Observed Signal · Jun 3, 2025 · Regulation · Source: Trending Topics · Impact: 3/5 · Sentiment: Negative
noyb to Sue CRIF Over Credit Scores for Millions of Austrians
Privacy advocacy group noyb, led by Max Schrems, announced plans to file a potential class action lawsuit against Austrian credit bureau CRIF over alleged GDPR violations. noyb claims CRIF unlawfully collects personal data such as address, age, and gender to generate 'creditworthiness scores' between 250 and 700 for millions of Austrians, which are then sold to banks, energy providers, and telecom companies. CRIF states it only possesses payment experience data for about 10% of the population, with scores for the rest derived largely from demographic attributes. noyb plans a scientific analysis of the scores using data donations from Austrians, in cooperation with a university, to determine if scoring is structurally flawed. CRIF denies the allegations, stating its scoring meets 'highest quality standards' and is required by consumer credit regulations. noyb says a class action could become the largest in Austria, potentially awarding damages to millions of affected consumers.
A major GDPR enforcement action in Austria against a large data broker selling scoring data to major banks, signaling increased regulatory risk for data-driven businesses relevant to the AdTech ecosystem.
Track Real-Time Privacy Signals & Market Shifts
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- noyb announced plans to file a class action lawsuit against Austrian credit bureau CRIF over alleged GDPR violations in credit scoring.
- CRIF reportedly creates creditworthiness scores (250-700) for millions of Austrians based on address, age, and gender.
- CRIF admits having payment experience data for only ~10% of the population; scores for the rest rely on demographic data.
- Scores are sold to banks including Volksbank Wien, Erste Bank, Raiffeisenbank, and Oberbank.
- noyb plans a scientific analysis of the scores using data donations and university collaboration, potentially leading to Austria's largest class action.
Ontology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Asos confirms data breach after rogue app notification
UK fashion retailer Asos has confirmed a data breach involving customers' personal information. Hackers broke into a third-party platform hosting data used for customer communications, stealing names, contact information, home addresses, phone numbers, email addresses, and customer profile notes including search queries. The hackers, calling themselves Xuanye Group, sent an unauthorized push notification through Asos' own app, referencing the compromise of data hosted on Snowflake, a cloud data platform. The notification pressured the company to engage or risk a leak. The attackers reportedly gained access by impersonating a trusted contact to obtain login credentials. Snowflake said its own systems were not breached. Asos has 17 million customers. The incident follows a similar breach at fintech firm Betterment earlier in the year.
German Federal Court Hears Cookie Storage Liability Case
Germany's Federal Court of Justice (BGH) is hearing a case on whether a technology and analytics company is liable for storing cookies on users' devices without consent on third-party websites. The plaintiff seeks damages, with lower courts awarding €1,500 and then €100. The case centers on the interpretation of the TDDDG. A ruling is not expected immediately. Legal experts say a BGH confirmation of the lower court's view would require companies to implement technical and organizational measures beyond contractual assurances to prevent unauthorized cookie placement. Meanwhile, the EU Commission proposed in November 2025 to reduce cookie banner pop-ups by allowing users to store preferences on their devices. The proposal faces scrutiny in the European Parliament and Council, with consumer advocates concerned about member states' resistance.
Apple Safari Blocklist Pushes Publishers to Trusted Server
Apple's latest software update has started blocking ad tech companies that track users for targeted advertising in Safari, prompting publishers to urgently revisit IAB Tech Lab's Trusted Server. This server-side solution moves ad auctions from users' devices to publisher-controlled servers, bypassing Apple's blocklist. Publishers like Paradium have already adopted it, while others are evaluating their options. The move highlights Apple's growing control over digital advertising, raising concerns about market power and the impact on publisher revenue. As Apple expands its own ad business, the blocklist underscores the shifting power dynamics in the ad tech ecosystem.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
