Back to all lessons
Awareness Lessons
4 months ago

Credit Agency Builds Secret Scoring System Without Consent

CRIF violated fundamental data protection principles by creating a comprehensive scoring system for Austrian adults without proper legal basis or consent. The company collected and processed personal data beyond what was necessary for legitimate credit assessment purposes, using factors like age and address that may not be relevant to creditworthiness. This case demonstrates how organizations can violate privacy rights by expanding data use beyond original collection purposes, creating hidden profiling systems that significantly impact individuals' lives without their knowledge or consent.

Tactical Insight

Immediate actions

  • Conduct a comprehensive data audit to identify all personal data being collected and processed
  • Review and document the legal basis for each data processing activity under GDPR Article 6
  • Implement explicit consent mechanisms for any data processing that requires user approval

Long-term improvements

  • Establish data minimization principles to collect only data necessary for specific business purposes
  • Implement privacy-by-design practices in all new data processing systems
  • Create transparent data processing notices that clearly explain scoring algorithms and their impact

Compliance measures

  • Conduct regular GDPR compliance assessments with legal counsel
  • Establish data subject rights processes including access, rectification, and erasure requests
  • Implement Data Protection Impact Assessments (DPIAs) for high-risk processing activities