EDPB requires Belgian DPA to handle the merits of NOYB cookie banner complaint

  • EDPB News
  • be

Brussels, 14 July–The EDPB has published its binding decision of 28 May 2026 under Art.65(1)(a) GDPR*. The decision concerns a dispute submitted by the Belgian Data Protection Authority (DPA) about a complaint against Vlaamse Radio-en Televisieomroeporganisatie (VRT) – a public broadcasting company based in Belgium.

The complaint was lodged with the Austrian DPA by the Austrian-based NGO Noyb on behalf of an individual. It concerns the use of cookie banners on the website of VRT.

The Belgian DPA, acting as Lead Supervisory Authority (LSA), submitted a draft decision proposing to dismiss the complaint on the basis of an alleged abuse of Art.77 GDPR and Art. 80(1) GDPR. The Austrian DPA, Concerned Supervisory Authority (CSA), objected, arguing that the LSA should not have dismissed the complaint on procedural grounds and should have instead issued a decision on the merits.

The Belgian DPA decided not to follow the objection and submitted the case to the EDPB. 

Outcome of the EDPB decision

The EDPB considered the Austrian DPA’s objection relevant and reasoned within the meaning of Art.4(24) GDPR and the EDPB Guidelines on the concept of relevant and reasoned objection and assessed it on the merits. 

The EDPB found that, based on the information available and in line with the CJEU’s test for alleged abuse, the complainant did not abuse their rights under Art.77 and Art.80(1) GDPR. This is because the objective and subjective components needed to prove such abuse were not demonstrated. 

Therefore, the EDPB instructed the LSA not to dismiss the complaint, but to assess it instead on its merits and to submit a new draft decision to the CSAs under Art.60(3) GDPR.

Note to editors:
*Art.65(1)(a) GDPR is a dispute resolution mechanism meant to ensure the correct and consistent application of the GDPR in cross-border cases, addressing disagreements that have arisen between the LSA and the CSAs in a given case.

Relevant topics
GDPR enforcement
Cooperation between authorities

Latest news

  • National News

Swedish DPA fines Miljödata i Karlskrona approximately EUR 160 000 for insufficient technical and organisational measures to ensure information security

  • National News

Dutch DPA fines Uber EUR 824 990 000 for unlawful automated decision-making and insufficient information on profiling

  • National News
  • gr

Hellenic DPA decision on a data breach involving E.E.T.A.A. S.A. as processor for the Ministry of Social Cohesion and Family Affairs