Back to blog

Audit Your Vendor Scoring APIs Now

Based on research by NOYB

data processingaidata protectiongdprschrems

Austrian credit reference agency CRIF is facing a landmark class action and injunction from NOYB for building a secret shadow registry of nearly every adult in the country. The lawsuit alleges that CRIF assigns credit scores based primarily on age, gender, and address for ninety percent of its database, despite having no actual financial data for those individuals. This development matters to Swedish tech leaders because it highlights the extreme legal risks of relying on opaque third-party scoring systems that make consequential decisions about users without their knowledge or consent.

The core allegation is that CRIF violates GDPR principles by collecting data for marketing purposes and repurposing it for credit assessments without a valid legal basis or transparency. NOYB argues that scoring people based on demographic proxies rather than financial history is disproportionate and unlawful. Crucially, the case challenges the notion that such scoring is not decisive; in practice, these scores determine whether consumers get mobile contracts, bank loans, or energy supplies. This sets a dangerous precedent for any company using automated decision-making tools that lack explainability or accurate underlying data.

For Swedish CTOs and CISOs, the immediate takeaway is to audit your reliance on external credit or risk scoring APIs. If your vendors use demographic proxies or data collected for unrelated purposes to generate scores that affect user access to services, you are exposed to significant compliance gaps. The risk is not just reputational damage but potential liability for facilitating unlawful processing. You must ensure that any third-party data processor can prove the lawfulness of their data sources and the accuracy of their algorithms. If you cannot verify that the scoring is based on relevant, accurate, and consensual data, you are building your product on a legal fault line.

This case reinforces the urgent need to process sensitive decision-making data locally within the EU. Relying on centralized, opaque external databases that operate in legal gray areas exposes your entire stack to systemic risk. By keeping data processing within your own controlled EU infrastructure, you maintain transparency, ensure accuracy, and avoid the pitfalls of secret registries. Control over your data pipeline is no longer just a security preference; it is a regulatory necessity in an era of strict algorithmic accountability.