Skip to content
Topic Contested in court

Notified Body Competence Challenges and Dispute Resolution

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

This new topic is needed because the content specifically addresses challenges to the competence of notified bodies, which is a distinct regulatory mechanism not adequately covered by existing topics. It encompasses dispute resolution procedures, grounds for challenges, and remedial actions related to notified body competence.

21 linked items 1 Laws5 Case Law5 Guidance6 Enforcement4 News

Overview

16 sources · Jul 23, 2026

Legal Framework

Article 37 of the EU AI Act establishes the procedural mechanism through which the competence of notified bodies can be formally challenged. Notified bodies are designated national organizations responsible for assessing the conformity of high-risk AI systems before they are placed on the Union market. The challenge mechanism serves as a critical accountability safeguard, ensuring that only qualified entities perform conformity assessments and that their decisions are subject to scrutiny.

The provision operates within the broader accountability-based framework that characterizes modern EU regulatory architecture. Just as the GDPR imposes structural obligations through designated officers and supervisory authority membership requirements—demanding transparent appointment procedures, defined qualifications, and clear terms of office—the AI Act similarly requires that notified bodies meet stringent competence criteria. Article 37 provides recourse where those criteria are arguably not met, allowing challenges to be raised on grounds relating to technical capability, impartiality, or procedural irregularity in the body's designation or operation.

The rationale is straightforward: conformity assessments determine whether high-risk AI systems may lawfully enter the market. If the body performing that assessment lacks competence, the integrity of the entire regulatory gatekeeping function is compromised.

Key Developments

The Data Protection Commissioner v. Schrems and Facebook ruling underscores a principle directly relevant to competence challenges: regulatory decisions must withstand scrutiny not only on substance but on the institutional capacity and legal authority of the decision-maker. The CJEU's analysis of whether US oversight mechanisms provided effective legal protection parallels the inquiry Article 37 invites—whether a notified body possesses the requisite qualifications and independence to render reliable conformity decisions.

Enforcement actions by the Irish DPC, including the EUR 1.2 billion fine against Meta Platforms and the EUR 5.5 million fine against WhatsApp Ireland, illustrate how supervisory authorities assess institutional compliance failures. These decisions demonstrate that regulators examine whether organizations have maintained proper governance structures—directly informing how competence challenges against notified bodies may be evaluated.

The EDPB Guidelines 06/2022 on amicable settlements between supervisory authorities provide a practical dispute resolution template. While developed in the GDPR context, the principles of structured negotiation, documentation, and escalation pathways inform how disputes involving notified body competence may be resolved before formal challenge proceedings are initiated.

Practical Guidance

  • Document the factual basis for any competence challenge with specificity: Article 37 challenges must identify concrete deficiencies—whether in technical expertise, impartiality safeguards, or procedural compliance—rather than asserting generalized dissatisfaction with a notified body's decision.

  • Engage the DPO or equivalent governance officer before initiating a challenge: Internal assessment of whether grounds exist should incorporate data protection and AI governance expertise, particularly where the challenge intersects with GDPR obligations.

  • Exhaust informal dispute resolution mechanisms first: Following the structured settlement approach reflected in EDPB Guidance 06/2022, pursue direct engagement with the notified body to resolve competence concerns before escalating to the notifying authority or the Commission.

  • Preserve evidence of the notified body's qualifications and appointment transparency: Challenges under Article 37 are strengthened by demonstrating that the body's appointment did not meet the transparent procedure and qualification standards required under the regulatory framework.

  • Monitor parallel supervisory authority positions: Where a DPA has taken enforcement action related to the AI system under assessment, coordinate the competence challenge strategy with ongoing data protection proceedings to avoid contradictory positions.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 1
Art. 44(3)(cont)(1) An appeal procedure against decisions of the notified bodies, including on conformity certificates issued, shall be available. AI Act art 37 Challenge to the competence of notified bodies AI Act Jun 2024
Case Law 5
¶56 In the order for reference and in its judgment of 20 November 2015, delivered in the appeal procedure, wherein it decided to send to the Court this re… Judgment of the Court (Grand Chamber) of 21 December 2016.#Tele2 Sverige AB v Post- och telestyrelsen and Secretary of State for the Home Department v Tom Watson and Others.#Requests for a preliminary ruling from the Kammarrätten i Stockholm and the Court of Appeal (England & Wales) (Civil Division).#Reference for a preliminary ruling — Electronic communications — Processing of personal data — Confidentiality of electronic communications — Protection — Directive 2002/58/EC — Articles 5, 6 and 9 ¶129 In those circumstances, there is no need to examine the first and fourth grounds of appeal, or the second and third parts of the second ground of appe… Judgment of the Court (Fifth Chamber) of 3 July 2025.#European Parliament v TC.#Appeal – Law governing the institutions – European Parliament – Rules governing expenses and allowances for Members of Parliament – Parliamentary assistance allowance – Recovery of sums unduly paid – Article 41(2) of the Charter of Fundamental Rights of the European Union – Right to be heard – Right of access to the file – Regulation (EU) 2018/1725 – Protection of natural persons with regard to the processing of pers ¶4 Inleiding Het EAB vermeldt in onderdeel d): “d) Mention if the person was present personally at the hearing which led to the decision rendered: 1. |X|… Rechtbank Amsterdam, 15-07-2026 (13-120073-26) ¶4 Inleiding Als het proces in twee opeenvolgende instanties heeft plaatsgevonden, namelijk een eerste aanleg gevolgd door een procedure in hoger beroep,… ECLI:NL:RBAMS:2026:1465 Rechtbank Amsterdam , 20-01-2026 / 13/283218-25 (EAB I) 252/21 Meta Platforms v noyb CJEU Jan 2023 362/14 Maximillian Schrems v Data Protection Commissioner CJEU Oct 2015 507/17 Google LLC v CNIL CJEU Sep 2019 CJEU Data Protection Commissioner v. Schrems and Facebook CJEU Oct 2015 Federal Administrative Court BVwG - W292 2270002-1 Federal Administrative Court Jul 2023
Guidance 5
§22 Recital 177 Adequacy Decision. 5 individuals in the EU/EEA, including obtaining relevant information from elements of the U.S. Intelligence Community,… Information Note on the Data Privacy Framework redress mechanism for national security purposes guidelines on the application of article 651a gdpr Guidelines 03/2021 on the application of Article 65(1)(a) GDPR EDPB May 2023 guidelines on the practical implementation of amicable settlements Guidelines 06/2022 on the practical implementation of amicable settlements EDPB May 2022 guidelines on the application of article 60 gdpr Guidelines 02/2022 on the application of Article 60 GDPR EDPB Mar 2022 guidelines on codes of conduct and monitoring bodies Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679 EDPB Jun 2019 note on the data privacy framework redress mechanism for Information Note on the Data Privacy Framework redress mechanism for national security purposes EDPB Apr 2024
Enforcement 6
APD/GBA (Belgium) Belgian DPA: Political campaign email without consent violates GDPR and ePrivacy APD/GBA (Belgium) May 2024 Data Protection Authority of Ireland Meta Platforms Ireland Limited: Insufficient legal basis for data processing Data Protection Authority of Ireland May 2023 Data Protection Authority of Ireland Meta Platforms Ireland Limited: Non-compliance with general data processing principles Data Protection Authority of Ireland Jan 2023 Data Protection Authority of Ireland WhatsApp Ireland Ltd.: Insufficient legal basis for data processing Data Protection Authority of Ireland Jan 2023 Data Protection Authority of Ireland WhatsApp Ireland Ltd.: Insufficient fulfilment of information obligations Data Protection Authority of Ireland Sep 2021 Data Protection Authority of Ireland Meta Platforms, Inc.: Non-compliance with general data processing principles Data Protection Authority of Ireland Sep 2022
News 4
EDPB Record fine for Instagram following EDPB intervention EDPB Sep 2022 EDPB Recordboete voor Instagram na ingrijpen van de EDPB. EDPB Sep 2022 NL EDPB EDPB: Lack of resources puts enforcement of individuals’ data protection rights at risk EDPB Sep 2022 EDPB EDPB: Gebrek aan middelen brengt de handhaving van de rechten van individuen met betrekking tot de bescherming van hun persoonsgegevens in gevaar. EDPB Sep 2022 NL