noyb files injunction against Austrian credit agency CRIF over GDPR violations
The injunction could halt a large‑scale secret credit scoring system and set a precedent for collective GDPR enforcement in the EU.
ADTP Regulatory Watch· June 9, 2026· EDPB
ImpactLow 39
Type⚖️ Enforcement Action
Statusfiledcase open
JurisdictionEU-AT
What happened
noyb, a state‑approved qualified entity, filed an injunction against CRIF to stop its alleged unlawful collection and scoring of personal data under the GDPR. The filing also suspends the limitation period and prepares a subsequent class action for damages. The case targets a secret "shadow registry" that influences contracts with telecom, energy and banking providers.
Why it matters for trust and compliance
Its status is filed. The case is still open; the outcome may change what it means.
The injunction could halt a large‑scale secret credit scoring system and set a precedent for collective GDPR enforcement in the EU.
It relates to GDPR. The regulations library explains what that law requires.
Who is affected
financial servicestelecommunicationsenergyretailmediatechnologyadvertisingcontrollerprocessordata brokerCRIF GmbHnoybSchibstedNorwegian Consumer Council
Recommended actions
Review consent, cookie and tracking practices against the requirement.
Check that privacy notices describe the practices this addresses.
Revisit retention schedules and data minimisation for the data involved.
Inventory where this data is shared or sold and whether opt-outs are honoured.
Inventory AI or automated decision systems in scope and their assessments.