Skip to main content
When the EDPB Asks You to Snitch on InconsistencySupervisory Authorities & Enforcement
5 min readFor Legal & Compliance Teams

When the EDPB Asks You to Snitch on Inconsistency

What Happened

On June 24, the European Data Protection Board (EDPB) launched a contact form for stakeholders to report inconsistencies in GDPR interpretation across Europe. You can now flag divergences between national supervisory authority positions or between a national position and EDPB guidance. The Board won't respond to individual submissions, but they'll compile the reports and discuss them to consider steps toward better consistency.

This isn't a complaints hotline. It's a structured attempt to address the enforcement gaps that complicate your compliance efforts.

Timeline

This initiative stems from the EDPB's Helsinki Statement on enhanced clarity, support, and engagement. That statement committed the Board to strengthening stakeholder dialogue and ensuring consistent GDPR enforcement. The contact form is the first tangible tool to emerge from those commitments.

Here's what matters for your planning:

  • June 24: Contact form goes live
  • Ongoing: EDPB compiles submissions regularly
  • Board meetings: High-level discussion of reported inconsistencies to determine next steps

No deadline has been announced for submitting reports, and there's no indication this is a temporary measure. The form appears to be a permanent channel.

Which Controls Failed or Were Missing

The contact form exists because existing mechanisms for consistency aren't working well enough. Here's what's broken:

Article 63 requires supervisory authorities to cooperate with one another. In practice, cooperation doesn't prevent interpretation drift. A French authority might interpret legitimate interests for analytics one way, while an Irish authority might take a different view. Both positions can align with GDPR text, yet create compliance headaches if you operate in both jurisdictions.

Article 70(1) tasks the EDPB with ensuring consistent application of GDPR. The Board issues guidelines and recommendations, but these aren't binding unless adopted as formal decisions under Article 65. Most EDPB output is persuasive, not mandatory. When a supervisory authority ignores or reinterprets EDPB guidance, you're left navigating conflicting standards with no clear escalation path.

The one-stop-shop mechanism under Article 56 was supposed to reduce friction for cross-border processing. Instead, it's created turf battles. Lead authorities and concerned authorities don't always agree on their roles, the interpretation of key obligations, or the appropriate enforcement response. You see this in delayed decisions, contradictory advice during audits, and public disagreements about major cases.

Before June 24, there was no formal channel for you to say: "These two authorities are telling me opposite things, and I need the EDPB to notice."

What the Relevant Standard Requires

Article 70(1) gives the EDPB explicit responsibility to "ensure the consistent application" of GDPR. This includes issuing guidelines on any question related to GDPR application and promoting cooperation between supervisory authorities.

Article 64(2) allows the EDPB to issue an opinion on a matter of general application or producing effects in more than one member state. Opinions aren't binding, but they carry weight. If the EDPB determines that a reported inconsistency reflects a broader interpretive problem, it can issue guidance to clarify.

Article 65 covers binding decisions in dispute resolution, but only when supervisory authorities formally disagree during the consistency mechanism process. The contact form doesn't trigger Article 65 proceedings. It's a softer tool: visibility without automatic escalation.

The Helsinki Statement isn't a legal instrument, but it signals the Board's recognition that consistency isn't just about formal dispute resolution. It's about surfacing problems early, before they become entrenched national positions.

Lessons and Action Items for Your Team

Start documenting divergences now. Don't wait until you're in the middle of an audit or enforcement action. When you encounter conflicting guidance from different supervisory authorities, record:

  • The specific GDPR article or obligation at issue
  • The positions taken by each authority (with citations to published guidance, FAQs, or correspondence)
  • The business impact on your organization
  • Whether the divergence contradicts EDPB guidance

Keep this log centrally. You'll need it to make a coherent submission.

Use the contact form strategically, not reactively. The EDPB won't solve your individual compliance problem. They're looking for patterns. Your submission is most useful when it:

  • Identifies a divergence affecting multiple organizations or sectors
  • Points to a gap between national practice and published EDPB guidance
  • Highlights an interpretive question the EDPB hasn't addressed yet

Don't submit edge cases or one-off disagreements. Submit the inconsistencies that make your cross-border operations genuinely harder to manage.

Coordinate with industry groups. If you're seeing an inconsistency, others in your sector probably are too. A single submission from your organization carries less weight than five submissions from different organizations describing the same problem. Work with trade associations or privacy networks to identify common pain points and submit coordinated reports.

Don't expect immediate relief. The EDPB has made clear they won't respond to individual submissions. You're contributing to a long-term project of regulatory alignment, not getting a binding answer to your specific question. Continue managing your compliance risk as you would otherwise: document your reasoning, apply EDPB guidance where it exists, and escalate through normal supervisory authority channels when you need a formal position.

Prepare for the EDPB to act on your report. If the Board decides to issue guidance on a topic you've flagged, you'll want to be ready. Monitor EDPB meeting agendas and published work programs. When new guidance emerges on an area where you've reported inconsistency, review your practices immediately. Supervisory authorities will expect you to align with clarified guidance, even if your previous approach was defensible under the old ambiguity.

Recognize what this tool won't fix. The contact form doesn't change the fact that GDPR is a regulation requiring national implementation. Member states retain discretion on certain questions. Some divergence is structural, not a bug. The EDPB can't harmonize what the regulation itself leaves open. Focus your submissions on interpretation, not on legitimate national choices.

This contact form is a test. The EDPB is betting that stakeholder input will help them target their consistency efforts more effectively. Your job is to give them the data they need to succeed.

You Might Also Like