EDPB updates GDPR fining guidelines, adopts final DSA-GDPR guidelines

Published: 21/09/2026
| EDPB

During its latest plenary session, the European Data Protection Board (EDPB) has adopted draft guidelines clarifying how data protection authorities (DPAs) across member states should apply administrative fines alongside other corrective powers under the EU General Data Protection Regulation (GDPR).

The guidelines establish a structured five-step methodology for DPAs. These include:

  • Verifying that an infringement is legally eligible for a fine under the GDPR or domestic statute. 
  • Determining whether the investigated controller or processor can be held liable. 
  • Establishing culpability, confirming whether the breach was committed intentionally or negligently. 
  • Assessing aggravating and mitigating factors; minor infringements generally warrant a reprimand rather than financial penalties, whilst non-minor violations trigger a strong presumption that a fine is required. 
  • Evaluating whether imposing a fine is an effective, proportionate, and dissuasive measure, or if circumstances justify deviating from standard practice.

Accompanied by 14 practical examples, the guidelines outline alternative corrective powers, including warnings, reprimands, orders, bans, and certificate revocations. 

The EDPB has launched a public consultation on the draft guidelines. The consultation closes on 13 November 2026.

Separately, the EDPB has adopted the final version of its guidelines on the relationship between the Digital Services Act (DSA) and the GDPR. The guidelines aim to ensure that both legal acts are applied consistently, especially in areas where DSA provisions address the processing of personal data by intermediary service providers and reference concepts and definitions established in the GDPR.


Training Announcement: Freevacy offers a range of independent data protection qualifications from IAPP and BCS. Our certified courses are available at foundation and practitioner levels and cover multiple legal jurisdictions, data protection operations management, and the implementation of complex privacy solutions in technical environments. Find out more.

Read Full Story
EU flag, euros, financial penalty, fine, enforcement

What is this page?

You are reading a summary article on the Privacy Newsfeed, a free resource for DPOs and other professionals with privacy or data protection responsibilities helping them stay informed of industry news all in one place. The information here is a brief snippet relating to a single piece of original content or several articles about a common topic or thread. The main contributor is listed in the top left-hand corner, just beneath the article title.

The Privacy Newsfeed monitors over 300 global publications, of which more than 3,250 summary articles have been posted to the online archive dating back to the beginning of 2020. A weekly roundup is available by email every Friday.