A Dictionary Site With 1,741 Data-Sharing Partners
Austrian privacy group noyb has filed a GDPR complaint against dict.cc, the popular online dictionary, over how it collects consent for online tracking. The problem isn't that the site asks for permission. It's what happens when a user tries to actually understand what they're agreeing to.
According to noyb's calculations, dict.cc's consent banner names 1,741 separate "partners" who may receive or process visitor data. To make an informed decision, a user would theoretically need to read every one of those partners' privacy policies before clicking accept. noyb estimates that task alone would take roughly 172 hours, more than a full week of nonstop reading, just to evaluate a single visit to a dictionary website.
That gap between what the law requires and what the interface actually allows is the core of the complaint, and it raises a question that goes well beyond one website: can consent that takes days to properly evaluate ever be considered informed?
Why This Looks Like a Dark Pattern, Not a Design Flaw
GDPR's foundational principle, laid out in Article 5(1)(a), requires that personal data be processed lawfully, fairly, and transparently. Consent under the law is only valid if it's freely given, specific, and informed. noyb's complaint argues that a banner listing over a thousand partners effectively makes informed consent structurally impossible. Users are left with two real options: click accept without understanding what they're agreeing to, or abandon the site entirely.
This is a familiar shape in the online tracking ecosystem. Consent walls with sprawling partner lists aren't accidental complexity. They function as friction, designed to make refusal or careful review so time-consuming that acceptance becomes the path of least resistance. The mechanism echoes what researchers have found in other tracking investigations, including reporting on how TikTok tracks users even without an installed app through pixels most people never see or consent to in any meaningful way. In both cases, the technical architecture of data collection outpaces any realistic user's ability to review it.
The scale of dict.cc's partner list also mirrors a broader pattern in how personal data flows through commercial ecosystems once collection begins. Once dozens or hundreds of third parties are contractually looped into an ad-tech or analytics chain, the original website operator often loses practical visibility into how that data is used downstream, even if it remains legally responsible for the initial consent collection.
What Austria's Regulator Must Now Decide
The complaint puts Austria's data protection authority in a difficult spot. Regulators have generally accepted that consent banners can list third parties, since GDPR doesn't ban complex advertising ecosystems outright. But noyb's complaint forces a more specific question: at what point does a partner list become so large that consent collected through it is no longer legally valid, regardless of how the banner is worded or designed?
If the regulator sides with noyb, the ruling could ripple across the ad-tech industry, where large partner lists tied to frameworks like the IAB's Transparency and Consent Framework are common practice, not a dict.cc-specific quirk. Many publishers rely on similarly long partner rosters to monetize traffic through programmatic advertising. A finding against dict.cc could pressure sites across Europe to shrink partner counts, simplify consent flows, or face similar complaints.
This isn't the first time regulators have had to grapple with data practices that technically comply with disclosure rules while functionally defeating their purpose. Employee and student data cases, like the scrutiny around PowerSchool's student tracking practices, show a similar tension: consent or notice exists on paper, but the practical ability of the affected person to understand or contest data collection is minimal.
What This Means For You
If you've ever clicked "Accept All" on a cookie banner without reading a word, you're not alone, and according to this complaint, you're not entirely to blame either. The design of many consent banners assumes, and arguably relies on, exactly that behavior.
A few practical steps can help:
- Look for a "Reject All" or "Manage Preferences" option before clicking through a banner. Many sites bury it, but GDPR requires it exist.
- Use browser privacy tools or extensions that block third-party trackers by default, reducing how much data even reaches those partner networks.
- Pay attention to how many "partners" a consent banner names. A number in the thousands, as with dict.cc, is a signal the site's data-sharing arrangement is closer to an ad-tech marketplace than a simple analytics setup.
- Support or follow enforcement actions like noyb's complaints. Regulatory pressure is often the only force that changes how these banners are built.
The Bottom Line
This GDPR complaint against dict.cc isn't really about a dictionary website. It's a test case for whether "consent" can survive contact with modern ad-tech's scale. When agreeing to a cookie banner would require more than a week of reading to do properly, the banner has arguably already failed at its one job: making sure users know what they're agreeing to. How Austria's regulator rules here could shape whether similarly bloated consent flows remain standard practice or start disappearing from the web.




