The EDPB Binding Decision 1/2026, published on July 14, 2026, addresses a key procedural question: when can you dismiss a GDPR complaint as abusive? The decision examined whether the Belgian SA should dismiss a complaint against VRT on grounds that the complainant abused their right to lodge a complaint or misused their right to mandate a not-for-profit body to file on their behalf.
If you're managing a complaint process, you've likely encountered patterns that feel abusive: serial complaints from the same party, coordinated complaints, or mandates to advocacy organizations that seem designed to overwhelm rather than resolve. The EDPB's position shapes how you can respond.
Essential Preparations
Before building a defensible complaint handling process that accounts for potential abuse, gather these elements:
Documentation infrastructure. Implement a system that timestamps every complaint, tracks the complainant's identity (including whether they're acting through a mandated body), and logs all correspondence. Your GDPR Article 30 processing records should already cover complaint handling as a distinct processing activity.
Legal basis clarity. Confirm your legal basis for processing complainant data. It's typically Article 6(1)(c) (legal obligation) combined with Article 9(2)(g) if special category data is involved. Document this in your records of processing activities.
Criteria for legitimate complaints. Define what makes a complaint substantive. Does it identify a specific processing activity? Does it articulate a plausible rights violation? Does it provide enough detail for investigation? Write these criteria down to anchor your abuse assessment.
Escalation authority. Identify who in your organization has the authority to flag a complaint as potentially abusive and who makes the final decision. This shouldn't be a unilateral call by a frontline operator.
Supervisory authority contact protocol. Know your lead supervisory authority and the process for consulting them when you're uncertain. The EDPB decision makes clear that dismissal on abuse grounds isn't a unilateral organizational decision.
Step-by-Step Implementation
Step 1: Intake and initial classification. When a complaint arrives, log it immediately with a unique identifier. Record whether the complainant is acting directly or through a mandated not-for-profit body under Article 80 GDPR. If it's a mandated complaint, verify the mandate documentation. The complainant must have explicitly authorized the organization to act on their behalf.
Step 2: Pattern analysis. Check your complaint log for prior submissions from the same complainant or mandated body. Look for:
- Multiple complaints on the same subject matter with no new information
- Complaints filed immediately after receiving responses to previous complaints, without allowing reasonable time for implementation
- Identical or near-identical language across complaints from different nominal complainants
- Complaints that don't engage with your substantive responses
Document what you find. Don't label it "abusive" yet; just note the pattern.
Step 3: Substantive assessment. Evaluate the complaint on its merits. Does it identify a genuine processing activity you conduct? Does it raise a plausible concern about lawfulness, fairness, transparency, or data subject rights? If the answer is yes, the complaint is legitimate regardless of the complainant's history or tone.
Step 4: Preliminary abuse determination. If the complaint appears substantively empty and fits a concerning pattern, draft a preliminary assessment. Reference specific prior complaints by identifier and date. Describe the pattern objectively. Explain why the current complaint doesn't advance any new concern or provide information that would enable further investigation.
Step 5: Escalation and documentation. Route your preliminary assessment to your designated decision authority (typically DPO or legal counsel). They should review independently. If they agree the complaint may be abusive, document the reasoning in writing before taking any action.
Step 6: Supervisory authority consultation. Before dismissing a complaint as abusive, consult your lead supervisory authority. The EDPB decision addresses this procedural question precisely because it's not a determination you make alone. Provide your documented assessment and ask whether dismissal is appropriate.
Step 7: Response to complainant. If your supervisory authority agrees the complaint should be dismissed (or if they instruct you to proceed with investigation), respond to the complainant in writing. If dismissing, cite the specific grounds: explain which aspect of their complaint constitutes abuse (repetitive filing, lack of substantive content, misuse of mandate) and reference any supervisory authority guidance you received.
Validation: How to Verify It Works
Your complaint handling process is working if you can answer yes to these questions:
Can you produce a complete timeline? For any complaint, you should be able to generate a chronological record showing receipt, classification, investigation steps, and resolution. If it took you more than five minutes to compile this for your last complaint, your logging system needs work.
Do your abuse assessments cite specific facts? Pull your three most recent abuse determinations. Each should reference specific prior complaints by date and identifier, quote the substantive overlap, and explain what new investigation the current complaint would require. If your assessments use general language like "the complainant has filed numerous complaints," they won't survive scrutiny.
Can you show you investigated before dismissing? Even potentially abusive complaints deserve initial review. Your records should show you examined the claimed processing activity and determined either (a) it doesn't exist, (b) it's already been investigated in a prior complaint, or (c) the complaint provides no information that would enable investigation.
Have you consulted your supervisory authority? Check your correspondence log. If you've dismissed complaints as abusive without supervisory authority input, you're exposed.
Maintenance and Ongoing Tasks
Quarterly complaint pattern review. Every three months, analyze your complaint log for emerging patterns. Are you seeing an uptick in complaints from mandated bodies? Are certain subject matters generating serial complaints? Adjust your intake questions and documentation requirements accordingly.
Annual criteria review. Once a year, revisit your criteria for substantive complaints. Has your supervisory authority issued new guidance? Has the EDPB clarified what constitutes abuse? Update your written criteria and retrain your team.
Supervisory authority relationship maintenance. Don't contact your supervisory authority only when you want to dismiss a complaint. Regular check-ins on your complaint handling process build the relationship that makes consultations on edge cases more productive.
Documentation retention. Keep complaint records for at least the limitation period for GDPR enforcement actions in your jurisdiction (often five to six years). If you dismissed a complaint as abusive, retain the supervisory authority correspondence indefinitely. It's your evidence that you followed procedure.
The EDPB decision doesn't give you carte blanche to dismiss complaints you find annoying. It confirms that abuse is a recognized ground for dismissal, but only when you can demonstrate the pattern, document the lack of substance, and secure supervisory authority agreement. Build your process around that reality.



