When a supervisory authority wants to dismiss a privacy complaint on procedural grounds and another authority objects, you're seeing Article 65(1)(a) GDPR at work. The EDPB's binding decision from 28 May 2026 on the VRT cookie banner complaint shows how this dispute resolution mechanism operates and what it means for your complaint response procedures.
Here's what happened: the Belgian supervisory authority proposed to dismiss a NOYB complaint about cookie banners, citing alleged abuse of complaint rights under Articles 77 and 80(1). The Austrian supervisory authority objected, arguing the complaint should be assessed on its merits. The Belgian supervisory authority didn't follow the objection, so the case went to the EDPB for binding resolution. The EDPB sided with Austria, instructing Belgium to evaluate the underlying cookie banner practices rather than dismissing on procedural grounds.
If you're handling cross-border complaints as a lead supervisory authority or preparing for potential enforcement as a controller, this decision clarifies the threshold for procedural dismissal and the EDPB's expectations around substantive assessment.
The Problem: When Procedural Dismissal Becomes a Consistency Issue
Cross-border complaints trigger the cooperation mechanism under Chapter VII. When the lead supervisory authority and concerned supervisory authorities disagree on handling a complaint, Article 65(1)(a) gives the EDPB power to issue a binding decision ensuring consistent GDPR application.
The VRT case illustrates a specific friction point: can a lead supervisory authority dismiss a complaint as abusive without examining the underlying data protection violation? The EDPB's answer is no, unless you can demonstrate both objective and subjective components of abuse per CJEU standards. This sets the bar for what constitutes a legitimate procedural dismissal versus an avoidance of substantive assessment.
For compliance teams, this decision signals that supervisory authorities will face pressure to assess complaints on their merits, particularly in cross-border cases where another authority has flagged concerns. If you're the subject of a complaint, expect a fuller investigation rather than early dismissal on procedural grounds.
What You Need Before Starting
Before implementing a cross-border complaint response process that accounts for EDPB consistency expectations:
Documentation of your processing activities: You need Article 30 records showing lawful basis, data categories, recipients, and retention periods for every processing operation that might be complained about. If a supervisory authority must assess your practices on the merits, they'll start here.
Evidence of your transparency obligations: Gather your privacy notices, cookie consent interfaces, and any documentation showing how you've implemented Articles 12-14 requirements. In the VRT case, the complaint concerned cookie banners, so your consent implementation records become critical evidence.
Cross-border processing map: Identify which of your processing activities fall under Article 4(23)'s definition of cross-border processing. This determines whether the cooperation mechanism applies and which authority acts as your lead supervisory authority.
Complaint intake protocol: Review how you currently respond to complaints lodged with supervisory authorities. You'll need internal procedures for rapid evidence gathering when an authority requests information during complaint assessment.
Legal analysis of abuse claims: If you believe a complaint is abusive, document the objective element (the complaint exceeds normal exercise of rights) and subjective element (intent to harm or obtain an advantage unrelated to data protection). The EDPB applied CJEU's test requiring both components.
Step-by-Step Implementation
Step 1: Identify your lead supervisory authority
Determine your main establishment under Article 4(16). This is where your central administration sits or where decisions about processing purposes and means are made. Document this determination because it governs which authority handles cross-border complaints about your processing.
If you have establishments in multiple member states, map which processing activities each location controls. The lead supervisory authority changes based on the specific processing complained about.
Step 2: Build your complaint response framework
Create a procedure for when a supervisory authority notifies you of a complaint:
Assign a response owner (typically your data protection officer or legal counsel). Set internal deadlines shorter than the authority's deadlines. Identify which teams hold evidence relevant to the complaint (engineering for technical measures, legal for lawful basis documentation, marketing for consent records).
For cookie banner complaints specifically, you need screenshots of your banner at the time of the complaint, consent management platform logs showing configuration, and documentation of any A/B tests or changes to the interface.
Step 3: Prepare substantive defenses, not procedural arguments
The VRT decision shows that procedural dismissal requires a high threshold. Instead of arguing a complaint is abusive or inadmissible, prepare to defend your actual processing practices.
For each processing activity that might be complained about, document:
- Your lawful basis under Article 6(1) and why it applies
- How you've met transparency obligations (what information you provided, when, and how)
- Your appropriate technical and organizational measures for security
- Evidence that you've respected data subject rights
If you're relying on consent for cookies, document how you've met the ePrivacy Directive requirements and Article 7 GDPR conditions: freely given, specific, informed, and unambiguous indication of wishes.
Step 4: Monitor the cooperation mechanism
When the lead supervisory authority circulates a draft decision to concerned supervisory authorities under Article 60(3), you won't see the draft, but you should track timing. Concerned authorities have four weeks to raise relevant and reasoned objections under Article 4(24).
If objections arise and aren't resolved, the case goes to the EDPB under Article 65. This extends the timeline significantly. The EDPB has one month (extendable by another month) to issue a binding decision.
Track these timelines in your matter management system. If a complaint hasn't resolved within the normal Article 60 timeframe, assume objections were raised and prepare for a more rigorous assessment.
Step 5: Implement changes based on the decision
When the EDPB instructs a lead supervisory authority to assess a complaint on its merits (as in the VRT case), expect the authority to issue a new draft decision under Article 60(3). This restarts the cooperation process.
If you're the subject of that complaint, you'll likely receive requests for additional information. The authority must now examine whether your cookie banner implementation complies with consent requirements, not just whether the complaint was procedurally proper.
Validation: How to Verify It Works
Test your evidence gathering: Simulate a complaint notification. Can you assemble all relevant documentation within 48 hours? If a supervisory authority asks how your cookie banner obtained consent on a specific date, can you produce the banner configuration, the consent management platform settings, and logs showing what the user saw?
Review your lawful basis documentation: For each processing activity in your Article 30 records, verify you can produce evidence supporting your stated lawful basis. If you claim consent, you need records of what the user agreed to and when. If you claim legitimate interests, you need a legitimate interests assessment.
Check cross-border processing identification: Confirm you've correctly identified which processing activities are cross-border under Article 4(23). The cooperation mechanism only applies to cross-border processing, so misidentification affects which procedures apply.
Audit your transparency materials: Compare your privacy notices against Articles 13 and 14 requirements. The EDPB's emphasis on substantive assessment means authorities will examine whether you've actually provided required information, not just whether you have a privacy policy.
Maintenance and Ongoing Tasks
Quarterly review of processing changes: When you add new processing activities or change existing ones, update your Article 30 records and assess whether the changes affect your lead supervisory authority determination or create new cross-border processing.
Annual evidence audit: Once per year, verify you can still produce evidence supporting your compliance claims for major processing activities. Consent records, legitimate interests assessments, and data protection impact assessments should be retrievable and current.
Monitor EDPB decisions: The EDPB publishes binding decisions under Article 65 several times per year. Each decision clarifies how the cooperation mechanism works and what substantive standards supervisory authorities will apply. Track these decisions and adjust your compliance documentation accordingly.
Update complaint response procedures: As the EDPB issues more Article 65 decisions, incorporate lessons learned into your internal procedures. The VRT decision establishes that procedural dismissal requires demonstrating both objective and subjective abuse components. Future decisions will clarify other aspects of complaint handling.
Maintain consent records: For cookie banners and other consent-based processing, implement technical measures to preserve evidence of consent at the time it was given. If a complaint arrives months later, you need to show what the user actually saw and agreed to, not just your current implementation.
The EDPB's decision in the VRT case reinforces that cross-border complaints will receive substantive assessment when concerned supervisory authorities object to procedural dismissal. Your preparation should focus on defending your actual processing practices, not on procedural arguments for dismissal.



