EDPB Consults on Guidelines for Deciding GDPR Fines and Finalises DSA-GDPR Guidance

European Union
Sep 21, 20262 sources
  • 01The EDPB adopted Guidelines 04/2026 on imposing GDPR administrative fines in relation to other corrective powers; the public consultation runs until 13 November 2026.
  • 02DPAs are to follow a five-step methodology: legal basis for a fine, liability of the party, intent or negligence, aggravating and mitigating factors, and whether a fine would be effective, proportionate and dissuasive.
  • 03Minor infringements generally lead to no fine and may lead to a reprimand; for other infringements there is a strong presumption that a fine should be imposed.
  • 04The guidelines include 14 practical examples of how DPAs choose among corrective measures.
  • 05The EDPB also adopted the final version of its guidelines on the interplay between the DSA and the GDPR.

The European Data Protection Board (EDPB) has adopted Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR. The guidelines are dated 17 September 2026, and the EDPB announced their adoption after its plenary on 21 September 2026. They are open for public consultation until 13 November 2026.

The guidelines set out a five-step methodology for data protection authorities (DPAs) deciding whether to impose a fine, either on its own or alongside other corrective measures. A DPA checks whether the infringement can lead to a fine under the GDPR or national law, whether the party under investigation can be fined for it, and whether it was committed intentionally or negligently. It then assesses aggravating and mitigating factors and whether a fine would be effective, proportionate and dissuasive.

If an infringement is minor, there will generally be no fine and a reprimand may be issued instead. If it is not minor, there is a strong presumption that a fine should be imposed. The guidelines also explain the purpose and scope of the other corrective powers, including warnings, reprimands, orders, limitations and bans, and the withdrawal of certification, with 14 practical examples.

At the same plenary, the EDPB adopted the final version of its guidelines on the interplay between the Digital Services Act (DSA) and the GDPR.

For controllers and processors, the guidelines indicate that corrective orders and fines are assessed together and that a fine is the expected outcome for infringements that are not minor. Organisations that want to comment on the methodology can respond to the consultation by 13 November 2026.

Sources (2)

edpb.europa.euSep 21, 2026

EDPB consults on GDPR fine methodology and finalises DSA-GDPR guidance

edpb.europa.euSep 17, 2026

EDPB issues guidance on GDPR fines and other corrective powers