Blogpost

The Schufa shadow database: a data protection scandal or a necessity for the credit industry?

The storage of historical data by Germany's major credit bureau (Schufa) serves the legitimate purpose of testing new scoring methods specifically for bank customers, which would not be possible with anonymised data. Nevertheless, the GDPR compliance of this data processing and the lack of information about it remain controversial and must still be definitively clarified from a legal standpoint.

Schufa-Schattendatenbank / Schufa shadow database

Included in this collection:

Open collection

Schufa shadow database: What NDR and the Süddeutsche Zeitung have uncovered

In addition to its regular credit reference database, Schufa stores personal data beyond the official retention periods, a fact unknown to the public. This was reported by German media outlets NDR and the Süddeutsche Zeitung (SZ) on 15 July 2026.1 This ‘historical data’ comprises information on loans, credit cards, wage garnishments, insolvencies and debts relating to millions of consumers, which may have had to be removed in accordance with the statutory retention periods under the GDPR. Schufa does not deny the existence of this database. It justifies the storage of this data on the basis of a clearly defined purpose: corporate clients such as banks, telecoms providers, energy suppliers and retail companies can use it to test what the current Schufa score would have been retroactively on a specific date in the past. According to Schufa, the aim is to demonstrate the reliability of its scoring process, particularly since a new score was introduced in March 2026.

The criticism of this practice varies considerably in severity. According to the Handwerksblatt2, lawyer Hendrik Frank believes that several principles of the GDPR have been breached: the storage limitation under Article 5(1)(e), the right to erasure under Article 17 and – due to the loss of control over one’s own data – a possible claim for non-pecuniary damages under Article 82. Matthias Spielkamp of AlgorithmWatch goes further and calls for the immediate deletion of the database: he argues that Schufa must answer for its ‘degree of irresponsibility’. According to heise online3, the Federation of German Consumer Organisations (vzbv) takes a more cautious stance on the incentive structure: Claudio Zeitz-Brandmeyer points out that it could be tempting for the companies receiving the data to actually use the historical figures – which were supposedly only provided for testing purposes – in their credit decisions. The Hessian State Data Protection Commissioner is overseeing the overall legality of the matter; he has been conducting his investigation since spring 2025, though no findings have been published to date.

Schufa’s most surprising stance

The aspect that is most perplexing when reading the report does not concern the storage of data itself, but rather how the information is handled. Schufa explained to NDR and SZ:

We do not provide a separate breakdown of historical data in the data copy pursuant to Article 15 of the GDPR.

Schufa

Since the end of March 2026, consumers have been able to view their Schufa score free of charge. However, according to Schufa itself, this self-disclosure does not include historical data.

Schufa’s interpretation is surprising because it is difficult to reconcile with the wording of Article 15 of the GDPR. Ruth Janal, Professor of Commercial Law at the University of Bayreuth, does not agree with Schufa: the right of access under the GDPR ‘naturally also covers this data, which Schufa refers to as historical data’. The provision grants a right of access to all stored personal data, regardless of whether this data is currently being used in relation to the data subject or not.

If it were permissible to exclude a category of data from the right of access solely because it is currently used ‘only’ for internal testing and not for the direct calculation of credit scores, this would, in the author’s view, open the floodgates to arbitrary exceptions: Then any data controller could define internal purposes that would undermine the right to full access. It remains to be seen whether the courts share this view. However, the obvious guiding principle should be that the scope of a right of access is determined by what is stored, not by the specific purpose for which the data controller is currently using the data.

The bank’s perspective: Why historical credit score data is not an end in itself

The public debate, which focuses almost exclusively on the relationship between Schufa and consumers, completely overlooks a third perspective: that of enterprises – particularly banks and financial institutions – which use the Schufa score as a risk driver, for example in a rating process recognised by the regulatory authorities. From this perspective, ‘historical enrichment’ is not an end in itself for Schufa, but a prerequisite for banks to be able to use the score in compliance with regulations at all.

The background to this lies in the interplay of two requirements that apply to internal rating procedures: demonstrating the discriminatory power of a risk driver and the prescribed minimum length of the data history. If Schufa introduces a new version of the score, as has recently happened, the bank’s own databases will initially only contain the old version of the score. If the bank wishes to adopt the new score as a risk driver, it cannot rely on Schufa’s general statements regarding the quality of the new procedure. It must demonstrate, for its own portfolio, that the new score exhibits good discriminatory power – and, as is typically required, better discriminatory power than the previous one. Such proof requires that the new score can be calculated using the same historical rating dates and customers as the old one. As the underlying data history for the Schufa score’s risk drivers is not held by the bank but exclusively by Schufa, the bank is reliant on Schufa being able to identify its customers and apply the new method retrospectively to their past data records.

Added to this is the minimum length of the data history required by the regulator. For internal rating procedures, the regulator generally requires an observation period of at least five years. Without the ability to apply the new score retrospectively to historical data, a bank would be unable to cover this period using the new score at all. It would have to collect new data over a period of years, whilst it would effectively have to continue using the old, less meaningful score. The same logic applies if a bank wishes to develop a completely new rating procedure and does not yet have any Schufa data in its own records: here, too, it is reliant on Schufa’s historical time series to develop and validate the procedure before it can be approved by the regulator.

Is the criticism of this use justified?

From this perspective, the purpose cited by Schufa – “quality assurance, data protection monitoring, documentation and the further development of our procedures and scores” – is not merely an internal justification, but corresponds to an actual, regulatory-based need of its banking customers. It is important to distinguish this from Schufa’s own model-building activities: for its own model development, Schufa could retain its historical data in anonymised form and would therefore not face the data protection issues described. Proving, however, that a score works for the customers of a particular bank requires the specific, personalised application of the new procedure to historical rating dates.

On the basis of consent (the ‘Schufa clause’), Schufa generally processes personal data lawfully and is therefore also entitled to store the relevant data for further development, validation and testing. Whether verifying the quality of the Schufa score as a risk driver in customers’ credit assessment procedures falls within the purposes covered by this consent remains to be clarified in legal terms. However, in the author’s view, the suspicion expressed by AlgorithmWatch4 – based on a statement by Ruth Janal – that Schufa stores historical data ‘in reserve for unspecified future purposes’ is unfounded:

The test described may only be carried out on the respective institution’s own customers who have consented to the use of their Schufa data. The purpose of use is therefore limited from the outset to a specific group of individuals and a specific area of application.

Manfred Puckhaber Senior Manager, msg for banking ag

The author also believes that the Federation of German Consumer Organisations’ suspicion that it ‘might be tempting’ for a financial institution to actually use historical figures when making credit decisions is out of touch with reality:

No company will make decisions based on out-of-date information when up-to-date information is available.

Manfred Puckhaber Senior Manager, msg for banking ag

Conclusion: Purpose does not justify lawfulness

From the author’s perspective, Schufa’s reasoning as to why it does not disclose historical data in the self-disclosure report under Article 15 of the GDPR is particularly unconvincing. However, that is only one side of the story. The other side is that Schufa’s storage of historical data serves the specific, demonstrable purpose of introducing and testing new scoring models for customers.

However, the regulatory purpose for the credit industry does not alter the fact that the GDPR is a stand-alone piece of legislation, and a breach of the storage limitation or the right to erasure cannot be justified on the grounds that the data is being put to good use elsewhere – in this case, by Schufa’s banking customers. Whether the storage and disclosure of historical data in the form practised by Schufa is compatible with the GDPR therefore remains an open question and will only be clarified by the ongoing investigation by the Hessian State Data Protection Commissioner and, if necessary, by the courts.

For institutions that have already completed the transition to the new score with the support of historical data enrichment, this does not currently pose a problem: validation has taken place and the process is in use.

The real risk lies in the future. Should the historical enrichment prove to be unlawful and have to be discontinued, the institutions would lack an obvious alternative method for validating future versions of the score against historical rating dates.

Manfred Puckhaber Senior Manager, msg for banking ag

Our expertise in financial risk and analytics

From IRBA applications and ongoing IRBA reviews, through parameter estimation, to quantitative methods in the ICAAP – benefit from our many years of experience in supporting SI and LSI institutions.

Sources