The score attached to your name
What a score is
A score is a number standing in for a prediction about you, produced by a model you cannot see, used by an organisation whose interests differ from yours. Credit is the oldest and most regulated example, and it is the template for everything that followed.
A credit score predicts one narrow thing: the probability of missing payments over some window. It is not a measure of worth, wealth or honesty, though it functions socially as though it were. In most systems it is built from repayment history, current debt, credit age, mix of products and recent applications — and it has a structural cruelty built in, which is that having no history scores similarly to having a bad one. A person who has never borrowed is invisible, and invisibility is treated as risk. Hundreds of millions of people worldwide are in this position.
Alternative data, and what it drags in
The response to invisibility has been to widen the inputs. Lenders now use, or have used: mobile phone top-up patterns, utility and rent payments, e-commerce history, education, employer, the make of the handset, app inventory, contact-list size, and how the applicant filled in the form — typing speed, whether they scrolled the terms, whether they typed their name in capitals.
Some of this genuinely helps. Rent and utility payments are real evidence of reliability and their absence from traditional scoring is a historic unfairness.
But notice what has happened. Phone model is a proxy for income. App inventory reveals religion, health and sexuality. Contact-list structure reveals community. So a model built to avoid using protected characteristics has been fed a set of variables that reconstruct them precisely — the proxy problem from the second module, at industrial scale, with the added feature that the applicant has no idea any of it was collected.
Regulators have begun to react. Several jurisdictions restrict lenders' access to phone contacts and media. But enforcement is patchy and the app you granted permissions to in 2021 has already read what it read.
Insurance: the same machinery, a different logic
Insurance pricing is prediction too, and it collides with fairness in its own way, because the business model is discrimination — sorting people by risk is the product.
The modern issue is granularity. When everyone in a category paid the same premium, low-risk people subsidised high-risk ones and that was the point of pooling. As models get more precise, pools dissolve into individuals, each paying their own predicted cost. Taken to its limit, insurance stops being insurance and becomes prepayment, and the people who most need cover are the ones priced out of it.
Two specific practices are worth being able to name. Price optimisation sets premiums partly on predicted willingness to pay rather than on risk — several regulators have prohibited it, because it means the least likely to shop around are charged the most. And proxy variables for prohibited factors: where using a factor is banned, a correlated one often is not, until someone notices.
Scores you did not know existed
Beyond credit and insurance there is a layer of scoring that is largely invisible: tenant screening, customer lifetime value, fraud and chargeback risk, employability screening, delivery risk, moderation trust levels on platforms.
These share three properties. You are rarely told a score exists. There is often no defined correction process, because the score is described as an internal assessment rather than a decision. And errors propagate — one data broker's mistake reaches every customer of that broker, so the same wrong record rejects you repeatedly and you never learn why.
What to actually do
Get your file. In the EU, India, the UK, Brazil, South Africa and many other places you have a statutory right of access to your personal data, and in several countries credit bureaux must provide a free report annually. Ask for it. Error rates in credit files are high enough that checking is worth an hour: studies in several countries have found material errors in a meaningful minority of reports.
Correct in writing, and keep the record. Bureaux have statutory deadlines to investigate. Written requests start clocks; phone calls do not.
Ask which data was used. Under GDPR and DPDP-style regimes you can ask what personal data an organisation holds and, in Europe, meaningful information about the logic of an automated decision. The answer may be thin. The request itself creates a record.
Watch what you grant. The permissions you gave a lending app — contacts, SMS, storage — are the alternative data. Refusing them may cost you the loan, which is exactly the not-freely-given consent problem from the last module, and knowing that at least makes it a decision.
The one thing to keep
Alternative scoring data — phone model, app inventory, contacts, form-filling behaviour — reconstructs the protected characteristics a model was forbidden to use, and the person scored is usually never told the score exists.
Before you move on
A lender excludes caste, religion and gender from its model but includes handset model, installed apps and contact-list size to serve applicants with no credit history. What is the main risk?
Pick the one you would defend. Nobody sees your answer.