noyb Files GDPR Complaint Against dict.cc Over 1,741 One‑Click Consents
dict.cc’s One‑Click Consent Bundles 1,741 Partners – Why It Breaches GDPR
Takeaway: noyb filed a GDPR complaint in Austria claiming that dict.cc’s consent banner illegally forces users to grant permission to 1,741 third‑party partners with a single click, making genuine “informed consent” impossible under the GDPR.
The Core Allegation
- What happened: dict.cc presents a consent banner that lists 1,741 “partner” companies. By clicking “accept,” users implicitly allow each partner to access their device and personal data.
- Why it matters: GDPR requires consent to be freely given, specific, informed, and unambiguous. Reading the privacy policies of 1,741 entities would take at least 170 hours (≈6 minutes per policy), far exceeding any realistic user effort. Consequently, users cannot be said to be informed.
- Legal claim: The Austrian Data Protection Authority (DPA) is asked to order the deletion of the unlawfully processed data, notify all recipients of that data, and impose a fine to deter similar practices.
“It would take days or even weeks to properly read and understand the data protection policies of 1,741 companies. It is ridiculous to assume that this would allow for an informed decision.” – Felix Mikolasch, data‑protection lawyer at noyb.
How GDPR Defines Informed Consent
- Freely given: Users must have a genuine choice; consent cannot be a condition of service unless strictly necessary.
- Specific: Consent must relate to a clearly defined purpose and a clearly identified data‑controller.
- Informed: Users must be provided with concise, transparent information about who will process their data and for what purpose.
- Unambiguous: A clear affirmative action (e.g., ticking a box) must indicate consent.
Bundling thousands of partners into a single “accept all” button collapses the specific and informed elements into an unreadable list, violating the regulation.
Industry Context – Consent Banners Are Widespread
- Common practice: Many websites and apps list hundreds of partners in their consent dialogs, often citing “legitimate interest” or offering a premium “no‑tracking” subscription.
- User experience: Commenters on Hacker News note similar experiences on Samsung TVs, Android apps, and other services, where a single click grants data access to hundreds of entities.
- Regulatory pressure: The complaint highlights a broader need for DPAs to enforce the quality of consent, not merely its presence.
“Consenting to thousands of ‘partner’ companies using your personal data does not only feel wrong, it indeed is. The data protection authority must finally put an end to this practice.” – Martin Baumann, data‑protection lawyer at noyb.
Potential Outcomes from the Austrian DPA
- Deletion order: Dict.cc may be forced to erase all data collected under the disputed consent.
- Notification requirement: All 1,741 partners would have to be informed of the deletion and cease further processing.
- Fine and deterrence: A monetary penalty could be levied to discourage other operators from using similar consent‑bundling tactics.
- Broader enforcement: The DPA could refer the case to the European Data Protection Board (EDPB) for a precedent‑setting opinion, potentially prompting EU‑wide guidance.
Community Reactions Highlight Core Issues
- Scale of consent: Users expressed disbelief at being asked to approve data sharing with hundreds of partners, calling for outright bans on ad‑tracking.
- Technical workarounds: Some suggested DNS‑level blocking (e.g., Pi‑hole) or opting for premium, ad‑free services as a practical defense.
- Regulatory gaps: Comments noted that many consent banners merely set a flag without actually disabling analytics, indicating a lack of enforcement on the effectiveness of consent.
What This Means for Users and Companies
- For users: The complaint underscores that a single click does not equate to informed consent. Users should demand granular controls and clear information about each data‑processor.
- For companies: Relying on massive “accept all” banners risks non‑compliance. Operators must redesign consent flows to meet GDPR’s specificity and transparency standards, potentially by limiting the number of disclosed partners or providing layered, easily navigable information.
Bottom Line
noyb’s complaint against dict.cc spotlights a systemic flaw in the way many online services obtain consent: bundling thousands of third‑party data processors into a single click makes genuine informed consent impossible under GDPR. The outcome of the Austrian DPA’s decision could set a critical precedent for how consent banners must be structured across the EU.