[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fh3WPEv1mcMt30YM63tCwzNgH8oKqNjiMPBFM347kc-M":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":26,"category":27,"article_tags":30},"89b9e908-ced4-43a9-be06-eb89673a2eb7","EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines","edpb-harmonises-fining-methodology-and-adopts-final-dsa-gdpr-guidelines-979e8c","EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines ikerinar Mon, 21\u002F09\u002F2026 - 11:42","The European Data Protection Board (EDPB) has adopted new guidelines to harmonize the application of administrative fines under the GDPR, establishing a five-step methodology for Data Protection Authorities (DPAs). Additionally, the EDPB finalized guidelines on the interplay between the Digital Services Act (DSA) and the GDPR, aiming for consistent application of both regulations, particularly concerning personal data processing by intermediary service providers. These guidelines will be open for public consultation.","EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines.","EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines EDPB News 21 September 2026 Brussels, 21 September – During its latest plenary, the EDPB has adopted guidelines on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR and the final version of its guidelines on the interplay between the Digital Services Act (DSA) and the GDPR.The new EDPB guidelines are a major step in further aligning how Data Protection Authorities decide whether an administrative fine should be imposed, either on its own or alongside other corrective measures.The GDPR significantly increased the corrective powers of DPAs, with fines serving as an important instrument for effective enforcement. The guidelines reaffirm our commitment to providing greater clarity and ensuring the consistent application of the GDPR across Europe.EDPB Deputy Chair, Jelena Virant BurnikData Protection Authorities (DPAs) should follow a five-step methodology when deciding whether to impose an administrative fine:the DPA checks if the infringement can lead to a fine, by finding support either directly in the GDPR or in national law.the DPA determines whether the party under investigation may be fined for the infringement in question. Whether the controller or the processor is liable depends on who is bound by the breached provision.the DPA assesses whether the infringement has been committed intentionally or negligently, since a culpable infringement is a condition for the imposition of a fine.the DPA assesses possible aggravating and mitigating factors. If the infringement is minor, there will generally be no fine and a reprimand may be issued instead; if it is not minor, there is a strong presumption that a fine should be imposed.the DPA assesses whether imposing an administrative fine would be effective, proportionate and dissuasive. In doing so, the DPA may consider whether, in the specific case, there is a reason to deviate from the standard approach.The guidelines also provide an overview of the corrective powers within the remit of national DPAs and explain their purpose, scope, and how they relate to one another. Corrective measures include warnings, reprimands, orders, limitations (including bans), and the withdrawal of certification.The Board also provides 14 practical examples illustrating how DPAs can assess the specifics of a case and decide which corrective measures should be imposed, if any.The guidelines will be subject to public consultation until 13 November 2026, providing stakeholders with the opportunity to comment and give feedback.Guidelines on DSA and GDPR finalised after public consultationAfter public consultation, the EDPB adopted the final version of its guidelines on the interplay between the DSA and the GDPR. The guidelines support the consistent application of both legal acts, particularly where DSA provisions concern the processing of personal data by intermediary service providers and refer to concepts and definitions laid down in the GDPR.Note to editors:* These Guidelines replace the WP29 guidelines on the application and setting of administrative fines for the purposes of the Regulation 2016\u002F679 and complement the previously adopted guidelines on the calculation of administrative fines under the GDPR, which rather focus on the methodology for calculating the amount of an administrative fine.** The guidelines on the interplay between the DSA and the GDPR will now undergo linguistic checks before publication. The document will be published soon on this page. Relevant topics Cross-regulatory cooperation GDPR enforcement Fines Latest news RSS Feed National News fr Failure to respect the rights of individuals: The CNIL fined EXTIA 300 000 EUR11 September 2026 National News fr Health data breach: the CNIL fined Hôpital Privé de la Loire 500 000 EUR09 September 2026 National News ie Data Protection Commission announces Final Decision following Inquiry into the Health Service Executive (HSE)03 September 2026All news","https:\u002F\u002Fwww.edpb.europa.eu\u002Fnews\u002Fedpb-harmonises-fining-methodology-and-adopts-final-dsa-gdpr-guidelines_en",null,"2026-09-21T09:42:05+00:00","2026-09-21T12:00:23.01496+00:00",7,[18,21,23],{"name":19,"type":20},"GDPR","product",{"name":22,"type":20},"DSA",{"name":24,"type":25},"EDPB","vendor","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":26,"icon":13,"name":28,"slug":29},"Policy","policy",[31,36,40,45],{"category":32},{"id":33,"icon":13,"name":34,"slug":35},"233dac9c-6b5b-4d83-9d6b-902ec3ffd7f2","DSA\u002FDMA","dsa-dma",{"category":37},{"id":38,"icon":13,"name":19,"slug":39},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","gdpr",{"category":41},{"id":42,"icon":13,"name":43,"slug":44},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":46},{"id":26,"icon":13,"name":28,"slug":29},[]]