Oracle and Equifax among seven firms accused of violating GDPR by Privacy International
Privacy International accuse seven data brokers, at-tech firms and credit agencies of being “premised on exploiting people’s data”


Seven companies including Oracle and Equifax have been accused of violating data protection laws by a privacy rights group and referred to data regulators.
Privacy International (PI) has filed complaints against two data brokers, three ad-tech firms and two credit referencing agencies with French authorities, the Irish Data Protection Commission (DPC) and the Information Commissioner's Office (ICO).
The EU's General Data Protection Regulation (GDPR), which came into force on 25 May, demands a far higher standard for data protection and individuals' privacy rights from organisations than ever before.
PI is accusing the firms of disregarding data protection principles, including purpose limitation (specifying exactly how data is used), data minimisation (data is held no longer than absolutely required), and data accuracy.
The organisation is basing their accusations on more than 50 subject access requests (SARs) files with the companies, as well as information they have provided in their marketing materials and privacy policies.
"The data broker and ad-tech industries are premised on exploiting people's data," said PI's legal office Ailidh Callander.
"Most people have likely never heard of these companies, and yet they are amassing as much data about us as they can and building intricate profiles about our lives.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"GDPR sets clear limits on the abuse of personal data. PI's complaints set out why we consider these companies' practices are failing to meet the standard - yet we've only been able to scratch the surface with regard to their data exploitation practices."
The group argues that the companies, which also include Acxiom, Criteo, Experian, Quantcast and Tapad, do not have a legal basis for the way they use people's data, and have not attained appropriate consents. PI also says they do not have the basis for processing sensitive personal data.
The ICO has already issued assessment notices to data broker Acxiom, as well as credit rating agencies Equifax and Experian. PI has urged the UK data regulator to widen its ongoing investigations to include the other four firms.
A Criteo spokesperson said the firm was requested to fill a questionnaire on privacy in May, and said they invited PI to meet for further discussions. They added they did not get a response, and instead learned of the complaint two days ago.
"Whilst disappointed that they have chosen to take this action, we have complete confidence in our privacy practices and we remain open to answer any questions that PI may have," the spokesperson said.
An Acxiom spokesperson said the company's associates need to pass data security and privacy tests, and in May the business passed a Direct Marketing Association (DMA) audit around data privacy and compliance.
"We have worked hard to ensure that we are compliant with GDPR and we continue to believe that our services meet its requirements," said an Experian spokesperson.
Oracle, Equifax and Quantcast refused to comment. Tapad was also approached.
"We are aware of concerns raised about the compliance of data protection laws by big tech companies, data brokers and credit referencing agencies," an ICO spokesperson said.
"These concerns have been raised with regulators in different EU countries and the ICO will be working with the relevant data protection authorities, and the new European Data Protection Board, to consider the facts and support any possible joint work or inquiries in other jurisdictions."

Keumars Afifi-Sabet is a writer and editor that specialises in public sector, cyber security, and cloud computing. He first joined ITPro as a staff writer in April 2018 and eventually became its Features Editor. Although a regular contributor to other tech sites in the past, these days you will find Keumars on LiveScience, where he runs its Technology section.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
ICO admits it's too slow dealing with complaints – so it's eying up automation to cut staff workloads
News The UK's data protection authority has apologized for being slow to respond to data protection complaints, saying it's been overwhelmed by increased workloads.
By Emma Woollacott Published
-
Tech leaders worry AI innovation is outpacing governance
News Business execs have warned the current rate of AI innovation is outpacing governance practices.
By Emma Woollacott Published
-
Top data security trends
Whitepaper Must-have tools for your data security toolkit
By ITPro Published
-
“Limited resources” scupper ICO probe into EasyJet breach
News The decision to drop the probe has been described as “deeply concerning” by security practitioners
By Ross Kelly Published
-
Surge in workplace monitoring prompts new ICO guidelines on employee privacy
News Detailed guidance on how to implement workplace monitoring could prevent data protection blunders
By Ross Kelly Published
-
SEC data breach rules branded “worryingly vague” by industry body
News The new rules announced last week leave many questions unanswered, according to security industry experts
By Ross Kelly Published
-
The gratitude gap
Whitepaper 2023 State of Recognition
By ITPro Published
-
Meta sues ‘data scraping for hire’ service that collected info on 600k users
News Meta says tackling data scraping will require a “collective effort” from platforms and policymakers
By Ross Kelly Published