The EU's Cookie Compliance Squeeze: EDPB Ends Easy Dismissals of Mass Complaints While the Council Guts the One Fix for Banner Fatigue

Two things happened to EU cookie compliance in the last six weeks, and if you only track one of them you'll misjudge your risk. On 14 July 2026, the European Data Protection Board published Binding Decision 1/2026, making it dramatically harder for a data protection authority to throw out an organised, NGO-led cookie complaint on procedural grounds instead of examining it on the merits. Five weeks earlier, in its fifth compromise text on the Digital Omnibus, the Council quietly dropped the one provision that would have let a browser-level signal replace cookie banners for good — while keeping the part that makes "reject" a required single click.
Put together: cookie banners are not going away, they are much more likely to get looked at closely if someone complains, and the standard they'll be judged against is not getting any easier to hit. This post walks through both developments and what to actually change in your consent stack.
Binding Decision 1/2026: The "Abuse of Rights" Defense Just Got Much Weaker
The case behind the decision goes back further than you'd expect. On 10 August 2021, a data subject mandated noyb — the Vienna-based "European Center for Digital Rights" founded by Max Schrems — to file a GDPR complaint with the Austrian data protection authority against VRT, the Flemish public broadcaster, over its cookie consent banner. Austria transferred the case to Belgium in June 2023 since VRT's main establishment sits there, making the Belgian authority the lead supervisory authority under GDPR's one-stop-shop mechanism.
Belgium didn't rule on whether the banner actually complied with the GDPR. Instead it proposed dismissing the complaint outright, arguing it was an abuse of the right to complain under Article 77 GDPR and the right to be represented by a not-for-profit body under Article 80(1) GDPR — pointing to noyb's standardised, templated approach to filing complaints and its stated organisational mission as evidence the complaint wasn't really about this one individual. Austria objected: procedural dismissal, it argued, isn't a substitute for actually assessing the complaint. That disagreement between two supervisory authorities triggered the Article 65 consistency mechanism — the GDPR's binding-arbitration procedure for when SAs can't agree, which sends the dispute to the full EDPB for a decision every SA involved must then implement.
The EDPB adopted Binding Decision 1/2026 on 28 May 2026 and published it on 14 July 2026. It applied the two-part abuse-of-rights test the CJEU itself uses — an objective component (were the formal conditions for exercising the right actually met?) and a subjective component (was the right being exercised for a purpose other than the one it was meant for?) — and found Belgium hadn't met the bar on either count. On the objective side: the data subject held a valid Article 80(1) mandate, so the formal conditions for representation were satisfied regardless of how standardised noyb's process is. On the subjective side, the Board reframed the question entirely — instead of treating noyb's institutional mission as separate from the complainant's personal interest, it held that both Article 77 and Article 80(1) are rights that belong to the data subject, and the complainant's own submission (from January 2026) asserting a genuine personal rights violation was enough to show real intent. Professional help gathering the technical evidence behind the complaint, the EDPB said, doesn't make the complaint abusive — it makes it competent.
The instruction to Belgium is concrete: abandon the dismissal, assess VRT's cookie banner on its actual merits, and submit a revised draft decision to the other concerned supervisory authorities within a month of notification.
As McCann FitzGerald's analysis of the decision puts it, the EDPB has now "set a very high bar for DPAs to dismiss representative complaints" on abuse-of-rights grounds, and "any activist body can replicate this model at scale to pursue a wide range of potential complaints under the GDPR." That's the sentence to sit with if your product runs a cookie banner in the EU: the templated, at-scale complaint pipeline that made VRT's case possible is now a validated model, not a dismissed one.
What "Merits Review Instead of Dismissal" Actually Changes for You
Nothing about GDPR's substantive cookie consent rules changed in this decision — the CJEU already established in Planet49, C‑673/17 (1 October 2019) that pre-ticked checkboxes are not valid consent, and existing EDPB guidance already treats "reject" needing to be materially harder to click than "accept" as a dark pattern. What changed is the odds that a real regulator actually checks whether your banner meets that standard, instead of a DPA waving the complaint away because it arrived through an NGO's standard process.
Practically, that means:
- Complaint volume from advocacy organisations will keep the same economics it had before Binding Decision 1/2026 — filing is cheap and templated — but the dismissal exit that DPAs used to take is now much narrower. Expect more complaints to reach a substantive review stage across all 27 member states, not just Belgium.
- "We get too many complaints to take this one seriously" is no longer a viable internal risk assessment. If a complaint about your banner lands with a lead SA, budget for it to be examined on the merits, not shelved.
- The actual bar being applied is the existing one — granular, purpose-level consent; reject as easy as accept; no forced re-consent loops; no dark patterns in visual weighting. If your banner already meets that bar, this decision doesn't change your exposure. If it's cutting corners because "nobody actually checks," that assumption just got measurably weaker.
Meanwhile: The Digital Omnibus Just Dropped the Provision That Would Have Ended Banners
The second development is legislative, not adjudicative, and it's easy to miss because it moves through Council working-party documents instead of a published decision. The Commission's Digital Omnibus proposal (COM/2025/837 final, 19 November 2025) would move cookie/terminal-equipment consent rules out of the ePrivacy Directive and into the GDPR itself, as two new articles: Article 88a and Article 88b. Neither exists in GDPR today — don't confuse them with the current, already-in-force Article 88 ("Processing in the context of employment"); these would be genuinely new provisions, still mid-negotiation.
- Article 88a would require controllers to accept single-click consent refusal — "in an easy and intelligible manner with a single-click button or equivalent means" — and bar them from making a new consent request for the same purpose for at least six months after a refusal. Processing without consent stays lawful only for narrow cases: pure transmission over a network, a service the user explicitly requested, first-party aggregated audience measurement (not shared with third parties), and restoring security.
- Article 88b would have gone further: a machine-readable, automated consent signal set once at browser or wallet level, which controllers would have to respect instead of running their own per-site banner — the actual mechanism that could have made banners largely obsolete, with a 24-month phase-in for controllers and 48 months for browser providers to build support.
According to noyb's press release of 23 June 2026, the Council's fifth compromise text — published 18 June 2026 and marked "Annex GIP.B Limite EN" — removed Article 88b entirely, reportedly after member states including Germany, France, and Poland pushed for its removal following industry lobbying (noyb cites a Google paper arguing browser-level consent signals would collapse advertising revenue). Article 88a survived in that same text. Max Schrems' comment on the removal: "Cookie banners are not an invention of data protection, but of the tracking industry. Without consent, there is no snooping online." And on the irony of the reversal: "You really have to let that sink in: the European Commission finally wants to get rid of cookie banners, but Google and some EU Member States are now determined to keep them."
As of the latest reporting, the European Parliament has not yet taken its own position on Article 88b — trilogue negotiations between Council, Parliament, and Commission are ongoing, and Parliament could still push to restore it. Nothing here is final. But as things stand, the provision that would have let you drop your banner in favour of reading a browser signal is off the table, while the provision that requires a working single-click reject button is intact across every compromise text seen so far.
What This Means for Your Consent Architecture
Combine the two developments and the engineering conclusion is straightforward: don't build your roadmap around cookie banners disappearing, and treat your banner's actual behaviour as something that might genuinely be audited.
- Reject must be exactly one click, with equal visual weight to accept. This is already the operative CJEU/EDPB standard and it's also the literal text of the proposed Article 88a — build to it now rather than waiting for the article to formally enter into force.
- Enforce the six-month re-prompt cooldown per purpose, even before Article 88a is adopted. It's a defensible floor regardless of whether the Digital Omnibus timeline slips, and re-prompting sooner is exactly the kind of "dark pattern" behaviour that turns a routine complaint into a merits case.
- Log consent decisions with enough detail to reconstruct what happened, not just what's true today. After Binding Decision 1/2026, a complaint against your banner is more likely to actually be investigated — which means a DPA may ask what your banner showed and how a specific user responded on a specific date, not just what your current implementation does.
- Don't treat browser-signal support (e.g. Global Privacy Control) as a substitute for a working banner. If you already support it, keep it — it's good practice and a hedge if Article 88b is restored in trilogue. But Article 88b is currently out of the Council's text, so a banner remains your primary compliance surface, not a fallback.
- Stop budgeting legal effort toward getting organised complaints dismissed as abusive. Binding Decision 1/2026 narrowed that path for every SA, not just Belgium's. Spend that effort on making the banner correct instead.
A minimal consent log that would actually hold up to the kind of merits review Belgium now has to run looks like this:
from dataclasses import dataclass, field
from datetime import datetime, timedelta, timezone
@dataclass
class ConsentRecord:
user_ref: str # pseudonymous/hashed identifier, not raw PII
banner_version: str # ties the record to the exact banner/policy text shown
purposes_offered: list[str]
purposes_granted: list[str]
action: str # "accept_all" | "reject_all" | "custom" | "no_interaction"
decided_at: datetime = field(default_factory=lambda: datetime.now(timezone.utc))
def can_reprompt(last_decision: ConsentRecord, purpose: str,
cooldown_days: int = 180) -> bool:
"""Digital Omnibus draft Art.88a: no new consent request for the same
purpose within 6 months of a refusal. Enforce this even pre-adoption —
it is the stable floor across every Council compromise text so far."""
if purpose in last_decision.purposes_granted:
return True # already granted, no need to re-prompt
elapsed = datetime.now(timezone.utc) - last_decision.decided_at
return elapsed >= timedelta(days=cooldown_days)
Store ConsentRecord rows append-only, keyed by banner_version, so that if a complaint ever references "the banner in place on 3 March 2026," you can reconstruct exactly what that user was shown and how they responded — not just what your banner does now.
What to Do This Quarter
- Audit your reject flow specifically — count the clicks to reject everything versus accept everything. If reject takes more steps, more scrolling, or a different visual path than accept, fix it before a complaint forces the question.
- Implement or verify a per-purpose 6-month re-prompt cooldown, even though Article 88a isn't in force yet — it's the one piece of the Digital Omnibus draft that hasn't moved in five compromise rounds.
- Build an append-only consent log keyed to a banner/policy version, not just current state, so you can answer "what did this user see and do on date X" if a complaint ever reaches a merits review.
- Don't defer cookie-banner fixes on the assumption Article 88b will make banners obsolete. It's currently dropped from the Council's text; Parliament hasn't weighed in; treat your banner as permanent infrastructure, not a stopgap.
- If you're relying on "this looks like a mass/templated complaint" as part of your incident-response playbook for GDPR complaints, retire that assumption. Binding Decision 1/2026 means that argument is now much less likely to get a complaint dismissed by any EU supervisory authority.
Related on this blog: our breakdown of the EDPB's web scraping guidelines for generative AI and the three-criteria anonymisation test if you're weighing legal bases beyond consent, and our Article 33 breach notification template guide for what happens once a complaint or incident does reach the merits stage.
Primary Sources
- EDPB Binding Decision 1/2026 on the dispute submitted by the Belgian SA on VRT (Art.65 GDPR), adopted 28 May 2026, published 14 July 2026
- EDPB News: "EDPB requires Belgian DPA to handle the merits of NOYB cookie banner complaint"
- noyb: "EU Member States (and Google) suddenly want to keep cookie banners!", 23 June 2026
- McCann FitzGerald: "EDPB Decision Opens Floodgates to Activist Driven Complaints"
- Regulation (EU) 2016/679 (GDPR) — full consolidated text on EUR-Lex
- CJEU Judgment, 1 October 2019, Planet49 GmbH, Case C-673/17
- Taylor Wessing: "The Digital Omnibus: cookies, consent and digital advertising"
EU-Native Hosting
Ready to move to EU-sovereign infrastructure?
sota.io is a German-hosted PaaS — no CLOUD Act exposure, no US jurisdiction, full GDPR compliance by design. Deploy your first app in minutes.