Since November 2023*, I have been giving lots of thought to EDPB accountability – and how to challenge it. The recent General Court judgment setting aside Meta’s challenge to the Consent or Pay Opinion appears at odds with the Advocate General’s Opinion in the CJEU case regarding a WhatsApp binding decision of the EDPB. The CJEU will have the final word, hopefully sooner rather than later, as it is critical for the applicable procedure to be clear.
[* Because the ePrivacy Guidelines were worse than previous excesses by the EDPB.]
As an EU Institution, the EDPB *must* remain accountable. Its guidance (Opinions, Guidelines) is not brought into question by supervisory authorities themselves, and seldom by the courts. Why? Because the EDPB is *the* body tasked with the interpretation of the GDPR and broader data protection (& to a certain extent privacy) rules.
Take the General Court’s judgment at face value, and this creates a serious problem: one EU Institution is allowed to publish a position as a set of Guidelines or as an Art. 64(2) GDPR Opinion that would be completely unchallengeable, but that would set in stone the way that authorities interpret and enforce a rule *and* that would have a strong influence on any court decision.
But that isn’t exactly true.
Even if the CJEU ends up following the General Court’s argument, there is always another option that needs to be properly tested: a complaint before the EU Ombudsman.
There has been at least one attempt to do so, but in my view it was a half-hearted attempt, and there was anyway a problem due to the existence of annulment proceedings in parallel.
If there is no way to attack Guidelines or Opinions, there must still be a way to challenge them if the process leading to them is in breach of the principles of good administration, which the EDPB is also bound to comply with.
Otherwise, if even that fails, then Guidelines and Opinions *cannot* have any legal value and must just be viewed as a piece of paper. Anything else would create something that is very undemocratic and undesirable: shadow laws that are untouchable but that affect everything going forward.
I don’t think that’s what the EU legislator ever intended, and I don’t think even the EDPB would like this to be the way it is viewed.
If the Commission really wishes for there to be “Better Regulation” and for the GDPR to be reformed, perhaps a bit more statutory clarity regarding this point would be good.
My first piece on “Better Regulation” was on the ePrivacy Directive, an in-depth look at each key provision to see what its fate should be: https://lnkd.in/e5CCEURt
My next piece will be a first set of musings regarding the upcoming GDPR reform, with probably a few to follow.
For more thoughts on the AG Opinion referenced above: https://lnkd.in/e34C3HvF
And on the recent General Court judgment: https://lnkd.in/en_mBdSD“
Did this analysis get you thinking? Reach out!
DataLaws.net is entirely open-access, and instead of getting your data in exchange for this content, how about another trade? If this commentary saved you research time or sparked an idea, feel free to invite me over for tea, chai or a hot chocolate next time you are around Brussels or Antwerp - or invite me over to your offices for a chat!
Get in touch ↗ Let's connect on LinkedIn ↗