Skip to main content
EDPB Binding Decision: When to Dismiss a Complaint vs. Assess on MeritsLaws and Regulations
5 min readFor Legal Counsel

EDPB Binding Decision: When to Dismiss a Complaint vs. Assess on Merits

When your Lead Supervisory Authority receives a cross-border cookie consent complaint, you face a pivotal decision: dismiss on procedural grounds or investigate the substance. The EDPB's binding decision of 28 May 2026 clarifies when each path is defensible.

The Belgian DPA tried to dismiss Noyb's complaint against VRT, citing alleged abuse of Art.77 and Art.80(1) GDPR. The Austrian DPA objected, and the EDPB sided with Austria, instructing Belgium to assess the complaint on its merits. For privacy officers and legal teams managing cookie consent practices, this decision highlights the threshold for procedural dismissal and the risks of misjudging it.

The Decision You Are Facing

You receive a cross-border complaint alleging invalid cookie consent. Your options:

Dismiss on procedural grounds (abuse of process, lack of standing, jurisdictional defect)

Assess on the merits (evaluate whether the Consent Notice meets GDPR requirements)

Request additional information before choosing either path

The EDPB decision establishes that abuse-of-process dismissals require both objective and subjective components under CJEU case law. If you can't demonstrate both, you must proceed to substantive assessment.

Key Factors That Affect Your Choice

Does the Complaint Allege a Genuine GDPR Violation?

If the complaint describes specific failures, like pre-ticked boxes, lack of granularity, cookie walls, or missing withdrawal mechanisms, it raises substantive questions. The EDPB found that Noyb's complaint about VRT's Consent Notice described conduct potentially violating GDPR consent requirements, indicating merit assessment rather than dismissal.

Can You Prove Objective Abuse?

Objective abuse exists when the complainant uses GDPR rights for purposes incompatible with the regulation's intent. Consider whether:

  • The complaint targets conduct clearly outside GDPR scope
  • The filing pattern suggests harassment rather than rights enforcement
  • The complainant seeks outcomes GDPR can't provide

In the VRT case, the Belgian DPA couldn't demonstrate that Noyb's complaint served purposes incompatible with Art.77 or Art.80(1) GDPR.

Can You Prove Subjective Intent to Abuse?

Subjective abuse requires evidence that the complainant knowingly misused GDPR mechanisms. Ask:

  • Does the complaint contain material misrepresentations?
  • Has the complainant admitted to non-compliance objectives?
  • Is there documentary evidence of improper motive?

Without both objective and subjective components, your abuse-of-process theory fails. The EDPB made clear that Belgium lacked sufficient evidence on both dimensions.

What Do Your Concerned Supervisory Authorities Say?

Under Art.60(4) GDPR, CSAs can raise relevant and reasoned objections to your draft decision. The Austrian DPA's objection argued that procedural dismissal was inappropriate given the substantive nature of the Consent Notice allegations. When a CSA objects to your procedural approach, evaluate whether defending your position is worth triggering the Art.65 dispute resolution mechanism.

Path A: Dismiss on Procedural Grounds

Choose this path when:

You have documented evidence of both objective and subjective abuse components. For example:

  • The complainant has filed hundreds of near-identical complaints targeting conduct that clearly falls outside GDPR scope
  • Internal communications reveal the complainant's stated goal is to overwhelm your authority rather than enforce data protection rights
  • The complaint contains demonstrable factual fabrications

Implementation steps:

  1. Document the objective abuse component with reference to CJEU standards
  2. Gather evidence of subjective intent (correspondence, public statements, filing patterns)
  3. Draft your dismissal decision with explicit citations to both components
  4. Anticipate CSA objections and prepare your response before circulating under Art.60(3) GDPR
  5. Accept that if you can't defend both components, the EDPB will likely instruct merit assessment

Risk assessment:

If you dismiss and the EDPB overturns your decision, you've delayed substantive resolution by months. The Belgian DPA now must assess VRT's Consent Notice on the merits and submit a new draft decision to CSAs. Your organization (if you're VRT) remains in regulatory limbo.

Path B: Assess on the Merits

Choose this path when:

The complaint describes specific GDPR violations, even if the complainant's broader objectives are unclear. The EDPB decision signals that substantive cookie consent allegations should receive substantive evaluation.

Implementation steps:

  1. Audit the complained-of Consent Notice against Art.4(11), Art.6(1)(a), and Art.7 GDPR
  2. Review your consent records for the complainant (or representative sample if the complaint is representative)
  3. Evaluate whether your Consent Management Platform configuration meets EDPB Guidelines 05/2020 on consent
  4. Assess granularity, withdrawal mechanisms, and Prior Consent cookie placement
  5. Draft findings on each substantive element before reaching a compliance conclusion

For organizations under investigation:

If your Lead Supervisory Authority chooses this path, prepare for detailed technical examination. Your legal team should:

  • Document your CMP configuration decisions and the reasoning behind each setting
  • Compile consent records showing timestamp, granular choices, and withdrawal availability
  • Identify any cookies placed before consent and your legal basis for each
  • Prepare evidence that your consent notice provides clear information about purposes and recipients

Risk assessment:

Substantive assessment exposes your actual compliance posture. If your Consent Notice fails GDPR requirements, you face corrective measures and potential fines. But you also get definitive guidance rather than prolonged procedural uncertainty.

Path C: Request Clarification Before Deciding

Choose this path when:

The complaint is ambiguous about the specific conduct challenged, or you need additional information to determine whether abuse components exist.

Implementation steps:

  1. Issue an information request to the complainant under your national procedural rules
  2. Ask for specific examples of the alleged GDPR violations
  3. Request clarification about the complainant's relationship to the data subject (if filed under Art.80(1) GDPR)
  4. Set a reasonable deadline for response
  5. Evaluate the response against the objective/subjective abuse framework

Risk assessment:

Delays can frustrate both complainants and CSAs. If the initial complaint already contains sufficient detail (as Noyb's complaint against VRT apparently did), requesting clarification may appear dilatory.

Summary Matrix

Factor Dismiss Assess Merits Request Clarification
Complaint Granularity Vague or clearly outside GDPR scope Describes specific consent failures Ambiguous about conduct challenged
Evidence of abuse Both objective and subjective components documented Neither component demonstrated Insufficient information to evaluate
CSA position CSAs agree dismissal is appropriate CSA objects to procedural dismissal CSAs neutral or awaiting more facts
Your risk tolerance High confidence in abuse defense Prefer definitive resolution Need more information before committing
Timeline priority Willing to defend through Art.65 process Want to resolve substantive questions Can afford additional investigation time

The EDPB's instruction to Belgium reflects a clear preference: when substantive GDPR questions are raised and abuse can't be proven, assess the complaint on its merits. For organizations managing cookie consent, this means your CMP configuration must withstand detailed scrutiny. Procedural defenses are narrowing; substantive compliance is your defensible path.

You Might Also Like