EDPB - Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR
The EDPB has adopted guidelines on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR.
Data Protection Authorities (DPAs) should follow a five-step methodology when deciding whether to impose an administrative fine: (i) the DPA checks if the infringement can lead to a fine, by finding support either directly in the GDPR or in national law; (ii) the DPA determines whether the party under investigation may be fined for the infringement in question. Whether the controller or the processor is liable depends on who is bound by the breached provision; (iii) the DPA assesses whether the infringement has been committed intentionally or negligently, since a culpable infringement is a condition for the imposition of a fine; (iv) the DPA assesses possible aggravating and mitigating factors. If the infringement is minor, there will generally be no fine and a reprimand may be issued instead; if it is not minor, there is a strong presumption that a fine should be imposed and (v) the DPA assesses whether imposing an administrative fine would be effective, proportionate and dissuasive. In doing so, the DPA may consider whether, in the specific case, there is a reason to deviate from the standard approach.
The guidelines also provide an overview of the corrective powers within the remit of national DPAs and explain their purpose, scope, and how they relate to one another. Corrective measures include warnings, reprimands, orders, limitations (including bans), and the withdrawal of certification.
The Board also provides 14 practical examples illustrating how DPAs can assess the specifics of a case and decide which corrective measures should be imposed, if any.
The guidelines will be subject to public consultation until 13 November 2026

