noyb filed a complaint against dict.cc GmbH with the Austrian Data Protection Authority today, arguing that a single click on the dictionary site's consent banner asks visitors to accept data sharing with 1,741 named "partners," a scale the privacy group says makes informed consent impossible to obtain.
A dictionary, a banner, and 1,741 names
The complaint, filed under Case Number C107, centers on an event that noyb - the European Center for Digital Rights - says took place on July 7, 2026, at 14:45, when a complainant visited www.dict.cc, a free multilingual dictionary site operated by dict.cc GmbH of Vienna. According to the filing, a banner appeared asking the visitor to accept data processing before continuing to the translation search that had brought them to the site in the first place.
The complainant clicked "Alle akzeptieren und Website besuchen" - "Accept all and visit website" - in order to reach the dictionary and look up translations, according to the complaint document. That single click, noyb argues, triggered consent to data processing by dict.cc and by 1,741 separate companies listed as "Technologiepartner," or technology partners, in a submenu of the banner.
The number appears with an exclamation mark in the complaint text itself: "Im Untermenü des Banners befinden sich Informationen zu den 1721 (!) Partnern" - a detail that in noyb's own numbering appears as 1,721 in the German-language legal filing, while the organization's separate media statement, sent the same morning to journalists including PPC Land, cites a count of 1,741. Both figures describe the same underlying banner and the same underlying problem: a count in the thousands, attached to one checkbox equivalent.
Under Article 80(1) of the General Data Protection Regulation, noyb represents the complainant before the Austrian Data Protection Authority, known by its German abbreviation DSB. The complaint asks the DSB to declare that dict.cc processed the complainant's personal data without a valid legal basis, order deletion of that data along with notification to every recipient the data reached, prohibit further processing without valid consent, and impose a fine.
The arithmetic behind the objection
The complaint does not rest primarily on abstract legal argument. It rests on a calculation of time.
Citing an online reading-time estimator, the complaint sets out how long it would take to read the privacy policies of just the first three partners listed in dict.cc's banner. Exponential Interactive, doing business as VDX.tv, has a privacy policy that the complaint estimates would take roughly 12 minutes to read at a standard silent-reading pace of 250 words per minute. Captify Technologies Limited's privacy notice would take approximately 32 minutes. Roq.ad GmbH's privacy policy would take about 36 minutes. Three policies, out of 1,721 named partners, already consume roughly 80 minutes.
Extrapolating from there, the complaint calculates that if the complainant spent just one minute per partner - not reading, merely locating basic information - the exercise would require 1,721 minutes, or 28 hours and 41 minutes. Applying a more realistic estimate of six minutes per partner to actually parse how each company processes data, the total rises to 10,326 minutes: 172 hours and 5 minutes, or more than seven full days.
noyb's media statement, distributed on July 30, 2026, frames the same underlying math slightly differently, citing 1,741 partners and stating that reading every privacy policy "would at least take 170 hours (even if you just scan each policy for 6 minutes)." Felix Mikolasch, a data protection lawyer at noyb, is quoted in that statement saying it would take "days or even weeks to properly read and understand the data protection policies of 1,741 companies" and calling it "ridiculous to assume that this would allow for an informed decision."
The complaint pushes the calculation further still. It notes that dict.cc's disclosed partners are known to redistribute data to further recipients, a common structure in programmatic advertising in which one named vendor may share data with dozens or hundreds of additional parties whose identities never appear in the original consent banner. Assuming, for illustration, that each of the 1,721 named partners shares data with 100 further recipients, the complaint arrives at a hypothetical chain of 172,100 parties potentially receiving data from a single click - a figure the filing describes as an unbounded or "stockpiled" consent covering entities the visitor could never identify in advance.
Legal grounds cited in the filing
The complaint alleges two categories of violation. First, it argues dict.cc breached Article 5(1)(a) of the GDPR, the principle requiring that personal data be processed lawfully, fairly, and in a transparent manner. Second, it argues the company breached Article 6(1), which requires a valid legal basis - most commonly consent - before personal data may be processed at all.
To support the transparency argument, the complaint quotes Recital 58 of the GDPR, which states that the principle of transparency requires information addressed to the public or to a data subject to be concise, easily accessible, and easy to understand, and that this holds particular relevance where the large number of actors and the technological complexity of a practice make it difficult for a data subject to know and understand whether personal data is being collected, by whom, and for what purpose - citing online advertising by name as an example.
The complaint also cites the Article 29 Working Party's guidelines on transparency (WP260 rev.01), which state that intelligibility of information "means that it should be understood by an average member of the intended audience," and that a central factor in the transparency principle is that a data subject should be able to determine in advance the scope and consequences of processing, rather than being taken by surprise later by how their data has been used.
On the requirement for informed consent specifically, the filing draws on Court of Justice of the European Union case law. It quotes the CJEU's Planet49 judgment (Case C-673/17), which held that clear and comprehensive information must put a user in a position to easily determine the consequences of any consent given, and must be clear and comprehensible enough for the user to understand the functioning of cookies being used. It also cites Orange Romania (Case C-61/19), where the Court held that a signature on a form containing a pre-ticked consent clause is not sufficient proof of valid consent absent evidence the clause was actually read and understood, and quotes Advocate General Szpunar's opinion in the same case stating that it must be beyond doubt that the data subject was adequately informed.
The complaint further cites European Data Protection Board guidelines from May 2020 on the concept of consent, which state that providing information to a data subject before consent is obtained is essential to enable an informed decision, to allow understanding of what is being agreed to, and to preserve the ability to exercise the right of withdrawal - and that where a controller fails to make information accessible, a user's control becomes illusory and consent becomes an invalid basis for processing.
Applying that framework to dict.cc, the complaint concludes that a data subject asked to review 1,721 or 1,741 partner disclosures in a single sitting cannot, in the Working Party's words, "recognize and comprehend" whether, by whom, and for what purpose personal data is being processed, and therefore cannot give informed consent under Article 4(11) of the GDPR - the article defining consent as a freely given, specific, informed, and unambiguous indication of a data subject's wishes.
Revenue and the request for a fine
The complaint states that dict.cc GmbH generates several million euros in annual revenue and at least several hundred thousand euros in annual profit, sourced primarily from online advertising, and asks the DSB to impose a fine that is effective, proportionate, and dissuasive under Article 83 of the GDPR. It leaves open the possibility that the Austrian authority could refer the matter to the European Data Protection Board for an opinion, given what the complaint describes as its general significance for the broader online advertising ecosystem.
dict.cc has operated since 2002 and describes itself as a free, multilingual online dictionary founded by Paul Hemetsberger, with headquarters in Vienna. The site allows dictionary lists to be downloaded for offline use and has built a large volunteer-reviewed vocabulary base over more than two decades of operation.
A familiar pattern for consent banners
The dict.cc complaint arrives against a backdrop of sustained regulatory attention to the machinery underpinning online advertising consent, much of it also driven by noyb. In March 2024, the Court of Justice of the European Union ruled in Case C-604/22 that IAB Europe, as manager of the industry's Transparency and Consent Framework, could be considered a joint controller for the TC String that carries a user's consent choices to advertising vendors, even though IAB Europe itself never directly accesses the underlying personal data.
That TCF infrastructure, and the sheer number of vendors it registers, has drawn repeated scrutiny. IAB Europe's own 2025 compliance report showed enforcement procedures against registered vendors rose 118 percent year over year to 587 cases, with 953 vendors and 181 consent management platforms registered by the end of the year, as PPC Land reported in March 2026. The scale of those registries - hundreds or thousands of named entities behind a single consent toggle - is structurally similar to what the dict.cc complaint describes, even though dict.cc's banner is not itself built on the TCF standard string described in the CJEU ruling.
Separately, Austria's own courts have already tested a related but distinct consent mechanism. In August 2025, an Austrian court ruled that the "Pay or Okay" model used by newspaper DerStandard was illegal, finding that publishers using such systems recorded consent rates near 99.9 percent while independent research suggested only 1 to 7 percent of users genuinely wanted to be tracked when asked directly, as PPC Land covered at the time. That case concerned the binary choice between paying a subscription fee or accepting tracking, rather than the sheer number of parties named within a single consent request, but both lines of complaint share a common thread: noyb's contention that consent mechanisms across the advertising industry are engineered to produce high acceptance rates rather than genuine, informed agreement.
The Austrian authority has separately faced questions about its own capacity to process complaints at this volume. PPC Land reported in September 2025 that the DSB implemented operational cuts starting in July 2025 amid budget constraints, with the agency's 2026 funding set at 5.9 million euros against a workload that includes complaint processing as its stated primary focus. Whether that capacity affects the timeline for resolving the dict.cc case remains to be seen; the complaint carries no statutory deadline for a decision, though GDPR complaints in Austria have in some instances taken years to resolve, including a YouTube data-access case the DSB decided in August 2025 after roughly five years, as PPC Land also reported.
Why this matters for advertising professionals
For publishers, advertisers, and the consent management platforms serving them, the dict.cc complaint functions as a stress test of a structural feature common across much of the programmatic advertising supply chain: the practice of listing hundreds or thousands of vendors inside a single consent request, on the theory that disclosure alone satisfies the GDPR's transparency and consent requirements.
noyb's own math - whether one accepts the 1,721 figure from the legal filing or the 1,741 figure from the accompanying media statement - argues that disclosure at this scale cannot function as genuine notice, because no realistic visitor will spend a working week reading privacy policies before searching for a word translation. If the Austrian DPA accepts that reasoning, the implications would not be confined to dict.cc. Any consent banner listing partner counts in the hundreds or thousands - a structure noyb's media statement says is common practice, citing examples including www.repubblica.it, www.bergfex.de, and www.fifa.com - would face the same underlying question about whether large-scale vendor lists can ever produce informed consent under Article 4(11).
The complaint also returns attention to the practice of sub-processing, in which a named partner in a consent banner may pass data to further recipients not disclosed to the original visitor. That structure has already drawn comment from the Court of Justice; the complaint itself cites paragraphs 22 and 23 of the CJEU's IAB Europe ruling as describing the passing of data to numerous further controllers as common practice in automated online advertising. Should the DSB find in noyb's favor, consent management platforms and publishers relying on similarly extensive partner lists may need to reassess how they structure disclosure - not merely whether a list of partners exists, but whether its scale defeats the purpose the list is meant to serve.
Timeline
- March 7, 2024 - The Court of Justice of the European Union rules in Case C-604/22 that IAB Europe can be a joint controller for TC Strings under the Transparency and Consent Framework, without itself accessing the underlying personal data, according to the published judgment.
- August 18, 2025 - An Austrian court rules the "Pay or Okay" consent model used by DerStandard illegal, citing a gap between near-99.9 percent recorded consent rates and independent estimates of 1 to 7 percent genuine user interest in tracking. PPC Land coverage
- September 2025 - The Austrian Data Protection Authority begins operational cuts tied to budget constraints, with 2026 funding set at 5.9 million euros. PPC Land coverage
- March 28, 2026 - IAB Europe publishes its 2025 Transparency and Consent Framework Compliance Report, recording a 118 percent rise in vendor enforcement procedures to 587 cases. PPC Land coverage
- July 7, 2026, 14:45 - The complainant visits dict.cc and clicks "Accept all and visit website" on the site's consent banner, according to the complaint filing.
- July 30, 2026 - noyb files the complaint with the Austrian Data Protection Authority under Case Number C107 and issues an accompanying media statement, according to the complaint document and noyb's press release.
Related PPC Land coverage
- TCF enforcement more than doubled in 2025, IAB Europe report shows - IAB Europe's annual compliance report documents a sharp rise in enforcement actions against registered advertising vendors, illustrating the scale of the vendor ecosystem behind consent banners generally.
- Austrian court rules "Pay or Okay" model illegal for DerStandard newspaper - An Austrian ruling against a different consent mechanism finds a wide gap between recorded consent rates and genuine user preference for tracking.
- Austrian data protection authority cuts operations amid budget constraints - The regulator that will handle the dict.cc complaint has faced budget-driven operational restrictions since mid-2025.
- Austrian authority orders YouTube to honor data access request after 5-year case - A separate Austrian GDPR case illustrates how long complaints before the same authority can take to resolve.
- noyb files GDPR complaint over LinkedIn's paywall for profile visitor data - Another recent noyb complaint filed with the same Austrian authority, illustrating the organization's active caseload.
Summary
Who: noyb - European Center for Digital Rights, representing an anonymous complainant, filed a complaint against dict.cc GmbH, a Vienna-based online dictionary operator.
What: The complaint alleges that dict.cc's consent banner asks visitors to accept data processing by 1,741 (or, per the legal filing's own count, 1,721) named partner companies through a single click, violating Articles 5(1)(a) and 6(1) of the GDPR because informed consent at that scale is not practically achievable. noyb asks the Austrian Data Protection Authority to declare the processing unlawful, order deletion of the data and notification of recipients, prohibit further processing without valid consent, and impose a fine.
When: The underlying website visit took place on July 7, 2026, at 14:45. The complaint was filed with the Austrian Data Protection Authority on July 30, 2026, the same day noyb issued its public statement.
Where: The complaint was filed with the Österreichische Datenschutzbehörde in Vienna, Austria, where both noyb and dict.cc GmbH are based.
Why: noyb argues that a consent request naming thousands of partners cannot satisfy the GDPR's requirements for transparent, informed consent, since properly reading and understanding that many privacy policies would take well over a week by the group's own calculation - a structural criticism that extends beyond dict.cc to any consent banner built on similarly large vendor lists.
Discussion