‘Shadow database’ scandal: noyb sends SCHUFA cease-and-desist letter; interest list for class action opened

Credit Scoring
 /  26 June 2026

In mid-July, investigations by NDR and the SZ revealed that the credit information agency SCHUFA stores millions of data records that should have been deleted long ago. It has since become clear that SCHUFA also uses this data for its customers’ ‘testing purposes’. Potentially, all 69 million people on whom SCHUFA holds data are affected. And SCHUFA continues to stonewall: Even in response to access requests under Article 15 GDPR, the company refuses to disclose this historical data. Given the obvious GDPR violations, noyb has now issued a formal warning to the credit information agency and announced an injunction. Data subjects whose historical data has been withheld by SCHUFA can also register their interest in a future class action for damages.

SCHUFA Schattendatenbank Header

SCHUFA and its transparency promise. In Germany, there is virtually no way around SCHUFA. Anyone who wants a loan, a mobile phone contract or a rental apartment must hope that the powerful credit information agency confirms that they have a sufficient credit rating. However, the way in which SCHUFA arrives at its credit scores has always been a black box – and, as a result, has regularly been the subject of criticism and legal proceedings, right up to the European Court of Justice. Recently, SCHUFA launched a ‘transparency campaign’ and has since been celebrating itself for having created ‘complete transparency’.

A basement full of ‘deleted’ data. According to the SCHUFA privacy policy, the retention period for data used to calculate the credit score is also to be determined by self-imposed codes of conduct. Debt collection claims or data on settled loans, for example, would be deleted three years after payment. However, ‘deleted’ apparently means something quite different to SCHUFA than it does under the GDPR – and to the general public: the data is apparently only ‘hidden’ and thus disappears from view of consumers, but not from SCHUFA’s systems. Quite the contrary: the data continues to be processed behind the scenes and is even used for third parties’ ‘credit score validations’.

Martin Baumann, data protection lawyer at noyb: “SCHUFA’s ‘shadow database’ is a textbook example of unlawful data processing. SCHUFA secretly processes data which, according to its own statements, should have been deleted long ago, and ultimately makes money from doing so."

Right of access flatly denied. SCHUFA becomes thoroughly inconsistent when it comes to the right of access: on the one hand, SCHUFA claims that the previously unknown ‘shadow database’ is entirely transparent. On the other hand, it admits that data subjects do not receive a copy of the historical data still stored when making an access request under Article 15 GDPR. In essence, SCHUFA argues that data subjects are only interested in which data is currently factored into their score. The data stored secretly therefore does not need to be disclosed. Legally speaking, this is a completely absurd line of reasoning. A company cannot simply limit its obligation to provide information to data which it itself deems ‘of interest’ to data subjects. The European Court of Justice has long since made it clear: a data copy must be a complete, faithful reproduction of all processed data.

Marco Blocher, data protection lawyer at noyb: “It is clearly unlawful for SCHUFA to store data that has supposedly been ‘deleted’ in a ‘shadow database’ but not to disclose it. SCHUFA is blatantly breaking the law here and those in charge at SCHUFA are probably well aware of this.”

Hessian supervisory authority remains inactive. In theory, the Hessian Data Protection Authority (HBDI) is supposed to oversee SCHUFA. In fact, the supervisory authority appears to have been aware of the ‘shadow database’ since spring 2025. However, the (notoriously inactive) authority seems to still protect SCHUFA. As a state-approved Qualified Entity, noyb has therefore taken action to protect consumers from SCHUFA’s unrestrained data-hoarding and secrecy. Compliance with the GDPR is now to be restored in several stages:

Step 1: Cease-and-desist letter and injunction: noyb has today sent a cease-and-desist letter to SCHUFA. With it, noyb requests that the credit information agency ceases to store data beyond the specified retention periods. In addition, noyb requests that SCHUFA provides affected individuals with historical data as part of their access requests and ensures transparency regarding its data processing practices. Should the credit information agency refuse to comply with these requests, noyb will bring an action for an injunction to have SCHUFA’s unlawful practices prohibited by the courts.

Max Schrems, Chair of noyb: “Unfortunately, we are increasingly witnessing a breakdown of the public data protection authorities in Germany. We must therefore take legal action as a non-profit organisation acting in the public interest.”

Possible step 2: Class action: Data subjects whose data is (or was) stored in the ‘shadow database’ and who have sent an access request under Article 15 GDPR to SCHUFA in recent years may have suffered non-material damages. According to its own information, SCHUFA stores data on more than 69 million people – which is almost the entire adult population in Germany. It appears that 1.6 million people a year have received incorrect responses to their access requests: Historical data wasn’t provided to anyone. Typically, immaterial damages can be estimated at around €500 per person.

A class action requires significantly more preparation than an injunction. Nevertheless, noyb has already set up an online interest list. Anyone can sign up here to be informed at a later date, should legal action be taken. As a donation-funded organisation, noyb takes legal action solely in the interests of those affected.

Max Schrems, Chair of noyb: “SCHUFA has not only broken the law, it has lied to and harmed those affected. We intend to seek compensation for these damages on a non-profit basis.”

A broad civil society front. Other NGOs and data protection experts are also massively criticising SCHUFA and demanding that the ‘shadow database’ be deleted. The NGO AlgorithmWatch has launched a petition against SCHUFA and the data protection authority in Hesse, which has failed to take action. It also provides a form that allows those affected to request specific information about their historical data from SCHUFA.

Matthias Spielkamp, AlgorithmWatch: “We and nearly 145,000 signatories to our petition are demanding: SCHUFA must provide those affected with full information; the Hessian Data Protection Authority must finally take action and oblige SCHUFA to permanently delete the ‘shadow database’, and impose the maximum possible fine.

Most recently, several lawyers have also voiced critical views and pointed out possible further consequences:

Raphael Rohrmoser, partner at AdvoAdvice Rechtsanwälte: “There have already been countless court cases against SCHUFA concerning the right of access and the right to erasure. It has now emerged that ‘deleted’ data is in fact still extensively available and that nobody was informed. This raises the key question of whether the information provided by SCHUFA in the court proceedings was always accurate.

Peter Hense, partner at Spirit Legal Rechtsanwälte: “If a credit agency passes on data labelled as ‘deleted’ to third parties in return for payment, this may constitute a criminal offense. Perhaps we need the public prosecutor’s office and the courts to finally drain the SCHUFA data swamp.”

Share