Skip to content

Regulatory Pulse

EDPB proposes five-step test for GDPR fines and corrective measures

Draft EDPB Guidelines 04/2026 set out a five-step methodology for deciding whether a GDPR administrative fine should be imposed alone or alongside other corrective measures.

European Union
GDPR enforcement, administrative fines and corrective powers
Guidance
Official source reviewed

PrivacyBuilt Editorial · Source published Draft EDPB guidelines open for public consultation · Reviewed 22 September 2026 · 7 min read

The 60-second summary

On 21 September 2026, the EDPB announced draft Guidelines 04/2026 on when supervisory authorities should impose GDPR administrative fines in addition to, or instead of, other corrective powers. The draft uses five steps: confirm that the infringement can attract a fine; determine whether the investigated party can be fined; establish intent or negligence; assess aggravating and mitigating factors and whether the infringement is minor; and decide whether a fine would be effective, proportionate and dissuasive. A minor infringement will generally attract no fine and may receive a reprimand, while a non-minor infringement carries a strong presumption in favour of a fine. The draft contains 14 practical examples, would replace earlier WP29 guidance, and complements the existing methodology for calculating fine amounts. Comments close on 13 November 2026 at 23:59 CET. The EDPB also adopted final DSA–GDPR interplay guidelines, but said the document will be published after linguistic checks.

Timeline that matters

  1. 17 September 2026

    Draft adopted

    The EDPB adopted Guidelines 04/2026 Version 1.0 for public consultation.

  2. 21 September 2026

    Publication and consultation opened

    The EDPB announced the methodology and opened the feedback period.

  3. 13 November 2026, 23:59 CET

    Consultation deadline

    Deadline for submitting comments through the EDPB consultation page.

  4. 22 December 2026

    Next review

    Check for consultation results, a final version and publication of the DSA–GDPR guidelines.

What changed

The EDPB has separated two questions that organisations sometimes conflate: whether a fine should be imposed and how its amount should be calculated. Draft Guidelines 04/2026 address the first question and relate fines to warnings, reprimands, orders, processing limitations or bans, and withdrawal of certification. They introduce a harmonised five-step decision method and a strong presumption of a fine for infringements that are not minor, subject to effectiveness, proportionality and dissuasiveness in the individual case.

Who should pay attention?

Privacy and legal teams

Align investigation files and remediation evidence with the five-step assessment.

Controllers and processors

Clarify which party owns each breached obligation and retain evidence of reasonable care.

Incident-response teams

Document containment, mitigation, notification and cooperation decisions contemporaneously.

Boards and risk owners

Understand that remediation may not remove exposure to a punitive fine.

Certification and monitoring bodies

Assess whether provisions applicable to them can attract administrative fines.

What the guidance clarifies

The guidelines are not final
Version 1.0 was adopted for public consultation. Feedback closes on 13 November 2026 at 23:59 CET.
This is about whether to fine
The draft complements, rather than replaces, the EDPB methodology for calculating the amount of a fine.
Culpability is a legal precondition
The authority assesses whether the infringement was intentional or negligent before deciding whether to impose a fine.
Minor and non-minor cases diverge
A minor infringement will generally not attract a fine; a non-minor infringement creates a strong presumption that a fine should be imposed.
Fines can accompany other measures
Authorities may combine a fine with orders, limitations or other corrective measures when appropriate and proportionate.
DSA–GDPR guidance is not yet published
The EDPB announced adoption of the final interplay guidelines but said the document will follow after linguistic checks.

Enforcement exposure depends on evidence, ownership and conduct—not remediation alone

Why this matters for global organisations

Organisations need investigation-ready records showing who owned each obligation, what safeguards existed, how risks were assessed, whether failures were intentional or negligent, and how harm was mitigated. Consistent evidence across business units and suppliers can materially affect how an authority characterises an infringement and selects corrective measures.

  • Assign accountable owners to each privacy obligation and control.
  • Preserve evidence of reasonable design, testing, monitoring and escalation.
  • Document mitigation and cooperation without assuming they eliminate fine exposure.
  • Prepare for fines and operational orders to be imposed together.

15 actions to start now

  1. Map GDPR obligations to the controller, processor, monitoring body or certification body responsible for each one.
  2. Update investigation playbooks to address all five EDPB assessment steps.
  3. Create an evidence checklist for intent, negligence, governance, control design and operational testing.
  4. Record the nature, gravity, duration and scale of suspected infringements consistently.
  5. Document harm-mitigation measures, decision times and accountable owners.
  6. Retain evidence of cooperation with supervisory authorities and delivery of ordered remediation.
  7. Track previous infringements, warnings, reprimands and related corrective measures across the organisation.
  8. Identify processing involving sensitive data, vulnerable people or large affected populations.
  9. Review whether incident and complaint records accurately show how an issue became known.
  10. Assess adherence to approved codes of conduct or certification mechanisms where applicable.
  11. Prepare for corrective orders, limitations or bans to accompany a fine.
  12. Align regulator-response, legal-hold, incident-response and board-escalation procedures.
  13. Review supplier contracts and evidence rights where processor conduct may affect liability.
  14. Decide whether to submit consultation feedback before 13 November 2026.
  15. Track the final guidelines and update assumptions when the text changes.

Suggested next steps

  • Run a tabletop investigation using the five-step method against one recent privacy incident or audit finding, then close gaps in ownership, evidence and escalation.

Evidence worth retaining

  • GDPR obligation-to-owner matrix.
  • Controller and processor responsibility records.
  • Risk assessments, DPIAs and approval decisions.
  • Policies, control designs and technical configuration baselines.
  • Training and role-competence records.
  • Monitoring, audit and control-test results.
  • Incident chronology and investigation notes.
  • Records of mitigation actions and affected-person support.
  • Supervisory-authority correspondence and cooperation logs.
  • Previous enforcement, complaint and remediation history.
  • Sensitive-data and affected-population assessments.
  • Code-of-conduct or certification evidence.
  • Board and senior-management escalation records.
  • Supplier contracts, instructions and assurance reports.
  • Legal advice, privilege decisions and documented exceptions where appropriate.

Questions to take to counsel or your conformity team

These are discussion prompts, not legal advice or conclusions.

  • Which provision was breached, and can it attract a fine under the GDPR or applicable national law?
  • Which party was legally bound by that obligation?
  • What evidence supports or rebuts intent or negligence?
  • Could the infringement reasonably be characterised as minor?
  • Which aggravating or mitigating factors are documented rather than asserted?
  • Would remediation alone fully enforce the GDPR in this case?
  • Could a fine and operational order be imposed together?
  • Have previous related failures or orders been considered consistently?
  • Do supplier records clarify instructions, responsibility and control failures?
  • What facts should be preserved immediately once an investigation is foreseeable?
  • Should the organisation contribute practical feedback during the consultation?

Official sources

PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.

PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.