What happened
In July 2026, the NGO noyb issued a cease‑and‑desist letter to German credit agency SCHUFA demanding it stop storing data beyond retention periods and provide full historical data under Article 15 GDPR. The organization warned it will seek an injunction if SCHUFA does not comply and opened an interest list for a possible class action.
Why it matters for trust and compliance
- Its status is announced. It is not law yet. Track it, but do not treat it as an obligation.
- The action targets a potential GDPR breach affecting up to 69 million Germans and could lead to a large‑scale class action.
- Takes effect August 26, 2026.
- It relates to GDPR. The regulations library explains what that law requires.
Who is affected
financial services controller data broker SCHUFA noyb
Recommended actions
- Check that privacy notices describe the practices this addresses.
- Confirm access, correction, deletion and opt-out requests are handled within the required time.
- Revisit retention schedules and data minimisation for the data involved.
- Inventory where this data is shared or sold and whether opt-outs are honoured.
- Inventory AI or automated decision systems in scope and their assessments.