Key Takeaways
- On 14 July 2026 the EDPB published Binding Decision 1/2026 (adopted 28 May 2026 under Article 65(1)(a) GDPR), ordering Belgium's data protection authority to stop dismissing a cookie-banner complaint on procedural grounds and to decide it on the merits instead.
- The complaint was filed by the NGO noyb with the Austrian DPA on behalf of one individual — under Article 80(1) GDPR, a person can mandate a non-profit to complain about your banner, and you may never hear from them directly.
- The EDPB applied the CJEU's two-part test for "abuse of rights" and found neither the objective nor the subjective component was met, closing a procedural escape hatch some DPAs had used to avoid ruling on mass, NGO-filed cookie complaints.
- The EDPB's Cookie Banner Taskforce report (adopted 17 January 2023, after ~700 noyb complaints) already catalogues the defects DPAs assess: no reject button on the first layer, pre-ticked boxes, deceptive button colours, "legitimate interest" for advertising, and mislabelled "essential" cookies.
- The fix is not a prettier banner but a documented one: a first-layer reject button, honest cookie classification, and a timestamped record of every consent — the evidence a merits review will ask you to produce.
Introduction
A complaint about your cookie banner does not have to come from one of your customers. It can be lodged by a privacy NGO in another country, on behalf of one person you have never heard from — and as of 14 July 2026, the data protection authority handling it can no longer set it aside on a technicality.
That is the practical upshot of EDPB Binding Decision 1/2026, published that day. The case itself is procedural rather than glamorous: two authorities disagreed about whether a complaint could be dismissed. But the outcome removes a route regulators had used to avoid ruling on the substance of cookie-banner complaints filed at scale. For any EU or UK store still running an "Accept all" button with the reject option buried a layer down, the window to fix it quietly just narrowed.
This article reflects publicly available regulatory guidance and news as of July 2026. It is informational content, not legal advice.
What the EDPB Decided on 14 July 2026
The EDPB ordered Belgium's data protection authority not to dismiss a noyb cookie-banner complaint against broadcaster VRT on procedural grounds, but to assess it on the merits and issue a new draft decision. The binding decision was adopted on 28 May 2026 under Article 65(1)(a) GDPR and published on 14 July 2026.
The dispute began when noyb, the Austrian privacy NGO, lodged a complaint with the Austrian DPA on behalf of an individual, concerning the cookie banners on the website of Vlaamse Radio-en Televisieomroeporganisatie (VRT), a Belgian public broadcaster. Because the case was cross-border, Belgium's DPA acted as Lead Supervisory Authority. It drafted a decision to dismiss the complaint, arguing the complainant had abused the right to lodge a complaint (Article 77 GDPR) and the right to mandate a non-profit to complain on their behalf (Article 80(1) GDPR). The Austrian DPA, as a Concerned Supervisory Authority, objected: dismissing on procedure was wrong, and the merits should be decided. Belgium declined to follow the objection and referred the disagreement to the EDPB under the Article 65 dispute-resolution mechanism.
Why did the "abuse of rights" argument fail?
The EDPB found the complainant did not abuse their rights. Applying the CJEU's test for alleged abuse, it held that neither the objective component (using a right contrary to its purpose) nor the subjective component (an intent to secure an improper advantage) had been demonstrated. It first confirmed the Austrian objection was "relevant and reasoned" within Article 4(24) GDPR.
The EDPB then instructed the Belgian DPA to assess the complaint on its merits and submit a new draft decision to the concerned authorities under Article 60(3) GDPR. This is the EDPB's reading of the abuse doctrine, not ours — but the practical takeaway for merchants is blunt: "the complainant is only an activist" is not, by itself, a defence.
Why This Raises the Stakes for Your Online Store
The overlooked part of this decision is not the cookie banner. It is who is allowed to complain about it — and how much harder it now is to make that complaint disappear.
Article 80(1) GDPR lets any data subject mandate a non-profit body to lodge a complaint on their behalf. noyb has built its cookie-banner campaign on exactly that mechanism, running an automated scanning system that detects non-compliant banners and generates complaints, giving the operator a grace period to fix the banner before the complaint is formally filed. The scale is the point: an earlier noyb wave produced roughly 700 cookie-banner complaints, which is why the EDPB convened a dedicated Cookie Banner Taskforce to coordinate how authorities handle them. noyb argues that dark patterns nudge more than 90% of users into clicking "agree," while only around 3% actually want to be tracked.
Until now, a DPA that did not want to process one of these had an easy exit: a procedural dismissal. Binding Decision 1/2026 removes it. More of these complaints will now reach a decision on what the banner actually does.
And the endgame is not a token fee. After noyb complained about 15 Belgian news sites in 2023, the Belgian DPA in 2024 ordered four of them — De Standaard, Het Nieuwsblad, Het Belang van Limburg and Gazet van Antwerpen, all run by publisher Mediahuis — to add a reject button to the first layer of their banners and to drop misleading button colours, on pain of a €50,000-per-day penalty for each site. An earlier "settlement" had let the group pay €10,000 and change nothing. The lesson for merchants is that the endgame of a cookie complaint is a binding order to rebuild the banner, not a rounding-error fine.
What Makes a Cookie Banner Non-Compliant?
A cookie banner is non-compliant when it makes accepting easier than refusing, sets non-essential cookies before consent, or misrepresents what it does. The EDPB Cookie Banner Taskforce catalogued the recurring defects in its 17 January 2023 report; the practices below are the ones supervisory authorities assess most often.
| Defect (Taskforce type) | What it looks like | Why it fails |
|---|---|---|
| No reject button on first layer (Type A) | "Accept all" and "Settings", but no "Reject" at the top level | Refusing should be no harder than accepting; a hidden reject undermines freely-given consent |
| Pre-ticked boxes (Type B) | Cookie categories switched on by default on the settings layer | GDPR Recital 32: silence, pre-ticked boxes, or inactivity do not constitute consent |
| Deceptive button colours/contrast (Type D/E) | "Accept" highlighted, "Reject" greyed into the background | The design nudges a choice, so the resulting consent is not freely given |
| "Legitimate interest" for advertising (Type H) | First layer offers accept but no refuse; refusal is routed through a legitimate-interest objection on layer two | Leads the average user to believe they cannot object at all |
| Mislabelled "essential" cookies (Type I) | Analytics or marketing tags classified "strictly necessary" | The purpose, not the label, decides what is strictly necessary |
| No withdrawal option (Type K) | No persistent way to change your mind after consenting | Withdrawing consent must be as easy as giving it |
For the UK, the ICO's position runs parallel: consent "must be actively and clearly given," and you cannot set non-essential cookies on your website's homepage before the user has consented. For the deeper treatment of what valid consent requires under Article 7 GDPR and the ePrivacy Directive, see our guide to cookie consent in 2026, and the broader obligations in our GDPR compliance guide.
How Do You Audit a Cookie Banner Before a Complaint Lands?
Audit the banner the way a regulator would: load the site cold, watch what fires before any click, and check that refusing is as easy as accepting. The six steps below map directly to the Taskforce defects and take an afternoon, not a project.
- Load your homepage in a fresh incognito session with developer tools open. If any non-essential cookie — analytics, ad pixels — is set before you click anything, you have the exact problem the ICO names.
- Check the first layer for equal prominence. "Reject all" must be reachable in one click, at the same level and visual weight as "Accept all", not hidden behind "Settings".
- Open the settings layer. Every non-essential category must be off by default. No pre-ticked boxes.
- Audit your "strictly necessary" list. Anything doing analytics, personalisation, or advertising does not belong there — re-tag it as optional.
- Confirm a persistent withdrawal control — a hovering icon or a standing link — so consent is as easy to revoke as it was to give.
- Keep the evidence. For every consent, log a timestamp, the purpose, the banner or notice version shown, and any later withdrawal. This is the record a merits review will ask you to produce.
Common Mistakes
The worst mistake is treating the banner as a design problem when it is a data-flow problem. A store can add a pristine "Reject all" button and still fire the Meta pixel on page load, because the tags never waited for the answer. Gate the tags on the consent event first; the button is theatre without it.
The second most common mistake is relying on legitimate interest for advertising cookies. The EDPB Taskforce flagged banners that offer "accept" on the first layer and route refusal through a legitimate-interest objection on the second — the effect, in the Taskforce's reading, is to make users believe they cannot say no.
Third is mislabelling analytics as "essential". It is the fastest defect for a regulator to verify and the hardest to argue away, because the purpose decides the label, not your convenience.
Fourth is keeping no consent records at all. If you cannot show what a specific visitor saw and what they chose, a merits review has nothing from your side to weigh — and Article 7(1) GDPR puts the burden of proving consent on you, not on the complainant. A record of processing that lives only in a spreadsheet nobody has opened since launch is, for this purpose, no record at all.
How PrivacyForge Helps
PrivacyForge's consent management is built around the part of a cookie banner that survives a merits review: the record. Every interaction with the banner is logged with a timestamp, the purpose, the consent-notice version, and any later withdrawal — the demonstrability Article 7(1) requires, rather than a screenshot and a hope.
The embeddable consent form ships with a first-layer reject button and per-category toggles switched off by default, so the defaults match what the Taskforce expects instead of what converts best. And because consent records sit alongside your data map, you can show not only that a visitor clicked "reject" but that the tags downstream respected it — the tag-gating gap that trips up most banner fixes. None of this makes cookie law simpler. It makes your position provable, which is the only thing a regulator's merits review actually weighs.
Frequently Asked Questions
Can an NGO file a GDPR complaint about my cookie banner without my customer contacting me?
Yes. Article 80(1) GDPR lets a data subject mandate a non-profit to lodge a complaint on their behalf, and noyb's cookie-banner campaign works this way, using automated scanning to detect non-compliant banners at scale. After EDPB Binding Decision 1/2026 (14 July 2026), a DPA can no longer dismiss such a complaint simply because it arrived through an NGO rather than the individual.
Does my cookie banner need a "reject all" button on the first layer?
In practice, yes. The EDPB Cookie Banner Taskforce (January 2023) treats an "accept" button with no equally accessible reject option on the same layer as a non-compliant "Type A" practice, and the UK ICO has warned websites over missing reject options. A one-click "reject all" on the first layer, at the same visual weight as "accept", is the safe standard.
Are pre-ticked cookie consent boxes allowed?
No. GDPR Recital 32 states that silence, pre-ticked boxes, or inactivity do not constitute consent, and the EDPB Cookie Banner Taskforce confirmed that pre-ticked opt-in boxes cannot produce valid consent. Every non-essential cookie category must be off by default until the user actively switches it on.
Can I classify analytics or marketing cookies as "strictly necessary"?
No. The EDPB Taskforce found that labelling cookies "essential" when they serve non-necessary purposes is a distinct defect. "Strictly necessary" under Article 5(3) of the ePrivacy Directive means necessary to deliver a service the user actually asked for — not necessary for your analytics, personalisation, or advertising.
What is EDPB Binding Decision 1/2026 in plain terms?
It is a binding EU decision, published on 14 July 2026, that ordered Belgium's data protection authority to rule on the substance of a cookie-banner complaint rather than dismiss it on procedural "abuse of rights" grounds. Its wider effect is that mass, NGO-filed cookie complaints are now more likely to reach a decision on the merits.
We are a UK store — does this EU decision affect us?
Not directly: the Article 65 mechanism binds EU authorities, not the ICO. But the underlying standard is the same. The ICO requires consent to be actively given and bars non-essential cookies before consent, and it has already pressed UK websites to add reject options. Treat the decision as a clear signal of where enforcement attention is pointing.
Conclusion
The cookie banner has been a compliance afterthought for years — a widget you install once and forget. EDPB Binding Decision 1/2026 is a reminder that the afterthought is now the front line: complaints arrive from NGOs across borders, and the procedural exits are closing. The work itself is unglamorous and entirely doable — a first-layer reject button, honest cookie labels, tags that wait for the answer, and a record of every consent.
Audit your banner this week against the Taskforce checklist above. If the reject button is buried or the pixel fires before the click, fix those two first — they are the defects a regulator verifies fastest. Then make the consent record something you could hand over on request, because after 14 July 2026, "the complaint came from an NGO" is no longer the answer it used to be. See how PrivacyForge's consent management keeps the evidence a merits review will ask for.
Sources
- EDPB requires Belgian DPA to handle the merits of noyb cookie banner complaint (14 July 2026)
- EDPB Binding Decision 1/2026 on the dispute submitted by the Belgian SA (VRT), Art. 65 GDPR
- EDPB Cookie Banner Taskforce report (adopted 17 January 2023)
- noyb — Cookie Banners campaign
- noyb WIN: Belgian DPA settlement turned into proper legal orders on deceptive cookie banners
- ICO — Cookies and similar technologies (Guide to PECR)