Germany's dominant credit bureau has declined to sign any of the four cease-and-desist declarations demanded by the privacy group noyb, making a court injunction over its archive of historical consumer records a certainty. The deadline expired on Wednesday, 9 September 2026, and SCHUFA Holding AG confirmed its refusal in a public statement published yesterday, 10 September 2026.

In Short

A German credit bureau keeps an old archive of financial records - loans, debts, insolvencies - that a privacy group says should have been deleted years ago. The group gave the bureau a deadline to promise it would stop, and the bureau said no and defended the archive instead. Because the bureau refused, the privacy group will now take it to court, and if you live in Germany your records could be among the millions in that archive.

A deadline set, and let to lapse

The dispute turns on what German media have labelled a Schattendatenbank, or shadow database. According to noyb, the organisation sent SCHUFA a cease-and-desist letter two weeks before the deadline and, at the same time, announced that it would bring an injunction if the credit reference agency refused to comply with the requests set out in the letter. That deadline has now passed. In its public statement, SCHUFA rejected the allegations. The consequence, as noyb frames it, is no longer conditional: the group states it will file an injunction.

SCHUFA did not sign any of the four declarations. The company disputes the data protection accusations and has set out its reasons in a written reply, which it published in full on schufa.de alongside the statement. The next procedural step belongs to noyb, which can now file suit. Should it do so, the credit bureau's counter-arguments would have to be entered into the court record as well.

noyb had signalled the litigation route in advance. According to the group's earlier announcement, should the credit agency refuse to comply with the demands, it would bring an action for an injunction to have the unlawful practices prohibited by the courts. SCHUFA, for its part, had staked out its position weeks earlier. In a press statement dated 26 August 2026, the company stated plainly that it would defend the storage of historical data in court, even if that meant once again taking the matter as far as the Federal Court of Justice.

Max Schrems, chair of noyb, did not soften the group's assessment of the reply. According to noyb, Schrems said: "SCHUFA's arguments are utterly grotesque. Apparently, SCHUFA believes itself to be some sort of semi-divine institution that stands above European law. We look forward to putting an end to this. Interest in a potential class action is also going extremely well."

What noyb is demanding, and what it claims

The accusation is that SCHUFA holds creditworthiness data on consumers in a shadow database even though, according to noyb, the information should long since have been deleted. The group asks the bureau to erase the historical data. It also accuses SCHUFA of withholding from consumers the disclosures that the law requires it to provide.

The scale attached to the case is what sets it apart. When noyb first opened the matter, the letter concerned an archive of historical consumer records covering potentially all 69 million people in Germany, a figure that matches the size of SCHUFA's active consumer file. The cease-and-desist letter set out three demands: that SCHUFA stop storing data beyond the specified retention periods, that it supply affected individuals with their historical data as part of access requests, and that it ensure transparency about its processing practices. Those three demands underpin the declarations SCHUFA declined to sign.

Running in parallel is a possible collective claim. An online interest list has opened for a class action, with immaterial damages estimated at around 500 euros per person and roughly 1.6 million people a year said to have received incomplete responses to their access requests. Schrems' remark that interest is "going extremely well" points to that list rather than the injunction, which is now settled.

SCHUFA's four-part rebuttal

The credit bureau's reply, published today, answers the accusations point by point. It is worth setting out each argument, because the injunction will be fought on this ground.

The archive is not secret

SCHUFA's first contention is that it operates no secret shadow database. It has a data archive, the company argues, in the way that all firms keep archives. Historical data sits there, held separately from the productive data holding from which current credit disclosures are issued. According to SCHUFA, historical data is necessary to meet legal and regulatory requirements, among them consumer rights and the associated control and documentation obligations owed to data protection authorities. The company's position is that deleting historical data would make data protection oversight impossible, because neither supervisory authorities nor courts could then verify whether personal data had been processed lawfully. On that basis, SCHUFA rejects noyb's demand to delete the records.

Scores depend on history

The second argument concerns the mechanics of credit scoring. SCHUFA supplies the economy with payment-default forecasts in the form of creditworthiness scores, and all forecasting models, the company states, rest on the analysis of historical data. It invokes Section 31 of the German Federal Data Protection Act, which sets particular statutory requirements for the scientific basis of score development and testing. Without historical data, SCHUFA argues, developing scores and continuously checking their quality would not be possible at all, and for banks such checks are prescribed by banking law. The company frames the alternative in economic terms: without reliable payment forecasts there would be more defaults, higher risk costs, rising interest rates, and fewer loans granted. On this reasoning too, the demand to delete is rejected.

Retention follows agreed rules

The third strand addresses the legality of the retention itself. According to SCHUFA, concrete storage periods for the use of creditworthiness data in the credit-bureau business were written into German federal data protection law until 2018. The General Data Protection Regulation, in force since May 2018, contains no such storage periods, but Article 40 provides for sector-specific solutions to be agreed with data protection authorities. The industry association "die Wirtschaftsauskunfteien" defined uniform periods together with the federal and regional data protection authorities in a "Code of Conduct Prüf- und Speicherfristen", which regulates how long data may be used in the productive credit-bureau business. For the historical data held in the archive, SCHUFA states, purpose-bound retention periods apply, as the GDPR envisages. Information on those periods, the company says, is set out in its data protection notices. SCHUFA therefore rejects the accusation that it stores data for longer than is permitted.

Disclosures go beyond the statutory minimum

The fourth argument answers the charge that SCHUFA withholds required disclosures. The company says it informs consumers comprehensively about the processing of their data and provides transparent explanations under Article 14 of the GDPR, together with a copy of the personal data actually processed in the productive operation under Article 15. Beyond the current statutory entitlement, according to SCHUFA, the data copy already includes all score values transmitted to companies about a person over the preceding twelve months, with explanations. The company states that in 2025 alone it provided consumers with around two million SCHUFA disclosures. It describes a tiered disclosure model: the productively stored data is provided first, and further information is supplied on request, including for the current requests relating to historical data.

A statutory change is due to take effect during the litigation. From 20 November, under the newly created Section 37a of the Federal Data Protection Act, the legislature will for the first time since the GDPR took effect require historical data to be shown in the data copy, specifically the score values calculated over the preceding twelve months, alongside the most important criteria feeding into the score calculation. SCHUFA states it will adjust its data copy accordingly, and that it will again go beyond the statutory entitlement by supplying the information regardless of whether a score was decisive for a company's decision. The new transparency right, the company notes, applies only where a score is material to that decision.

Why this matters for the advertising and data industry

The case sits at the centre of a longer contest over Germany's credit bureau and the boundaries of European data protection law, and PPC Land has tracked that contest through a run of rulings that bear directly on how consumer data may be processed, retained, and explained.

The most consequential thread is transparency. In January, a Wiesbaden administrative court ordered SCHUFA to explain the individual factors behind an 85.96 percent risk score under Article 15, pushing the bureau toward meaningful disclosure rather than generic descriptions. That decision referenced SCHUFA's April 2025 move to a scoring system it presents as fully transparent, reducing more than 250 possible factors to twelve categories with disclosed point values. The Section 37a requirement now arriving in November formalises part of that direction in statute, and the reply SCHUFA published today leans heavily on the claim that it already exceeds it.

A second thread concerns what data may flow into the bureau in the first place. In November 2025, the Federal Court of Justice held that telecommunications companies may transmit positive contract data to SCHUFA for fraud prevention under Article 6(1)(f), a balancing decision that left open how the bureau processes that data afterwards. Data protection advocates have long warned that widening credit-bureau access builds comprehensive personality profiles, a concern the court did not resolve.

A third thread is enforcement against automated scoring itself. In August, a Berlin administrative court examined when a business may run a credit check during contract initiation, upholding a supervisory order against a solar firm running SCHUFA checks before site visits. The reasoning there, and in the Austrian authority's September 2025 finding that fully automated scoring indicators were unlawful, travels across any system that assigns a person a score and attaches an automatic consequence to it.

For marketers and ad tech operators, the stakes are not abstract. Credit scoring is one of the oldest and most entrenched applications of consumer profiling in Europe, and it operates under the same GDPR that governs almost every identifier used to target, frequency-cap, or measure a campaign. A court ruling on whether SCHUFA may retain historical records, and on what it must disclose to the people in its files, sets a reference point for retention and access obligations that reaches well beyond the credit-bureau business. The pattern noyb has established in Austria, where it is separately pursuing the credit bureau CRIF, shows the group intends to test these questions across jurisdictions, and its cross-border complaints have repeatedly moved from formal warning to litigation.

The immediate question is procedural. noyb will file its injunction; SCHUFA will defend the archive. Whether the Federal Court of Justice, the venue SCHUFA has already named as its likely destination, ultimately rules on the retention of historical data, and how it weighs the bureau's audit-and-documentation justification against the erasure claim, will shape how every large data holder in Germany treats the records it keeps out of sight.

Timeline

  • May 2018 - The General Data Protection Regulation takes effect, removing the concrete storage periods that German federal law had set for credit-bureau data
  • 15 July 2026 - NDR and Süddeutsche Zeitung publish parallel investigations describing SCHUFA's archive of historical consumer records, reported by PPC Land
  • 24 July 2026 - SCHUFA publishes its own account, "Die Wahrheit über die vermeintliche 'Schattendatenbank'", drawing a line between its productive and archived data holdings
  • 26 August 2026 - SCHUFA states in a press statement that it will defend the storage of historical data in court, up to the Federal Court of Justice if necessary
  • 26 August 2026 - noyb sends its cease-and-desist letter to SCHUFA and opens the interest list for a possible class action
  • 9 September 2026 - The deadline for SCHUFA to sign the four cease-and-desist declarations expires
  • 10 September 2026 - SCHUFA publishes its written reply, rejects the allegations, and declines to sign any declaration; noyb confirms it will file an injunction
  • 20 November 2026 - Section 37a of the Federal Data Protection Act takes effect, requiring historical score data to be shown in the data copy for the first time since the GDPR

Summary

Who: The Vienna privacy group noyb, chaired by Max Schrems, and SCHUFA Holding AG, Germany's dominant credit bureau.

What: SCHUFA declined to sign any of four cease-and-desist declarations demanded by noyb over its archive of historical consumer records, and published a four-part written rebuttal rejecting the accusations. noyb has confirmed it will now file for a court injunction, with a possible class action valued at around 500 euros per person still open.

When: The deadline expired on 9 September 2026, and SCHUFA confirmed its refusal in a public statement on 10 September 2026. A related statutory transparency requirement, Section 37a of the Federal Data Protection Act, takes effect on 20 November 2026.

Where: Germany, with the dispute likely to reach the Federal Court of Justice, the venue SCHUFA has named as its expected destination.

Why: noyb argues the archive holds creditworthiness data that should have been deleted and that SCHUFA withholds legally required disclosures. SCHUFA argues the archive is necessary for regulatory oversight, score development, and audit documentation, and that its retention follows agreed sector rules. The outcome will set a reference point for retention and access obligations affecting every large data holder in Germany.