EU privacy rules hinder banks' assessment of climate-related credit risks
European banks say GDPR and national privacy laws block access to detailed property and insurance data, complicating regulators' push to gauge wildfire, flood and drought exposure.
European lenders are finding it increasingly difficult to measure credit risk from extreme weather events as GDPR and national privacy rules prevent them from obtaining detailed data on property conditions and insurance policies. Regulators, including France’s Autorite de Controle Prudentiel et de Resolution, are urging banks to provide a precise geographic breakdown of their exposure to wildfires, floods and droughts, especially after severe heat-wave damage.
The banks contend that without access to granular insurance information, loss assumptions are unreliable, while insurers adjust coverage annually, creating a duration mismatch with long-dated loans. Experts at the ECB note that the idiosyncratic nature of these risks and the gap between insurers’ short-term pricing and banks’ multi-decade loan terms create a “blind spot.” Some institutions, such as Deutsche Bank and UniCredit, are developing internal risk models and adding provisions, but the overarching data-privacy barrier remains a key challenge for the sector.
Why it matters
Without detailed risk data, banks may underestimate climate-related losses, threatening financial stability.
In this story
