Back to Feed
PolicyJul 21, 2026

EDPB - Binding Decision 1/2026

EDPB binding decision finds no abuse of rights in standardized data protection complaints.

Summary

The European Data Protection Board (EDPB) issued a binding decision clarifying that a standardized approach to lodging data protection complaints does not inherently constitute an abuse of rights. The decision instructs the Belgian Data Protection Authority (APD) to assess a complaint filed by noyb against Vlaamse Radio- en Televisieomroeporganisatie (VRT) on its merits, rejecting the APD's initial proposal to dismiss it based on alleged abuse.

Full text

Help EDPB - Binding Decision 1/2026: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 14:33, 21 July 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators211 edits Tag: submission [1.0]Newer edit → (No difference) Revision as of 14:33, 21 July 2026 EDPB - Binding Decision 1/2026 Authority: EDPB Jurisdiction: European Union Relevant Law: Article 4(24) GDPR Article 57(1)(f) GDPR Article 57(4) GDPR Article 60(3) GDPR Article 60(4) GDPR Article 65(1)(a) GDPR Article 77 GDPR Article 80(1) GDPR Article 8 CFR Type: Other Outcome: n/a Started: Decided: 28.05.2026 Published: 14.07.2026 Fine: n/a Parties: APD (Belgian DPA) DSB (Austrian DPA) Vlaamse Radio - en Televisieomroeporganisatie Data subject (represented by noyb) National Case Number/Name: Binding Decision 1/2026 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): English Original Source: EDPB (in EN) Initial Contributor: bms The EDPB held that an organised and standardised complaint strategy does not, in itself, constitute an abuse of rights and instructed the Belgian DPA to assess the complaint on its merits. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts On 10 August 2021, a data subject represented by noyb lodged a complaint with the Austrian DPA against Vlaamse Radio- en Televisieomroeporganisatie (VRT), the controller. The complaint concerned the controller’s cookie banner and alleged infringements of Articles 5(1)(a), 6(1)(a), 12(1), 12(2) and 13(1)(c) GDPR, as well as Article 5(3) ePrivacy Directive. It formed part of a wider project involving similar cookie banner complaints submitted by noyb across the EEA. The Austrian DPA transferred the complaint to the Belgian DPA, which acted as the lead supervisory authority. In its draft decision, the DPA proposed dismissing the complaint without examining its merits. It considered that the data subject and noyb had abused the rights provided under Articles 77 and 80(1) GDPR. The DPA relied on factors including the standardised and partly automated preparation of the complaints, noyb’s role in selecting the targeted controllers, the relationship between the data subject and noyb, and the broader strategic objectives pursued by the organisation. It considered that both the objective and subjective elements required to establish an abuse of rights were present. The Austrian DPA raised a relevant and reasoned objection under Article 60(4) GDPR. It argued that the circumstances did not demonstrate an abuse of rights and requested that the complaint be examined on its merits in accordance with Article 57(1)(f) GDPR. As the DPA did not follow the objection, it referred the dispute to the EDPB under Article 65(1)(a) GDPR. Holding The EDPB first held that it was competent to decide the dispute. Its powers under Article 65(1)(a) GDPR are not limited to determining whether a controller infringed the GDPR. They also cover disputes concerning whether an action envisaged by a supervisory authority, including the dismissal of a complaint, complies with the GDPR. The EDPB found that the Austrian DPA’s objection met the requirements of Article 4(24) GDPR. The objection was directly connected to the draft decision, proposed a different outcome and sufficiently demonstrated the risks that the dismissal would create for data subjects’ rights and the consistent application of the GDPR. On the merits, the EDPB recalled that the prohibition of abuse of rights must be interpreted strictly, particularly where its application may restrict the fundamental right to data protection and the rights provided by Articles 77 and 80(1) GDPR. The supervisory authority alleging abuse bears the burden of establishing both its objective and subjective elements on the basis of sufficient evidence. Regarding the objective element, the EDPB acknowledged that noyb had organised a project involving predefined selection criteria, standardised complaints and automated tools. However, the data subject had validly mandated noyb under Article 80(1) GDPR and had lodged a complaint concerning an alleged infringement of their own data protection rights. Consequently, the objectives of Articles 77 and 80(1) GDPR had been fulfilled rather than circumvented. Regarding the subjective element, the EDPB found no evidence that the complaint had been submitted to obtain an undue advantage unrelated to the purposes of the GDPR. The objectives pursued by noyb could not be separated from those of the data subject merely because the organisation had played a leading role in preparing the complaint. Nor was there evidence that the data subject or noyb had sought compensation or another financial benefit. The EDPB therefore concluded that the data subject had not abused the right to lodge a complaint under Article 77 GDPR or the right to be represented under Article 80(1) GDPR. It instructed the DPA not to dismiss the complaint on that basis, to assess it on its merits and to submit a new draft decision to the supervisory authorities concerned under Article 60(3) GDPR. No fine or corrective measure against the controller was imposed, since the alleged cookie banner infringements remained to be examined. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the English original. Please refer to the English original for more details. Binding Decision 1/2026 on the dispute submitted by the Belgian SA on Vlaamse Radio- en Televisieomroeporganisatie (Art. 65 GDPR) Adopted on 28 May 2026 1 | Adopted Table of contents 1 Summary of the dispute .............................................................................................. 3 2 The Right to good administration ............................................................................... 5 3 Conditions for adopting a binding decision............................................................... 6 3.1 Objection(s) expressed by CSA(s) in relation to the Draft Decision........................ 6 3.2 The LSA does not follow the objection(s) to the Draft Decision or is of the opinion they are not relevant or reasoned ................................................................................ 6 3.3 Admissibility of the case and competence of the EDPB ......................................... 7 3.4 Structure of the binding decision ............................................................................ 9 4 On the envisaged dismissal of the complaint in the Draft Decision ...................... 10 4.1 Analysis by the LSA in the Draft Decision ............................................................ 10 4.2 Summary of the objection raised by the CSA ....................................................... 12 4.3 Position of the LSA on the objections................................................................... 13 4.4A nalysis of the EDPB ........................................................................................... 14 4.4.1 Assessment of whether the objection was relevant and reasoned ................ 14 4.4.2 Assessment on the merits............................................................................. 18 5 Binding Decision........................................................................................................ 24 6 Final remarks ............................................................................................................. 24 European Data Protection Board 2 | Adopted The European Data Protection Board Having regard to Article 63 and Article 65(1)(a) of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free

Entities

EDPB (vendor)GDPR (product)ePrivacy Directive (product)cookie banner (product)noyb (vendor)VRT (vendor)