[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fT33ELnlu-1NJ-k0d8uFrKCmCdWQLxBUc7KZ_IphGJvM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":42},"645a21ea-81f4-48a0-b0bd-d64db41e8fac","edpb-issues-new-gdpr-fine-guidelines-and-dsa-gdpr-interaction-rules","124a0804-a7e6-44a6-b016-a4c17e0d32f3","EDPB Issues New GDPR Fine Guidelines and DSA-GDPR Interaction Rules","The European Data Protection Board has formalized a five-step methodology for Data Protection Authorities to calculate and impose administrative fines under the GDPR, incorporating intent, negligence, and aggravating or mitigating factors. This matters because organizations operating across the EU must now anticipate a more structured and consistent enforcement approach, leaving less room for ambiguity when regulators assess violations. The additional guidelines clarifying the interaction between the Digital Services Act and the GDPR place increased compliance burdens on intermediary service providers who process personal data. Failure to align internal data governance practices with both regulatory frameworks simultaneously could result in compounding penalties from multiple supervisory authorities. Companies that treat compliance as a checkbox exercise rather than an ongoing program are most at risk under this tightened enforcement landscape.","**Immediate actions:**\n- Conduct a dual-compliance gap assessment mapping your current data processing activities against both GDPR and DSA requirements.\n- Review your organization's existing data protection impact assessments (DPIAs) to ensure they account for intermediary service obligations under the DSA.\n\n**Long-term improvements:**\n- Establish a cross-functional compliance committee responsible for monitoring evolving EDPB guidelines and translating them into internal policy updates.\n- Implement a documented accountability framework that records intent, decision rationale, and mitigating actions to demonstrate good faith in the event of a DPA investigation.\n- Integrate DSA-specific obligations (e.g., content moderation, transparency reporting) into your broader privacy-by-design and data governance program.\n\n**Detection & Response measures:**\n- Set up regulatory monitoring alerts for EDPB publications, national DPA guidance, and DSA enforcement notices to ensure timely awareness of new requirements.\n- Define escalation procedures and assign clear ownership for responding to DPA inquiries or formal investigations within documented SLA timelines.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 83 (Administrative fines)","GDPR Article 58 (Powers of supervisory authorities)","GDPR Article 35 (Data Protection Impact Assessment)","Digital Services Act (DSA) – Regulation (EU) 2022\u002F2065","EDPB Guidelines on calculation of administrative fines","NIST Privacy Framework PR.PO (Policies, Processes, and Procedures)","NIST SP 800-53 PT-1 (Privacy Policies and Procedures)","ISO\u002FIEC 27701:2019 (Privacy Information Management)","CIS Control 18 (Penetration Testing \u002F Compliance Validation)","ITIL – Compliance Management Practice","published","2026-09-23T19:21:32.167419+00:00","2026-09-23T19:21:31.878+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fwww.cnil.fr\u002Ffr\u002Fpleniere-cepd-amendes-reglement-services-numeriques","amendes-rgpd-et-interaction-avec-le-reglement-sur-les-services-numeriques-retour-9ee9f2","Amendes RGPD et interaction avec le règlement sur les services numériques : retour sur la plénière du CEPD du 17 septembre 2026",[30,36],{"id":31,"name":32,"slug":33,"description":34,"color":35},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]