EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines

Imported from official source

Announcement

Cybersecurity Classified by Officially

EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines

EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines

During its latest plenary, the EDPB has adopted guidelines on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR and the final version of its guidelines on the interplay between the Digital Services Act (DSA) and the GDPR.

"The new EDPB guidelines are a major step in further aligning how Data Protection Authorities decide whether an administrative fine should be imposed, either on its own or alongside other corrective measures. The GDPR significantly increased the corrective powers of DPAs, with fines serving as an important instrument for effective enforcement. The guidelines reaffirm our commitment to providing greater clarity and ensuring the consistent application of the GDPR across Europe," said EDPB Deputy Chair, Jelena Virant Burnik

Data Protection Authorities (DPAs) should follow a five-step methodology when deciding whether to impose an administrative fine:

  • the DPA checks if the infringement can lead to a fine, by finding support either directly in the GDPR or in national law.
  • the DPA determines whether the party under investigation may be fined for the infringement in question. Whether the controller or the processor is liable depends on who is bound by the breached provision.
  • the DPA assesses whether the infringement has been committed intentionally or negligently, since a culpable infringement is a condition for the imposition of a fine.
  • the DPA assesses possible aggravating and mitigating factors. If the infringement is minor, there will generally be no fine and a reprimand may be issued instead; if it is not minor, there is a strong presumption that a fine should be imposed.
  • This is an extract. The publication continues at the source.

    Read the original at the source: https://idpc.org.mt/news-latest/edpb-harmonises-fining-methodology-and-adopts-final-dsa-gdpr-guidelines/

    Officially imported this from Information and Data Protection Commissioner (Malta)’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    Information and Data Protection Commissioner (Malta) — imported from official source
    Official source
    https://idpc.org.mt/feed/ RSS
    Imported
    October 03, 2026 20:31
    Versions
    1 recorded
    Identity
    https://idpc.org.mt/?p=5250

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.