noyb, the Vienna-based privacy group founded by Max Schrems, sent German credit reference agency SCHUFA a cease-and-desist letter on August 26, 2026, alleging the company operates a "shadow database" that retains consumer records long after GDPR-mandated retention periods should have erased them. According to noyb's release, the practice potentially touches up to 69 million people — nearly the entire adult population of Germany — and the group has opened a public interest list toward a follow-on class action.
What noyb Alleges
The complaint centers on two GDPR provisions: Article 15, the right of access, and Article 17, the right to erasure. noyb says SCHUFA's own code of conduct commits to deleting debt-collection and settled-loan records three years after payment, but that the underlying data continues to be processed behind the scenes — reportedly reused for "testing purposes" and third-party credit-score validations — even after it disappears from what a consumer sees when they request their file. noyb lawyer Marco Blocher put it plainly: "It is clearly unlawful for SCHUFA to store data that has supposedly been 'deleted' in a 'shadow database' but not to disclose it." noyb further estimates that roughly 1.6 million people a year receive incomplete responses to Article 15 access requests, because the historical data simply isn't included. SCHUFA disputes the characterization, telling The Local that its processing "complies with legal and regulatory requirements" and that deleting the data "would be harmful for consumers and the economy."
The Steelman: Why Credit Bureaus Want to Keep Old Data
SCHUFA's defense isn't frivolous. Credit scoring models are only as reliable as the data used to validate them, and a scoring agency that deletes every record the moment a debt is settled loses the ability to backtest whether its risk models actually predict default. Regulators themselves require credit institutions to validate scoring models against historical outcomes under EU prudential rules, and a bureau serving that function has a real institutional interest in retaining a research dataset even after individual consumer-facing files are cleared. There's a coherent argument that outright deletion could degrade score accuracy for everyone, including the "good" borrowers the system is meant to protect. That's the trade-off GDPR's retention-limitation principle is supposed to force controllers to make explicitly and disclose — not resolve unilaterally by keeping the data anyway and calling it hidden rather than deleted.
Why This Isn't an Isolated Complaint
This isn't SCHUFA's first brush with EU data law. In December 2023 the Court of Justice of the European Union ruled in Case C-634/21 that SCHUFA's automated credit scoring itself constitutes "automated individual decision-making" under Article 22 GDPR — meaning the bureau, not just the banks relying on its scores, bears direct compliance obligations. The shadow-database complaint extends that scrutiny from how SCHUFA scores people to how long it keeps the data behind those scores.
The broader pattern matters more than any single company. The European Data Protection Board's Coordinated Enforcement Framework report on the right to erasure, published February 18, 2026, surveyed 764 controllers across 32 national data protection authorities and found retention-period determination and deletion-in-backups among the most persistent compliance failures in the entire regulation. Some controllers, the EDPB found, were substituting "inefficient anonymisation techniques" for actual deletion — functionally the same complaint noyb is now making against SCHUFA at much larger scale. Article 17 (as anchored in GDPR Regulation (EU) 2016/679) has been law since 2018. Eight years on, an EU-wide regulatory sweep still finds erasure to be the right most honored in the breach.
The Proportionate Regulation Case
That gap is precisely why this is a case worth defending, not resisting, from a pro-innovation standpoint. GDPR's critics are right that vague, over-broad compliance obligations chill useful data processing — genuine model validation is exactly the kind of legitimate interest the regulation should accommodate through documented retention schedules and purpose limitation, not blanket bans. But that only works if the disclosure half of the bargain holds: a company can argue for retaining validation data, but it cannot simultaneously tell consumers under Article 15 that their file is clean while quietly using the same data commercially. That's not a disagreement about how long retention should be; it's a transparency failure, and transparency failures are exactly what erasure and access rights exist to police without banning data reuse outright.
noyb's history is instructive here: the group has previously forced court and regulatory action against Meta, Google, and Grindr over consent design rather than data use itself. The SCHUFA case fits the same mold — it isn't an attack on credit scoring as a business, but a test of whether the "delete" button an EU consumer is legally promised actually deletes anything. If SCHUFA's shadow database holds up under EDPB and national DPA scrutiny, the practical lesson for every controller managing legacy retention systems is that "hidden from the user" and "erased" are not the same thing under EU law — and regulators are finally resourced enough, eight years in, to notice the difference.