EDPB Orders Belgian DPA to Investigate NOYB Cookie Complaint Against VRT
The EDPB has issued a binding decision instructing the Belgian Data Protection Authority (DPA) to assess the merits of a complaint lodged by NGO NOYB concerning cookie banners on the Flemish public broadcaster VRT's website, rather than dismissing it. The Belgian DPA had initially proposed dismissal based on an alleged abuse of right, citing case law from the Brussels Market Court. The EDPB found insufficient evidence of abuse under the GDPR and requires the Belgian DPA to proceed with a substantive review.
Related updates
PensionStat.be: Official Belgian Pension Statistics Portal
Key figures on the pension situation of women and men, and more specifically the difference between the two, i.e. the pension gap.
17 Jun 2026
Cyber Resilience Act: EU reporting obligation enters into force
From 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe product security incidents through ENISA's single reporting platform. Belgium's CCB, acting as national CSIRT, will process notifications addressed to Belgium and forward them to other competent authorities. Reporting follows a 24-hour early warning, 72-hour notification and final report sequence.
11 Sep 2026
Threat Hunting: Detecting Intruders Already Inside the Network
The Centre for Cybersecurity Belgium (CCB) published a summary of its Cybertips webinar on threat hunting, explaining how attackers using valid credentials can bypass automated defences without triggering alerts. The article contrasts penetration testing, threat hunting and purple teaming, and sets out practical guidance for organisations assessing whether threat hunting fits their risk profile. No new legal obligations are introduced.
08 Sep 2026

