noyb obtained data requests from 2,440 individuals and analyzed more than 40,000 CRIF credit queries, finding that banks, telecoms and other firms provide personal address data to the credit agency. The analysis shows gender and geographic biases in scores and raises questions about the legality of data transfers under Austrian law and the GDPR. noyb plans further investigations and may consider a class‑action lawsuit.
Why it matters: The report highlights potential unlawful mass processing of personal data by CRIF and its network, prompting privacy scrutiny and possible legal action.
Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.