More Consistent GDPR Fines: EDPB Introduces a Five-Step Approach and Finalises Its DSA-GDPR Guidelines

More Consistent GDPR Fines: EDPB Introduces a Five-Step Approach and Finalises Its DSA-GDPR Guidelines

When should a GDPR infringement result in a reprimand, and when should it lead to an administrative fine? The European Data Protection Board (EDPB) is seeking to further harmonise how supervisory authorities across the European Union answer that question. The new Guidelines 04/2026 introduce a five-step methodology for deciding whether to impose an administrative fine and how such a fine should interact with other corrective measures. The Guidelines were adopted on 17.09.2026 and remain open for public consultation until 13.11.2026.

Supervisory authorities should assess, step by step, whether the infringement can be subject to a fine, who can be held liable, whether the infringement was intentional or negligent, which aggravating or mitigating circumstances apply and, finally, whether a fine would be effective, proportionate and dissuasive. Minor infringements may generally be addressed without a fine, while for other infringements the EDPB establishes a strong presumption in favour of imposing one. The Guidelines also address the broader range of corrective powers available under the GDPR, including warnings, reprimands, orders, restrictions and withdrawal of certifications.

The focus is therefore not primarily on how high the fine should be, but on the preceding question of whether a fine should be imposed and how it should interact with other corrective powers. The Guidelines complement the EDPB’s existing methodology on calculating administrative fines and aim to make GDPR enforcement more consistent across Member States.

At the same time, the EDPB adopted the final version of Guidelines 3/2025 on the interplay between the Digital Services Act and the GDPR. These are particularly relevant to online platforms and other intermediary service providers, as compliance with the DSA frequently involves the processing of personal data. The Guidelines therefore clarify how both regulatory frameworks should operate together and be applied consistently. The final version was adopted following public consultation on 17.09.2026.

For businesses, the common theme of both documents is a shift from formal GDPR compliance towards the question of how those rules will actually be enforced. Controllers and online platforms should therefore avoid assessing individual obligations in isolation. In enforcement proceedings, the seriousness of the infringement, fault, the controller’s response and the combination of corrective measures will become increasingly important, while platforms must also ensure that GDPR compliance is coordinated with their obligations under the DSA.


Write to us