Regulatory Watch  /  DE-BAVARIA  /  Data protection authority action
Moderate impactData protection authority actionPublished

Bavarian DPA declares CRIF‑Acxiom data trading illegal under GDPR

The Bavarian data protection authority ruled that credit reference agency CRIF illegally purchased personal data from address trader Acxiom and breached GDPR purpose‑limitation and information duties. The decision follows a similar Austrian DPA ruling and the Hessian DPA rejected Acxiom’s attempt to block case‑file access.

Why it matters: The ruling marks a first enforcement step against secret data trading for credit scoring in Germany.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
German DPA declares data trading between credit agency and address trader illegal
noyb · primary source · Feb 5, 2024
German DPA declares data trading between credit agency and address trader illegal
noyb · Feb 5, 2024
Details
JurisdictionDE-BAVARIA
RegulatorBavarian Data Protection Authority
LawGeneral Data Protection Regulation
StatusPublished
PublishedFebruary 5, 2024
Effectivenot stated
OrganisationsCRIF, Acxiom, noyb, Bavarian Data Protection Authority, Hessian Data Protection Authority
Topicspurpose limitation, consent, data brokers, privacy, transparency, profiling, automated decision making
Datapersonal