Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

EDPB Sets Five-Step Method for GDPR Fines & Finalizes DSA Privacy Guidelines

EDPB Sets Five-Step Method for GDPR Fines & Finalizes DSA Privacy Guidelines

By
Key Takeaways
  • Five-Step Fining Methodology: The EDPB has established a common five-step approach for national data protection authorities deciding whether a GDPR infringement should result in an administrative fine.
  • Minor and Non-Minor Infringements Treated Differently: Minor infringements will generally not result in fines and may instead draw reprimands, while non-minor infringements carry a strong presumption that a fine should be imposed.
  • Fines Remain One Tool Among Several: Authorities must consider fines alongside warnings, reprimands, orders, processing limitations and bans, and withdrawal of certification.
  • Public Consultation Runs Through Nov. 13: The fining guidelines remain open for stakeholder feedback until Nov. 13, 2026, and will replace earlier Article 29 Working Party guidance once finalized.
  • DSA-GDPR Guidelines Finalized: The EDPB also adopted its final guidance on how the DSA and GDPR interact where intermediary service providers process personal data. Publication will follow linguistic checks.
Deep Dive

Europe’s data protection authorities have never lacked ways to punish a GDPR violation. They can warn an organization, reprimand it, order it to change what it is doing, restrict its processing or stop that processing altogether. And, of course, they can fine it. What has been less settled is how an authority should decide among those choices.

The European Data Protection Board moved to adopt new guidelines that set out a common five-step method for deciding when an administrative fine should follow a GDPR infringement and when another corrective measure may be enough. The guidelines are intended to bring greater consistency to decisions made by national data protection authorities across Europe, where the same regulation is enforced by different regulators in different legal systems.

The question here is not how large a fine should be. The EDPB has already issued separate guidance on calculating administrative fines. The new guidelines concern the decision that comes before the arithmetic, when an authority must decide whether a fine belongs in the case at all and how it should sit alongside the other powers available to the regulator.

“The new EDPB guidelines are a major step in further aligning how Data Protection Authorities decide whether an administrative fine should be imposed, either on its own or alongside other corrective measures,” EDPB Deputy Chair Jelena Virant Burnik said.

The method begins with the legal basis. An authority must determine whether the infringement is one that can lead to a fine, either directly under the GDPR or under national law. It must then establish whether the party under investigation can be fined for that particular infringement. That depends on the provision that was breached and whether its obligations fell on the controller or the processor.

The third question is culpability. Before imposing a fine, the authority must assess whether the infringement was committed intentionally or negligently. Under the EDPB’s methodology, a culpable infringement is a condition for an administrative fine.

From there, the judgment becomes more particular to the case. Authorities are instructed to weigh aggravating and mitigating factors, and it is at this stage that the guidelines draw one of their clearest lines. A minor infringement will generally not attract a fine and may instead result in a reprimand. If the infringement is not minor, the position changes considerably. There is a strong presumption that a fine should be imposed.

Even then, the decision is not automatic. The final step requires the authority to determine whether a fine would be effective, proportionate and dissuasive. A regulator may depart from the standard approach where the circumstances of the case give it reason to do so.

That last judgment matters because the GDPR did not give regulators fines in isolation. Its enforcement structure is broader than that, and the EDPB’s guidelines spend considerable attention on how the pieces fit together. National authorities can issue warnings and reprimands, make orders, impose limitations including bans, and withdraw certifications. A fine can stand alone or accompany another corrective measure.

The guidelines include 14 practical examples showing how authorities can work through the circumstances of individual cases and decide what response, if any, is warranted. Their purpose is not to erase regulatory discretion. It is to give that discretion a more consistent shape.

The EDPB said the guidelines replace earlier Article 29 Working Party guidance on the application and setting of administrative fines under the GDPR. They also complement the Board’s existing guidelines on calculating fines, which address the amount to be imposed rather than the threshold decision of whether to impose one.

For organizations facing enforcement, that division is worth keeping straight. One set of guidelines concerns the size of the bill. The other concerns why there should be a bill in the first place.

The new fining guidelines are not yet final. They have been opened for public consultation through Nov. 13, 2026, giving stakeholders an opportunity to comment before the EDPB adopts a final version.

At the same plenary, the Board completed another piece of guidance dealing with a different problem created by Europe’s expanding digital rulebook.

Following public consultation, the EDPB adopted the final version of its guidelines on the interplay between the Digital Services Act and the GDPR. The document is meant to support consistent application of the two laws where they meet, particularly when provisions of the DSA involve the processing of personal data by intermediary service providers or rely on concepts and definitions drawn from the GDPR.

That intersection is more than a matter of legal housekeeping. The DSA created its own obligations for intermediary services, but those obligations do not displace the rules governing personal data simply because the processing occurs in a DSA context. The EDPB’s guidance is intended to clarify how the two bodies of law operate together when the same activity engages both.

The DSA-GDPR guidelines have already passed through public consultation and are final. They are not yet published, however. The EDPB said the document must first undergo linguistic checks and will be released soon.

The two decisions address different questions, but each reflects the same practical difficulty of European digital regulation. Writing a common rule is one thing. Having different authorities apply it consistently, alongside other rules and other enforcement powers, is harder. The EDPB’s latest work is aimed squarely at that second problem.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong