Skip to main content
Category: Supervisory Authorities & Enforcement

Relevant and Reasoned Objection

Also known as: RRO, relevant and reasoned objection, reasoned objection
Simply put

In the GDPR's cooperation system, when one data protection authority prepares a draft decision on a cross-border case, other supervisory authorities that are concerned can formally challenge it. A 'relevant and reasoned objection' is such a challenge, but it must meet a specific threshold: it has to be genuinely connected to the case and clearly explained rather than a general disagreement. If this threshold is met, the disagreement may need to be resolved through the wider cooperation and consistency process.

Formal definition

A 'relevant and reasoned objection' is a term defined in the GDPR referring to an objection raised by a concerned supervisory authority to a lead supervisory authority's draft decision, addressing whether there is an infringement of the Regulation or whether the envisaged action against the controller or processor complies with it. To be 'relevant', the objection must generally have a direct connection to the substance of the draft decision at issue; to be 'reasoned', it must, according to European Data Protection Board (EDPB) guidance, be coherent, clear, and precise, and set out in detail the reasons for the objection. The EDPB's Guidelines 09/2020 elaborate on how these two elements should be assessed; practitioners should note that this term operates within the GDPR's cooperation mechanism (governing lead authority and concerned authority interaction) and its consistency mechanism (including dispute resolution by the EDPB where a lead authority does not follow, or considers not relevant and reasoned, an objection). The precise article references and procedural detail should be verified against the current text of the Regulation and the EDPB Guidelines, and this definition does not extend to the distinct concept of 'reasoned objections' used in other legal contexts such as patent examination.

Why it matters

The relevant and reasoned objection (RRO) is a pivotal control point in the GDPR's cross-border enforcement architecture. Because the one-stop-shop model concentrates responsibility for a cross-border case in a single lead supervisory authority, the RRO is the principal formal means by which other concerned supervisory authorities can influence, challenge, or resist a draft decision they consider flawed. Whether an objection clears the 'relevant and reasoned' threshold can therefore determine whether a case proceeds on the lead authority's terms or is escalated into the wider cooperation and consistency machinery, potentially including dispute resolution by the European Data Protection Board (EDPB).

For controllers and processors under investigation, the stakes are practical rather than abstract. An objection that meets the threshold can reopen questions about whether there is an infringement at all, or about the nature and severity of the envisaged corrective action, and can lead to an outcome that differs from the lead authority's original draft. This introduces a degree of uncertainty into cross-border cases: the position reflected in a draft decision is not necessarily the final position, and organisations should treat the cooperation phase as one where the substantive conclusions may still shift.

The threshold itself matters because it is not a mere formality. The EDPB's Guidelines 09/2020 set out how the 'relevant' and 'reasoned' elements should be assessed, distinguishing genuine, case-connected challenges from general disagreement. Where a lead authority does not follow an objection, or considers it not relevant and reasoned, the consistency mechanism may be triggered. Practitioners should note that the interpretation of this threshold continues to be shaped by EDPB guidance and practice, and the precise procedural steps and article references should be verified against the current text of the Regulation and the Guidelines.

Who it's relevant to

Data Protection Officers and in-house privacy leads
For organisations subject to cross-border investigations, DPOs should understand that a lead authority's draft decision is not necessarily final. Concerned authorities may raise objections meeting the RRO threshold that reopen the question of infringement or the envisaged corrective action, so the cooperation phase warrants active monitoring rather than assuming the draft outcome will stand.
Data protection lawyers and enforcement counsel
Counsel advising on cross-border cases need to track whether objections raised by concerned authorities are likely to be treated as 'relevant and reasoned' under EDPB Guidelines 09/2020, as this affects whether a matter escalates into the consistency mechanism and potential EDPB dispute resolution. The assessment is fact-specific and the interpretation continues to evolve, so advice should be qualified accordingly.
Supervisory authorities
Both lead and concerned supervisory authorities operate directly within this framework: concerned authorities must frame objections to meet the relevant and reasoned threshold, while lead authorities must decide whether to follow an objection or treat it as not meeting the threshold, a decision that can trigger the consistency mechanism. The EDPB Guidelines 09/2020 are the primary reference for how these judgments should be made.
Compliance leads managing multi-jurisdiction operations
Organisations processing personal data across multiple EU member states should factor in that the outcome of a cross-border case may reflect input from several authorities, not only the lead. Member state derogations and differing regulator positions can shape the objections raised, so compliance planning should account for a degree of uncertainty in cross-border enforcement outcomes.

Inside RRO

Objection to a Draft Decision
A relevant and reasoned objection is raised by a supervisory authority concerned in response to a draft decision circulated by the lead supervisory authority under the GDPR's cooperation and consistency mechanisms. It is a formal instrument within cross-border cooperation between EU/EEA regulators.
Relevance Requirement
The objection must relate to whether the draft decision complies with the GDPR, or to whether the envisaged action toward the controller or processor is in conformity with the Regulation. In most cases the objecting authority must show a connection to the substance of the case rather than a general disagreement.
Reasoned Requirement
The objection must be substantiated, typically setting out the arguments and reasoning behind the disagreement, including the significance of the risks posed by the draft decision to fundamental rights and freedoms of data subjects and, where applicable, the free flow of personal data. The precise threshold has been addressed in regulatory guidance and should be verified against the current official text and European Data Protection Board materials.
Trigger for the Dispute Resolution Mechanism
Where the lead supervisory authority does not follow a relevant and reasoned objection, or considers it not to meet the threshold, the matter can generally be escalated to the consistency mechanism and the European Data Protection Board's binding dispute resolution process. The exact procedural steps derive from the Regulation's cooperation provisions and associated guidance.
Scope Limited to Cross-Border Cases
This concept operates in the context of cross-border processing involving a lead supervisory authority and one or more concerned supervisory authorities. It is EU/EEA-specific; the position under the UK GDPR and national implementing law may differ and should be checked separately.

Common questions

Answers to the questions practitioners most commonly ask about RRO.

Does any objection raised by a supervisory authority during the cooperation process qualify as a 'relevant and reasoned objection'?
No. Not every comment or disagreement meets the threshold. The term has a specific meaning: an objection must demonstrate the significance of the risks posed by the draft decision to the fundamental rights and freedoms of data subjects and, where applicable, to the free flow of personal data. A mere expression of disagreement, or an objection that is not substantiated by reasoning connected to those risks, would generally not qualify. The concept is defined within the GDPR's consistency and cooperation framework, and its application has been elaborated in guidance from the European Data Protection Board, which the reader should consult for the detailed criteria.
Is a supervisory authority free to object to any part of a lead authority's draft decision on any ground it chooses?
Not without constraint. To be treated as relevant and reasoned, an objection must relate to the concerned authority's own position, typically because data subjects in its territory are affected or an establishment is in its member state, and it must be substantive rather than a general policy preference. The objection should engage with whether the draft decision correctly applies the Regulation or adequately addresses the risks to data subjects. An objection falling outside these bounds may not trigger the mechanisms that follow, though how strictly this is assessed can be a matter of judgment and evolving practice among regulators.
What happens procedurally after a concerned authority raises an objection during a one-stop-shop case?
In general terms, the lead supervisory authority must consider the objection. If the lead authority intends to follow it, a revised draft decision is typically circulated. If the lead authority does not intend to follow an objection it regards as relevant and reasoned, or disputes whether the objection meets that threshold, the matter can be referred to the European Data Protection Board under the consistency mechanism. Readers should verify the precise procedural steps and any applicable timeframes against the current official text of the Regulation and EDPB guidance, as these details govern the outcome.
How should a concerned supervisory authority draft an objection to maximise the chance it is treated as relevant and reasoned?
As a matter of good practice, an objection should identify the specific element of the draft decision it challenges, explain the connection to risks to data subjects' fundamental rights and freedoms or to the free flow of data, and set out the reasoning supporting that position rather than asserting a conclusion. Referencing the relevant provisions and the factual basis tends to strengthen an objection. The EDPB has issued guidance on the notion that elaborates on these expectations, and authorities generally align their drafting to those criteria; the guidance itself is the appropriate reference point.
What is the practical consequence for an organisation if a relevant and reasoned objection is raised against a decision affecting it?
In practice, such an objection can delay finalisation of the decision, because the lead authority must address it and the matter may proceed to dispute resolution before the EDPB. The eventual binding decision may differ from the lead authority's original draft. For an organisation, this means the outcome and its timing may remain uncertain while the cooperation and consistency processes run their course. The specific effects depend on the facts of the case and how the authorities proceed, so organisations should seek current procedural detail rather than assume a fixed timeline.
Who decides whether an objection meets the 'relevant and reasoned' threshold when the lead authority and a concerned authority disagree?
Where there is disagreement about whether an objection is relevant and reasoned, or the lead authority does not follow it, the question can ultimately be resolved through the EDPB's dispute resolution role under the consistency mechanism, which can issue a binding decision. This means the assessment is not left solely to the lead authority. The precise allocation of these functions and the conditions that trigger EDPB involvement are set out in the Regulation, which the reader should consult directly to confirm how the threshold is adjudicated in a given case.

Common misconceptions

Any disagreement by a concerned supervisory authority automatically qualifies as a relevant and reasoned objection.
Not every comment or disagreement meets the threshold. The objection generally must be both relevant, connecting to GDPR conformity or the envisaged action, and reasoned, demonstrating the significance of risks to data subjects' rights and freedoms. Guidance has addressed how this threshold is assessed, and its application can be contested.
A relevant and reasoned objection by itself overrides or replaces the lead authority's draft decision.
The objection does not, on its own, dictate the outcome. Where the lead authority does not follow it, the matter can typically be escalated to the European Data Protection Board's binding dispute resolution process, which then determines the position through the consistency mechanism.
The concept applies uniformly across the EU, UK, and to all types of processing.
It is tied to the EU/EEA cooperation and consistency mechanisms for cross-border processing. The equivalent position under the UK GDPR and under national implementing measures may vary, and member state derogations can affect surrounding procedures. Practitioners should confirm the applicable framework.

Best practices

When raising an objection, address both limbs explicitly: articulate the relevance to GDPR conformity or the envisaged action, and provide substantiated reasoning demonstrating the significance of risks to data subjects' rights and freedoms.
Frame the objection against the specific content of the draft decision rather than expressing general disagreement, so it is more likely to be treated as meeting the threshold.
Verify the applicable procedural steps and threshold criteria against the current official GDPR text and European Data Protection Board guidance, as interpretation of the threshold can evolve.
Anticipate escalation: prepare arguments on the basis that an unresolved objection may proceed to the Board's binding dispute resolution, and document the case record accordingly.
Confirm whether the matter falls within the EU/EEA cross-border cooperation framework or under a separate regime such as the UK GDPR, since the mechanism and its availability may differ.
Treat regulatory guidance on this concept as subject to change and avoid relying on a single point-in-time interpretation as settled law.