Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: Enforcement and Compliance

noyb Complaints

Also known as: NOYB complaints, None of Your Business complaints, noyb GDPR complaints
Simply put

noyb complaints are formal privacy complaints filed by noyb, an Austrian-based advocacy group, with European data protection authorities against organizations it believes are breaking EU privacy rules. Many of these complaints target cookie banners, consent practices, and cross-border transfers of personal data. Filing a complaint asks a regulator to investigate; it does not by itself determine that a company has broken the law.

Formal definition

The term refers to complaints lodged by noyb (also styled NOYB, from 'None of Your Business'), an Austria-based non-governmental organization, with supervisory authorities under the GDPR and, in cookie-related matters, provisions implementing the ePrivacy Directive. Complaints are typically filed on behalf of an individual data subject with a national data protection authority, and may allege defects in cookie banner design and consent collection, absence of a valid legal basis for processing, or unlawful international data transfers. According to the evidence, noyb complaints have addressed cookie banners (a complaint lodged with the Austrian DPA that the EDPB required the Belgian DPA to handle on the merits), consent validity for online services (for example, a complaint against dict.cc concerning whether one-click consent can be 'freely given' and 'informed'), the legitimate interest and permission basis in a complaint concerning Meta's AI processing, and data transfers to China in six complaints filed across Greece, the Netherlands, Belgium, Italy, and Austria against firms including AliExpress, TikTok, and WeChat. A complaint initiates a regulatory process before the competent authority; the outcome, including any finding of infringement or corrective measures, depends on that authority's assessment and any subsequent appeal or cross-border cooperation procedures. The scope, procedure, and enforcement consequences vary by jurisdiction and by the legal regime invoked, and this entry does not address the merits or final disposition of any particular complaint.

Why it matters

For organizations operating in the EU, noyb complaints are one of the more visible drivers of regulatory scrutiny around cookie banners, consent design, and cross-border data flows. Because noyb systematically targets common consent practices, its complaints can turn a design choice that many companies share into the subject of a formal investigation by a supervisory authority. A complaint does not itself establish that a company has broken the law, but it obliges the competent authority to consider the matter, and the resulting decisions can influence how similar practices are assessed across the market.

Who it's relevant to

Privacy officers and data protection officers
DPOs and privacy teams should monitor noyb complaints because they often target consent practices and transfer arrangements that are widely used, meaning a complaint against another organization may signal risk in their own setups. A complaint initiates a regulatory process rather than determining liability, so the relevant task is generally to review whether the organization's consent design and legal bases would withstand similar scrutiny.
Legal counsel and compliance teams
Legal teams may need to assess exposure where their organization's practices resemble those challenged in noyb complaints, such as one-click consent flows, reliance on legitimate interest, or transfers of personal data outside the EU. Because outcomes depend on the competent authority's assessment and any cross-border cooperation or appeal procedures, counsel should treat a complaint as the start of a process whose disposition is not predetermined.
Web developers and CMP implementers
Developers and those configuring consent management platforms are relevant because cookie banner design and consent collection are recurring subjects of noyb complaints. A CMP can support compliant consent capture but does not by itself guarantee compliance, so implementers should focus on whether banners obtain consent through a clear affirmative action and present information in line with applicable EU requirements.
Marketing and analytics compliance teams
Teams responsible for analytics, advertising, and tracking technologies should be aware that consent-dependent practices, including those relying on pixels, SDKs, or similar technologies, can attract complaints. Where processing depends on consent that must be freely given, specific, informed, and unambiguous under the GDPR, marketing teams have an interest in ensuring that consent mechanisms do not resemble practices that have been challenged.

Inside noyb Complaints

Complainant organization
noyb (None of Your Business) is a European privacy advocacy organization founded by Max Schrems that files complaints with data protection authorities alleging non-compliance with EU data protection and ePrivacy rules, including in relation to cookie consent practices.
Cookie banner focus
A significant portion of noyb's activity has targeted cookie consent banners, challenging designs that it argues fail to meet the GDPR standard for valid consent, such as banners lacking an equally prominent reject option or using deceptive design patterns.
Alleged consent deficiencies
Complaints typically assert that consent obtained through the challenged banners is not freely given, specific, informed, or unambiguous as required under the GDPR, and may point to practices such as pre-selected options, obstructed refusal, or misleading interface design.
Regulatory pathway
The complaints are directed to national data protection authorities, which retain discretion over how to investigate, prioritize, and resolve them; a complaint is an allegation and does not by itself constitute a finding of unlawfulness.
Automated and large-scale approach
noyb has used tooling to identify and address non-compliant banners at scale, in some cases issuing warnings to organizations before escalating to formal complaints, though outcomes depend on each authority's response and applicable national implementation of the ePrivacy Directive.

Common questions

Answers to the questions practitioners most commonly ask about noyb Complaints.

Does a noyb complaint mean my organization has automatically broken the law?
No. A complaint filed by noyb is an allegation that triggers a review, not a determination of unlawfulness. The relevant supervisory authority must assess the facts before reaching any conclusion, and organizations generally have the opportunity to respond. A complaint reflects noyb's position rather than a binding legal finding, and outcomes can vary between jurisdictions and depend on the specific facts, which may not be fully known at the complaint stage.
Is noyb a regulator with the power to issue fines?
No. noyb is a non-profit advocacy and litigation organization, not a data protection authority. It cannot impose sanctions or issue binding decisions itself. Instead, it typically files complaints with the competent supervisory authorities or pursues litigation, and it is those authorities or courts that hold enforcement and penalty powers. Any fine or corrective measure would come from a regulator or court, not from noyb directly.
How can our organization reduce the likelihood of being targeted by this kind of complaint?
The general approach is to align cookie consent practices with the applicable legal standards in each jurisdiction where you operate. In most EU jurisdictions this includes obtaining prior, freely given, specific, informed, and unambiguous consent through a clear affirmative action before setting non-essential cookies or similar technologies, avoiding pre-ticked boxes and patterns that make refusing as hard as accepting, and maintaining consent records. Because requirements differ across the EU, UK, and individual US states, and because regulatory guidance evolves, alignment should be assessed against the specific regimes that apply to your operations rather than a single universal checklist.
What should we do if we receive notice of a complaint concerning our consent practices?
As a practical matter, organizations typically engage their data protection or legal function promptly, preserve relevant records such as consent logs and CMP configurations, and prepare a factual account of the practices at issue. Cooperation with the supervisory authority handling the matter is generally advisable, along with reviewing whether the challenged practices align with current requirements in the relevant jurisdiction. Because procedures and expectations vary by authority and by facts, specific steps should be confirmed with qualified legal counsel rather than assumed from general guidance.
Does implementing a consent management platform protect us from these complaints?
A CMP can support compliance by helping present consent choices, capture affirmative actions, and log consent records, but it does not by itself guarantee compliance or immunity from complaints. Whether a configuration meets the applicable standard depends on how the CMP is set up, the design of the banner and choices, and the underlying legal requirements in each jurisdiction. Tools support compliance but do not replace legal judgment about whether the specific implementation is defensible.
How do complaint standards differ if we operate outside the EU, such as in the US?
The consent standards commonly at issue in EU complaints reflect the ePrivacy rules on placing or accessing information on a device and the GDPR's opt-in consent requirements. These do not apply uniformly elsewhere. Several US state privacy frameworks, such as those in California, often rely on an opt-out model rather than prior opt-in consent, and may recognize signals like Global Privacy Control. The UK applies its own implementation of these rules. Consequently, the practices that draw complaints in the EU may not map directly onto obligations in other regimes, and the geographic and legal scope of any obligation should be identified before drawing conclusions.

Common misconceptions

A noyb complaint means an organization has been found to have broken the law.
A complaint is an allegation submitted to a data protection authority, not a legal ruling. Whether any violation exists is determined by the competent authority or a court, and outcomes vary by jurisdiction and by the facts of each case.
noyb complaints establish binding rules that apply everywhere.
noyb is an advocacy organization, not a regulator or legislator. Any binding effect comes only from decisions by data protection authorities or courts, and those decisions apply within their own legal scope. Cookie consent obligations differ across the EU, the UK, and US state regimes such as the CCPA and CPRA.
Following noyb's stated banner expectations guarantees compliance.
Aligning a banner with the practices noyb advocates may reduce certain risks, but it does not guarantee compliance. Valid consent depends on the full factual context, applicable national implementation of the ePrivacy Directive and GDPR, and evolving authority guidance; legal judgment remains necessary.

Best practices

Review cookie banners against the GDPR consent standard, ensuring a reject option is generally as accessible and prominent as the accept option, and avoid pre-ticked boxes or deceptive design patterns.
Confirm that non-essential cookies and similar technologies (such as pixels, SDKs, local storage, and fingerprinting) are not placed or accessed before valid prior consent is obtained, in line with the ePrivacy Directive as implemented nationally.
Maintain clear, accessible consent records and logging so the organization can demonstrate how and when consent was obtained if an authority responds to a complaint.
Treat any warning or complaint as an opportunity to reassess banner design and underlying data processing, rather than assuming a fixed template will satisfy every authority.
Account for jurisdictional differences, recognizing that opt-in expectations common in the EU and UK differ from the opt-out approaches often used under US state privacy laws such as the CCPA and CPRA.
Combine consent management tooling with legal review, since a CMP or standardized framework supports compliance but does not replace case-specific legal judgment.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps