HomePostsPlatform GovernanceThe Admissibility of Judicial Review of EDPB Binding Decisions: WhatsApp Ireland v...

Related Posts

The Admissibility of Judicial Review of EDPB Binding Decisions: WhatsApp Ireland v European Data Protection Board (Case C-97/23 P)

Introduction

The judgment of the Court of Justice of the European Union („CJEU“) in WhatsApp Ireland Ltd v European Data Protection Board (Case C-97/23 P), issued on 10 February 2026, clarifies an important question concerning the legal position of the European Data Protection Board („EDPB“) in judicial proceedings. Specifically, the Court addressed whether binding dispute resolution decisions adopted by the EDPB under Article 65 General Data Protection Regulation („GDPR“) constitute reviewable acts within the meaning of Article 263 Treaty on the Functioning of the European Union („TFEU“). The CJEU ruled that such decisions, although formally addressed to national supervisory authorities, may produce binding legal effects for data controllers and are therefore capable of being challenged directly before the EU courts.

This blog post outlines the factual and procedural background of the case, examines the Court’s reasoning, and considers its broader implications for GDPR enforcement and access to judicial review under EU law.

Background of the Case

The background of the case was an investigation conducted by the Irish Data Protection Commission („DPC“), acting as lead supervisory authority for WhatsApp Ireland Ltd, into WhatsApp’s compliance with transparency obligations under Articles 12 to 14 GDPR.

Following the publication of its draft decision, several concerned supervisory authorities raised objections under the GDPR cooperation mechanism. As the supervisory authorities were unable to reach a consensus on these matters, the dispute was referred to the EDPB for binding resolution pursuant to Article 65 GDPR.

The EDPB subsequently adopted a binding decision requiring the Irish DPC to amend its draft decision in line with the EDPB’s findings. The decision addressed each of the objections raised by the concerned supervisory authorities, providing detailed guidance on the interpretation of the disputed Articles, the assessment of infringements, and the appropriate corrective measures. In particular, the EDPB clarified the qualification of user data, the identification of additional potential infringements, and the methodology for calculating administrative fines.

Following the EDPB decision, the Irish DPC issued its final decision, which incorporated the Board’s findings and imposed an administrative fine of EUR 225 million on WhatsApp Ireland Ltd.

In addition to challenging the administrative fine imposed by the Irish DPC, WhatsApp also contested the EDPB’s binding decision itself, arguing that it directly affected its legal position and should therefore be subject to judicial review under Article 263 TFEU, even though the decision was formally addressed to the Irish DPC.

On 7 December 2022, the European General Court („EGC“) dismissed the action as inadmissible, holding that the EDPB decision was not addressed to WhatsApp and did not directly concern the company.

Unsatisfied with this outcome, WhatsApp filed an appeal to the CJEU, seeking clarification on whether binding EDPB decisions constitute reviewable acts under EU law.

Judgement of the CJEU

Assessment of the Timeliness of the Claim

The CJEU first addressed the question of whether WhatsApp’s action was filed in time under Art. 263 (6) TFEU. The EDPB had suggested that the two-month limitation period might have begun when WhatsApp became aware of parts of the contested EDPB decision on 13 August 2021.

The Court confirmed that, under Article 263(6) TFEU, the starting point of the limitation period depends on the circumstances of the case, giving priority to the formal notification or communication of the act to the addressee. Knowledge of the act only serves as a subsidiary criterion. In this case, because WhatsApp was not formally notified, the limitation period began with the publication of the EDPB decision on the Board’s website on 2 September 2021, in line with Article 65(5) GDPR. Since the action was filed on 1 November 2021, the Court concluded that the action was timely.

Assessment of the Reviewability of the EDPB Decision under Art. 263(1) TFEU

The CJEU next addressed the question of whether the contested decision of the EDPB constitutes a reviewable act under Article 263(1) TFEU. The Court emphasized that, in determining whether a measure is contestable, the focus must be on the objective legal effects of the act itself, not on the procedural position or claims of the applicant. A measure is reviewable if it is intended to produce legal effects on third parties, irrespective of whether it is addressed directly to the applicant.

The Court noted that the contested EDPB decision establishes the Board’s final position on the issues under consideration and produces binding legal effects. In particular, the decision binds the lead supervisory authority as well as all concerned national supervisory authorities, which are treated as third parties in relation to the EDPB. The lead authority must adopt its final decision on the basis of the EDPB decision and explicitly refer to it, giving the contested decision a direct and binding impact.

It rejected the characterization of the EDPB decision as a mere preparatory measure or intermediate step in the coherence procedure. While it is true that preparatory measures are generally preliminary opinions or steps that facilitate the adoption of a final act, they do not independently produce legal effects on third parties.

The Court concluded that the contested EDPB decision constitutes a reviewable act under Art. 263(1) TFEU. At this stage, there was no need to determine whether the decision resulted in a qualified alteration of WhatsApp’s legal position.

Assessment of WhatsApp’s Immediate and Individual Concern under Article 263(4) TFEU

The CJEU then addressed whether the EGC had incorrectly concluded that the contested EDPB decision did not directly affect WhatsApp within the meaning of Article 263(4) TFEU, making the action inadmissible.

The Court clarified that the requirement of direct effect consists of two cumulative conditions: (i) the measure must directly affect the legal position of the person concerned, and (ii) the addressee of the measure must have no discretion in its implementation, which must follow automatically from Union law. The fact that the decision is not directly enforceable against the applicant or that it is not the final step in a multi-stage procedure does not preclude direct effect if the implementing authority has no discretion.

The Court then examined whether these conditions were met. The contested EDPB decision found that WhatsApp had violated Articles 13(1)(d) and 13(2)(e) GDPR, thereby changing its legal position, including the need to adjust its contractual relationships with users of its messaging service. This established a direct link between the decision and its effects on WhatsApp, fulfilling the first condition of direct effect.

Regarding the second condition, the Court emphasized that the EDPB decision binds both the lead supervisory authority and the concerned national authorities, leaving them no discretion in implementing the findings of the decision. In particular, the authorities cannot alter the assessment of GDPR violations, the classification of hashed data as personal data, or the obligation to increase the prescribed fines. Consequently, the decision directly imposes obligations on WhatsApp through its binding effect on the supervisory authorities, without the authorities being able to modify its outcome.

The Court further clarified that it is irrelevant that the Irish authority is the only point of contact for WhatsApp under Article 56(6) GDPR, as this provision governs the relationship between the responsible controller and the authorities, not the applicant’s right to challenge decisions. The Court also addressed the procedural interlinkage between the EDPB decision and the final national decision, noting that parallel proceedings do not render the EDPB decision indirect.

Consequently, the Court concluded that WhatsApp is directly affected by the contested EDPB decision under Article 263(4) TFEU and that the claim is admissible.

Implications of the Judgment and Broader Lessons for EU Digital Regulation

One immediate implication of the Court’s judgment is that the overall duration of enforcement and litigation processes in the EU will likely increase. Since national courts may need to await the outcome of an EU decision, parallel proceedings, such as challenges against a national authority’s implementing act, could be put on hold. While this ensures that national courts do not issue decisions inconsistent with the interpretation of EU law by the CJEU, it also opens the door for strategic litigation tactics. Affected companies could use the parallel review process to prolong uncertainty, buying time before obligations must be fully implemented.

Looking beyond the GDPR, the Court’s reasoning could have broader relevance for emerging EU digital regulatory frameworks. Under the Artificial Intelligence Act („AI Act“), Art. 65(1) establishes an AI Board designed to ensure consistent application of the Regulation across Member States, comparable in structure to the European Data Protection Board. If national authorities have little or no discretion in implementing its measures, these could similarly be considered reviewable acts under Article 263 TFEU, creating new avenues for judicial oversight.

Similarly, Art. 61(1) Digital Services Act („DSA“) establishes a European Board for Digital Services to contribute to the consistent application of the Regulation and facilitate cooperation between national authorities. However, unlike the dispute resolution mechanism under Article 65 GDPR, the DSA does not currently grant the Board the power to adopt clearly defined binding decisions addressed to national authorities. It therefore remains uncertain to what extent the Board’s opinions and recommendations will shape national enforcement outcomes in practice. Much will depend on whether its role gradually evolves beyond coordination and guidance into a de facto determinative influence on supervisory decisions, or whether it continues to function primarily in an advisory capacity, leaving room for interpretation and discretion at the national level.

Adiriaan Ramesh
LL.M. at Católica Global School of Law

Adiriaan Ramesh is currently pursuing an LL.M. at Católica Global School of Law in the program “Law in a Digital Economy” after completing his First State Examination in Germany. His research interests focus on data protection law, AI regulation, and cybersecurity.

Julian Lörscher
LL.M. at Católica Global School of Law i

Julian Lörscher is currently pursuing an LL.M. at Católica Global School of Law in the program “Law in a Digital Economy” after completing his First State Examination in Germany, where he specialized in commercial and corporate law. His research interests focus on data protection, AI regulation and competition law.

[citationic]

Featured Artist