Affiliate marketing consent: the dict.cc case

Affiliate marketing consent sits in one of the thinner areas of GDPR practice. There's very little authority on how the informed consent standard applies when customer data travels down a chain of partners, so most brands are working from assumption rather than precedent.

A complaint filed in Austria may start to change that.

Reading the privacy policies of 1,741 companies would take roughly 170 hours, and that assumes a six minute skim of each one. A visitor to dict.cc was asked to agree to all of them with a single click.

On July 30, 2026, noyb, the privacy group founded by Max Schrems, filed a GDPR complaint against dict.cc GmbH with the Austrian Data Protection Authority over that banner.

Nothing has been decided yet. But we think the complaint targets a practice a lot of ecommerce brands rely on without thinking of it as consent collection at all: passing customer consent along to a long tail of partners.

What the noyb complaint alleges

dict.cc is a popular online dictionary run by dict.cc GmbH in Vienna. According to noyb, its banner nudged users into agreeing to tracking by 1,741 "partners" with one click on an "Accept All and Visit Website" button.

The complaint alleges that consent gathered this way cannot meet the GDPR standard. A user has no realistic way to know who is receiving their data, or what those recipients will do with it. It cites Article 4(11), which defines consent, alongside Article 5(1)(a) and Article 6(1).

noyb is asking the authority to declare that dict.cc breached the GDPR, order deletion of the data, notify everyone it was shared with, prohibit further processing without valid consent, and impose a fine.

"It would take days or even weeks to properly read and understand the data protection policies of 1,741 companies," said Felix Mikolasch, a data protection lawyer at noyb.

To be clear about where this stands: a complaint has been filed. The Austrian authority has not ruled, and every claim above is an allegation.

Why affiliate marketing consent is the real exposure

The mechanism under challenge is bundling: one button, one click, and an undisclosed number of recipients behind it. That pattern is not unique to a dictionary site, and it is not unique to ad tech.

Affiliate and partner programs run on the same shape. If your store runs affiliate marketing, network partnerships, or co-registration, customer data is moving to parties your customer never named. They probably couldn't name them if you asked.

The question a regulator would ask isn't whether you have a consent record. It's whether the consent your customer gave was specific and informed enough to cover the party who ended up with their data.

Our read is that this case matters less for what it decides than for what it clarifies. There's so little authority on affiliate marketing consent that a reasoned decision would give you something firmer to design against than you have today.

The second thing worth noticing is who brought this. A data protection authority did not open the case on its own initiative. A nonprofit filed it on behalf of one individual.

Most brands model privacy exposure as regulator risk, which quietly assumes someone at an agency has to notice you first. Organizations like noyb exist to make sure someone notices, and 2025 was a record year for privacy complaints globally.

An individual with a screenshot and a template is now a viable route to a formal proceeding.

It's the same pattern we wrote about in Texas SB140: the rules that create real exposure for ecommerce brands are rarely the ones that arrive with a press conference.

What this complaint does not mean

This is the part most coverage will skip, so it's worth being precise.

  • Nothing has been decided. The authority has issued no finding, no fine, and no order. A complaint is an argument, not an outcome.
  • The consent standard has not changed. Article 4(11) requires what it required before July 30. What's being tested is how it applies when the recipient list runs to four figures.
  • It's one member state. noyb asks the Austrian authority to consider a broader prohibition or a referral to the European Data Protection Board. Neither has happened, and an Austrian decision would not bind other authorities.
  • It's about tracking consent, not direct marketing consent. The banner governs cookies and third-party tracking. That's a different surface from the email or SMS direct marketing opt-in your customer gives at checkout, and conflating the two produces bad remediation work.

What GDPR requires for informed consent

noyb's argument rests on Article 4(11), which requires consent to be freely given, specific, informed, and unambiguous.

The claim is that "informed" and "specific" do real work. They are not satisfied by making a recipient list technically available behind a submenu if nobody could reasonably process it.

The Austrian authority has not endorsed that reading, and this post does not assume it will. But it's the argument you should expect to see aimed at partner disclosure, because it's now on the record.

How to audit your affiliate marketing consent

You don't need to wait for a decision. Here are five checks you can run this week.

Count your partners. Open your consent management platform and get the actual number of vendors in your banner's list. If nobody on your team can say the number without looking, that's the finding.

Map what leaves the store, and to whom. For every affiliate program, network, or partner integration, identify what customer data moves and which entity receives it. Then compare that against what your consent language actually told the customer.

Keep tracking consent and direct marketing consent separate. They have different legal bases, different disclosure obligations, and different remediation paths. Store them as one flag and you inherit the weaker position on both.

Check that your vendor list is current. Partner lists accumulate, because vendors get added during a campaign and never removed. What your customer sees may describe relationships that no longer exist while omitting ones that do.

Assume the complaint could come from a customer. Have a route for handling an individual privacy complaint that does not depend on it arriving as a regulator's letter.

Frequently asked questions

Does GDPR require separate consent for every affiliate partner?

Article 4(11) requires consent to be specific and informed. noyb's complaint argues a single click cannot satisfy that when 1,741 recipients sit behind it.

It does not follow that every partner needs its own checkbox, and no authority has drawn that line. If you're running a large partner list, that's a question for your counsel.

Can one accept button cover multiple partners?

Bundled consent is common and has not been declared unlawful in itself. What this complaint challenges is scale: at some volume, a recipient list stops being something a person can meaningfully be informed about. Where that threshold sits is exactly what's unresolved.

Does this affect direct marketing consent collected at checkout?

This complaint does not reach checkout opt-ins directly. The banner governs cookies and third-party tracking, which is a different legal surface from a direct marketing opt-in your customer gives while purchasing. The underlying principle still carries across, though: your customer should be able to understand who receives their data.

Who can file a GDPR complaint against an ecommerce store?

This one came from a nonprofit acting for an individual, not from a regulator. That's the practical point: a proceeding does not have to start with a supervisory authority deciding to look at you.

Where Dataships fits

Dataships is consent infrastructure for your direct marketing channels. It handles the consent your customer gives at checkout or on a form, collected under the correct rule for their market, with a timestamped record of the wording they saw and what they agreed to.

That record is what makes a specific and informed claim defensible later, and it's the part most brands cannot produce when asked.

It's worth being straight about the boundary, though. The vendor list in your cookie banner is a separate system, and this complaint is aimed there.

What we can tell you is whether the direct marketing consent you collect stands up on its own, across every form collecting it, and what it'd cost to build that yourself instead.

We'll post an update when the Austrian authority issues a decision. In the meantime, affiliate marketing consent is worth an hour of your team's attention. The audit above is cheap, and the alternative is finding out from a complaint.

If you want to know whether the direct marketing consent you collect would hold up in every market you sell in, book a demo and we'll walk your setup market by market.

This post is for general information and is not legal advice. Consult qualified counsel about your specific circumstances.

Read More Stories Like This

Compliance
Affiliate marketing consent: the dict.cc case
Integrations
Now Live: Klaviyo Forms Integration
Product updates
Now live: WhatsApp Consent Collection

Read More Stories Like This

Compliance
Affiliate marketing consent: the dict.cc case
Integrations
Now Live: Klaviyo Forms Integration
Product updates
Now live: WhatsApp Consent Collection
Get an incrementality assessment
See how Dataships can move more customers into your high LTV cohorts
Get all 10 prompts in the Notion companion

Read More Stories Like This

Compliance
Affiliate marketing consent: the dict.cc case
Integrations
Now Live: Klaviyo Forms Integration
Product updates
Now live: WhatsApp Consent Collection

Read More Stories Like This

Compliance
Affiliate marketing consent: the dict.cc case
Integrations
Now Live: Klaviyo Forms Integration
Product updates
Now live: WhatsApp Consent Collection

See How Much Revenue You’re Missing Out On

We'll A/B test against your current setup, show you exactly how much more revenue you're missing, and project your 12-month growth opportunity. Get your free revenue analysis today.