Don’t do SECURITY. Do business SECURELY.
Threat intel

EDPB adopts new guidelines on calculating GDPR fines

The EDPB has adopted Guidelines 04/2026 on administrative fines, replacing the 2017 guidelines, and finalised its DSA–GDPR guidelines.

At its September plenary, the European Data Protection Board (EDPB) adopted Guidelines 04/2026 on the use of administrative fines alongside other corrective powers under the GDPR, and the final version of its Guidelines 03/2025 on the interplay between the Digital Services Act and the GDPR.

Key points

  • The fines guidelines set out a five-step method for supervisory authorities, with 14 worked examples.
  • They replace the 2017 Article 29 Working Party guidelines on administrative fines.
  • The fines guidelines are open for public consultation until 13 November 2026.
  • The DSA–GDPR guidelines explain how online platforms should meet both regimes when processing personal data.

Organisations subject to the EU GDPR should note how aggravating and mitigating factors, including co-operation and the measures in place before an infringement, can affect the level of a fine.

Source: EDPB press release

This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe

More insights