Skip to content
News · noyb - European Center for Digital Rights EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

EU pledged to improve GDPR cooperation - and made it worse

National Administrative Procedures and DPA inactivity As of 2018, the GDPR is supposed to ensure that Europeans enjoy privacy rights throughout the entire EU.

Full text

National Administrative Procedures and DPA inactivity As of 2018, the GDPR is supposed to ensure that Europeans enjoy privacy rights throughout the entire EU. However, when people's rights are violated by companies based in another EU/EEA Member State, complaints are dealt with through a complex "cooperation mechanism" between the Data Protection Authority (DPA) in the users' Member State and the DPA in the company's Member State. This enforcement mechanism is at the core of the generally acknowledged enforcement failure of the GDPR. Complaints get lost, decisions take years and there is virtually no possibility to act against inactive DPAs. The EU has ventured to solve this through a "GDPR Procedural Regulation". But it becomes clear now, that it is about to fail miserably. The final so-called “trilogue” negotiations between the European Parliament, the Member States and the European Commission has led to a legislative mess that will likely make procedures more complex, slower and pro

How it connects

T-70/23 Data Protection Commission v European Data Protection Board The Irish Data Protection Commission (DPC) challenged provisions of EDPB Binding Decisions 3/2022, 4/2022, and 5/2022, arguing the EDPB exceeded its competence under Article… General Court ·Tenth Chamber, Extended Composition Jan 29, 2025 Supervision Supervisory Authorities Monitoring
449212 CE upholds CNIL competence to fine Google €100M for cookies despite no lead authority role On December, 7 2020, the French DPA imposed a financial penalty of 60 Million euros fine against Google LLC and a 40 million euros against Google Ireland Limited in accordance… Mar 4, 2021 Supervisory Authorities Supervision Cookies
Guidelines 8/2022 identifying a controller or processor's lead supervisory authority Guidelines for identifying a controller or processor’s lead supervisory authority Guidelines ·EDPB Apr 17, 2023 Supervision Controllers Supervisory Authorities