During its plenary session on September 17, 2026, the EDPB adopted guidelines on the power of Data Protection Authorities (DPAs) to impose administrative fines. These guidelines outline a five-step process for deciding on fines: verifying if an infringement is finable, determining the entity's liability, assessing intent or negligence, considering aggravating and mitigating circumstances, and finally, evaluating the fine's effectiveness, proportionality, and dissuasiveness.
These guidelines, which also provide an overview of possible corrective measures (warnings, reprimands, injunctions, processing limitations, certification withdrawal) and 14 practical examples, will be open for public consultation until November 13, 2026. Stakeholders are invited to submit their feedback.
Furthermore, the EDPB has finalized the guidelines on the interplay between the Digital Services Act (DSA) and the GDPR. The aim is to ensure consistent application of both regulations, particularly when the DSA pertains to the processing of personal data by intermediary service providers, referencing GDPR concepts.




