Key Takeaways
- On 30 July 2026 the privacy NGO noyb filed a GDPR complaint with the Austrian data protection authority against dict.cc, whose consent banner asks visitors to approve data sharing with 1,741 named "partner" companies in a single click.
- noyb calculates that reading all 1,741 partners' privacy policies would take at least 170 hours, even allowing just 6 minutes to scan each one.
- The IAB Europe Transparency and Consent Framework Global Vendor List registered 1,202 vendors as of 6 August 2026 — meaning a 1,741-partner banner is larger than the entire TCF list, and most merchants never chose a single name on it.
- EDPB guidance pulls in two directions at once: every controller relying on your consent must be named, yet the request must be understandable to an average person. On our reading, the only way to satisfy both is to reduce the number of controllers, not to redesign the banner.
- 428 of the 1,202 registered vendors (35.6%) declare at least one purpose on a legitimate-interest basis, so "Reject all" typically does not stop them — a visitor has to object separately, usually on a second screen.
Introduction
Open your own store in a fresh incognito window and click whatever your cookie banner calls its settings link. Then scroll. On a default consent setup you will likely pass a few hundred company names you have never heard of, never contracted with, and could not describe to a customer who asked.
That list is now the subject of a formal GDPR complaint. On 30 July 2026, the Austrian NGO noyb filed against the online dictionary dict.cc over a banner offering 1,741 "partners" in one click, arguing that consent spread that thin cannot be informed consent. The theory is new, the pattern is not, and the vendor list on a typical Shopify or WooCommerce store came from the same place: a default setting nobody revisited.
This article reflects publicly available regulatory guidance and news as of August 2026. It is informational content, not legal advice.
Why Your Cookie Banner Has Too Many Vendors
Your banner lists hundreds of partners because your consent management platform ships an industry-wide vendor list, and enabling all of it is the path of least resistance. The list reflects the ad-tech ecosystem's total membership, not the four or five tools your store actually runs.
Two registries do most of the work. The IAB Europe Transparency and Consent Framework (TCF) publishes a Global Vendor List of companies that have signed up to the framework; on 6 August 2026 that list (version 171) contained 1,202 vendors. Separately, Google's Additional Consent provider list covers ad technology providers that are not TCF-registered, and it held 714 providers on the same date. Between them, that is 1,916 companies a banner could name without anyone at your business making a single decision.
What the dict.cc number actually tells you
The complaint's headline figure is worth sitting with: 1,741 partners exceeds the entire TCF Global Vendor List of 1,202. Whatever combination of registries produced that banner, no plausible reading has dict.cc individually vetting 1,741 data recipients. That is the point noyb is pressing.
"It would take days or even weeks to properly read and understand the data protection policies of 1,741 companies," said noyb data protection lawyer Felix Mikolasch. "It is ridiculous to assume that this would allow for an informed decision." His colleague Martin Baumann put the user's side of it: "Consenting to thousands of 'partner' companies using your personal data does not only feel wrong, it indeed is."
noyb has asked the Austrian authority to order deletion of the unlawfully processed data, to require all recipients to be informed of that deletion, and to impose a deterrent fine. It also notes the authority may issue a wider ban or refer the matter to the European Data Protection Board for an opinion, given its general significance. And noyb explicitly frames this as an industry practice rather than one site's error, naming repubblica.it, bergfex.de and fifa.com as running the same pattern.
Does GDPR Require You to Name Every Cookie Vendor?
Yes — and that is exactly the problem. EDPB guidance requires every controller who relies on your consent to be named, while separately requiring the consent request to be understandable to an ordinary person. A 1,741-name list satisfies the first rule by breaking the second.
The naming rule is explicit. EDPB Guidelines 05/2020 on consent, paragraph 65, states that "in a case where the consent sought is to be relied upon by multiple (joint) controllers or if the data is to be transferred to or processed by other controllers who wish to rely on the original consent, these organisations should all be named." Processors do not need naming for consent purposes, though Articles 13 and 14 still require a full list of recipients or categories of recipients.
So the vendor list is not a bug your CMP introduced. It is the visible consequence of a legal requirement — every ad-tech company that wants to rely on your visitor's consent has to be named to them.
Where the requirement collides with itself
Paragraph 64 of the same guidelines sets the minimum for informed consent: the controller's identity, the purpose of each processing operation, what type of data is collected, the right to withdraw, any Article 22(2)(c) automated decision-making, and the risks of transfers made without an adequacy decision or Article 46 safeguards. Recital 42 GDPR, quoted in the guidelines, puts the floor plainly: "For consent to be informed, the data subject should be aware at least of the identity of the controller and the purposes of the processing for which the personal data are intended."
Then paragraph 67 closes the trap. "When seeking consent, controllers should ensure that they use clear and plain language in all cases," the EDPB writes. "This means a message should be easily understandable for the average person and not only for lawyers. Controllers cannot use long privacy policies that are difficult to understand or statements full of legal jargon."
Our read: these two obligations cannot both be met at scale, and the resolution has to come from the data flows rather than the interface. Article 4(11) GDPR defines consent as a "freely given, specific, informed and unambiguous indication" of wishes; Recital 32 adds that an electronic request "must be clear, concise and not unnecessarily disruptive." No amount of banner design makes 1,741 controllers concise. Cutting the list to the vendors you genuinely use is the only move that improves both sides of the equation at once — and unlike a banner redesign, it also shrinks your actual disclosure surface. The trade-off is real: pruning means someone has to reconcile the list against your live tag stack, and marketing will lose a few integrations that were quietly firing.
What 1,202 Vendors Are Actually Asking For
Behind the names sit 11 standard TCF purposes and 2 special features, and they are not all equally consequential. The distribution below is taken from the Global Vendor List's own machine-readable registry, version 171, dated 6 August 2026.
| What the vendor declares | Vendors (of 1,202) |
|---|---|
| Store and/or access information on a device (Purpose 1) — consent | 976 |
| Create profiles for personalised advertising (Purpose 3) — consent | 729 |
| Use profiles to select personalised advertising (Purpose 4) — consent | 729 |
| Measure advertising performance (Purpose 7) — legitimate interest | 353 |
| Use precise geolocation data (Special Feature 1) | 349 |
| Develop and improve services (Purpose 10) — legitimate interest | 294 |
| Identify devices based on information actively requested (Special Feature 2) | 190 |
Two figures deserve attention. 349 vendors — 29% of the list — declare precise geolocation, a category most merchants would not knowingly switch on for a checkout flow. And 428 vendors (35.6%) declare at least one purpose under legitimate interest rather than consent: 353 for advertising measurement, 294 for service development, 251 for selecting advertising, 182 for audience statistics, 145 for content measurement and 58 for content selection.
That second number is the one that surprises people. Where a vendor claims legitimate interest, clicking "Reject all" typically does not switch it off — depending on how your platform transmits the signal, the visitor may have to lodge a separate objection, usually on a screen behind the main choice. It is worth noting what the framework does not allow, though: not one of the 1,202 vendors claims legitimate interest for Purpose 1, storing or accessing information on a device. Every one of the 976 vendors declaring that purpose declares it under consent. Whatever else is contested, the framework's own data treats reading and writing to a visitor's device as a consent question.
How to Audit and Prune Your Cookie Banner Vendor List
Audit the list the way you would audit a supplier register: start from what you actually run, not from what is switched on. The steps below take an afternoon for a typical store and produce the record you would want if a complaint ever landed.
- Inventory the tags that genuinely fire. Load your storefront, checkout and a product page in a fresh incognito session with developer tools open, and write down every third-party domain that makes a request. This is your real list, and on most stores it is a small fraction of what the banner currently names.
- Export your CMP's currently enabled vendor list. Every major consent platform exposes the enabled TCF vendors and, separately, its Google Additional Consent selection. Menu names differ between platforms and change often; what you are looking for is the TCF or vendor-configuration screen, and the count on it.
- Compare the two lists and mark the gap. Any vendor enabled in the CMP that does not appear in your tag inventory is a name your visitors are being asked to approve for no operational reason.
- Deselect everything, then re-add deliberately. Most platforms offer a select-none control precisely so you can rebuild from zero. Re-add only vendors you have a contract or a live integration with — the ones you could name and describe if a customer asked who received their data.
- Handle the legitimate-interest declarations separately. For each vendor you keep, check which purposes it claims under legitimate interest, since those survive a rejection. If a vendor's legitimate-interest claims are broader than the job you hired it for, that is a reason to drop it rather than a detail to note.
- Write the decision down. Record who reviewed the list, the date, which vendors were removed and why. Pruning without a record leaves you re-deriving the same reasoning at the next audit, and it is the accountability evidence Articles 5(2) and 24 expect you to hold.
- Re-run it on a schedule. The Global Vendor List changes continually — version 171 was published on 6 August 2026 — and a CMP set to track it can quietly reintroduce vendors you removed. Quarterly is a reasonable cadence for most stores.
Common Mistakes
Treating the default vendor list as the required one. This is the single most expensive error here, because it is invisible: nothing in a CMP's onboarding tells you the list is a menu rather than an obligation. You are the controller deciding who receives your visitors' data. Nobody at IAB Europe made that choice for you.
Assuming more names means more transparency. The instinct is understandable and backwards. Under paragraph 67's plain-language standard, a list nobody can read is worse than a short one, not more thorough — and noyb's 170-hour calculation exists precisely to make that arithmetic concrete.
Reading "legitimate interest" as "no consent needed." It is a different lawful basis for downstream processing, not a general exemption, and it is why a visitor who rejected everything can still be measured by 353 of the vendors on the list.
Fixing the banner instead of the flows. Reject buttons, colour contrast and first-layer parity all matter — we have covered those defects in our guide to cookie banner complaints after EDPB Binding Decision 1/2026, alongside what valid consent requires in our 2026 cookie consent guide. But a perfectly designed banner attached to 800 unreviewed vendors still asks the visitor for something they cannot meaningfully give.
Never reconciling the vendor list with your record of processing. If a vendor is enabled in your CMP, it is a recipient, and recipients belong in your record of processing activities. A vendor list and a RoPA that disagree is a finding waiting to happen.
How PrivacyForge Helps
The pruning work above is mostly a reconciliation problem: what is enabled, what actually runs, and what your documentation says — three lists that drift apart quietly.
PrivacyForge's consent management keeps a timestamped record of every consent, including the purposes shown and the banner version in force, so you can demonstrate what a visitor was actually asked at a given date rather than what your current configuration implies. The data mapping module holds vendors as named recipients against each processing activity, which is what turns a CMP export into an accountability record you can hand a regulator. Compliance scoring then flags the gap that matters here — recipients present in your consent configuration but absent from your record of processing.
None of that replaces the afternoon spent reading your own tag requests. It replaces having to do that reconciliation from memory every quarter.
Frequently Asked Questions
Why does my cookie banner show hundreds of partners I have never heard of?
Because your consent platform enabled an industry-wide vendor registry by default rather than your actual tool stack. The IAB Europe TCF Global Vendor List held 1,202 vendors on 6 August 2026, and Google's Additional Consent list another 714. Enabling them wholesale is a configuration choice, not a legal requirement, and most merchants never revisit it after installation.
How many vendors is too many in a cookie consent banner?
There is no legal number, but there is a workable test: if you cannot name a vendor and describe what data it receives, your visitor cannot give informed consent to it. Most eCommerce stacks involve far fewer recipients than a default vendor list names. noyb's complaint against a 1,741-partner banner argues that scale defeats the informed limb of consent entirely.
Do I need to list every cookie vendor on my website?
Every controller that relies on your visitor's consent must be named. EDPB Guidelines 05/2020 paragraph 65 states that where consent is relied upon by multiple joint controllers, or data goes to other controllers relying on that consent, "these organisations should all be named." Processors need not be named for consent, though Articles 13 and 14 still require recipients or categories of recipients.
Does "legitimate interest" in a cookie banner mean I do not need consent?
No. Legitimate interest is a different lawful basis for downstream processing, and a visitor may have to object separately rather than simply rejecting. In the TCF's own registry, 428 of 1,202 vendors (35.6%) declare at least one legitimate-interest purpose. Notably, none claims it for storing or accessing information on a device — all 976 vendors declaring that purpose declare it under consent.
Is the IAB TCF actually GDPR-compliant?
Its legal status has been contested for years and is not fully settled. The Belgian data protection authority ruled on IAB Europe and the TCF on 2 February 2022. The Court of Justice held on 7 March 2024 in Case C-604/22 that a TC String constitutes personal data and that IAB Europe is a joint controller for recording consent preferences. The Brussels Market Court gave judgment on 14 May 2025.
How do I reduce the number of vendors in my consent banner?
Start from your live tag stack, not the CMP list. Record every third-party domain that fires on your storefront and checkout, export your platform's enabled vendor list, then deselect all and re-add only vendors you hold a contract or live integration with. Document who reviewed the list and why each vendor was removed, and repeat quarterly.
Conclusion
The dict.cc complaint has not been decided, and no regulator has yet set a number above which consent stops being informed. What has changed is that the argument is now on a supervisory authority's desk, with a request that it be referred to the EDPB as a matter of general significance — and the practice it targets is running, unmodified, on a large share of European online stores.
You do not need to wait for the outcome to act, because the remedy is one you would want regardless. A vendor list you have actually read is shorter, easier to explain, cheaper to document, and considerably harder to complain about. Open your banner's settings screen, count the names, and see how many you can account for.
Ready to reconcile your consent configuration with your record of processing? Explore PrivacyForge's consent and data mapping tools.
Sources
- noyb: 1,741 "informed" consents in one click — GDPR complaint against dict.cc filed
- IAB Europe TCF Global Vendor List (version 171, 6 August 2026)
- Google Additional Consent provider list
- EDPB Guidelines 05/2020 on consent under Regulation 2016/679
- CJEU Press Release No 44/24: Judgment in Case C-604/22 IAB Europe (7 March 2024)
- IAB Europe: FAQ on the APD decision on IAB Europe and TCF (updated May 2025)
- GDPR Article 4(11) — definition of consent
- GDPR Recital 32 — conditions for consent