On September 21, 2026, the European Data Protection Board (EDPB) adopted Guidelines 04/2026 harmonising how the 27 national data protection authorities (DPAs) decide whether to impose an administrative fine under Article 83 GDPR, alongside other corrective powers. At the same plenary, the Board finalised its guidelines on the interplay between the Digital Services Act (DSA) and the GDPR after a prior public consultation.

The fining guidelines replace the seven-year-old Article 29 Working Party guidance on administrative fines and complement the EDPB's 2022 methodology for calculating the amount of a fine. They set out a single five-step test every DPA must follow, map the full catalogue of corrective measures, and include 14 worked examples. The text is open for public consultation until November 13, 2026.

How must a DPA now decide whether to impose an administrative fine?

Every DPA must work through a fixed five-step methodology before deciding whether a fine is warranted, instead of exercising discretion case by case. The test moves from legal eligibility to the choice of sanction:

StepWhat the DPA must determine
1Whether the infringement can lead to a fine at all, by finding support in the GDPR or in national law.
2Whether the controller or processor under investigation may be fined for that infringement, depending on who is bound by the breached provision.
3Whether the infringement was intentional or negligent, since culpability is a condition for any fine.
4Aggravating and mitigating factors: a minor infringement generally draws no fine (a reprimand instead), while a non-minor one carries a strong presumption that a fine should follow.
5Whether a fine would be effective, proportionate and dissuasive, including any reason to deviate from the standard approach.

The methodology governs the decision to fine, not the arithmetic. The amount itself remains governed by the EDPB's 2022 calculation guidelines, which these new guidelines complement rather than replace.

Which corrective powers sit alongside fines, and when does each apply?

The guidelines lay out the full range of corrective measures a DPA can deploy: warnings, reprimands, orders, limitations (including bans), and withdrawal of certification. The five-step test decides whether a fine is added on top of, or used instead of, one of these measures. The 14 worked examples show how a DPA weighs case specifics, such as intent, the number of data subjects affected, and whether the controller self-reported, to pick the proportionate combination.

For enforcement-risk teams, the practical point is that a non-minor infringement now carries a stated presumption that a fine will follow. Reprimands are reserved for minor infringements, and a DPA must justify any departure from the standard approach in writing.

What should compliance teams do before the 13 November 2026 consultation deadline?

Stakeholders have until November 13, 2026 to submit comments on the fining guidelines through the EDPB consultation page. Privacy counsel and DPOs should review the 14 examples against their own breach-response playbooks, because the examples signal how DPAs will likely weigh intent, mitigation, and cooperation once the guidelines are final. No new substantive obligation takes effect on adoption, but the methodology will shape every DPA enforcement decision across the EU once finalised.

What does the finalised DSA-GDPR guidance change for intermediary service providers?

The Board also adopted the final version of its DSA-GDPR interplay guidelines, which clarify how the two acts apply together where the DSA touches the processing of personal data by intermediary service providers and refers to GDPR concepts and definitions. The final text undergoes linguistic checks before publication, so it is not yet live, but it confirms the consistent application both acts require. Compliance teams at online platforms should align their data-protection and DSA procedures now rather than wait for the published version.

Continuous, per-jurisdiction regulatory monitoring surfaces guidance like this the moment an apex supervisor such as the EDPB publishes it, before national DPAs operationalise the new methodology.

Subscribe to the free newsletter

Digital Omnibus data reform triloguesLive
Monitor the EU Digital Omnibus data strand for the AI, data and digital governance industry.
Email report 6 news
You will receive an email report each time something new happens on this topic. Free, no account required.
Subscribe to the newsletter

Next steps: confirm whether your processing falls within the DSA-GDPR interplay scope, map your incident-response procedure against the five-step fining test and the 14 examples, and brief your privacy and platform teams ahead of the November 13, 2026 consultation deadline. Obsidian will track the final adoption and each national DPA's uptake of the methodology as it lands.