All news
EDPB / EDPS July 14, 2026 7 min

EDPB binding decision 1/2026: a cookie complaint cannot be dismissed by claiming the complainant is abusing their rights

Published on 14 July 2026, the decision of 28 May 2026 under Art. 65(1)(a) GDPR: the Belgian DPA must decide on the merits the noyb complaint against public broadcaster VRT

TL;DR for the DPO

If a client receives a complaint and the temptation is to answer 'this is a serial complaint, there is no real interest', this decision shows that road is narrow: abuse of rights must be proven in two components, objective and subjective, under the CJEU test. If you cannot prove them, the complaint must be examined on the merits.

What happened

The complaint was lodged with the Austrian DPA by the NGO noyb on behalf of an individual and concerned the cookie banners on the website of Vlaamse Radio- en Televisieomroeporganisatie (VRT), the Belgian public broadcaster. The Belgian DPA, acting as Lead Supervisory Authority, submitted a draft decision dismissing the complaint on the basis of an alleged abuse of Art. 77 and Art. 80(1) GDPR. The Austrian DPA, as Concerned Supervisory Authority, objected: the complaint should not have been dismissed on procedural grounds but decided on the merits. The lead authority chose not to follow the objection and referred the case to the EDPB.

What the EDPB decided

The EDPB considered the Austrian objection relevant and reasoned within the meaning of Art. 4(24) GDPR and in line with its Guidelines 09/2020, and assessed it on the merits. On the basis of the information available and applying the CJEU test for alleged abuse, it concluded that the complainant did not abuse their rights under Art. 77 and Art. 80(1): neither the objective nor the subjective component needed to prove abuse was demonstrated. It therefore instructed the lead authority not to dismiss the complaint, to assess it on its merits and to submit a new draft decision to the concerned authorities under Art. 60(3).

Why this matters to a DPO

  • Dismissal for abuse of rights is not a shortcut: two components must be proven, it is not a matter of expediency
  • The fact that a complaint arrives through a body under Art. 80(1) does not make it abusive in itself
  • Art. 65 is a dispute resolution mechanism between the lead and the concerned authorities: in cross-border cases the decision of the authority in the controller's country is not the last word
  • The case started from a cookie banner: the topic remains under scrutiny across Europe

What I would do with clients

  • In the complaint-handling procedure, remove any wording such as 'vexatious complaint' as a ground for closing: if you use it, it must be documented with the two elements of abuse
  • If a client has a cookie banner where refusing costs more than accepting, that is another signal this is not a quiet area
  • If the client is a group with its main establishment in another Member State, explain that the lead authority can be overruled: the merits must be assessed from the start
Official source:EDPB - Comunicato del 14 luglio 2026Official source:EDPB - Binding Decision 1/2026 del 28 maggio 2026Official source:EDPB - Guidelines 09/2020 on relevant and reasoned objection

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

EDPB / EDPS
12-14gli articoli sotto esame

In 2026 every European authority is looking at the same thing: privacy notices

Each year the EDPB picks a topic and every national authority checks it together, in the same period, through questionnaires and inspections. For 2026 the topic is transparency: how controllers tell people what happens to their data. In scope are Article 13, where data comes from the data subject, and Article 14, where it comes from elsewhere. The Czech authority has already written the theme into its inspection plan.

Aug 10, 2026New 6 min
EDPB / EDPS
28 agotermine per candidarsi

Competition and data protection: the EDPB opens the table, and there is a deadline

After the DSA and before the DMA and the AI Act, the fourth piece of the European regulatory mosaic concerns the relationship between competition and data protection. This is not theoretical: it touches data as a market asset, mergers, and the position of those who process data because they dominate a market. The EDPB and the Commission are asking for input before they write, and this time the deadline is close.

Jul 30, 2026New 6 min
EDPB / EDPS
10 lug 2027quando si potra' condividere

Anti-money laundering and privacy: the EDPB and AMLA write the sharing rules together

On 1 July 2026 the EDPB and the European Anti-Money Laundering Authority announced joint guidelines on a question neither could solve alone: how banks, professionals and authorities can share information about suspicions without building unchecked lists of suspects. The possibility applies from 10 July 2027 and the public consultation is expected in the first half of that year. Anyone advising obliged entities has a year to prepare.

Jul 01, 2026New 6 min