EU Data Watchdog Finalizes DSA-GDPR Fining Rules for Global Tech Platforms
The European Data Protection Board has adopted a strict five-step methodology that standardizes how national regulators issue fines for GDPR violations.
By Sergei Orlov
- European Regulators
- Harmonized rules are necessary to prevent forum-shopping and ensure consistent privacy enforcement across the bloc.
- Corporate Compliance Teams
- The strict presumption of fines for non-minor breaches reduces flexibility and increases financial risk for technology platforms.
- Industry Analysts
- The practical impact depends entirely on how strictly national authorities interpret subjective terms like 'negligence'.
Perspectives this story doesn't cover
- Small and Medium Enterprises (SMEs)
Why this matters
By replacing ad-hoc regulatory discretion with a rigid five-step test, the new guidelines dictate exactly how and when technology companies will face financial penalties for privacy violations in Europe. The framework removes leniency for non-minor breaches, fundamentally altering the risk calculus for global platforms operating in the bloc.
Key points
- The EDPB adopted Guidelines 04/2026 to standardize how national authorities issue GDPR fines.
- Regulators must now follow a strict five-step methodology before imposing financial penalties.
- Non-minor infringements now carry an explicit presumption that a fine will be levied.
- The board also finalized guidance clarifying the interplay between the GDPR and the Digital Services Act.
The outcome of a European privacy investigation is now determined at the fourth step of a newly mandated regulatory test: the classification of an infringement as either minor or non-minor. Once a national authority decides a breach crosses that threshold, the European Data Protection Board (EDPB) has established a "strong presumption" that a financial penalty must follow. This structural shift, adopted by the EDPB on September 21, removes the ad-hoc discretion that previously allowed some regulators to issue warnings for severe violations, replacing it with a standardized enforcement pipeline across the bloc.[1][2]
The new framework, designated Guidelines 04/2026, harmonizes how the 27 national data protection authorities (DPAs) apply their corrective powers under the General Data Protection Regulation (GDPR). "The new EDPB guidelines are a major step in further aligning how Data Protection Authorities decide whether an administrative fine should be imposed, either on its own or alongside other corrective measures," stated EDPB Deputy Chair Jelena Virant Burnik. While the EDPB previously published rules on calculating the mathematical size of a fine in 2022, this new directive dictates whether a fine should be levied in the first place. It replaces seven-year-old guidance from the Article 29 Working Party, establishing a uniform protocol that every European regulator must now follow.[1][4]
The methodology forces regulators through a rigid sequence before they can levy a fine or issue a ban. Steps one and two establish the legal basis for the penalty and identify whether the data controller or the processor is the liable party. This distinction is critical for cloud providers and enterprise software vendors, who frequently process data on behalf of clients and rely on clear liability boundaries.[1][2][4]
Step three introduces a strict culpability requirement, demanding proof that the infringement was committed intentionally or negligently. The EDPB treats this culpability as an unwritten condition deduced from the GDPR's text, meaning strict liability—where a company is fined simply because a breach occurred, regardless of fault—is not the standard.[1][4]
Step four weighs aggravating and mitigating factors to classify the severity of the incident. For compliance teams at global technology platforms, this is where the guidelines clarify the boundary between a reprimand and a financial penalty. Minor infractions will generally draw warnings or orders to change processing behavior, while non-minor breaches trigger the explicit presumption of a fine.[2][4]
Step four weighs aggravating and mitigating factors to classify the severity of the incident.
The fifth and final step evaluates whether the resulting fine would be "effective, proportionate and dissuasive." The EDPB included 14 worked examples in the text to demonstrate how authorities should weigh factors like self-reporting, the number of affected users, and the sensitivity of the data. These examples serve as a practical playbook for enforcement-risk teams preparing for future regulatory scrutiny.[1][5]
Alongside the fining methodology, the EDPB finalized its guidance on the interplay between the GDPR and the Digital Services Act (DSA). As the DSA imposes new content moderation, targeted advertising, and transparency mandates on large online platforms, the dual frameworks frequently overlap. The finalized guidelines clarify how intermediary service providers must handle personal data when complying with DSA obligations.[1][4]
The goal of the DSA-GDPR guidance is to ensure that adherence to one regulation does not inadvertently trigger a violation of the other. For instance, when a platform retains user data to comply with DSA transparency reporting, it must still satisfy GDPR principles of data minimization and purpose limitation. The finalized text will undergo linguistic checks before official publication.[1][3]
Despite the definitive language of the fining methodology, the rules are not yet fully binding. The EDPB has opened the text for public consultation until November 13, 2026, allowing industry stakeholders and privacy advocates to submit feedback. No new substantive obligations take effect immediately, but the methodology will shape every DPA enforcement decision across the EU once finalized.[2][3]
The practical impact of this harmonization will depend on how strictly national authorities interpret the culpability and severity thresholds. While the EDPB markets the guidelines as a definitive end to fragmented enforcement—where the same violation drew a massive fine in one jurisdiction and a quiet warning in another—the subjective nature of determining "negligence" leaves a wide margin of interpretation. The true uniformity of European privacy enforcement will only be measurable once national regulators begin issuing decisions under the finalized framework.[2][4]
Viewpoints in depth
European Regulators' View
Harmonized rules are necessary to prevent forum-shopping by tech giants.
For the EDPB and national authorities, the primary goal is eliminating the inconsistencies that have plagued GDPR enforcement since 2018. When 27 different regulators apply 27 different standards for what constitutes a fineable offense, multinational companies can exploit the fragmentation by establishing headquarters in more lenient jurisdictions. By mandating a rigid five-step test, regulators aim to ensure that a data breach in Dublin carries the exact same regulatory risk as an identical breach in Berlin, reinforcing the credibility of the bloc's privacy regime.
Corporate Compliance Teams' View
The strict presumption of fines for non-minor breaches reduces flexibility and increases financial risk.
Legal counsel and compliance officers at major technology platforms view the new methodology with cautious skepticism. While the 14 worked examples provide welcome predictability, the explicit directive that non-minor infringements carry a 'strong presumption' of a fine removes the leniency that companies previously relied upon when self-reporting accidental breaches. Industry groups argue that if regulators are forced to issue fines rather than reprimands for complex but unintentional violations, companies may become less transparent and more adversarial during investigations.
Sources
[1]European Data Protection BoardEuropean RegulatorsEDPB harmonises fining methodology and adopts final DSA-GDPR guidelines
Read on European Data Protection Board →
[2]Bird & BirdCorporate Compliance TeamsEU: EDPB Harmonises GDPR Fining Powers, Finalises DSA-GDPR Guidance
Read on Bird & Bird →
[3]Pinsent MasonsCorporate Compliance TeamsEuropean Data Protection Board consults on new GDPR fining framework
Read on Pinsent Masons →
[4]GRC ReportIndustry AnalystsEDPB Sets Five-Step Method for GDPR Fines & Finalizes DSA Privacy Guidelines
Read on GRC Report →
[5]Ísland.isEuropean RegulatorsEDPB harmonises fining methodology and adopts guidelines on the DSA and GDPR
Read on Ísland.is →
Comments
More in Technology
See all →Data Center Efficiency
The Ratio That Defines the Internet's Energy Footprint: How Power Usage Effectiveness (PUE) Works
5 sources
Cloud Infrastructure
Evidence Pack: Does 'Confidential Computing' Actually Secure the Cloud?
4 sources
DMDC Breach
Pentagon Data Breach Exposes Social Security Numbers of 4 Million Military Personnel
3 sources
Robotics Kinematics
The Four Degrees of Freedom and Three Types of Joints That Define a SCARA Robot Arm
7 sources
Every angle. Every day.
Get Technology stories with full source coverage and perspective breakdowns delivered to your inbox.




