# Notified Body Competence Challenges and Dispute Resolution — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/notified-body-competence-challenges
> Sources are cited per item. Verify against the official texts before relying on them.

This new topic is needed because the content specifically addresses challenges to the competence of notified bodies, which is a distinct regulatory mechanism not adequately covered by existing topics. It encompasses dispute resolution procedures, grounds for challenges, and remedial actions related to notified body competence.

## Overview

## Legal Framework

Article 37 of the EU AI Act establishes the procedural mechanism through which the competence of notified bodies can be formally challenged. Notified bodies are designated national organizations responsible for assessing the conformity of high-risk AI systems before they are placed on the Union market. The challenge mechanism serves as a critical accountability safeguard, ensuring that only qualified entities perform conformity assessments and that their decisions are subject to scrutiny.

The provision operates within the broader accountability-based framework that characterizes modern EU regulatory architecture. Just as the GDPR imposes structural obligations through designated officers and supervisory authority membership requirements—demanding transparent appointment procedures, defined qualifications, and clear terms of office—the AI Act similarly requires that notified bodies meet stringent competence criteria. Article 37 provides recourse where those criteria are arguably not met, allowing challenges to be raised on grounds relating to technical capability, impartiality, or procedural irregularity in the body's designation or operation.

The rationale is straightforward: conformity assessments determine whether high-risk AI systems may lawfully enter the market. If the body performing that assessment lacks competence, the integrity of the entire regulatory gatekeeping function is compromised.

## Key Developments

The *Data Protection Commissioner v. Schrems and Facebook* ruling underscores a principle directly relevant to competence challenges: regulatory decisions must withstand scrutiny not only on substance but on the institutional capacity and legal authority of the decision-maker. The CJEU's analysis of whether US oversight mechanisms provided effective legal protection parallels the inquiry Article 37 invites—whether a notified body possesses the requisite qualifications and independence to render reliable conformity decisions.

Enforcement actions by the Irish DPC, including the EUR 1.2 billion fine against Meta Platforms and the EUR 5.5 million fine against WhatsApp Ireland, illustrate how supervisory authorities assess institutional compliance failures. These decisions demonstrate that regulators examine whether organizations have maintained proper governance structures—directly informing how competence challenges against notified bodies may be evaluated.

The EDPB Guidelines 06/2022 on amicable settlements between supervisory authorities provide a practical dispute resolution template. While developed in the GDPR context, the principles of structured negotiation, documentation, and escalation pathways inform how disputes involving notified body competence may be resolved before formal challenge proceedings are initiated.

## Practical Guidance

- **Document the factual basis for any competence challenge with specificity**: Article 37 challenges must identify concrete deficiencies—whether in technical expertise, impartiality safeguards, or procedural compliance—rather than asserting generalized dissatisfaction with a notified body's decision.

- **Engage the DPO or equivalent governance officer before initiating a challenge**: Internal assessment of whether grounds exist should incorporate data protection and AI governance expertise, particularly where the challenge intersects with GDPR obligations.

- **Exhaust informal dispute resolution mechanisms first**: Following the structured settlement approach reflected in EDPB Guidance 06/2022, pursue direct engagement with the notified body to resolve competence concerns before escalating to the notifying authority or the Commission.

- **Preserve evidence of the notified body's qualifications and appointment transparency**: Challenges under Article 37 are strengthened by demonstrating that the body's appointment did not meet the transparent procedure and qualification standards required under the regulatory framework.

- **Monitor parallel supervisory authority positions**: Where a DPA has taken enforcement action related to the AI system under assessment, coordinate the competence challenge strategy with ongoing data protection proceedings to avoid contradictory positions.

## Legislation (full text of key provisions)

### Challenge to the competence of notified bodies

*Source: AI Act, aiact-art-37-en, 2024-06-12 — https://overview.legal/posts/92569*

## Case law

### BVwG - W292 2270002-1

*Source: Federal Administrative Court, 2023-07-27 — https://overview.legal/posts/109002 — original: https://gdprhub.eu/index.php?title=BVwG_-_W292_2270002-1*

Facts — On 4 October 2020, the controller sent a non-anonymised court judgement of the Regional Criminal Court (Landesgericht für Strafsachen) as a PDF file to a different recipient via WhatsApp. Less than a year later, on 28 July 2021, the same non-anonymised court judgement was sent to the same recipient again, this time via email. The data subject lodged two complaints with the DPA (DSB) regarding the violation of their right to secrecy under § 1(1) DSG. In the first proceedings (DSB-D124.5125), the DPA ruled on the transmission of the judgement via WhatsApp and notably highlighted that the transmission via email was not the subject of the proceedings. In the second procedure (DSB-D124.0310/22) concerning the transmission via email, the DPA dismissed the complaint on the grounds that the data subject had no legitimate interest of legal protection and referred to its first administrative decision. The data subject appealed against the second decision of the DPA and asked the court to decide in that subject matter. In their opinion, the two transmissions of the judgement at different times represent two separate data processing operations. Holding — First, the court held that, in this specific case, there was no identity of the subject matter in comparison with the first proceedings within the meaning of § 68(1) AVG. In accordance with established legal practice (VwGH 31.07.2006, 2006/05/0158; VwGH 21.06.2007, 2006/10/0093 etc.), the court based its decision on the legal and temporal identity of the case. On the one hand, the data processing operation via email took place at a later date. On the other hand, the resulting time difference could lead to a potentially different legal assessment compared to the previous proceedings. Second, the court ruled that it could only examine the rightfulness of the dismissal of the complaint and therefore could not rule on the subject matter itself (See, for example, VwGH 18.12.2014, Ra 2014/07/0002). Third, the court held that no appeal to the Austrian Supreme Administrative Court (Verwaltungsgerichtshof) was admissible pursuant to Article 133(4) B-VG, as the decision raised no legal questions of fundamental importance. Therefore, the court quashed the DPA's administrative decision DSB-D124.0310/22.

### Meta Platforms v noyb

*Source: CJEU, C-252/21, 2023-01-12 — https://overview.legal/posts/51484 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0252*

GDPR consent requirements and lead supervisory authority mechanism.

### Google LLC v CNIL

*Source: CJEU, C-507/17, 2019-09-24 — https://overview.legal/posts/51476 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0507&ref=51476*

Right to delisting does not require global de-referencing under EU law.

### Maximillian Schrems v Data Protection Commissioner

*Source: CJEU, C-362/14, 2015-10-06 — https://overview.legal/posts/51471 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362&ref=51471*

Invalidated Safe Harbor adequacy decision. National supervisory authorities can examine adequacy decisions.

### Data Protection Commissioner v. Schrems and Facebook

*Source: CJEU, 2015-10-06 — https://overview.legal/posts/6145 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362&ref=6145*

Necessity/proportionality: The Decision does not contain any finding regarding US rules intended to limit the interference when they pursue legitimate objectives such as national security, nor refer to effective legal protection against such interference. FTC procedures and private dispute resolution mechanisms concern compliance with safe harbor principles (against US organizations) and cannot be applied with respect to measures originating from the State. Moreover, the Commission found that if

## Guidance

### Information Note on the Data Privacy Framework redress mechanism for national security purposes

*Source: EDPB, information-note-on-the-data-privacy-framework-redress-mechanism-for-en, 2024-04-24 — https://overview.legal/posts/125754 — original: https://www.edpb.europa.eu/documents/other-guidance/information-note-on-the-data-privacy-framework-redress-mechanism-for_en*

1 Information Note on the redress mechanism for EU/EEA individuals in relation to alleged violations of U.S. law with respect to their data collected by U.S authorities competent for national security 2 Context about complaints on government access by U.S. intelligence authorities On 10 July 2023, the European Commission adopted its Implementing Decision C(2023) 4745 on the adequate level of protection of personal data under the EU-U.S. Data Privacy Framework ( ‘DPF Adequacy decision ’ ) 1 . An…

### Guidelines 03/2021 on the application of Article 65(1)(a) GDPR

*Source: EDPB, edpb-guidelines-on-the-application-of-article-651a-gdpr, 2023-05-24 — https://overview.legal/posts/38137 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-032021-on-the-application-of-article-651a-gdpr_en*

The European Data Protection Board (EDPB) adopted Guidelines 03/2021 to clarify the dispute resolution mechanism under Article 65(1)(a) GDPR, which governs the EDPB's authority to issue binding decisions when a Lead Supervisory Authority receives relevant and reasoned objections from Concerned Supervisory Authorities that it does not follow. The Guidelines address the procedural framework, the threshold for "relevant and reasoned" objections, the scope of the EDPB's substantive competence, and applicable procedural safeguards including the right to be heard, access to the file, and available judicial remedies.

### Guidelines 06/2022 on the practical implementation of amicable settlements

*Source: EDPB, edpb-guidelines-on-the-practical-implementation-of-amicable-settlements, 2022-05-12 — https://overview.legal/posts/38072 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-062022-on-the-practical-implementation-of-amicable-settlements_en*

The EDPB adopted Guidelines 06/2022 to provide practical guidance on the implementation of amicable settlements between supervisory authorities and controllers or processors under the GDPR. The guidelines address the scope and definition of amicable settlements, the legal basis for this power, and its procedural operation within the one-stop-shop mechanism, including the roles of the complaint-receiving competent supervisory authority and the lead supervisory authority. No fines are imposed as this is a guidance document rather than an enforcement decision.

### Guidelines 02/2022 on the application of Article 60 GDPR

*Source: EDPB, edpb-guidelines-on-the-application-of-article-60-gdpr, 2022-03-14 — https://overview.legal/posts/38066 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-022022-on-the-application-of-article-60-gdpr_en*

With the introduction of the GDPR, the concept of the one-stop shop was established as one of the main innovations. In cross-border processing cases, the supervisory authority in the Member State of the controller's or processor's main establishment is the authority leading the  enforcement of the GDPR for the respective cross-border processing activities, in cooperation with all the authorities which may face the effects of the processing activities at stake: be it  through  the establishments ...

### Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679

*Source: EDPB, edpb-guidelines-on-codes-of-conduct-and-monitoring-bodies, 2019-06-04 — https://overview.legal/posts/38051 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-12019-on-codes-of-conduct-and-monitoring-bodies-under-regulation_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the framework for codes of conduct and monitoring bodies under Articles 40 and 41 of the GDPR. The guidelines address the admissibility, content, and approval requirements for draft codes of conduct, as well as the criteria and accreditation process for monitoring bodies responsible for verifying compliance with such codes. This version (2.0) was adopted on 4 June 2019 following public consultation.

## Enforcement decisions

### Meta Platforms Ireland Limited: Insufficient legal basis for data processing

*Source: Data Protection Authority of Ireland, 2023-05-12 — https://overview.legal/posts/47959 — original: https://www.enforcementtracker.com/ETid-1844*

The Irish DPA (DPC) has fined Meta Platforms Ireland Limited EUR 1.2 billion. This is the highest fine imposed to date under the GDPR. In its decision, the DPC found that Meta had violated Art. 46 GDPR by continuing to transfer personal data to the U.S. after the Schrems II ruling of the CJEU. According to the Schrems II ruling, U.S. law does not provide a level of protection for personal data substantially equivalent to that provided by EU law and that the standard contractual clauses (SCCs) al

### WhatsApp Ireland Ltd.: Insufficient legal basis for data processing

*Source: Data Protection Authority of Ireland, 2023-01-19 — https://overview.legal/posts/47693 — original: https://www.enforcementtracker.com/ETid-1578*

The Irish DPA (DPC) has fined WhatsApp Ireland Ltd. EUR 5.5 million. The Austrian organization 'None of Your Business' (NOYB) had filed a complaint with the DPA on behalf of an individual. WhatsApp had updated its terms of service shortly before the GDPR came into force. In its new terms of service, WhatsApp informed its users to click 'Agree and Continue' to indicate their agreement with the new terms of service. This was required for further access to the services. WhatsApp assumed that the ac

### Meta Platforms Ireland Limited: Non-compliance with general data processing principles

*Source: Data Protection Authority of Ireland, 2023-01-04 — https://overview.legal/posts/47658 — original: https://www.enforcementtracker.com/ETid-1543*

The Irish DPA (DPC) has fined Meta Platforms Ireland Limited EUR 390 million. The DPA has imposed a fine of EUR 210 million for violations related to the provision of its Facebook service and EUR 180 million for violations related to the provision of its Instagram service. The Austrian organization 'None of Your Business' (NOYB) had filed a complaint with the DPA on behalf of two individuals. Meta had updated its terms of service shortly before the GDPR came into force. In its new terms of servi

### WhatsApp Ireland Ltd.: Insufficient fulfilment of information obligations

*Source: Data Protection Authority of Ireland, 2021-09-02 — https://overview.legal/posts/46935 — original: https://www.enforcementtracker.com/ETid-820*

The Irish DPA (DPC) has imposed a fine of EUR 225,000,000 on WhatsApp Ireland Ltd. The DPA had started extensive investigations into the messaging service's compliance with transparency obligations back in December 2018. In this context, the DPC investigated whether WhatsApp complied with its obligations under the GDPR regarding the provision of information and the transparency of this information to users and non-users of WhatsApp. In the course of the investigation, the DPC found that WhatsApp

### Belgian DPA: Political campaign email without consent violates GDPR and ePrivacy

*Source: APD/GBA (Belgium), 2024-05-16 — https://overview.legal/posts/158448 — original: https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_74/2024*

Facts — On 30 January 2024, the data subject received an email from a candidate in the June 2024 regional elections (‘controller’), promoting their programme. On 3 January 2024, the data subject responded to the email indicating that Belgian law prohibits political spamming practices. He also indicated that he no longer wished for the controller to use his data, and made an access request, in particular to understand where the controller collected his personal data. On 5 February 2024, the controller responded to the access request by explaining that the data subject’s personal data was probably already in his address book, although it was possible that friends had given it to him. On 5 April 2024, the data subject lodged a complaint with the Belgian DPA (‘APD’). Holding — First, regarding the use of the data subject’s email address for electoral propaganda purposes, Article 6(1)(a) GDPR establishes that the processing of personal data is lawful if the data subject has consented to the processing. Article 13(1) ePrivacy directive states that the use of an email for the purposes of direct marketing may be authorised only if the targeted subscribers have given consent. Furthermore, the APD published a note on the processing of personal data in the context of elections in which it established that the targeting people with political propaganda on the basis of voters’ personal data must be considered direct marketing within the meaning of the GDPR and ePrivacy Directive. In the present case, the APD noted that the data subject did not give consent to the processing of his email address for direct marketing purposes. Therefore, the DPA held that the controller may have breached Article 6(1)(a) GDPR as well as Article 13(1) ePrivacy directive. The DPA examined the possibility of invoking legitimate interest under Article 6(1)(f) GDPR as a legal basis. This article establishes that the processing of personal data is lawful if it is necessary for the purposes of the legitimate interests pursued by the controller, unless the interests or fundamental rights and freedoms of the data subject prevail. Recital 47 GDPR states that the processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest. In CJEU, 4 May 2017, Rigas, C-13/16, the Court of Justice held that Article 6(1)(f) GDPR lays down three cumulative conditions. (i) the pursuit of a legitimate interest by the controller, (ii) the necessity of the processing in order to achieve the legitimate interest pursued and (iii) the fundamental rights and freedoms of the data subject must not prevail. Regarding the pursuit of a legitimate interest, Belgian law provides that candidates in elections may promote their programme through communications. Moreover, the APD described the controller’s interest as ‘sending direct marketing communications to promote the electoral programme for the regional elections in June 2024’. Thus, the controller’s interest is sufficiently specific that it represents a real and present interest. The APD considered that the controller is pursuing a legitimate interest. Regarding the necessity of the processing in order to achieve the legitimate interest, the APD took into account the existence of less intrusive means to attain the objective. The DPA considered that an election programme can be promoted by means of flyers placed in people’s mailboxes for example, which is far less intrusive, even if It may require some extra effort. Therefore, the APD held that the direct marketing was not strictly necessary to the legitimate interest pursued, namely the promotion of its electoral programme. Thus, the APD concluded that the controller may have committed a potential breach of Article 6 GDPR. Second, regarding the access request in order to discover the source of the data used, the APD considered that the controller sent vague and imprecise information about the source of the data subject’s personal data. Therefore, the APD concluded that there may have been a breach of Articles 5(1)(a) and 12(1) GDPR. Hence, the APD issued a prima facie warning to the controller.

### Meta Platforms, Inc.: Non-compliance with general data processing principles

*Source: Data Protection Authority of Ireland, 2022-09-05 — https://overview.legal/posts/47488 — original: https://www.enforcementtracker.com/ETid-1373*

The Irish DPA (DPC) has imposed a fine of EUR 405,000,000 on Meta Platforms, Inc. (Instagram). Following the investigation, the DPC submitted a draft decision under Art. 60 GDPR to other European supervisory authorities concerned. The initial draft proposed a fine of EUR 30-50 million. The DPC subsequently received objections from six supervisory authorities, which led to a dispute resolution procedure at the European Data Protection Board (EDPB) in Brussels. In its decision, the EDPB requested

## Recent developments

### Record fine for Instagram following EDPB intervention

*Source: EDPB, 2022-09-15 — https://overview.legal/posts/6279 — original: https://edpb.europa.eu/news/news/2022/record-fine-instagram-following-edpb-intervention_en#entry-378*

> Following the EDPB’s binding dispute resolution decision of July 28th, the Irish Data Protection Authority (DPA) has adopted its decision regarding Instagram (Meta Platforms Ireland Limited (Meta IE)) and has issued a record GDPR fine of €405 million.

### Recordboete voor Instagram na ingrijpen van de EDPB.

*Source: EDPB, 2022-09-15 — https://overview.legal/posts/51820*

Na de bindende beslissing van het Europees Comité voor de Bescherming van Persoonsgegevens (EDPB) van 28 juli, heeft de Ierse Autoriteit voor de Bescherming van Persoonsgegevens (DPA) haar beslissing met betrekking tot Instagram (Meta Platforms Ireland Limited, ook bekend als Meta IE) aangenomen en een recordboete van 405 miljoen euro opgelegd op grond van de AVG.

### EDPB: Lack of resources puts enforcement of individuals’ data protection rights at risk

*Source: EDPB, 2022-09-13 — https://overview.legal/posts/6282 — original: https://edpb.europa.eu/news/news/2022/lack-resources-puts-enforcement-individuals-data-protection-rights-risk_en#entry-380*

> “We are deeply concerned that the 2023 budget, if not substantially increased, will be significantly too small to allow the EDPB and the EDPS to fulfil their tasks appropriately,” Andrea Jelinek, Chair of the European Data Protection Board (EDPB), and Wojciech Wiewiórowski, European Data Protection Supervisor (EDPS), write in an Open Letter to the European Parliament and the European Council.

### EDPB: Gebrek aan middelen brengt de handhaving van de rechten van individuen met betrekking tot de bescherming van hun persoonsgegevens in gevaar.

*Source: EDPB, 2022-09-13 — https://overview.legal/posts/51823*

"Wij maken ons ernstig zorgen dat het budget voor 2023, indien het niet aanzienlijk wordt verhoogd, veel te klein zal zijn om het EDPB en de EDPS in staat te stellen hun taken op een adequate manier uit te voeren," schrijven Andrea Jelinek, voorzitter van het Europees Comité voor gegevensbescherming (EDPB), en Wojciech Wiewiórowski, Europees Supervisor voor gegevensbescherming (EDPS), in een open brief aan het Europees Parlement en de Europese Raad.

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Human Resources** — https://overview.legal/topics/human-resources
  Processing of employee and HR data

---
Generated by overview.legal · https://overview.legal/topics/notified-body-competence-challenges · 2026-08-22
