This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.
Data Sovereignty
EDPB requires Belgian DPA to handle the merits of NOYB cookie banner complaint
The decision concerns a dispute submitted by the Belgian Data Protection Authority (DPA) about a complaint against Vlaamse Radio-en Televisieomroeporganisatie (VRT) – a public broadcasting company based in Belgium. The Belgian DPA, acting as Lead Supervisory Authority (LSA), submitted a draft decision proposing to dismiss the complaint on the basis of an alleged abuse of Art.77 GDPR and Art. The EDPB considered the Austrian DPA’s objection relevant and reasoned within the meaning of Art.4(24) GDPR and the EDPB Guidelines on the concept of relevant and reasoned objection and assessed it on the merits. The EDPB found that, based on the information available and in line with the CJEU’s test for alleged abuse, the complainant did not abuse their rights under Art.77 and Art.80(1) GDPR. Therefore, the EDPB instructed the LSA not to dismiss the complaint, but to assess it instead on its merits and to submit a new draft decision to the CSAs under Art.60(3) GDPR. Note to editors:*Art.65(1)(a) GDPR is a dispute resolution mechanism meant to ensure the correct and consistent application of the GDPR in cross-border cases, addressing disagreements that have arisen between the LSA and the CSAs in a given case.