What Changed
- The EDPB established a five-step methodology for DPAs assessing whether and how to impose GDPR administrative fines.
- The EDPB published 14 practical examples for DPA corrective measures and launched a public consultation on the fine guidelines until November 13, 2026.
- The EDPB finalized guidelines on the interplay between the Digital Services Act and GDPR for intermediary service providers.
On September 17, 2026, the European Data Protection Board (EDPB) adopted new regulatory guidance concerning data protection authorities' (DPAs) power to impose administrative fines under the General Data Protection Regulation (GDPR), alongside the final version of its guidelines on the interaction between the Digital Services Act (DSA) and the GDPR.
The draft guidelines on administrative fines establish a harmonized five-step methodology for DPAs across the European Union:
1. Verification of Legal Basis: DPAs check whether the infringement can give rise to a fine based directly on the GDPR or national legislation (such as France's Data Protection Act / loi Informatique et Libertés).
2. Entity Liability: DPAs determine whether the investigated controller or processor is liable for the specific provision violated.
3. Intentionality or Negligence: DPAs assess whether the infringement was committed intentionally or negligently, as fault is a prerequisite for imposing a fine.
4. Aggravating and Mitigating Circumstances: DPAs evaluate case circumstances. Minor breaches generally result in a reprimand rather than a fine, whereas non-minor breaches carry a strong presumption that a fine will be imposed.
5. Effectiveness, Proportionality, and Dissuasiveness: DPAs verify whether imposing a fine meets these criteria and whether grounds exist to deviate from the standard approach.
The guidance also details corrective measures within DPAs' enforcement powers—including warnings, reprimands, compliance orders, processing limitations or prohibitions, and certification revocations—and provides 14 practical examples. Stakeholders can submit feedback on these fine guidelines during a public consultation open through November 13, 2026.
Concurrently, the EDPB adopted the final version of its guidelines on the interaction between the DSA and the GDPR following public consultation. These guidelines aim to foster consistent application across both regulations, particularly where DSA provisions govern personal data processing by intermediary service providers (such as internet service providers and hosting platforms) and reference GDPR concepts and definitions.
This regulatory update directly affects data controllers, processors, and intermediary service providers operating within the EU or offering services to EU users by enhancing predictability in administrative enforcement and cross-regulatory compliance.
Who May Be Affected
Data controllers, processors, and intermediary service providers (including ISPs and hosting providers) subject to EU data protection and digital service regulations.
Cross-Border Context
Applies across the European Union and impacts foreign and multinational entities processing personal data of EU residents or providing intermediary services under the DSA.
What to check next
- Review the draft guidelines on administrative fines and submit comments before the November 13, 2026 public consultation deadline.
- Examine the 14 practical examples published by the EDPB regarding DPA corrective measures.
- Assess operational compliance under the finalized EDPB guidance on DSA and GDPR interaction.
This article provides general information and does not constitute legal advice. Consult the official text and obtain advice appropriate to your circumstances where needed.