Your Vendors May Be Hiding Data
Based on research by NOYB
The European privacy watchdog noyb has confirmed it will sue SCHUFA, Germany’s massive credit reference agency, after the company refused to stop maintaining a secret shadow database. This is not just a German domestic issue; it is a stark warning for any Swedish tech leader relying on external data brokers or third-party scoring APIs. If a major credit bureau can operate outside the law, your supply chain is likely full of similar hidden risks.
SCHUFA allegedly kept a parallel database of personal data that was not subject to the same transparency or deletion rules as its main system. In simple terms, they were tracking users in the dark, bypassing the right to be forgotten and the right to access your own data. This violates the core principles of the GDPR, which demands that data processing be lawful, fair, and transparent. When a company hides data processing from regulators and users, it breaks the trust contract that underpins the entire European digital economy.
For Swedish CTOs and CISOs, the practical takeaway is that you cannot trust your vendors’ compliance claims at face value. You must audit your data processors rigorously. Are there shadow copies of your user data in third-party LLM training sets or analytics platforms? The risk is not just reputational; it is financial. GDPR fines can reach four percent of global turnover, and class actions like the one noyb is organizing can drain resources for years. You need to know exactly where your data goes and ensure it can be deleted on demand.
This situation reinforces the urgent need to keep sensitive data processing local and under your own control. Relying on opaque external systems creates liability you cannot manage. By processing data within your own secure EU infrastructure, you eliminate the risk of hidden databases and maintain full visibility over compliance. It is the only way to ensure that your users’ rights are not sacrificed for the sake of convenience or cost-cutting.