EDPB opens consultation on draft guidelines for deciding when to fine
EditorialBy TrustList Editorial
The EDPB published draft Guidelines 04/2026 on when regulators should fine under the GDPR, open for comment until 13 November 2026. Liability depends on who is bound by the breached rule, so buyers should check how DPAs split duties.
About EDPB opens consultation on draft guidelines for deciding when to fine
EDPB opens consultation on draft guidelines for deciding when to fine
22 September 2026 — The European Data Protection Board (EDPB) announced on 21 September 2026 that it has adopted Guidelines 04/2026, which set out how data protection authorities should decide whether to impose a fine under the GDPR, either alone or alongside other corrective powers. The text is version 1 and is open for public consultation until 13 November 2026 (23:59 CET). It is a draft for comment, not final guidance.
The EDPB's headline says it adopted "final" guidelines, but that word refers to a separate document: its guidelines on how the Digital Services Act and the GDPR interact, finalised after an earlier consultation. The fining guidelines are listed on the EDPB's consultations page as open for feedback, and the document page dates them 17 September 2026.
What changes
The draft gives authorities a five-step method:
- Check whether the infringement can lead to a fine under the GDPR or national law.
- Decide whether the party under investigation can be fined for it. The EDPB says whether the controller or the processor is liable depends on who is bound by the provision that was breached.
- Assess whether the infringement was intentional or negligent, since culpability is a condition for a fine.
- Weigh aggravating and mitigating factors. A minor infringement will generally lead to no fine, and a reprimand may be issued instead; otherwise there is a strong presumption that a fine should follow.
- Check that a fine would be effective, proportionate and dissuasive, and whether there is a reason to depart from the standard approach.
The draft also explains the other corrective powers (warnings, reprimands, orders, limitations including bans, and withdrawal of certification) and gives 14 worked examples. The EDPB says the guidelines replace the old Article 29 Working Party guidance on fines and complement its earlier guidelines on calculating fine amounts.
What to do
- Review your data processing agreements. Because liability turns on who is bound by the breached provision, check that each agreement says clearly which obligations sit with the supplier as processor and which stay with you as controller.
- Revisit liability and indemnity clauses that mention regulatory fines, so they reflect that a processor can be fined where the breached obligation is its own.
- Ask key suppliers how they document their own compliance as processors, since the draft makes intent or negligence an explicit step in the assessment.
- Comment if it affects you. Organisations and individuals can respond through the EDPB's consultation form by 13 November 2026. Responses are published on the EDPB website.
What the draft does not settle
The text may change after consultation, and the EDPB has not said when it will adopt a final version. The draft deals with whether to fine, not how much; the amount is covered by the EDPB's separate guidelines on calculating fines (04/2022).
Sources
- European Data Protection Board — EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines — 21 September 2026
- European Data Protection Board — Public consultation: Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR — 21 September 2026
- European Data Protection Board — Guidelines 04/2026 (document page) — 17 September 2026
- GRC Report — EDPB Sets Five-Step Method for GDPR Fines & Finalizes DSA Privacy Guidelines — 21 September 2026
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.