In a binding decision of 28 May 2026, made public on 14 July, the European Data Protection Board (EDPB) has ruled that a supervisory authority cannot dispose of a cookie banner complaint by branding it an abuse of the right to complain. The Belgian authority, acting as lead on a complaint brought by the Austrian NGO NOYB against the Flemish public broadcaster (VRT), intended to dismiss it on procedural grounds; the EDPB, called upon to settle the dispute with the Austrian authority, ordered it to rule on the merits. What is at stake goes beyond the single banner: the right to lodge a complaint and to be represented by an association is not a formality that an authority may neutralise, and cookie banners remain an open front in the enforcement of the GDPR.
The case: one banner, two authorities, one dispute
At the origin there is a complaint brought by NOYB, on behalf of an individual, before the Austrian authority, concerning the cookie banners used on VRT’s website. Because the broadcaster is based in Belgium, the Belgian authority acted as lead supervisory authority and proposed a draft decision aimed at dismissal, alleging an abuse of Articles 77 and 80(1) of the GDPR, namely the right to lodge a complaint and the right to mandate a not-for-profit body. The Austrian authority, as concerned supervisory authority, raised an objection to the contrary: the complaint should not have been closed on procedural grounds, but examined on the merits. As the Belgian authority chose not to follow the objection, the case was referred to the EDPB through the consistency mechanism laid down in Article 65 of the GDPR for cross-border disputes between authorities.
The decision: turning to an association is not an abuse
The EDPB considered the Austrian objection relevant and reasoned within the meaning of Article 4(24) of the GDPR and assessed it on the merits. Applying the test developed by the Court of Justice of the European Union on abuse of rights, it concluded that the complainant had not abused the entitlements granted by Articles 77 and 80(1), since neither the objective nor the subjective component that abuse requires had been demonstrated. It therefore instructed the lead authority not to dismiss the complaint, but to assess it on the merits and to submit a new draft decision to the concerned authorities under Article 60(3). In concrete terms, a citizen’s choice to rely on an organisation such as NOYB to assert their rights cannot be treated, in itself, as a device: it is the legitimate exercise of an entitlement that the legislature has expressly provided.
Why cookie banners remain under scrutiny
The case does not establish whether VRT’s banner was compliant: it removes the procedural obstacle and returns the question to the merits. It does, however, place it in a well-known context. Cookie banners have for years been a systematic front of litigation: since May 2021 NOYB has brought more than seven hundred complaints against website operators whose banners, in its view, breached the European rules, and the EDPB set up a dedicated task force whose findings, adopted on 17 January 2023, established a minimum threshold of acceptable practices, treating as problematic, among other things, the absence of a reject button on the banner’s first layer, pre-ticked boxes and deceptively designed buttons. It is no accident that national authorities’ attention to online processing is growing, as shown by the Italian Garante’s 2026 inspection plan, and the EDPB’s role as guardian of uniform application returns to the fore precisely as the Digital Omnibus proposes to redefine the very notion of personal data.
The lesson for those who run a website and those who supervise
For controllers and website operators the message is twofold. On the substantive side, a compliant banner is not a graphic detail: consent must be free, specific, informed and as easy to withdraw as it is to give, which presupposes a reject option as accessible as the accept option and the absence of pre-ticked boxes. On the procedural side, the decision is a reminder that the one-stop-shop mechanism is not a means to close cases summarily, but to coordinate them: a complaint is to be investigated, not circumvented. This is a line consistent with the EDPB’s intense activity in recent weeks, from the rules on anonymisation and web scraping for generative AI to its positions on the ongoing reform.
In light of the foregoing, one may ask whether the true test of consent is not the banner the user sees, but the authority’s willingness to look behind it, and whether effective protection depends less on harmonising decisions than on the guarantee that a complaint, once lodged, is actually decided.




