Back to blog

Stop Using Hidden Data for AI Models

Based on research by NOYB

aigdprschremsdata protectiondata processing

The credit bureau SCHUFA has been exposed for maintaining a secret “shadow database” of millions of records that should have been deleted under GDPR retention rules. Instead of erasing this data, the agency allegedly kept it hidden and used it for third-party credit score validations, while actively refusing to disclose these historical records to users exercising their right of access under Article 15. This is not just a German compliance failure; it is a stark warning for any company using external data processors or AI models that rely on historical data for scoring or inference.

In simple terms, “deletion” under the GDPR means the data must be irretrievable, not just invisible to the user. SCHUFA’s practice of hiding data in a backend system while continuing to process it for commercial purposes violates the core principles of storage limitation and transparency. The European Court of Justice has already ruled that a data copy provided to a user must be a complete reproduction of all processed data. By withholding historical data, SCHUFA is denying individuals the full picture of how their information is used, creating a massive compliance gap that noyb is now challenging through cease-and-desist letters and potential class actions.

For CTOs and CISOs, the risk is immediate and financial. If your organization uses similar external APIs or data brokers that retain “deleted” data for model training or secondary validation, you are liable for the same GDPR violations. The fines for such breaches can be severe, but the reputational damage is worse. More critically, if you are relying on a processor that hides data from you or the end-user, you cannot fulfill your own Article 15 obligations. You are effectively blind to the true scope of the data you are processing, which breaks the chain of accountability required by law.

This scandal reinforces the urgent need to process sensitive data locally within the EU. When you keep data on-premises or within your own controlled cloud environment, you eliminate the black-box risk of third-party shadow databases. You retain full visibility over data lifecycle management, ensuring that when you say data is deleted, it is truly gone. This local control is the only way to guarantee compliance with the right of access and prevent the kind of systemic opacity that is now inviting legal action on a massive scale.