Regulatory Watch  /  Austria  /  Investigation
Low impactInvestigationAnnounced

noyb uncovers over 40,000 CRIF credit queries linking Austrian banks, telecoms and retailers

noyb obtained data requests from 2,440 individuals and analyzed more than 40,000 CRIF credit queries, finding that banks, telecoms and other firms provide personal address data to the credit agency. The analysis shows gender and geographic biases in scores and raises questions about the legality of data transfers under Austrian law and the GDPR. noyb plans further investigations and may consider a class‑action lawsuit.

Why it matters: The report highlights potential unlawful mass processing of personal data by CRIF and its network, prompting privacy scrutiny and possible legal action.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
Over 40,000 CRIF queries: Klarna, banks and telecoms entangled in CRIF network
noyb · primary source · Sep 25, 2025
Over 40,000 CRIF queries: Klarna, banks and telecoms entangled in CRIF network
noyb · Sep 25, 2025
Details
JurisdictionAustria
RegulatorEDPB
LawGeneral Data Protection Regulation
StatusAnnounced
PublishedSeptember 25, 2025
Effectivenot stated
OrganisationsCRIF, Erste Bank, Verbund, Drei, T‑Mobile, Otto, Allianz, Klarna, Trulioo, card complete, TF Bank, bank99, MaxEnergy, Energie AG, Breuninger
Topicstransparency, data minimization, purpose limitation, access, correction, profiling, automated decision making, data brokers, consent, deletion, privacy
Datapersonal, financial, location