PrivacySignal
Enforcement

SCHUFA insists on shadow database. noyb lawsuit now certain

noyb (None of Your Business) · · EU · Enforcement

German privacy group noyb will file an injunction against credit agency SCHUFA after the company rejected a cease-and-desist letter over its so-called shadow database. SCHUFA has publicly denied the allegations, and noyb is also inviting people to register interest in a potential class action.

Why this matters: SCHUFA is Germany's most powerful credit agency. If it runs a shadow database, that means it may be collecting and using personal data that people cannot see, correct, or contest. Credit scores already shape whether you get a loan, a rental, or a phone contract. Hidden data feeding those scores makes that power even harder to challenge. The noyb lawsuit is a direct test of whether GDPR rights are real in practice or just on paper.

Who should care: Lawyers · Privacy officers · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Enforcement
EFF — Deeplinks · · International

Cops Play Hide and Seek About Using Spy Tech to Avoid Scrutiny and Bad PR

Police departments across the United States are actively concealing their use of surveillance tools — including license plate readers, cell-site simulators, and facial recognition — by instructing officers to omit these technologies from reports and structuring records to evade public disclosure requests.

Who should care: Lawyers · Privacy officers · Compliance · Cybersecurity · General readers · Policy

#enforcement#surveillance#privacy Read original →
Enforcement
The Record · · International

Grindr settles privacy lawsuit tied to disclosure of users’ HIV statuses for $35 million

Grindr has agreed to a $35 million settlement with UK users who sued the dating app over claims it shared their HIV status data without proper consent, in violation of British privacy law. The lawsuit was filed in April 2024.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Enforcement
N News4JAX · · International

Netflix lawsuit: Florida AG alleges streaming giant tracked kids, broke data privacy promises

Florida's Attorney General has filed a lawsuit against Netflix, alleging the company tracked children's data and violated its own privacy commitments to users. The suit centers on claims that Netflix broke promises it made about how it handles personal information.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Enforcement
HIPAA Journal · · US Federal

FBI Raises Alarm About OAuth Consent Phishing Activity

The FBI has issued a public warning about an active phishing campaign that exploits OAuth consent flows, a legitimate authorization mechanism used across countless apps and services. The technique is sophisticated enough to warrant a formal federal alert.

Who should care: Lawyers · Privacy officers · Compliance · Healthcare professionals · General readers · Policy

#enforcement#healthcare#privacy#security Read original →
Enforcement
CNIL · · EU / France

Failure to respect the rights of individuals: EUR 300,000 fine against EXTIA

France's data protection authority, the CNIL, fined consulting firm EXTIA €300,000 for failing to respect individuals' rights under data protection law. The penalty reflects a formal finding that the company did not meet its legal obligations toward the people whose data it held.

Who should care: Lawyers · Privacy officers · Compliance

#enforcement Read original →
Enforcement
The Guardian — Tech · · International

Trump administration to confront Australia over Labor’s social media algorithm plan

The Trump administration plans to challenge Australia's proposed digital platform rules, which would require social media companies to remove harmful content, give users the ability to opt out of algorithmic feeds, and expose platforms to fines exceeding $100 million for violations.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · Administrators · General readers · Policy

#enforcement#ai-governance#ai#privacy Read original →