At a Glance
- The European Data Protection Board (EDPB) has introduced guidelines setting out a five-step methodology to determine whether to impose an administrative fine, either in conjunction with other corrective measures or as a stand-alone measure.
- The EDPB's aim is to provide clarity and a consistent application of the General Data Protection Regulation (GDPR) across EU Member States.
- The new Guidelines 04/2026 deal with the threshold question of whether a fine should be imposed. They replace the earlier Article 29 Working Party guidance (WP253) and sit alongside, rather than displace, the EDPB's Guidelines 04/2022 on calculating the amount of a fine.
- Any data controller or processor with European operations which are potentially subject to a fine will be affected.
The Five-Step Methodology
The proposed five-step methodology is as follows:
- Can the infringement lead to a fine based on GDPR and/or national law?
- Is the party under investigation liable for the infringement in question?
- Was the infringement committed intentionally or negligently? Following the Court of Justice of the European Union (CJEU) in Deutsche Wohnen (C-807/21), the EDPB treats intent or at least negligence as an unwritten precondition of any fine.
- Are there any mitigating or aggravating circumstances and, consequently, is this a minor infringement? Where the Article 83(2) factors point to a minor infringement, the general rule is that no fine will follow and the authority may opt for a reprimand. Where the factors do not, the EDPB expects a fine to be the default outcome.
- Would imposing an administrative fine be effective, proportionate, and dissuasive? Further, is there a reason to deviate from the standard approach?
A minor finding is not a safe harbour: the EDPB expressly preserves the authority's ability to fine in such cases, having regard to effectiveness, dissuasiveness, and proportionality. Equally, relying on the CJEU's ruling in Land Hessen (C-768/21), the new guidelines accept that an authority may take no corrective action at all — for example, where the controller promptly ended the infringement and prevented recurrence.
Conversely, a finding that an infringement is not minor does not oblige the authority to fine; it may combine or substitute other Article 58(2) measures. The new guidelines give two illustrations of a reprimand in place of a fine: where a fine would be disproportionately burdensome for the person concerned, whether an individual or a company, and where national law (as permitted by Article 83(7) of the GDPR) does not permit fines on public bodies.
Alongside the methodology, the guidance sets out 14 (purely hypothetical) practical examples illustrating how Data Protection Authorities (DPAs) could assess the specifics of a case, although the new guidelines expressly note that they should not be considered as precedents or indicators of how a supervisory authority may approach a particular case.
Differences from the Current Guidelines
The current Guidelines 04/2022 on the calculation of administrative fines under the GDPR harmonise the methodology that supervisory authorities use when calculating the amount of the fine, and complement previous guidelines on the circumstances in which fines should be imposed. Under the new guidelines, the DPAs should focus first on the relevance of imposing a fine, before assessing the amount of the fine. The new guidelines will add certainty to the investigation process and may encourage clearer reasoning to justify fining.
The new guidelines stress the importance of culpability (intent or negligence). Following the CJEU in Deutsche Wohnen, a fine can only be imposed if the infringement was at least negligent. In practice this will rarely help a defence. Negligence turns on whether the organisation should have known its conduct was unlawful. If an issue giving rise to a breach is covered by EDPB guidelines, an error will always be considered avoidable and therefore at least negligent. Minor infringements become a central point under the new guidelines in determining whether a fine should be imposed and they are described in the practical examples. The new guidelines also provide further guidance on the interaction between fines and other corrective powers, such as warnings, reprimands, orders, limitations, and bans. The minor-infringement assessment runs through each of the Article 83(2)(a)–(k) factors. Several are framed restrictively: ordinary cooperation with the authority, compliance with earlier orders, and a clean enforcement record carry no mitigating weight because they are already required; self-reporting on the organisation's own initiative, before the authority is aware, may count in mitigation; and the involvement of special category or other sensitive data makes a fine more likely.
On scale, the authority may weigh the number of affected individuals against the relevant population, such as a company's customer base or workforce, to judge whether a problem is systemic, and the harm suffered is assessed as a distinct factor so that a high headcount with limited harm is not treated as automatically serious.
Under the new guidelines, previous infringements established by different supervisory authorities may be considered if they concern the same controller or processor. This illustrates the EDPB's wish to harmonise GDPR enforcement across Member States and is a strong incentive for controllers and processors to comply with GDPR rules.
Implications
The harmonised methodology aims to ensure GDPR enforcement outcomes become predictable and standardised across Member States, although significant national divergences are likely to remain.
However, the new guidelines may result in a more aggressive fining attitude from DPAs.
Businesses should also plan for nonfinancial outcomes. The new guidelines confirm that compliance orders, temporary or permanent processing limitations and bans, and suspension of international data flows may be imposed alongside a fine. For processing that underpins core services, such measures may prove more costly than the penalty itself, and contingency planning is advisable.
The five-step methodology may change substantially following the public consultation.
Next Steps
Impacted companies should consider submitting comments during the consultation window, closing on 13 November 2026.
Controllers should note that they are, as a rule, answerable for infringements committed by their processors; liability shifts only where the processor acts for its own purposes or in a way incompatible with the framework or arrangements the controller has set. Processor oversight, and evidence of it, is therefore a priority.
Final guidelines are expected to be published following the public consultation. Data controllers or processors should monitor their publication and ensure compliance with GDPR rules.