Privacy group noyb today sent a cease-and-desist letter to Germany's dominant credit bureau and opened a sign-up list for a possible damages action, six weeks after broadcasters revealed a second, undisclosed store of consumer records.

The European Centre for Digital Rights, better known as noyb, today issued a formal warning to SCHUFA Holding AG and announced that it will seek a court injunction if the company does not change its practices. The letter concerns what German media have called a shadow database: an archive of historical consumer records that, according to noyb, should have been erased under the retention periods SCHUFA itself publishes.

The dispute began on 15 July 2026, when public broadcaster NDR and the Süddeutsche Zeitung published parallel investigations. According to the NDR report written by Peter Hornung, alongside the official SCHUFA database there exists a second collection of historical data on millions of consumers, containing information that reaches back years and that affected individuals assumed had long been deleted. The report listed old loans and credit cards, wage garnishments, private insolvencies, and debts that borrowers had often settled years earlier.

SCHUFA does not dispute the existence of the archive. It disputes the framing, the legal characterisation, and the word database itself.

What noyb is asking for

The cease-and-desist letter sets out three demands. According to noyb, SCHUFA must stop storing data beyond the specified retention periods, must supply affected individuals with their historical data as part of access requests, and must ensure transparency about its processing practices. Should the company refuse, noyb states it will bring an action for an injunction to have the practices prohibited by the courts.

That is step one. Step two, described in the announcement as possible rather than certain, is a class action for damages.

The scale claimed is unusual even by the standards of German privacy litigation. According to noyb, potentially all 69 million people on whom SCHUFA holds data are affected, a figure the organisation notes is close to the entire adult population of Germany. The announcement further states that around 1.6 million people a year received incorrect responses to their access requests, on the basis that historical data was never provided to anyone. Typical immaterial damages, according to noyb, can be estimated at around 500 euros per person.

An online interest list is already live. The registration form asks two questions that define the likely claimant pool: whether the person purchased a SCHUFA BonitätsAuskunft before June 2026, and whether they requested the free data copy under Article 15 of the General Data Protection Regulation, either directly or through a third-party provider, before that same month.

Martin Baumann, data protection lawyer at noyb, said in the announcement that the archive is a textbook example of unlawful data processing, arguing that SCHUFA secretly processes data which by its own account should have been deleted long ago, and ultimately makes money from doing so.

The retention argument

The technical heart of the dispute is what deletion means.

According to the SCHUFA privacy policy, the retention period for data used to calculate the credit score is determined by self-imposed codes of conduct. The company's Article 14 information notice, dated December 2023, states that retention periods are set out in a code of conduct maintained by the industry association Die Wirtschaftsauskunfteien e. V. Debt collection claims and data on settled loans, for example, are deleted three years after payment.

noyb's reading is that deletion in SCHUFA's usage means something narrower than deletion under the GDPR. The data, according to the announcement, is only hidden. It disappears from the consumer's view but not from the company's systems, where it continues to be processed and is used for what noyb describes as credit score validations performed for third parties.

SCHUFA published its own account on 24 July 2026 under the headline "Die Wahrheit über die vermeintliche 'Schattendatenbank'", or the truth about the alleged shadow database. The company draws a line between what it calls the productive data holding and the archived data holding. According to SCHUFA, the productive holding contains current credit information on around 69 million people in Germany and supports approximately 350,000 disclosures per day. Archived records sit separately from that holding, are immutable for audit reasons, and have no influence on a consumer's current creditworthiness assessment.

SCHUFA sets out five purposes for archiving: regulatory control and documentation obligations towards data protection authorities and courts, compliance with score development requirements under Section 31 of the German Federal Data Protection Act and Article 5 of the GDPR, quality assurance of scores, support for banks meeting supervisory requirements, and research and development.

On duration, the company gives numbers that sit awkwardly against the shadow-database framing. According to SCHUFA, archived historical data is subject to purpose-bound retention periods of at most ten years. The worked example offered is a bank credit enquiry: the transmitted data and the calculated score are deleted from the archive after five years at the latest, once the purpose of storage, such as legal defence, has lapsed.

One exception, and who receives it

SCHUFA's own document contains the concession that gives the story its commercial edge.

According to the company, no external party has access to historical data in the archive, and only legitimated SCHUFA personnel can reach it. There is, it states, exactly one case in which a personal historical data point is passed on: when banks and other companies check the forecast quality of a new score model before deploying it in practice. Those companies receive scores calculated on historical data for their testing purposes. Banks, SCHUFA notes, are required by supervisory law to perform such backtestings.

The NDR reporting describes the same mechanism in less clinical terms. According to that account, SCHUFA calculates, at the request of corporate customers such as banks, the creditworthiness of consumers for a specific day in the past, on a test basis only. Such historically calculated scores allow customers to be shown how reliable the new SCHUFA score is, the score the company presented in spring with substantial advertising expenditure and is now marketing.

The recipient list widens the picture considerably. According to NDR, alongside banks the results can go to telecommunications firms, energy suppliers, large retailers, eCommerce providers and payment service providers. NDR and the Süddeutsche Zeitung sent dozens of enquiries to companies in those categories. Only three responded affirmatively: one bank, one payment service provider and one energy supplier admitted using such historical SCHUFA data. Many answered evasively, some not at all, and several suggested the reporters ask SCHUFA directly.

SCHUFA told the broadcasters that handling of the data is contractually restricted strictly to test and control purposes, and that it must be deleted at the banks and other companies once the tests are complete.

Claudio Zeitz-Brandmeyer of the Federation of German Consumer Organisations put the counterargument to NDR. Translated from German, he said the arrangement is problematic because it is very tempting for the companies receiving the data to use it not only for test purposes but also, for instance, to actually draw on it for credit decisions.

The access-request problem

The second limb of noyb's complaint concerns Article 15 of the GDPR, and it is the limb most likely to produce a court ruling with consequences beyond credit reporting.

According to noyb, SCHUFA is inconsistent: it presents the archive as entirely transparent while admitting that data subjects do not receive a copy of stored historical data when they make an access request. The reasoning attributed to SCHUFA is that data subjects are only interested in which data currently feeds their score. noyb's response is that a company cannot limit its information obligation to data it deems of interest, and that the Court of Justice of the European Union has established that a data copy must be a complete and faithful reproduction of all processed data.

SCHUFA's public position, as reported by NDR, is close to that summary. The company wrote on its website in the days before the investigation appeared that consumers mainly want to know how their current creditworthiness stands and which data influences their score, which is not the case for historical data. That statement, according to NDR, was the first time SCHUFA itself made the existence of such historical data public, and it followed enquiries from the two newsrooms.

Ruth Janal, professor at the University of Bayreuth and a specialist in data protection and consumer credit law, rejected that position in blunt terms. Translated from German, she said the idea that consumers need not learn about such storage is nonsense, and that the right of access anchored in the GDPR naturally covers the data SCHUFA describes as historical.

Janal also questioned the tests themselves. Translated from German, she told NDR that historical scores give a certain insight into the financial situation of the affected persons in the past, and that this is simply none of SCHUFA's contract partners' business. On the archive as a whole, she said permanent storage of such historical data on stock for indeterminate future purposes is not permissible under the case law of the Court of Justice of the European Union, adding that verifying the reliability of scores would be possible with a considerably smaller dataset.

Marco Blocher, data protection lawyer at noyb, framed the access question as the clearer of the two violations, stating that it is unlawful for SCHUFA to store supposedly deleted data in a shadow database and then not disclose it.

A supervisory authority that has been looking since spring 2025

Both the reporting and the noyb announcement converge on the Hessian Data Protection Authority, which supervises SCHUFA because the company is headquartered in Wiesbaden.

According to NDR, the Hessian commissioner has been examining the data tests since spring 2025, reviewing their legal basis and the question of whether consumers must be informed via the data copy. The procedure, the authority said on enquiry, is not yet concluded.

noyb's characterisation is sharper. The organisation states that the authority appears to have known about the archive since spring 2025 and describes it as notoriously inactive. As a state-approved qualified entity, noyb says it has therefore taken action itself.

Max Schrems, chair of noyb, said the organisation is increasingly witnessing a breakdown of the public data protection authorities in Germany, and must therefore take legal action as a non-profit acting in the public interest. In a second statement he said SCHUFA has not only broken the law but lied to and harmed those affected, and that noyb intends to seek compensation on a non-profit basis.

The Hessian authority has been on the receiving end of this argument before. noyb sued data protection authorities in Hesse and North Rhine-Westphalia in June 2025 over nearly four years of inaction on pay-or-okay consent complaints against faz.net and t-online.de. It sued the Hamburg authority in April 2026 after the regulator acknowledged that facial recognition service PimEyes operates unlawfully and then declined to act meaningfully.

The civil society front and the criminal question

AlgorithmWatch launched a petition on 15 July 2026 addressed to SCHUFA chief executive Tanja Birkholz and Alexander Roßnagel, the Hessian data protection commissioner. The petition demands immediate deletion of the archive and asks the regulator to conclude its review and, if it finds the database unlawful, to impose the maximum possible penalty of 20 million euros. The signature counter on the petition page stood at 145,769 against a target of 200,000.

Matthias Spielkamp of AlgorithmWatch told NDR that the scale of the matter can hardly be overestimated, and that SCHUFA must answer the question of what degree of irresponsibility prevails there. In the noyb announcement he is quoted stating that the organisation and nearly 145,000 petition signatories demand full information for those affected, action from the Hessian authority to compel permanent deletion, and the maximum possible fine.

Two practitioners raise consequences that go past administrative law. Raphael Rohrmoser, partner at AdvoAdvice Rechtsanwälte, said countless court cases have already run against SCHUFA over the right of access and the right to erasure, and that the emergence of extensively available deleted data raises the key question of whether the information SCHUFA provided in those proceedings was always accurate.

Peter Hense, partner at Spirit Legal Rechtsanwälte, went further, stating that if a credit agency passes on data labelled as deleted to third parties in return for payment, this may constitute a criminal offense.

Numbers that do not line up

Three population figures circulate in the source material, and they do not match. noyb and SCHUFA both cite more than 69 million people. AlgorithmWatch, citing SCHUFA's own published figures, refers to payment behaviour data on 68 million persons. Court filings covered by PPC Land in November 2025, when Germany's Federal Court of Justice permitted telecoms operators to transmit positive contract data to SCHUFA, recorded 943 million records on 67.9 million individuals. The differences plausibly reflect measurement dates rather than dispute, but no source reconciles them.

A second gap is more material. SCHUFA states a maximum archive retention of ten years, and five years for credit enquiry records. noyb states that data which should have been deleted long ago is still stored. Neither the company statement nor the noyb announcement identifies which record categories exceed which limit, and the primary reporting does not supply a figure for how far back the oldest retained records reach beyond the general statement that they go back years.

A third tension sits inside SCHUFA's own document. The company states that no external party accesses archived data, then describes the backtesting exception in which historical scores calculated on that data are transmitted to banks and other companies. Both statements can be true simultaneously, since a derived score is not the underlying record, but the distinction carries the entire weight of the company's no-external-access claim.

Why this matters beyond credit reporting

The mechanics under challenge here are not specific to credit bureaus. Retaining records past their stated deletion date in order to validate a model, hiding those records from the interface a data subject can see, and transmitting model outputs rather than raw records to commercial partners are all patterns that recur across advertising and measurement infrastructure.

Model validation on retained historical data is standard practice in attribution modelling, audience scoring, and clean room analytics. The legal question noyb has put to SCHUFA is whether purpose limitation and storage limitation permit a controller to keep an indefinite backtesting corpus at population scale. If a court answers that in the negative, the reasoning transfers directly to any organisation holding a historical event store for model quality assurance.

The Article 15 argument transfers just as cleanly. A data copy that reflects only the records currently feeding an active system, while excluding archived records that are still processed, is a design pattern rather than an accident. noyb has already tested a version of this argument against advertising-adjacent platforms: it filed a complaint against LinkedIn in May 2026 over profile visitor data available to paying subscribers but withheld from access requests, and it challenged dict.cc over a consent banner listing more than 1,700 technology partners.

German credit data has been under sustained judicial pressure throughout the period. A Wiesbaden court ordered SCHUFA to give individualised explanations of the factors producing a score in January 2026. Austrian regulators found fully automated credit scoring unlawful under Article 22 in September 2025, and an Austrian court required greater disclosure of scoring logic the month before. In July 2026 an Austrian court held that the macroeconomic statistical parameters feeding a score are not themselves personal data, a ruling that narrows one route while leaving the transparency route open. A Berlin administrative court upheld a warning against a solar firm that ran SCHUFA checks before site visits in a judgment reported in August 2026.

The damages exposure is the part that will register on balance sheets. noyb secured EU-wide collective redress authoritythrough approvals from the Irish Ministry of Justice in October 2024 and the Austrian Federal Cartel Attorney on 2 December 2024, under Directive (EU) 2020/1828. That framework contemplates compensation in the range of 100 to 1,000 euros per affected user for non-material damage. The 500 euros noyb cites for SCHUFA sits in the middle of that band. Multiplied against 1.6 million people a year, the arithmetic reaches figures well beyond the 20 million euro administrative ceiling AlgorithmWatch is asking the Hessian regulator to impose.

Context for the size of that exposure: national authorities across Europe issued a combined 1,145,760,374 euros in GDPR fines during 2025, according to the European Data Protection Board annual report published in April 2026. Separate analysis covered by PPC Land found that nearly 40 percent of the 7.1 billion euros in announced GDPR fines have been annulled or are under active legal challenge, which is part of why civil litigation by qualified entities has become an increasingly used route.

noyb states it has filed around 800 cases and is funded by more than 5,000 supporting members. SCHUFA has not published a response to the cease-and-desist letter.

Timeline

Summary

Who: noyb, the Vienna-based European Centre for Digital Rights, acting against SCHUFA Holding AG of Wiesbaden, Germany's dominant credit bureau. Named individuals include noyb lawyers Martin Baumann and Marco Blocher, noyb chair Max Schrems, Matthias Spielkamp of AlgorithmWatch, University of Bayreuth professor Ruth Janal, Claudio Zeitz-Brandmeyer of the Federation of German Consumer Organisations, and lawyers Raphael Rohrmoser and Peter Hense.

What: A cease-and-desist letter demanding that SCHUFA stop retaining records past its stated deletion periods, disclose historical data in Article 15 access responses, and provide transparency about its processing. An injunction action follows if the company refuses. An online interest list has opened for a possible class action, with immaterial damages estimated at around 500 euros per person and roughly 1.6 million people a year said to have received incomplete access responses.

When: The letter was sent today. The underlying reporting by NDR and the Süddeutsche Zeitung appeared on 15 July 2026, SCHUFA published its rebuttal on 24 July 2026, and the Hessian Data Protection Authority has been examining the practice since spring 2025.

Where: Germany, with SCHUFA supervised by the Hessian Data Protection Authority because of its Wiesbaden headquarters. noyb's collective redress authority operates EU-wide under Directive (EU) 2020/1828.

Why: SCHUFA maintains an archived data holding alongside its productive database, retaining records for up to ten years for purposes including score backtesting, and does not surface those records in Article 15 data copies. Historical scores derived from that archive are transmitted to banks, telecoms operators, energy suppliers, retailers, eCommerce providers and payment service providers for model validation. noyb argues the retention breaches storage limitation and the non-disclosure breaches the right of access. SCHUFA argues both rest on complementary legal bases, including supervisory obligations on banks. The Hessian authority has not concluded its review after more than a year.