GDPR and DSA: EDPB Clarifies Fines and Regulation Interaction

The European Data Protection Board has published guidelines on administrative fines and the interplay between GDPR and the Digital Services Act.

Close-up of a gavel resting on a stack of legal documents, with blurred digital circuit board patterns in the background. Soft, professional lighting.
AI

Close-up of a gavel resting on a stack of legal documents, with blurred digital circuit board patterns in the background. Soft, professional lighting.

On September 17, 2026, the European Data Protection Board (EDPB) adopted new guidelines on administrative fines and the interaction between the GDPR and the Digital Services Act (DSA).

During its plenary session on September 17, 2026, the EDPB adopted guidelines on the power of Data Protection Authorities (DPAs) to impose administrative fines. These guidelines outline a five-step process for deciding on fines: verifying if an infringement is finable, determining the entity's liability, assessing intent or negligence, considering aggravating and mitigating circumstances, and finally, evaluating the fine's effectiveness, proportionality, and dissuasiveness.
These guidelines, which also provide an overview of possible corrective measures (warnings, reprimands, injunctions, processing limitations, certification withdrawal) and 14 practical examples, will be open for public consultation until November 13, 2026. Stakeholders are invited to submit their feedback.
Furthermore, the EDPB has finalized the guidelines on the interplay between the Digital Services Act (DSA) and the GDPR. The aim is to ensure consistent application of both regulations, particularly when the DSA pertains to the processing of personal data by intermediary service providers, referencing GDPR concepts.
Based on information from the official source: CNIL (23/09/2026)