At its September plenary, the European Data Protection Board (EDPB) adopted Guidelines 04/2026 on the use of administrative fines alongside other corrective powers under the GDPR, and the final version of its Guidelines 03/2025 on the interplay between the Digital Services Act and the GDPR.
Key points
- The fines guidelines set out a five-step method for supervisory authorities, with 14 worked examples.
- They replace the 2017 Article 29 Working Party guidelines on administrative fines.
- The fines guidelines are open for public consultation until 13 November 2026.
- The DSA–GDPR guidelines explain how online platforms should meet both regimes when processing personal data.
Organisations subject to the EU GDPR should note how aggravating and mitigating factors, including co-operation and the measures in place before an infringement, can affect the level of a fine.
Source: EDPB press release
This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.