The Bavarian data protection authority ruled that credit reference agency CRIF illegally purchased personal data from address trader Acxiom and breached GDPR purpose‑limitation and information duties. The decision follows a similar Austrian DPA ruling and the Hessian DPA rejected Acxiom’s attempt to block case‑file access.
Why it matters: The ruling marks a first enforcement step against secret data trading for credit scoring in Germany.
Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.