Supreme Court: CRIF illegally collected data of millions in Austria. Way clear for class action!
Austria's Supreme Court has ruled that credit reference agency CRIF violated GDPR's purpose limitation principle by collecting personal data from address publishers without a lawful basis. The decision, secured before a full hearing, strengthens a parallel class action brought by privacy group noyb on behalf of millions of affected Austrians.
Why this matters: Credit agencies collect data on you without ever asking you. CRIF was pulling personal information from address publishers and using it for credit scoring — which is exactly the kind of repurposing GDPR is supposed to stop. Austria's highest court agreed, before the case even went to a full hearing. That is a significant early signal. If the class action follows through, millions of people who had no idea their data was being used this way could have a real remedy. The broader point: credit scoring affects your ability to rent a home or get a loan, and you rarely get to see or challenge what feeds into it.
Who should care: Lawyers · Privacy officers · AI governance
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.