EU data protection

The EDPB's Fining Test Standardises Process, but a 'Strong Presumption' of Fines Tilts the Scale Against Proportionality

The EDPB's draft Guidelines 04/2026 give EEA regulators one five-step fining test. Its presumption of a fine for non-minor breaches needs guardrails.

EDPB Guidelines 04/2026 at a glance People of Internet Research · EU 5 Steps in fining test Legal checks first, then the fine-… 14 Worked practical examples Illustrate the corrective powers i… 13 Nov Consultation closes Stakeholder comments due in 2026. peopleofinternet.com
EDPB Guidelines 04/2026 at a glance People of Internet Research · EU 5 Steps in fining test 14 Worked practical examples 13 Nov Consultation closes peopleofinternet.com

Key Takeaways

The European Data Protection Board's announcement of draft Guidelines 04/2026, dated 21 September 2026, tries to fix a real GDPR problem: national authorities decide very differently when a breach deserves a fine. The Board's own news release describes a five-step methodology for deciding whether to fine at all. It is separate from the earlier guidelines on calculating the amount. The Board also finalised its guidance on how the Digital Services Act and the GDPR apply together. The first document is the more consequential one, and its central presumption deserves scrutiny.

What the guidelines actually say

Per the EDPB's release, a data protection authority (DPA) works through five steps:

The text includes 14 practical examples, and the consultation on it runs to 13 November 2026. The Board says the guidelines are not a formal binding legal instrument. In practice, though, EDPB guidelines are what national regulators and courts treat as the reference point.

The strongest case for the presumption

The case for the Board's approach is serious. The GDPR has applied since 2018, yet enforcement still varies sharply between member states. A company facing one regulator may get a reprimand where another would issue a fine for the same conduct. That inconsistency undermines the single-market logic of the regulation and rewards forum shopping. A written test also makes decisions easier to appeal and to compare. Article 83(1) of the GDPR already requires fines to be effective, proportionate and dissuasive, and a presumption that real breaches get real consequences answers the complaint that DPAs have been too timid with large platforms. Predictability about process is also good for innovators: a firm that knows the steps can plan for them.

Where the presumption goes wrong

The problem is the default. Recital 148 of the GDPR says a reprimand may be issued instead of a fine for a minor infringement, and the guidelines build on that. But the legislator left DPAs discretion to choose the sanction that fits the case. Turning that discretion into a presumption shifts the burden: after step four, the regulator needs a reason not to fine, rather than a reason to fine.

That matters because the line between "minor" and "not minor" is where almost all the action will be. Documentation lapses, a cookie banner that is partly compliant, a processor agreement missing a clause, a late breach notification with no harm to individuals: are these minor? Each regulator will draw the line in its own place, so the harmonisation the Board seeks may be only partial. Meanwhile, the downside of a wrong call falls unevenly. A large platform can absorb a fine and litigate. A 30-person startup or a hospital IT team cannot, and the guidelines' own steps three and five (negligence and proportionality) are the only real protection for them.

There is also an incentive problem. If most non-minor findings end in fines, firms have less reason to cooperate early, self-report, or remediate, because the presumption leaves less room for those efforts to change the outcome. The guidelines list mitigating factors in step four, but the more heavily the presumption weighs, the less those factors will matter. Evidence-based regulation should measure whether fines improve compliance and reduce harm to individuals, not only whether they are imposed.

The DSA-GDPR guidance

The Board's other announcement, per its release, is the final version of its guidelines on the interplay between the DSA and the GDPR, adopted after public consultation. They address DSA provisions that involve personal data processing by intermediary service providers and aim to align the two regimes' concepts. For platforms, this is the more useful document: content moderation, recommender-system transparency and notice-and-action procedures all involve personal data, and overlapping regulators with different readings are a compliance cost that does nothing for users. Clear guidance reduces that cost. It will matter more if DPAs and Digital Services Coordinators then apply it the same way, which is untested. A regulator who has just been told to presume fines will have its own view on how that sits next to DSA obligations.

What to watch

Three things will show whether this helps or hurts. First, the consultation: the Board should be pressed to define "minor" with concrete examples beyond the 14, including cases involving small organisations. Second, whether national authorities treat the presumption as rebuttable in practice, with reasoned decisions that explain why a fine was not imposed. Third, whether courts accept guidance that is not binding as a basis for fining. Those that tie fines to the GDPR's proportionality language, rather than to a Board presumption, are likelier to survive appeal.

A common test is a sound idea. A presumption of sanctions in a regime with open-ended fine ceilings and vague thresholds is a blunter one. The Board has until 13 November to hear that argument and should keep reprimands, remediation and cooperation as live outcomes, not exceptions.

Sources & Citations

  1. Icelandic Data Protection Authority (island.is): EDPB harmonises fining methodology and adopts DSA-GDPR guidelines
  2. EDPB Guidelines 04/2026 (PDF)
  3. GDPR (Regulation (EU) 2016/679), EUR-Lex
  4. Obsidian Regulatory Intelligence: EDPB harmonises GDPR fining powers