The Allegation
On August 26, 2026, the Austrian privacy group noyb sent a formal cease-and-desist letter to SCHUFA Holding AG, Germany's dominant credit bureau, alleging that the company operates a "shadow database" holding historical records on essentially its entire customer base — up to 69 million people, close to Germany's adult population (noyb). The allegation, which followed a mid-July 2026 investigation by NDR and Süddeutsche Zeitung, is that SCHUFA retains debt-collection and settled-loan records well past the deletion periods it publishes in its own code of conduct — by some accounts for up to a decade — and then declines to disclose that historical data when consumers file access requests under Article 15 of the GDPR (ppc.land). noyb estimates roughly 1.6 million access requests a year have received incomplete answers as a result, and has opened a sign-up list for a future class action seeking damages of around €500 per affected person.
Not SCHUFA's First GDPR Reckoning
This is SCHUFA's second serious brush with GDPR enforcement in three years. In December 2023, the Court of Justice of the EU ruled in SCHUFA Holding (Scoring), Case C-634/21, that when a credit bureau generates a score that lenders treat as decisive, the bureau itself — not just the bank relying on it — is subject to Article 22's restrictions on automated decision-making (CJEU press release). That ruling established that SCHUFA cannot hide behind its customers' contractual relationships with borrowers to avoid GDPR obligations attaching directly to its own processing. The shadow-database allegation follows the same pattern: a company treating a core data protection duty — this time storage limitation and access rights rather than automated decision-making — as negotiable so long as no one outside the company can see the underlying architecture.
Steelmanning SCHUFA's Position
SCHUFA's defense, as reported, is that the archived data is "not only permissible, but necessary" to validate and audit its risk-scoring models, and that deleting it prematurely would harm both consumers and the broader credit market by degrading score accuracy (The Local). This is a genuinely serious argument. Credit-scoring models require historical ground truth — did a person who looked risky at time X actually default? — to be back-tested and recalibrated, and financial regulators in Germany and the EU do expect credit bureaus and lenders to retain model-validation data for defined periods. A blanket rule requiring instant deletion of every record the moment a consumer's active file is cleared could make scoring models less accurate for everyone, which is not obviously a pro-consumer outcome. GDPR itself recognizes this trade-off: Article 5(1)(e)'s storage-limitation principle permits longer retention for statistical or research purposes, provided appropriate safeguards — typically pseudonymization — are applied.
Where the Steelman Breaks Down
The problem is not that SCHUFA retains data for model validation; it is that it appears to have done so silently, in a form indistinguishable enough from live data that it could not honestly answer an Article 15 request without revealing the practice. The EDPB's Guidelines 01/2022 on the right of access are explicit that the right of access carries no general proportionality carve-out for the controller's convenience, and that a controller cannot narrow its search to only the systems it finds easiest to query (EDPB Guidelines 01/2022). If SCHUFA genuinely believed its archived records qualified for a lawful retention exception, the GDPR-compliant path was to disclose that exception openly — in its privacy notice and in response to access requests — not to keep the archive undisclosed until investigative journalists found it. A retention practice that cannot survive being named to the people it affects is not a proportionality judgment; it is an access-rights violation wearing a data-governance justification.
The Real Lesson Is Enforcement, Not New Rules
The instructive part of this story for policymakers is what didn't happen: no data protection authority caught this. It took NDR and SZ's reporting, followed by an NGO's cease-and-desist, to surface a practice affecting nearly all of Germany's adult population. Hesse's data protection authority, which supervises SCHUFA, has not been reported as having flagged the issue independently. That is an argument for the EU and its member-state regulators to direct existing audit and coordinated-enforcement resources — the same kind used in the EDPB's 2024 right-of-access sweep — toward high-impact controllers like credit bureaus, rather than for legislators to draft new statutory obligations SCHUFA is already bound by. The GDPR's storage-limitation and access-right provisions are not the weak link here; investigative capacity is. Piling additional rules onto controllers broadly, including smaller fintechs that pose none of SCHUFA's near-monopoly risk, would raise compliance costs across the market without addressing the actual failure: a dominant incumbent quietly deciding its own disclosure obligations didn't apply to it. If noyb's injunction proceeds and forces disclosure, that outcome vindicates the GDPR as written — proof that proportionate, existing law can discipline market power without a new regulatory instrument.