
Two files matter in this situation, and FIAON fetches both in a single pass rather than three separate attempts: the company file, and, under a power of attorney, the file held on you as owner. Each entry is then taken apart – who reported it, how long the agency may keep it, whether the four conditions of Section 31(2) BDSG were ever satisfied. Anything that looks challengeable becomes two letters, the objection to the agency and the request to the creditor who filed the report. FIAON sends both and keeps the deadlines until an answer comes back, and prepares the complaint to the supervisory authority if none does. You see every step before it leaves the building.
What does not work
A justified entry does not disappear. Where the claim really was open and the report followed the rules, settling it and letting the storage period run its course is the only route there is.
An objection is not an excuse either. Disputing a claim only after it has been reported rarely gets anywhere; what counts is whether it was disputed at the time of the report. Which is why every objection to an invoice belongs in the file in writing from the first day, not in a phone call nobody wrote down.
And nobody can say how the business credit index will move once an entry comes off. The weighting of the features is published. The formula behind it is not.
The three sentences that matter
Your suppliers report your payment behaviour without any involvement from you, and it carries a quarter of your business credit index. A report is permitted only where the claim was due, reminded twice at four weeks' distance, announced in advance and not disputed, and if any one of those four is missing, the entry can be attacked. Ask for your file before a business partner tells you what is in it.
Häufige Fragen
Does my GmbH have a right of access under the GDPR?
No. The regulation protects natural persons; it does not apply to data about legal persons (Recital 14). You personally do have the right where you appear in the file as managing director. Separately from that, the credit agencies do let a company inspect its own file.
When may a supplier report an outstanding claim at all?
Under Section 31(2) BDSG, and only on four conditions at once: the claim is due, you were reminded twice with at least four weeks between the reminders, you were warned that a report was on its way, and you never disputed the claim. A claim established by a court order or expressly acknowledged may be reported without them. Miss one of the four and the report should not have been filed.
How long may the credit agency take to answer?
One month. For complex or numerous enquiries it may extend by two months, but has to tell you inside the first month (Article 12(3) GDPR). If no answer comes at all, the complaint to the supervisory authority under Article 77 GDPR is the next step.
The entry is gone, so why does my supplier still treat me worse?
Because the old data is still sitting in that supplier's systems or with its trade credit insurer. Under Article 19 GDPR the agency has to notify the correction to every recipient it passed the data to. Ask for that list explicitly; this is the point forgotten most often.
Does the same apply in Austria and Switzerland?
In Austria yes, because the same GDPR applies; KSV1870 and CRIF hold the files, and complaints go to the data protection authority in Vienna. In Switzerland the right of access follows Article 25 of the Swiss Data Protection Act and likewise covers natural persons only. For a company the extract from the debt enforcement register under Article 8a SchKG matters just as much.