REGULATORY WATCH BRIEF Low 39 ⚖️ Enforcement Action filed

noyb files injunction against Austrian credit agency CRIF over GDPR violations

The injunction could halt a large‑scale secret credit scoring system and set a precedent for collective GDPR enforcement in the EU.

ImpactLow 39
Type⚖️ Enforcement Action
Statusfiled case open
JurisdictionEU-AT

What happened

noyb, a state‑approved qualified entity, filed an injunction against CRIF to stop its alleged unlawful collection and scoring of personal data under the GDPR. The filing also suspends the limitation period and prepares a subsequent class action for damages. The case targets a secret "shadow registry" that influences contracts with telecom, energy and banking providers.

Why it matters for trust and compliance

  • Its status is filed. The case is still open; the outcome may change what it means.
  • The injunction could halt a large‑scale secret credit scoring system and set a precedent for collective GDPR enforcement in the EU.
  • It relates to GDPR. The regulations library explains what that law requires.

Who is affected

financial services telecommunications energy retail media technology advertising controller processor data broker CRIF GmbH noyb Schibsted Norwegian Consumer Council

Recommended actions

  1. Review consent, cookie and tracking practices against the requirement.
  2. Check that privacy notices describe the practices this addresses.
  3. Revisit retention schedules and data minimisation for the data involved.
  4. Inventory where this data is shared or sold and whether opt-outs are honoured.
  5. Inventory AI or automated decision systems in scope and their assessments.