Privacy group takes aim at credit agency over hidden “shadow database”
You can't ask to see these records.

Image by Shutterstock
- Noyb alleges SCHUFA kept old credit data in a hidden database instead of deleting it.
- SCHUFA reportedly holds data on more than 69 million people in Germany.
- Noyb says SCHUFA failed to disclose hidden historical data when people requested their records.
- Noyb may file a class-action lawsuit if SCHUFA does not stop the practice.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Noyb is accusing German credit agency SCHUFA of unlawfully keeping the personal information of millions of people in a hidden “shadow database,” even though it was supposed to be deleted.
SCHUFA is a credit rating agency in Germany. Anyone who needs a loan, a mobile phone contract, or to sign a lease for a rental car has to provide detailed financial information to the firm to get a credit rating. Reportedly, it holds data on more than 69 million people.
In July, the German news outlets NDR and SZ reported that SCHUFA secretly stored outdated data from millions of customers beyond its self-imposed retention periods. This includes settled loans, personal bankruptcies, and other debts.
However, instead of deleting this historical information, the credit rating agency kept it hidden from the public. As a matter of fact, the data continues to be processed behind the scenes and is even used for third parties’ credit score validations.
According to Martin Baumann, data protection lawyer at noyb, SCHUFA’s so-called “shadow database” is a textbook example of unlawful data processing.
“SCHUFA secretly processes data which, according to its own statements, should have been deleted long ago, and ultimately makes money from doing so,” he says.
To make matters worse, when people invoke their right to request a copy of their personal information that’s been stored by the company, they don’t receive a copy of the historical data that’s accumulated in the “shadow database.”
This is a violation of Article 15 of the General Data Protection Regulation (GDPR), which states that people have the right to obtain all data that’s been processed by a business. It’s not up to a company to decide what data needs to be disclosed: a data copy must be a complete and faithful reproduction of all processed data.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
As a result, noyb has sent SCHUFA a cease-and-desist letter. The privacy advocacy group is demanding that the credit rating firm immediately stop storing data beyond the specified retention periods.
In addition, SCHUFA must disclose historical data to affected individuals who submit an information request. Lastly, the agency has to become more transparent about its data-processing practices.
If SCHUFA fails to meet these demands, noyb will potentially launch a class-action lawsuit.
“SCHUFA has not only broken the law – it has lied to and harmed those affected. We intend to seek compensation for these damages on a non-profit basis,” Max Schrems, Chair of noyb, said.