Relevant and Reasoned Objection
In the GDPR's cooperation system, when one data protection authority prepares a draft decision on a cross-border case, other supervisory authorities that are concerned can formally challenge it. A 'relevant and reasoned objection' is such a challenge, but it must meet a specific threshold: it has to be genuinely connected to the case and clearly explained rather than a general disagreement. If this threshold is met, the disagreement may need to be resolved through the wider cooperation and consistency process.
A 'relevant and reasoned objection' is a term defined in the GDPR referring to an objection raised by a concerned supervisory authority to a lead supervisory authority's draft decision, addressing whether there is an infringement of the Regulation or whether the envisaged action against the controller or processor complies with it. To be 'relevant', the objection must generally have a direct connection to the substance of the draft decision at issue; to be 'reasoned', it must, according to European Data Protection Board (EDPB) guidance, be coherent, clear, and precise, and set out in detail the reasons for the objection. The EDPB's Guidelines 09/2020 elaborate on how these two elements should be assessed; practitioners should note that this term operates within the GDPR's cooperation mechanism (governing lead authority and concerned authority interaction) and its consistency mechanism (including dispute resolution by the EDPB where a lead authority does not follow, or considers not relevant and reasoned, an objection). The precise article references and procedural detail should be verified against the current text of the Regulation and the EDPB Guidelines, and this definition does not extend to the distinct concept of 'reasoned objections' used in other legal contexts such as patent examination.
Why it matters
The relevant and reasoned objection (RRO) is a pivotal control point in the GDPR's cross-border enforcement architecture. Because the one-stop-shop model concentrates responsibility for a cross-border case in a single lead supervisory authority, the RRO is the principal formal means by which other concerned supervisory authorities can influence, challenge, or resist a draft decision they consider flawed. Whether an objection clears the 'relevant and reasoned' threshold can therefore determine whether a case proceeds on the lead authority's terms or is escalated into the wider cooperation and consistency machinery, potentially including dispute resolution by the European Data Protection Board (EDPB).
For controllers and processors under investigation, the stakes are practical rather than abstract. An objection that meets the threshold can reopen questions about whether there is an infringement at all, or about the nature and severity of the envisaged corrective action, and can lead to an outcome that differs from the lead authority's original draft. This introduces a degree of uncertainty into cross-border cases: the position reflected in a draft decision is not necessarily the final position, and organisations should treat the cooperation phase as one where the substantive conclusions may still shift.
The threshold itself matters because it is not a mere formality. The EDPB's Guidelines 09/2020 set out how the 'relevant' and 'reasoned' elements should be assessed, distinguishing genuine, case-connected challenges from general disagreement. Where a lead authority does not follow an objection, or considers it not relevant and reasoned, the consistency mechanism may be triggered. Practitioners should note that the interpretation of this threshold continues to be shaped by EDPB guidance and practice, and the precise procedural steps and article references should be verified against the current text of the Regulation and the Guidelines.
Who it's relevant to
Inside RRO
Common questions
Answers to the questions practitioners most commonly ask about RRO.