Skip to content
MONDAY, JULY 20, 2026
Policy & Governance

EDPB orders Belgian regulator to rule on NOYB’s VRT cookie-banner complaint on the merits

By Jordan Vale2 min read
EDPB orders Belgian regulator to rule on NOYB’s VRT cookie-banner complaint on the merits

Image / edpb.europa.eu

The binding GDPR decision rejects a proposed procedural dismissal and requires Belgium’s Data Protection Authority to circulate a new draft decision for cross-border review.

The European Data Protection Board has instructed Belgium’s Data Protection Authority to reopen and assess a GDPR complaint over cookie banners on Belgian public broadcaster VRT’s website, rather than dismissing it as an alleged abuse of complaint rights.

The EDPB’s binding decision, adopted on 28 May and published on 14 July, resolves a disagreement between the Belgian authority and Austria’s Data Protection Authority. The case was brought to the Austrian regulator by privacy group NOYB on behalf of an individual.

Belgium acted as the lead supervisory authority because VRT is based in Belgium. Its proposed decision would have dismissed the complaint on procedural grounds, arguing that the complainant had abused rights under Articles 77 and 80(1) of the GDPR. Article 77 gives individuals the right to lodge a complaint with a supervisory authority, while Article 80(1) governs representation by a not-for-profit body such as NOYB.

Austria objected, arguing that Belgium should decide the complaint’s substance instead of ending the case on procedural grounds. Belgium did not accept that objection and referred the dispute to the EDPB under the GDPR’s cross-border dispute-resolution process.

The EDPB found that Austria’s objection was relevant and reasoned. It also concluded that the available record did not establish either of the objective and subjective elements required to show an abuse of rights under the applicable Court of Justice of the European Union test.

Belgium’s regulator must now assess the complaint on its merits and submit a new draft decision to the concerned supervisory authorities under Article 60(3) of the GDPR. That process gives other regulators involved in the cross-border case an opportunity to review and, where necessary, object to the proposed merits decision.

The compliance reading is clear: companies and regulators should not assume that a complaint involving a privacy advocacy group, repeat enforcement activity, or coordinated representation can be rejected as procedurally abusive without evidence satisfying the full legal test. The EDPB’s decision does not decide whether VRT’s cookie-banner practices comply with the GDPR. It decides that the complaint must receive a substantive assessment.

For organisations operating websites across the EU, cookie-consent interfaces remain a likely enforcement entry point because they directly affect the legal basis for online tracking and the validity of consent. A procedural defence may still be available in appropriate circumstances, but the EDPB has signalled that it requires demonstrated objective and subjective evidence, not an assertion that a complainant or representative has used GDPR rights improperly.

Uncertainty remains over the underlying allegations against VRT’s banners, because the EDPB’s published notice does not describe the claimed design, consent, tracking, or information failures. The final outcome is also not yet known. Belgium’s forthcoming merits-based draft decision, and any subsequent cross-border review, will determine whether VRT must change its practices or face corrective measures.

Sources & methodology
  1. EDPB requires Belgian DPA to handle the merits of NOYB cookie banner complaint
    edpb.europa.eu / Primary / Published JUL 14, 2026 / Accessed JUL 20, 2026

Newsletter

The Robotics Briefing

A daily front-page digest delivered around noon Central Time, with the strongest headlines linked straight into the full stories.

No spam. Unsubscribe anytime. Read our privacy policy for details.