noyb – European Center for Digital Rights
noyb files formal complaints with EU data protection authorities and pursues strategic litigation to enforce the GDPR and ePrivacy rules against private-sector data practices. It specializes in cross-border, multi-jurisdiction complaint campaigns targeting major tech and e-commerce platforms over tracking, consent, and international data transfers.
- Type
- GDPR enforcement NGO / strategic litigation nonprofit
- Based in
- Vienna, Austria
- Focus region
- EU/EEA, filed simultaneously across multiple member-state data protection authorities
Notable projects
Filed two 2025 complaints against TikTok, AppsFlyer and Grindr over unlawful cross-app tracking of sensitive data; filed six complaints (Jan 2025) against TikTok, AliExpress, SHEIN, Temu, WeChat and Xiaomi over unlawful data transfers to China; filed nine complaints (Aug 2024) against X/Twitter over training its Grok AI on 60+ million EU users’ data.
Founded by Austrian lawyer Max Schrems (of Schrems I/II CJEU fame); operates as a formal complaint-filing machine, lodging high volumes of detailed GDPR complaints with national DPAs rather than only publishing research, funded by roughly 4,400+ supporting members.
- Investigations
- 3
- Platforms tracked
- 2
- Active since
- 2024
- Latest report
- Dec 2025
Topics covered
- Data Access & Research Tools3
- Platform Compliance & Governance2
- Algorithmic Harm & Recommender Systems1
Watchdog vs. platform
Publicly documented legal proceedings, access disputes, or other platform pushback. Allegations, findings, and outcomes are labelled separately and linked to their sources.
Schrems v. Meta Platforms Ireland
Meta / Facebook2021–2024In case C-446/21, the Court of Justice of the European Union held that a social network such as Facebook cannot use all personal data obtained for targeted advertising without limits as to time or type. It also held that a public statement about sexual orientation did not authorise Meta to process other related data obtained outside the platform for personalised advertising. [1][2]
Status: CJEU judgment issued in October 2024 on questions referred by the Austrian Supreme Court.
Researchers
Current
- Kleanthi SardeliData Protection Lawyer2
- Lisa SteinfeldData Protection Lawyer1
- Max SchremsChairman1
Reports
Full database2025
2 reports- Dec 2025TikTokOther
TikTok unlawfully tracks your shopping habits – and your use of dating apps
A user discovered TikTok knew he had used the gay dating app Grindr and what he did there, data likely passed via AppsFlyer, an intermediary. TikTok also gave only an incomplete, hard-to-parse response to his GDPR access request across multiple attempts. noyb argues neither AppsFlyer nor Grindr had a valid legal basis under Article 6(1) or Article 9(1) GDPR to share this special-category data with TikTok.
Data Access & Research ToolsPlatform Compliance & GovernanceBy Kleanthi Sardeli and Lisa Steinfeld
- Jan 2025TikTokOther
TikTok, AliExpress, SHEIN & Co surrender Europeans’ data to authoritarian China
Six complaints filed in five European countries allege TikTok, AliExpress, SHEIN, Temu, WeChat and Xiaomi unlawfully transfer EU users’ personal data to China, which lacks an EU adequacy decision. Four of the six openly admit transfers to China in their privacy policies; two only reference undisclosed ‘third countries.’ None adequately answered users’ Article 15 access requests.
Data Access & Research ToolsPlatform Compliance & Governance
2024
1 report- Aug 2024X/Twitter
Twitter’s AI plans hit with 9 more GDPR complaints
X began using the personal data of over 60 million EU/EEA users to train its ‘Grok’ AI model from May 2024 without proactively notifying users or obtaining consent; most users learned of it only via a viral post more than two months later. X relies on a ‘legitimate interest’ legal basis rather than opt-in consent.
Data Access & Research ToolsAlgorithmic Harm & Recommender SystemsBy Max Schrems