What happened
The European Data Protection Board adopted guidelines on how data protection authorities should decide whether to impose an administrative fine under the GDPR, together with the final version of its guidelines on the interplay between the Digital Services Act and the GDPR. The board announced both after its plenary on September 21.
The fining guidelines give regulators a five-step method. First, the authority checks whether the infringement can lead to a fine at all, on the basis of the GDPR or national law. Second, it decides who can be fined, since liability turns on whether the controller or the processor is bound by the provision that was breached. Third, it assesses whether the infringement was intentional or negligent, because a culpable infringement is a precondition for a fine. Fourth, it weighs aggravating and mitigating factors. A minor infringement will generally draw a reprimand rather than a penalty, while a non-minor one carries a strong presumption that a fine should follow. Fifth, it tests whether a fine would be effective, proportionate and dissuasive, and whether the case justifies departing from the standard approach.
The document also maps the corrective powers open to national authorities, including warnings, reprimands, orders, limitations such as bans, and the withdrawal of certification. It works through 14 practical examples of how those choices are made. It replaces the older WP29 guidance on applying and setting fines, and sits alongside the board's 2022 guidelines on how fine amounts are calculated. Consultation on the new text runs until November 13, 2026.
Why this is a GRC story
Consistency is the point. The board frames the guidance as a step toward aligned enforcement across member states, which has been the recurring criticism of GDPR enforcement. A shared method does not cap or equalise penalty amounts, but it narrows the room for unpredictable decisions on whether a fine is imposed in the first place.
The controllership question is now explicit. Step two puts the controller and processor distinction in front of compliance teams. If a processor breaches a provision that binds you, the exposure can still be yours. That is the same logic your vendor contracts are supposed to reflect, and it is worth checking whether they actually do.
Remediation evidence is a decision input. With reprimand written in as a real outcome rather than an informal deal, the record you keep about how fast and how thoroughly a problem was fixed carries weight in the decision, not just the severity of the incident.
What to watch
Watch the consultation responses before November 13 and whether authorities actually reason through the steps in published decisions, since a method only matters if it shows up in the reasoning. Watch too whether the finalised DSA and GDPR guidance changes how regulators treat intermediary platforms that process personal data.
The practical takeaway: treat the five steps as a checklist your own file should answer before a regulator asks. Who is bound by the provision, was the failure culpable, what did you do about it, and can you show the remediation was more than a memo.
Attribution: Analysis based on European Data Protection Board and related public reporting. This article is original commentary, not a repost of the source material.
