PrivacySignal
GDPR / Intl

‘Shadow database’ scandal: noyb sends SCHUFA cease-and-desist letter; interest list for class action opened

noyb (None of Your Business) · · EU · GDPR & International

German privacy group noyb has sent a cease-and-desist letter to credit agency SCHUFA after investigations revealed it retained millions of records that should have been deleted, and used them for customer testing. Noyb has opened an interest list for a class action, with up to 69 million people potentially affected.

Why this matters: SCHUFA shapes whether Germans get loans, apartments, or phone contracts. If the agency kept data it was legally required to delete, and then used that data to score people, those people were judged by information they had a right to have erased. That is not a technicality. It changes real outcomes in people's lives. Refusing to disclose the data even when people formally ask under GDPR makes it worse. You cannot challenge a score you are not allowed to see. A class action of this scale could force credit agencies across Europe to take deletion rights seriously.

Who should care: Lawyers · Privacy officers · AI governance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

GDPR / Intl
C Computing UK · · International

ICO: Police facial recognition needs stronger oversight

The UK's Information Commissioner's Office has called for stronger oversight of how police use facial recognition technology, signaling concern that current controls are insufficient to govern the practice.

Who should care: Lawyers · Privacy officers · AI governance · Cybersecurity · General readers · Policy

#gdpr#surveillance#privacy Read original →
GDPR / Intl
C Computer Weekly · · International

ICO police facial recognition audits reveal ‘mixed’ bag

The UK's Information Commissioner's Office conducted audits of police use of facial recognition technology and found inconsistent results across the forces reviewed. The findings suggest compliance and practice vary significantly, with no uniform standard being met.

Who should care: Lawyers · Privacy officers · AI governance · Cybersecurity · General readers · Policy

#gdpr#surveillance#privacy Read original →
GDPR / Intl
B Biometric Update · · International

UK ICO finds police facial recognition use mostly compliant with data regulations

The UK's Information Commissioner's Office reviewed police use of facial recognition technology and found it to be largely compliant with data protection law. The assessment stops short of a full endorsement but does not identify systemic violations.

Who should care: Lawyers · Privacy officers · AI governance · Compliance · Cybersecurity · General readers · Policy

#gdpr#regulation#surveillance#privacy Read original →
GDPR / Intl
I Infosecurity Magazine · · International

ICO Urges Police to Improve Data Governance in Facial Recognition Roll

The UK's Information Commissioner's Office has called on police forces to strengthen how they manage data as facial recognition technology is deployed more widely. The ICO's intervention signals concerns about compliance and oversight during the rollout.

Who should care: Lawyers · Privacy officers · AI governance · Cybersecurity · General readers · Policy

#gdpr#surveillance#privacy Read original →
GDPR / Intl
K keyt.com · · International

State Privacy Regulator Issues Second Decision Penalizing Out-of-State Data Broker

A state privacy regulator has issued its second enforcement decision against an out-of-state data broker, signaling continued regulatory action beyond its own borders. The decision adds to a pattern of state-level agencies asserting jurisdiction over companies that collect and sell resident data regardless of where those companies are based.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#state-privacy#regulation#privacy Read original →