EDPB Requires Review of Cookie Banner Complaint on the Merits
The European Data Protection Board decision highlights the data-protection checks digital teams should make around consent flows, processing roles, and evidence before legal review.

The European Data Protection Board published a binding decision dated 28 May 2026 concerning a dispute between supervisory authorities over a complaint about cookie banners used on the website of Belgian broadcaster Vlaamse Radio-en Televisieomroeporganisatie (VRT). The complaint was filed with the Austrian supervisory authority by Noyb on behalf of an individual, while the Belgian Data Protection Authority acted as the lead supervisory authority.
The decision concerns more than the wording of a consent banner. For companies operating digital products, it highlights the need to review the processing model, the controller or processor role, user consent records, and the evidence available if a privacy dispute reaches a regulator.
Check the data role and processing evidence
For GDPR-related reviews, a privacy notice alone does not describe the entire processing model. A product team should map the actual process: which personal data is collected, why the processing occurs, who determines the purposes of processing, and who acts on another party's instructions.
Before legal review, companies can prepare:
- a map of personal data flows in the product;
- versions of consent interfaces and cookie banner settings for relevant dates;
- records showing consent-management changes;
- contracts with analytics providers and other vendors involved in processing.
The EDPB decision does not establish the same outcome for every similar service. The assessment depends on the product architecture, the roles of the parties, and the documents showing how processing decisions were made.
Align consent interfaces with complaint-response procedures
The source also illustrates a procedural point: the dispute involved supervisory authorities resolving a disagreement after a complaint was examined, with the EDPB adopting a binding decision under the GDPR cooperation mechanism. For businesses, this means that interface design and internal evidence should be reviewed together.
A practical review can include:
- what choices users receive before optional data processing begins;
- whether consent and withdrawal records are retained;
- whether the company can explain the purpose of each tracking technology used;
- which internal role manages responses to regulator requests.
The decision does not replace a review of a specific product or compliance process. Where the answer depends on system settings, contracts, jurisdiction, or allocation of responsibilities, the issue requires a fact-specific legal assessment.