Some of the biggest concerns around GDPR enforcement have centred on the size of fines imposed on major technology companies. But the EDPB’s latest guidelines are not about changing the calculation of those fines.
The EDPB already has separate guidance, adopted in 2023, on how to calculate the amount of a GDPR fine. The new guidelines address an earlier stage of the process: how Data Protection Authorities (DPAs) should decide whether a fine is appropriate in the first place, and how a fine should relate to other corrective measures such as warnings, reprimands and processing restrictions.
That distinction could prove important. One of the most significant points in the new guidance is the EDPB’s emphasis on culpability. Its five-step methodology says that a fine requires an infringement to have been committed intentionally or negligently. This means that where a business has made a mistake but can demonstrate that it had appropriate controls and acted responsibly, the circumstances surrounding that mistake should form part of the regulator’s assessment.
The guidelines have the potential to change the way some GDPR enforcement cases are approached. Rather than treating an infringement as automatically leading to a fine, DPAs are expected to consider the organisation’s responsibility, culpability, mitigating circumstances and the seriousness of the infringement before deciding whether a financial penalty is warranted.
A five-step approach to GDPR fines
On 21 September 2026, the EDPB adopted guidelines on the application of administrative fines alongside other corrective powers under GDPR. The guidelines replace the previous guidance on when fines should be imposed and complement the EDPB’s existing guidance on calculating the amount of a fine.
The new guidelines are currently open for public consultation until 13 November 2026.
The methodology requires regulators to work through five stages.
First, they must establish that the particular infringement is capable of attracting a fine under GDPR or applicable national law. They must then determine whether the organisation being investigated can be held responsible for the infringement.
The third stage is especially significant. The EDPB says that a culpable infringement is a condition for imposing an administrative fine. Regulators must therefore consider whether the infringement was committed intentionally or negligently.
That does not mean accidental breaches are automatically protected from fines. Negligence can still amount to culpable conduct. But it does indicate the importance of how a business manages its data protection obligations before and after something goes wrong.
The fourth stage involves considering aggravating and mitigating factors. The EDPB says that where an infringement is minor, there will generally be no fine and a reprimand may instead be appropriate. Where the infringement is not minor, there is a strong presumption that a fine should be imposed.
Finally, the regulator must consider whether a fine would be effective, proportionate and dissuasive. The EDPB has included 14 practical examples to illustrate how these decisions might work in practice.
The result is not a simple formula for avoiding fines. Instead, it provides a more structured framework for regulators to assess the circumstances of each case.
Why ordinary businesses should care
For most businesses, the headline maximum penalties are not the most useful way to think about this development. The GDPR allows fines of up to €20 million or 4% of worldwide annual turnover for the most serious infringements, but these are statutory ceilings, not automatic penalties.
The more immediate issue is whether a business can demonstrate that it took its data protection responsibilities seriously.
Take two businesses experiencing a similar data breach. One identifies the risk, puts appropriate controls in place, trains its staff and responds quickly when the problem is discovered. The other identified the same risk but failed to implement the necessary controls and could not show who was responsible for managing it.
The incidents are similar, but the regulatory circumstances are not.
This is where documentation becomes important. Training records, risk assessments, security reviews, data protection impact assessments and records of remedial action can provide evidence of how an organisation approached its obligations. They do not guarantee that a fine will be avoided, but they can be relevant when a regulator considers culpability and mitigating factors.
The processor problem
The EDPB’s approach also puts the relationship between controllers and processors under scrutiny.
Most businesses rely on third parties to handle personal data, whether that means payroll providers, HR platforms, cloud services, CRM systems, marketing providers or IT suppliers. A data processing agreement is important, but it does not remove the need to understand what those suppliers actually do with the data.
The new guidance indicates that controllers remain responsible for infringements relating to obligations that apply to them, while processors may become responsible where they move beyond the controller’s instructions or process data for their own purposes.
This is an area where the EU and UK approaches could develop differently. Data protection expert Malcolm Dowden of Pinsent Masons has noted that the EDPB’s approach may indicate continued emphasis on controllers, whereas the UK Information Commissioner’s Office has demonstrated a willingness to take enforcement action directly against processors for data security failures.
Businesses operating across both jurisdictions should not assume that their UK and EU exposure will be identical.
The fine is not the only risk
Another important feature of the new guidance is its focus on the relationship between fines and other corrective measures.
A regulator does not have to choose between doing nothing and imposing a large financial penalty. It can issue a warning or reprimand, require an organisation to take particular action, restrict processing or, in some circumstances, prohibit it.
For an ordinary business, being ordered to stop or substantially change a processing activity could be more disruptive than the fine itself.
That makes operational resilience part of data protection compliance. Businesses should understand which processing activities are essential to their operations and whether they could respond if a regulator required significant changes to those activities.
Where does the DSA fit in?
Alongside the fining guidance, the EDPB has also adopted the final version of its guidelines on the interplay between the Digital Services Act (DSA) and the GDPR.
These guidelines are particularly relevant to intermediary service providers and businesses within the scope of the DSA. They clarify how the two regimes interact where DSA requirements involve personal data processing and rely on concepts defined by the GDPR.
For a typical employer, retailer or professional services firm, this is unlikely to create an immediate new obligation. But it reflects a wider trend in European regulation that data protection increasingly overlaps with other digital regulation, particularly around online platforms, advertising, AI and automated processing.
What businesses should think about now
The new EDPB guidance is still subject to consultation, so it may change before it is finalised. But businesses do not need to wait before reviewing their own approach.
Look at your company’s existing GDPR programme through the lens of the EDPB’s five stages. If something went wrong, could the business demonstrate who was responsible, what controls were in place, what risks had been identified and how the organisation responded?
This is particularly important for higher-risk processing, including employee monitoring, profiling, large-scale personal data processing, international transfers and the use of AI tools. It is also worth revisiting key processor relationships to ensure that contractual arrangements accurately reflect what suppliers are actually doing with personal data.
A data breach or other GDPR infringement does not automatically equal a fine, but neither does having a privacy policy demonstrate compliance. As European regulators move towards a more consistent approach to fines, businesses should be thinking not only about whether they are compliant, but about whether they can demonstrate responsible compliance when something goes wrong.
Don't miss our webinar, Data protection now: Managing AI, cyber security and GDPR risks
Register here →