IDPC Logo
  • Home
  • Our Office
  • For Individuals
  • For Organisations
  • Artificial Intelligence
c

EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines

EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines

 

22 September 2026

During its latest plenary, the EDPB has adopted guidelines on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR and the final version of its guidelines on the interplay between the Digital Services Act (DSA) and the GDPR.

"The new EDPB guidelines are a major step in further aligning how Data Protection Authorities decide whether an administrative fine should be imposed, either on its own or alongside other corrective measures. The GDPR significantly increased the corrective powers of DPAs, with fines serving as an important instrument for effective enforcement. The guidelines reaffirm our commitment to providing greater clarity and ensuring the consistent application of the GDPR across Europe," said EDPB Deputy Chair, Jelena Virant Burnik

Data Protection Authorities (DPAs) should follow a five-step methodology when deciding whether to impose an administrative fine:

  1. the DPA checks if the infringement can lead to a fine, by finding support either directly in the GDPR or in national law.
  2. the DPA determines whether the party under investigation may be fined for the infringement in question. Whether the controller or the processor is liable depends on who is bound by the breached provision.
  3. the DPA assesses whether the infringement has been committed intentionally or negligently, since a culpable infringement is a condition for the imposition of a fine.
  4. the DPA assesses possible aggravating and mitigating factors. If the infringement is minor, there will generally be no fine and a reprimand may be issued instead; if it is not minor, there is a strong presumption that a fine should be imposed.
  5. the DPA assesses whether imposing an administrative fine would be effective, proportionate and dissuasive. In doing so, the DPA may consider whether, in the specific case, there is a reason to deviate from the standard approach.

The guidelines also provide an overview of the corrective powers within the remit of national DPAs and explain their purpose, scope, and how they relate to one another. Corrective measures include warnings, reprimands, orders, limitations (including bans), and the withdrawal of certification.

The Board also provides 14 practical examples illustrating how DPAs can assess the specifics of a case and decide which corrective measures should be imposed, if any.

The guidelines will be subject to public consultation until 13 November 2026, providing stakeholders with the opportunity to comment and give feedback.

Read more here

 

Our Office
  • Annual Reports
  • Careers
  • Organigram
  • Contact us
Actions
  • Notify a Personal Data Breach
  • File a Complaint
  • File an FOI Application
For Individuals
  • CCTV Guidelines
  • Your Rights
  • Conditions for Valid Consent
For Organisations
  • Legislation
  • Lawfulness of processing
  • Data Protection Principles

© | Office of the Information and Data Protection Commissioner 2026

  • Data Protection Notice
  • Cookies Policy
  • Accessibility Statement
  • Copyright
  • Disclaimer
  • IDPC Newsletter subscription
Powered By9H Digital

IDPC Newsletter

Stay up to date and get the latest from the IDPC, including a newsletter.

Subscribe today to our newsletter here