noyb’s investigation of CRIF shows that most address data comes from brokers who scrape public registers, violating GDPR purpose‑limitation. The Austrian DSB has already ruled that further processing for advertising breaches the GDPR.
Why it matters: The probe highlights large‑scale misuse of public register data for credit scoring, raising GDPR compliance concerns and potential class‑action liability.
Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.