Privacy group noyb today sent a cease-and-desist letter to Germany's dominant credit bureau and opened a sign-up list for a possible damages action, six weeks after broadcasters revealed a second, undisclosed store of consumer records.
The European Centre for Digital Rights, better known as noyb, today issued a formal warning to SCHUFA Holding AG and announced that it will seek a court injunction if the company does not change its practices. The letter concerns what German media have called a shadow database: an archive of historical consumer records that, according to noyb, should have been erased under the retention periods SCHUFA itself publishes.
The dispute began on 15 July 2026, when public broadcaster NDR and the Süddeutsche Zeitung published parallel investigations. According to the NDR report written by Peter Hornung, alongside the official SCHUFA database there exists a second collection of historical data on millions of consumers, containing information that reaches back years and that affected individuals assumed had long been deleted. The report listed old loans and credit cards, wage garnishments, private insolvencies, and debts that borrowers had often settled years earlier.
SCHUFA does not dispute the existence of the archive. It disputes the framing, the legal characterisation, and the word database itself.
What noyb is asking for
The cease-and-desist letter sets out three demands. According to noyb, SCHUFA must stop storing data beyond the specified retention periods, must supply affected individuals with their historical data as part of access requests, and must ensure transparency about its processing practices. Should the company refuse, noyb states it will bring an action for an injunction to have the practices prohibited by the courts.
That is step one. Step two, described in the announcement as possible rather than certain, is a class action for damages.
The scale claimed is unusual even by the standards of German privacy litigation. According to noyb, potentially all 69 million people on whom SCHUFA holds data are affected, a figure the organisation notes is close to the entire adult population of Germany. The announcement further states that around 1.6 million people a year received incorrect responses to their access requests, on the basis that historical data was never provided to anyone. Typical immaterial damages, according to noyb, can be estimated at around 500 euros per person.
An online interest list is already live. The registration form asks two questions that define the likely claimant pool: whether the person purchased a SCHUFA BonitätsAuskunft before June 2026, and whether they requested the free data copy under Article 15 of the General Data Protection Regulation, either directly or through a third-party provider, before that same month.
Martin Baumann, data protection lawyer at noyb, said in the announcement that the archive is a textbook example of unlawful data processing, arguing that SCHUFA secretly processes data which by its own account should have been deleted long ago, and ultimately makes money from doing so.
The retention argument
The technical heart of the dispute is what deletion means.
According to the SCHUFA privacy policy, the retention period for data used to calculate the credit score is determined by self-imposed codes of conduct. The company's Article 14 information notice, dated December 2023, states that retention periods are set out in a code of conduct maintained by the industry association Die Wirtschaftsauskunfteien e. V. Debt collection claims and data on settled loans, for example, are deleted three years after payment.
noyb's reading is that deletion in SCHUFA's usage means something narrower than deletion under the GDPR. The data, according to the announcement, is only hidden. It disappears from the consumer's view but not from the company's systems, where it continues to be processed and is used for what noyb describes as credit score validations performed for third parties.
SCHUFA published its own account on 24 July 2026 under the headline "Die Wahrheit über die vermeintliche 'Schattendatenbank'", or the truth about the alleged shadow database. The company draws a line between what it calls the productive data holding and the archived data holding. According to SCHUFA, the productive holding contains current credit information on around 69 million people in Germany and supports approximately 350,000 disclosures per day. Archived records sit separately from that holding, are immutable for audit reasons, and have no influence on a consumer's current creditworthiness assessment.
SCHUFA sets out five purposes for archiving: regulatory control and documentation obligations towards data protection authorities and courts, compliance with score development requirements under Section 31 of the German Federal Data Protection Act and Article 5 of the GDPR, quality assurance of scores, support for banks meeting supervisory requirements, and research and development.
On duration, the company gives numbers that sit awkwardly against the shadow-database framing. According to SCHUFA, archived historical data is subject to purpose-bound retention periods of at most ten years. The worked example offered is a bank credit enquiry: the transmitted data and the calculated score are deleted from the archive after five years at the latest, once the purpose of storage, such as legal defence, has lapsed.
One exception, and who receives it
SCHUFA's own document contains the concession that gives the story its commercial edge.
According to the company, no external party has access to historical data in the archive, and only legitimated SCHUFA personnel can reach it. There is, it states, exactly one case in which a personal historical data point is passed on: when banks and other companies check the forecast quality of a new score model before deploying it in practice. Those companies receive scores calculated on historical data for their testing purposes. Banks, SCHUFA notes, are required by supervisory law to perform such backtestings.
The NDR reporting describes the same mechanism in less clinical terms. According to that account, SCHUFA calculates, at the request of corporate customers such as banks, the creditworthiness of consumers for a specific day in the past, on a test basis only. Such historically calculated scores allow customers to be shown how reliable the new SCHUFA score is, the score the company presented in spring with substantial advertising expenditure and is now marketing.
The recipient list widens the picture considerably. According to NDR, alongside banks the results can go to telecommunications firms, energy suppliers, large retailers, eCommerce providers and payment service providers. NDR and the Süddeutsche Zeitung sent dozens of enquiries to companies in those categories. Only three responded affirmatively: one bank, one payment service provider and one energy supplier admitted using such historical SCHUFA data. Many answered evasively, some not at all, and several suggested the reporters ask SCHUFA directly.
SCHUFA told the broadcasters that handling of the data is contractually restricted strictly to test and control purposes, and that it must be deleted at the banks and other companies once the tests are complete.
Claudio Zeitz-Brandmeyer of the Federation of German Consumer Organisations put the counterargument to NDR. Translated from German, he said the arrangement is problematic because it is very tempting for the companies receiving the data to use it not only for test purposes but also, for instance, to actually draw on it for credit decisions.
The access-request problem
The second limb of noyb's complaint concerns Article 15 of the GDPR, and it is the limb most likely to produce a court ruling with consequences beyond credit reporting.
According to noyb, SCHUFA is inconsistent: it presents the archive as entirely transparent while admitting that data subjects do not receive a copy of stored historical data when they make an access request. The reasoning attributed to SCHUFA is that data subjects are only interested in which data currently feeds their score. noyb's response is that a company cannot limit its information obligation to data it deems of interest, and that the Court of Justice of the European Union has established that a data copy must be a complete and faithful reproduction of all processed data.
SCHUFA's public position, as reported by NDR, is close to that summary. The company wrote on its website in the days before the investigation appeared that consumers mainly want to know how their current creditworthiness stands and which data influences their score, which is not the case for historical data. That statement, according to NDR, was the first time SCHUFA itself made the existence of such historical data public, and it followed enquiries from the two newsrooms.
Ruth Janal, professor at the University of Bayreuth and a specialist in data protection and consumer credit law, rejected that position in blunt terms. Translated from German, she said the idea that consumers need not learn about such storage is nonsense, and that the right of access anchored in the GDPR naturally covers the data SCHUFA describes as historical.
Janal also questioned the tests themselves. Translated from German, she told NDR that historical scores give a certain insight into the financial situation of the affected persons in the past, and that this is simply none of SCHUFA's contract partners' business. On the archive as a whole, she said permanent storage of such historical data on stock for indeterminate future purposes is not permissible under the case law of the Court of Justice of the European Union, adding that verifying the reliability of scores would be possible with a considerably smaller dataset.
Marco Blocher, data protection lawyer at noyb, framed the access question as the clearer of the two violations, stating that it is unlawful for SCHUFA to store supposedly deleted data in a shadow database and then not disclose it.
A supervisory authority that has been looking since spring 2025
Both the reporting and the noyb announcement converge on the Hessian Data Protection Authority, which supervises SCHUFA because the company is headquartered in Wiesbaden.
According to NDR, the Hessian commissioner has been examining the data tests since spring 2025, reviewing their legal basis and the question of whether consumers must be informed via the data copy. The procedure, the authority said on enquiry, is not yet concluded.
noyb's characterisation is sharper. The organisation states that the authority appears to have known about the archive since spring 2025 and describes it as notoriously inactive. As a state-approved qualified entity, noyb says it has therefore taken action itself.
Max Schrems, chair of noyb, said the organisation is increasingly witnessing a breakdown of the public data protection authorities in Germany, and must therefore take legal action as a non-profit acting in the public interest. In a second statement he said SCHUFA has not only broken the law but lied to and harmed those affected, and that noyb intends to seek compensation on a non-profit basis.
The Hessian authority has been on the receiving end of this argument before. noyb sued data protection authorities in Hesse and North Rhine-Westphalia in June 2025 over nearly four years of inaction on pay-or-okay consent complaints against faz.net and t-online.de. It sued the Hamburg authority in April 2026 after the regulator acknowledged that facial recognition service PimEyes operates unlawfully and then declined to act meaningfully.
The civil society front and the criminal question
AlgorithmWatch launched a petition on 15 July 2026 addressed to SCHUFA chief executive Tanja Birkholz and Alexander Roßnagel, the Hessian data protection commissioner. The petition demands immediate deletion of the archive and asks the regulator to conclude its review and, if it finds the database unlawful, to impose the maximum possible penalty of 20 million euros. The signature counter on the petition page stood at 145,769 against a target of 200,000.
Matthias Spielkamp of AlgorithmWatch told NDR that the scale of the matter can hardly be overestimated, and that SCHUFA must answer the question of what degree of irresponsibility prevails there. In the noyb announcement he is quoted stating that the organisation and nearly 145,000 petition signatories demand full information for those affected, action from the Hessian authority to compel permanent deletion, and the maximum possible fine.
Two practitioners raise consequences that go past administrative law. Raphael Rohrmoser, partner at AdvoAdvice Rechtsanwälte, said countless court cases have already run against SCHUFA over the right of access and the right to erasure, and that the emergence of extensively available deleted data raises the key question of whether the information SCHUFA provided in those proceedings was always accurate.
Peter Hense, partner at Spirit Legal Rechtsanwälte, went further, stating that if a credit agency passes on data labelled as deleted to third parties in return for payment, this may constitute a criminal offense.
Numbers that do not line up
Three population figures circulate in the source material, and they do not match. noyb and SCHUFA both cite more than 69 million people. AlgorithmWatch, citing SCHUFA's own published figures, refers to payment behaviour data on 68 million persons. Court filings covered by PPC Land in November 2025, when Germany's Federal Court of Justice permitted telecoms operators to transmit positive contract data to SCHUFA, recorded 943 million records on 67.9 million individuals. The differences plausibly reflect measurement dates rather than dispute, but no source reconciles them.
A second gap is more material. SCHUFA states a maximum archive retention of ten years, and five years for credit enquiry records. noyb states that data which should have been deleted long ago is still stored. Neither the company statement nor the noyb announcement identifies which record categories exceed which limit, and the primary reporting does not supply a figure for how far back the oldest retained records reach beyond the general statement that they go back years.
A third tension sits inside SCHUFA's own document. The company states that no external party accesses archived data, then describes the backtesting exception in which historical scores calculated on that data are transmitted to banks and other companies. Both statements can be true simultaneously, since a derived score is not the underlying record, but the distinction carries the entire weight of the company's no-external-access claim.
Why this matters beyond credit reporting
The mechanics under challenge here are not specific to credit bureaus. Retaining records past their stated deletion date in order to validate a model, hiding those records from the interface a data subject can see, and transmitting model outputs rather than raw records to commercial partners are all patterns that recur across advertising and measurement infrastructure.
Model validation on retained historical data is standard practice in attribution modelling, audience scoring, and clean room analytics. The legal question noyb has put to SCHUFA is whether purpose limitation and storage limitation permit a controller to keep an indefinite backtesting corpus at population scale. If a court answers that in the negative, the reasoning transfers directly to any organisation holding a historical event store for model quality assurance.
The Article 15 argument transfers just as cleanly. A data copy that reflects only the records currently feeding an active system, while excluding archived records that are still processed, is a design pattern rather than an accident. noyb has already tested a version of this argument against advertising-adjacent platforms: it filed a complaint against LinkedIn in May 2026 over profile visitor data available to paying subscribers but withheld from access requests, and it challenged dict.cc over a consent banner listing more than 1,700 technology partners.
German credit data has been under sustained judicial pressure throughout the period. A Wiesbaden court ordered SCHUFA to give individualised explanations of the factors producing a score in January 2026. Austrian regulators found fully automated credit scoring unlawful under Article 22 in September 2025, and an Austrian court required greater disclosure of scoring logic the month before. In July 2026 an Austrian court held that the macroeconomic statistical parameters feeding a score are not themselves personal data, a ruling that narrows one route while leaving the transparency route open. A Berlin administrative court upheld a warning against a solar firm that ran SCHUFA checks before site visits in a judgment reported in August 2026.
The damages exposure is the part that will register on balance sheets. noyb secured EU-wide collective redress authoritythrough approvals from the Irish Ministry of Justice in October 2024 and the Austrian Federal Cartel Attorney on 2 December 2024, under Directive (EU) 2020/1828. That framework contemplates compensation in the range of 100 to 1,000 euros per affected user for non-material damage. The 500 euros noyb cites for SCHUFA sits in the middle of that band. Multiplied against 1.6 million people a year, the arithmetic reaches figures well beyond the 20 million euro administrative ceiling AlgorithmWatch is asking the Hessian regulator to impose.
Context for the size of that exposure: national authorities across Europe issued a combined 1,145,760,374 euros in GDPR fines during 2025, according to the European Data Protection Board annual report published in April 2026. Separate analysis covered by PPC Land found that nearly 40 percent of the 7.1 billion euros in announced GDPR fines have been annulled or are under active legal challenge, which is part of why civil litigation by qualified entities has become an increasingly used route.
noyb states it has filed around 800 cases and is funded by more than 5,000 supporting members. SCHUFA has not published a response to the cease-and-desist letter.
Timeline
- December 2023: SCHUFA's Article 14 information notice, still the current version, states that retention periods are set in a code of conduct maintained by Die Wirtschaftsauskunfteien e. V.
- December 2023: The Court of Justice of the European Union decides case C-634/21 on SCHUFA credit scoring, establishing that automated processing constitutes prohibited decision-making under Article 22 when it plays a decisive role, as later applied by an Austrian court
- 11 October 2024: The Irish Ministry of Justice approves noyb for collective redress actions
- 2 December 2024: The Austrian Federal Cartel Attorney grants the same approval
- Spring 2025: The Hessian Data Protection Authority begins examining SCHUFA's data tests
- 17 June 2025: noyb files lawsuits against the data protection authorities in Hesse and North Rhine-Westphalia over inaction on consent complaints
- 19 August 2025: An Austrian court mandates greater transparency in automated credit decisions
- 25 September 2025: The Austrian Data Protection Authority rules fully automated credit scoring unlawful
- 14 October 2025: Germany's Federal Court of Justice permits telecoms operators to transmit positive contract data to SCHUFA
- January 2026: A Wiesbaden court requires SCHUFA to explain individual score factors
- Spring 2026: SCHUFA presents its new score with substantial advertising expenditure
- 9 April 2026: The European Data Protection Board publishes its 2025 annual report recording 1,145,760,374 euros in GDPR fines
- 30 April 2026: noyb sues the Hamburg data protection authority over PimEyes
- 5 May 2026: noyb files a GDPR complaint against LinkedIn over profile visitor data withheld from access requests
- June 2026: The cut-off date noyb uses in its interest list for prior SCHUFA credit reports and data copies
- 13 July 2026: NDR broadcasts its report on the archive
- 15 July 2026: NDR publishes the written investigation; the Süddeutsche Zeitung runs its own version under the headline about SCHUFA's almost secret archive; AlgorithmWatch launches its petition
- 20 July 2026: An Austrian court holds that statistical credit-score inputs fall outside the GDPR definition of personal data
- 24 July 2026: SCHUFA publishes its response distinguishing productive and archived data holdings
- August 2026: A Berlin administrative court judgment on pre-visit SCHUFA checks by a solar firm is reported
- 26 August 2026: noyb sends its cease-and-desist letter to SCHUFA and opens the interest list for a possible class action
Related PPC Land coverage
- German court says SCHUFA must explain why credit scores hurt consumers - A Wiesbaden court ordered individualised explanations of the factors behind an 85.96 percent risk score under Article 15.
- German court permits telecoms to share customer data with SCHUFA for fraud - The Federal Court of Justice held that transmitting positive contract data to the bureau serves legitimate fraud prevention interests.
- Solar firm loses GDPR fight over Schufa checks run before site visits - A Berlin administrative court examined when a business is allowed to run a credit check during contract initiation.
- Statistical credit-score inputs fall outside GDPR, Austrian court rules - The macroeconomic parameters used to calculate a score were held not to be personal data in their own right.
- Austrian authority rules credit scoring fully automated decisions unlawful - KSV1870's automated risk indicators were found to constitute prohibited automated decision-making under Article 22.
- Austrian court mandates greater transparency in automated credit decisions - A credit agency breached Article 15 by inadequately disclosing its scoring logic and processing purposes.
- Austrian court rules employment algorithm complies with GDPR Article 22 - The decision distinguishes meaningful human review from perfunctory oversight, referencing the CJEU SCHUFA judgment.
- German DPAs face court action over 'Pay or OK' inactivity - noyb sued the Hesse and North Rhine-Westphalia authorities after nearly four years without a decision.
- noyb sues Hamburg DPA as PimEyes keeps scanning faces unhindered - A regulator acknowledged unlawful processing and declined to act meaningfully against it.
- noyb files GDPR complaint over LinkedIn's paywall for profile visitor data - Data available to paying subscribers was withheld from an Article 15 access request.
- dict.cc faces GDPR complaint over 1,741-partner consent click - A single banner click was treated as consent for more than 1,700 separate companies.
- Digital rights group NOYB gains EU-wide authority for collective data protection cases - The approvals that allow noyb to pursue injunctive and redress measures across the EU.
- EDPB 2025 annual report: EUR1.15bn in GDPR fines, new AI and DMA rules - The European enforcement totals against which any SCHUFA penalty would be measured.
- Eight years of GDPR: 40% of the EUR7.1B in fines annulled or under challenge - Analysis of how much announced enforcement survives judicial review.
- Hesse data protection authority fines IT company EUR10,000 for email marketing - An example of the enforcement scale at the authority responsible for supervising SCHUFA.
- Criminal charges filed against Clearview AI after regulatory fines fail - noyb's earlier move from administrative complaints to criminal referral when fines went unenforced.
Summary
Who: noyb, the Vienna-based European Centre for Digital Rights, acting against SCHUFA Holding AG of Wiesbaden, Germany's dominant credit bureau. Named individuals include noyb lawyers Martin Baumann and Marco Blocher, noyb chair Max Schrems, Matthias Spielkamp of AlgorithmWatch, University of Bayreuth professor Ruth Janal, Claudio Zeitz-Brandmeyer of the Federation of German Consumer Organisations, and lawyers Raphael Rohrmoser and Peter Hense.
What: A cease-and-desist letter demanding that SCHUFA stop retaining records past its stated deletion periods, disclose historical data in Article 15 access responses, and provide transparency about its processing. An injunction action follows if the company refuses. An online interest list has opened for a possible class action, with immaterial damages estimated at around 500 euros per person and roughly 1.6 million people a year said to have received incomplete access responses.
When: The letter was sent today. The underlying reporting by NDR and the Süddeutsche Zeitung appeared on 15 July 2026, SCHUFA published its rebuttal on 24 July 2026, and the Hessian Data Protection Authority has been examining the practice since spring 2025.
Where: Germany, with SCHUFA supervised by the Hessian Data Protection Authority because of its Wiesbaden headquarters. noyb's collective redress authority operates EU-wide under Directive (EU) 2020/1828.
Why: SCHUFA maintains an archived data holding alongside its productive database, retaining records for up to ten years for purposes including score backtesting, and does not surface those records in Article 15 data copies. Historical scores derived from that archive are transmitted to banks, telecoms operators, energy suppliers, retailers, eCommerce providers and payment service providers for model validation. noyb argues the retention breaches storage limitation and the non-disclosure breaches the right of access. SCHUFA argues both rest on complementary legal bases, including supervisory obligations on banks. The Hessian authority has not concluded its review after more than a year.
Discussion