PrivacySignal
GDPR / Intl

‘Shadow database’ scandal: noyb sends SCHUFA cease-and-desist letter; interest list for class action opened

noyb (None of Your Business) · · EU · GDPR & International

German privacy group noyb has sent a cease-and-desist letter to credit agency SCHUFA after investigations revealed it retained millions of records that should have been deleted, and used them for customer testing. Noyb has opened an interest list for a class action, with up to 69 million people potentially affected.

Why this matters: SCHUFA shapes whether Germans get loans, apartments, or phone contracts. If the agency kept data it was legally required to delete, and then used that data to score people, those people were judged by information they had a right to have erased. That is not a technicality. It changes real outcomes in people's lives. Refusing to disclose the data even when people formally ask under GDPR makes it worse. You cannot challenge a score you are not allowed to see. A class action of this scale could force credit agencies across Europe to take deletion rights seriously.

Who should care: Lawyers · Privacy officers · AI governance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Deep Signal · Part I of III

The Algorithm Said So

Federal rulemakers are deciding what to do when artificial intelligence produces the kind of conclusion that once required an expert. They disagree about how to regulate it. They also disagree about whether the problem has arrived.

· 10 min read Read →

Related stories

GDPR / Intl
ICO · · UK

Complaints about automated nuisance calls hit five-year high

Complaints about automated nuisance calls have reached their highest level in five years, according to the UK's Information Commissioner's Office. The spike points to a persistent and growing problem with unsolicited automated calls reaching people at home.

Who should care: Lawyers · Privacy officers · AI governance

GDPR / Intl
EPIC · · US Federal

EPIC Offers Comments on Vermont Age-Appropriate Design Code Rulemaking

EPIC submitted formal comments to the Vermont Attorney General on two proposed rules designed to implement Vermont's Age-Appropriate Design Code, which sets design and data protection standards for online products likely to be accessed by children.

Who should care: Lawyers · Privacy officers · Compliance

#state-privacy#regulation Read original →
GDPR / Intl
W WIS News 10 · · International

SC Attorney General Alan Wilson presses Flock Safety for answers on AI use, data privacy

South Carolina Attorney General Alan Wilson has contacted Flock Safety, a license plate reader and surveillance technology company, seeking information about how the company uses AI and handles personal data collected through its systems.

Who should care: Lawyers · Privacy officers · Compliance · General readers · AI governance · Policy

#state-privacy#ai#privacy Read original →
GDPR / Intl
T The National Law Review · · International

Delaware Expands State Privacy Law

Delaware has expanded its state privacy law, according to a report in the National Law Review. The specific changes and their scope are not detailed in the available information.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#state-privacy#privacy Read original →