P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

EDPB's new fining guidelines decide whether to fine, not how much, and they are still a draft

The EDPB's Guidelines 04/2026 set a five-step test for whether EU regulators should fine at all, leaving the 2023 calculation untouched and open for consultation until 13 November. Its final DSA and GDPR guidance is adopted but unpublished. UK firms with EU users are still in scope.

By Parminder Kumar Sharma · · 23 min read

Editorial illustration for the briefing: EDPB's new fining guidelines decide whether to fine, not how much, and they are still a draft

Three fines in fourteen examples

The European Data Protection Board's new fining guidelines contain 14 worked examples. Count how they end and only three finish with a fine. Five end in a reprimand, three end with the regulator taking no corrective measure at all, and the remaining three are there to show that a controller was negligent rather than to show an outcome. The Board announced the document on 21 September 2026 under the headline that it had harmonised fining methodology.

That count does not establish that EU regulators are going soft. The Board says plainly that its examples are imaginary cases that cannot be treated as precedents, and the same document sets a strong presumption that any infringement which is not minor should be fined. What the count does show is the shape of the document. It is about the decision to fine at all, the step before any number is calculated. It does not touch the calculation, which still sits in Guidelines 04/2022, unchanged since 2023.

There are two other things to know before reading any summary of this announcement. The fining guidelines are a draft, open for consultation until 13 November 2026. And the other document announced the same day, the "final" guidelines on the interplay between the Digital Services Act (DSA) and the GDPR, has not been published: the Board says it will undergo linguistic checks first. Everything this briefing says about the DSA and GDPR overlap therefore comes from the consultation version, 3/2025 version 1.1, and the final text may differ.

What was actually adopted

The announcement bundles two documents with different status. The table separates what each document is from what the headline implies.

Status of the two EDPB documents announced on 21 September 2026. Source: EDPB announcement, document pages and version histories.

DocumentWhat it isStatedNot stated or not yet true
Guidelines 04/2026 on imposing finesVersion 1.0, adopted 17 September 2026 for public consultationConsultation 21 September to 13 November 2026; replaces the WP29 fining guidelines (WP253); complements 04/2022Not final. No date for the post-consultation version
Guidelines 04/2022 on calculating finesVersion 2.1, final after consultation (v2.0 adopted 24 May 2023, minor correction 29 June 2023)Still the method for the amount; 04/2026 tells regulators to refer to itAny change to starting points, turnover bands or factors
Guidelines 3/2025 on the DSA and GDPRFinal version adopted after consultation, per the announcementConsultation ran 12 September to 31 October 2025 on version 1.1Final text: not published; awaiting linguistic checks. Adoption date of the final version not given

Two arithmetic points. The fining consultation runs for 53 days (21 September to 13 November 2026). The DSA consultation ran for 49 days, and 375 days separate the adoption of the DSA draft (11 September 2025) from the announcement that it is final.

The five steps that come before any number

Guidelines 04/2026 give regulators a five-step test for whether to fine. The first three steps are legal preconditions and the last two are judgement.

Step 1: can this infringement be fined at all? The regulator must find support in Article 83(4) to (6) GDPR or in national law. The Board notes that Articles 10 and 24 are missing from Article 83's lists, but says a breach of Article 24 may amount to a breach of the accountability principle in Article 5(2), which is finable.

Step 2: who is liable? The addressee of the provision that was breached. The Board restates direct corporate liability as the Court of Justice set it out in Deutsche Wohnen: management need not have acted or known, and no individual needs to be identified. A controller answers for its processor unless the processor went off on its own purposes.

Step 3: intent or negligence? A culpable infringement is required, but the bar is low. Negligence needs only that the organisation "could not be unaware" of the infringing nature of its conduct. Legal advice does not rescue it: the examples reject an external opinion that went against the majority view, internal advice that contradicted the regulator's known position, and advice the company could not document. One sentence deserves attention from anyone who relies on reading the rules their own way: where EDPB guidelines exist, the Board says, an error is always avoidable and therefore at least negligent.

Step 4: is it minor? The regulator weighs the Article 83(2) factors (nature, gravity and duration, intent, mitigation, responsibility, previous infringements, cooperation, data categories, how the regulator found out, compliance with earlier orders, codes of conduct, and anything else). If the infringement is minor, as a general rule there is no fine and a reprimand may be issued instead. If it is not minor, there is "a strong presumption to impose an administrative fine".

Step 5: would a fine be effective, proportionate and dissuasive? This is where the regulator may depart from the presumption either way. A minor breach can still be fined. A serious breach can still end in a reprimand where a fine would be a disproportionate burden, and the Board extends that to legal persons, not only the natural persons mentioned in Recital 148. In exceptional cases a regulator can decline to use any corrective power, following the Court of Justice's Land Hessen judgment.

Flow diagram in three bands. Top: the five steps of EDPB draft Guidelines 04/2026 (can it be fined, who is liable, intent or negligence, is it minor, would a fine be effective, proportionate and dissuasive). Middle: minor means as a rule no fine but a reprimand or nothing; not minor means a strong presumption of a fine, with a reprimand still possible. Bottom: the unchanged five calculation steps of Guidelines 04/2022, from linked processing to the legal maximum and a final check.
How the new draft sits in front of the existing calculation. Drawn from EDPB Guidelines 04/2026 v1.0 and 04/2022 v2.1.

The draft also sets out what each corrective power is for, and that affects which ones can be combined. A warning under Article 58(2)(a) is issued before any infringement has occurred, so it cannot be combined with a fine for the same conduct. A reprimand and a fine share a purpose, deterrence, so both are not normally needed for the same infringement, although the GDPR does not rule out combining them. Orders and fines can be combined freely because orders restore compliance while fines punish.

How the fourteen examples end

Outcomes of the 14 practical examples in EDPB Guidelines 04/2026 v1.0, counted by this briefing. The Board states the examples are imaginary and not precedents.

OutcomeExamplesCount
Fine (with a warning in example 1)1 (AI productivity monitoring despite a warning), 5 (repeated erasure failures after a reprimand), 10 (delayed access responses, repeated)3
Reprimand, infringement minor6 (missed access request in spam), 7 (tracking pixel sent hashed data of about 50,000 users for two years), 8 (refused CCTV access), 9 (sports club transparency)4
Reprimand, infringement not minor14 (health data published under a certificate of publication)1
No corrective measure11 (employee snooping at a savings bank), 12 (raffle notice not updated), 13 (driving licence emailed in error)3
Negligence illustrations, no outcome2 (changed law), 3 (one-person company), 4a to 4c (legal advice)3

Two of the three fines follow the same pattern: a problem first treated as minor becomes finable once it repeats. In example 5 a recruitment agency is reprimanded over two erasure complaints and fined after three more arrive. In example 10 a small telecoms company is first reprimanded for a one-month delay in answering an access request, then fined once further identical cases turn up. The lesson for a compliance team is that a reprimand is not the end of a matter. It becomes the record against which the next complaint is judged.

The calculation did not change

The request most readers will have is how 04/2026 changes the starting points, the turnover adjustments and the aggravating and mitigating factors in 04/2022. The answer, from reading both documents, is that it does not change the numbers at all. Chapter 4 of 04/2022 still sets them, and 04/2026 twice tells regulators to go to the Calculation Guidelines once they decide to fine. For reference, those numbers are:

Starting point for a fine under EDPB Guidelines 04/2022 v2.1, paragraphs 60, 65 and 66. Percentages apply to the legal maximum, then to the result.

StageRule in 04/2022Range
Seriousness: lowShare of the applicable legal maximum0 to 10%
Seriousness: mediumShare of the applicable legal maximum10 to 20%
Seriousness: highShare of the applicable legal maximum20 to 100%
Turnover up to EUR 2mMultiply the starting amount by0.2 to 0.4%
EUR 2m to 10mMultiply by0.3 to 2%
EUR 10m to 50mMultiply by1.5 to 10%
EUR 50m to 100mMultiply by8 to 20%
EUR 100m to 250mMultiply by15 to 50%
EUR 250m to 500mMultiply by40 to 100%
Above EUR 500mNo adjustment; the 2% or 4% turnover maximum already scales the fineNone

What 04/2026 does change is how the same Article 83(2) factors are read at the earlier stage. The text is largely carried over from 04/2022 and adapted to the question "is this minor?", but a few points are new or sharper.

The same Article 83(2) factors in the two sets of guidelines. Source: 04/2022 v2.1 chapters 4 and 5; 04/2026 v1.0 section 5.2.

Factor04/2022: effect on the amount04/2026: effect on whether to fine
Intent or negligenceIntent weighs more; negligence at best neutralCulpability is a precondition (step 3); higher negligence points away from minor
Previous infringementsAggravating; absence is neutralSame, plus only infringements established before preliminary findings need count, citing Regulation (EU) 2025/2518
Failure to heed a warningNot addressedNot a previous infringement, but may count as ignoring an earlier measure; proceeding despite a warning points to intent
Mitigation of damageMay reduce the fine; timing mattersMay help show the breach is minor; early, unprompted action counts most
CooperationOrdinary cooperation neutralSame; only cooperation beyond the legal duty that limited harm counts
Codes of conductMay mitigateRegulator may refrain from further measures if the monitoring body acted
Profit from the breachAggravatingA strong indication that the breach is not minor and a fine is needed

The new material is procedural. The previous-infringements cut-off follows the EU's GDPR Procedural Rules Regulation, (EU) 2025/2518 of 26 November 2025, which 04/2026 cites repeatedly. The Board also says the 04/2026 method should be considered, where appropriate, when regulators draft the summary of key issues and the preliminary findings under that regulation, not only final decisions. The practical effect is that the decision whether to fine starts to take shape early in a cross-border case.

A worked fine, using the EDPB's own numbers

The Board's calculation annex includes a complete worked example (Example A in 04/2022). It is reproduced here step by step with the arithmetic checked. It is the EDPB's hypothetical, not a real case.

EDPB Guidelines 04/2022, Annex, Example A: a social media company with EUR 200m turnover sold users' sensitive data, infringing Article 9. Arithmetic checked by this briefing.

StepDecision in the exampleResult
Legal maximumArticle 9 falls under Article 83(5); turnover is under EUR 500m, so the static maximum appliesEUR 20m
SeriousnessHigh: range 20 to 100% of EUR 20m, which is EUR 4m to 20mSet at EUR 10m (50%)
Turnover adjustmentEUR 200m falls in the EUR 100m to 250m band (15 to 50%); chosen at 40%EUR 10m x 40% = EUR 4m
Sanity checkAnnex table range for high seriousness in this band: EUR 600,000 to 10mEUR 4m is inside the range
NextAggravating and mitigating factors, legal maximum, effectiveness checkNot calculated in the example

The example stops at the starting point. For a sense of what the next step can do, the Board's aggravation examples in chapter 5 move starting amounts by between minus 13% and plus 33%: example 7a goes from EUR 2m to EUR 2.6m for a repeat offence (plus 30%), 7b from EUR 260,000 to EUR 225,000 for mitigation (about minus 13%), 7c from EUR 100,000 to EUR 130,000 and 7d from EUR 150,000 to EUR 200,000 for profiting from the breach. The Board warns that these percentages are illustrations and must not be read as rates for real cases, so this briefing does not apply them to Example A.

To compare the EU and UK methods, take the ICO's own Example A: a medium-seriousness breach of a higher-tier provision by an undertaking with £30 million turnover, a 16% seriousness starting point and a 5% size adjustment. The ICO works it through to £140,000 (£17.5m x 16% x 5%). Feed the same percentages into the EDPB method and the result is EUR 160,000 (EUR 20m x 16% x 5%), within the EDPB's range for that band. The two figures are in different currencies and this briefing has not converted them. The point is structural: both regulators use the same three multiplications, and the gap comes from the size of the statutory maximum and slightly different turnover bands.

What the DSA and GDPR guidelines say about the overlap

The final text has not been published, so what follows is taken from the consultation version (3/2025, version 1.1). The Board describes the final version as adopted "after public consultation" and has not said what changed. Read this section as the Board's stated direction, not as final guidance.

The starting point is that the DSA does not override the GDPR. Article 2(4)(g) DSA says the DSA is without prejudice to the GDPR and the ePrivacy Directive, and the Board concludes that the DSA is not a lex specialis that derogates from data protection rules. Where the two overlap they must be applied consistently, and the Board says consistency must not lower the level of protection.

Where the DSA and GDPR meet, per EDPB Guidelines 3/2025 v1.1 (consultation version) and the DSA text in the Official Journal.

TopicDSA ruleGDPR overlay per the EDPB draft
Targeted ads with sensitive dataArt 26(3): no ads based on profiling using Article 9 special category dataProhibition applies even with a lawful basis and an Article 9(2) exception; inferred data counts
Ads and minorsArt 28(2): no profiling-based ads when the platform is aware with reasonable certainty the user is a minorArt 28(3): no duty to collect extra data to find out; Art 28(1) and (2) can be an Article 6(1)(c) legal basis if necessary and proportionate
Age assuranceArt 28(1): high level of privacy, safety and security for minorsAvoid mechanisms that identify users unambiguously, such as government ID, on Art 28 alone; do not store age or age range, only whether the user qualifies
Ad transparencyArt 26(1): real-time information on each ad, including main targeting parametersDSA information arrives after processing; GDPR Article 13 information is due at collection, before it
Recommender systemsArt 38: very large platforms must offer at least one option not based on profilingPresent options equally, no nudging; no profiling at all while the non-profiling option is on; a recommendation can be an Article 22 decision
Content moderationArt 7: voluntary detection of illegal contentLegitimate interests is the likely basis; solely automated removals may fall under Article 22; a DPIA is likely
Systemic riskArts 34 and 35: very large platforms assess and mitigateIf a systemic risk to data protection is found, a DPIA is likely to be mandatory

Which authority acts. The draft is clear that enforcing the GDPR belongs only to data protection authorities. The European Commission alone supervises the extra obligations on very large online platforms and search engines in Section 5 of Chapter III DSA, while national Digital Services Coordinators handle other providers. Neither law sets out a formal consultation duty between DSA enforcers and data protection authorities. The Board relies instead on the principle of sincere cooperation as the Court of Justice applied it in Meta Platforms (C-252/21): an authority examining conduct under the other regime should consult its counterpart, especially where the counterpart has already ruled on similar conduct, partly to avoid breaching the rule against being punished twice for the same conduct (ne bis in idem).

Deceptive design. Article 25(2) DSA switches off the DSA's dark-pattern ban for practices covered by the GDPR. The Board's test is whether personal data are processed and whether the pattern influences behaviour related to that processing. A "few left in stock" banner is a consumer or DSA matter. The same banner asking for an email address to reserve the item is a GDPR matter for the data protection authority.

What changes for a UK firm with EU customers

None of these EDPB documents binds the UK. The ICO says EDPB decisions and guidance have no legal force in the UK, though it may have regard to them where relevant. For a UK organisation, what matters is whether it falls under the EU regimes directly.

It does if it offers goods or services to people in the EU, or monitors their behaviour there. That is Article 3(2) GDPR. In that case Article 27 requires a written appointment of a representative in the EU, in a member state where affected people are located, unless the processing is occasional, low-risk and involves no large-scale special category or criminal data, or the organisation is a public authority. The ICO's guidance tells UK organisations the same thing and adds that having a representative does not affect the organisation's own liability. The DSA has an equivalent: Article 2(1) applies it to intermediary services offered to recipients in the EU wherever the provider is established, and Article 13 requires a provider with no EU establishment to appoint a legal representative, who can be held liable and whose details go to a Digital Services Coordinator.

For a UK organisation offering services to people in the EU. Sources: GDPR Arts 3 and 27; DSA Arts 2, 13 and 52; EDPB 04/2026; ICO guidance; UK Online Safety Act explainer.

AreaWhat changesWhat does not change
EU GDPR enforcementEU regulators get a draft common test for whether to fine; repeat minor breaches point more clearly to a fineWhether EU GDPR applies (Art 3(2)); the Art 27 representative duty; the 04/2022 amounts
Which EU regulator04/2026 envisages that, with no lead authority (controller not in the EU), any authority may count infringements found by othersWithout an EU establishment there is no lead authority under the one-stop shop (inference from the text)
NegligenceWhere EDPB guidelines exist, the Board treats an error as avoidable, so 3/2025 raises the bar for EU-facing platformsThe ICO is not bound by the EDPB
DSA (if an intermediary)EDPB's view on ads, minors, recommenders and age assurance now final, text pendingArt 13 legal representative; fines up to 6% of worldwide turnover (Art 52(3))
UK regimeNothing in this announcementUK GDPR under the ICO's March 2024 fining guidance; Online Safety Act under Ofcom, fines up to £18m or 10% of qualifying worldwide revenue

The inference in the second row needs stating plainly. The GDPR's one-stop shop gives a single lead authority to controllers with a main establishment in the EU. The 04/2026 draft discusses the case where there is "no lead supervisory authority (for example, in case the controller or processor is not established in the European Union)" and says authorities could then take account of infringements found by other authorities. A UK firm with customers across several member states should therefore plan to be dealing with more than one regulator, and assume that a reprimand in one country can count against it in another. That is this briefing's reading, not a statement the Board makes about UK firms.

On the UK side, the rules have not moved. The ICO's Data Protection Fining Guidance was published on 18 March 2024, 917 days before this announcement. The version online on 21 September 2026 still uses the March 2024 method, and the ICO's October 2025 enforcement consultation describes it as the current statutory guidance. No revised version was found. The ICO's published plan of general data protection guidance being updated for the Data (Use and Access) Act 2025 does not list the fining guidance. The EU also renewed the UK's adequacy decisions on 19 December 2025, running to 27 December 2031 according to the ICO, so data can still flow from the EEA to the UK without extra safeguards.

EDPB and ICO fining approaches side by side

The ICO's method was clearly built alongside the EDPB's: the same Article 83(2) factors, the same three seriousness bands, the same idea of turnover bands for smaller firms. The differences are in the detail, and one is a difference of philosophy.

EDPB (04/2026 draft and 04/2022) compared with the ICO Data Protection Fining Guidance (March 2024). Figures as published; not converted between currencies.

PointEDPBICO
Status04/2022 final; 04/2026 draft to 13 November 2026Statutory guidance under s160 DPA 2018, laid before Parliament
Whether to fineMinor: as a rule no fine. Not minor: strong presumption of a fineSerious: likely a penalty notice unless mitigation outweighs; finely balanced cases may still be fined
Minor-breach conceptExplicit, from Recital 148, with 14 examplesNo equivalent presumption in the guidance
GrowthNot a stated factorMust have regard to promoting economic growth (s108 Deregulation Act 2015)
Legal maximumEUR 10m or 2%; EUR 20m or 4%£8.7m or 2%; £17.5m or 4%
Turnover-based maximum applies aboveEUR 500m£435m (standard) or £437.5m (higher)
Seriousness bands0 to 10, 10 to 20, 20 to 100% of maximumSame
Turnover band, 10m to 50m1.5 to 10%2 to 10%
Turnover band, 250m to cap40 to 100%50 to 100%
Reporting to other bodiesNo equivalent in 04/2026Proactive reporting to NCSC and following its advice can mitigate
Legal advice as a defenceRejected in the examples; EDPB guidelines make errors avoidableHuman error without training cited as negligence

The turnover bands matter for mid-sized firms. For every band between 2 million and the turnover cap, the ICO's lower bound is higher than the EDPB's: 0.4% against 0.3%, 2% against 1.5%, 10% against 8%, 20% against 15% and 50% against 40%. The upper bounds are the same. Applied to the same infringement and turnover, the ICO's floor for the starting point is higher, but its statutory maximum is lower. Which regime produces a bigger number depends on where in each band the regulator lands.

Comfortable labels that are not controls

"Harmonised". The fining methods were already harmonised in 2023. What 04/2026 harmonises is the decision to fine, and it is still a draft. A board paper that says "EU fines harmonised" and moves the budget line is reading the headline, not the document.

"Final". The DSA and GDPR guidelines are final in the sense that the Board has adopted them. Nobody outside can read the final text yet. Build compliance work on the consultation version and expect changes.

"Only a reprimand". In the Board's own examples a reprimand is the first step on the path to a fine. Treat a reprimand as the first strike.

"We have an EU representative". The ICO is explicit that a representative does not change your own liability under EU GDPR, and Article 13(3) DSA makes the DSA representative liable as well as you. A representative is a point of contact, not a shield.

"We offer a non-profiling feed". For very large platforms, the EDPB draft says that while that option is on, the provider cannot keep collecting data to profile the user for later. A toggle that switches the display but not the data collection does not meet the Board's reading.

Method, not accusation

The EDPB is the collective of the EU's data protection regulators, so these are enforcers writing guidance for themselves. That is the point of them, and it is also why the negligence passages lean firmly towards the regulator: legal advice rarely helps, and published EDPB guidance makes errors avoidable. Consultation is the check on that. The DSA consultation drew responses from trade associations in the advertising and digital sectors, a civil society group and a national media regulator, among others, and industry will have a similar chance on 04/2026 until 13 November. Firms that sell EU representative services or age assurance tools have an obvious interest in how these texts are read. None of that makes the Board's reasoning wrong. It means compliance teams should read the documents rather than the vendor summaries.

What to do, in order

Take this with you

Actions for UK organisations with EU users

  • Confirm in writing whether Article 3(2) GDPR catches you: do you offer goods or services to people in the EU, or monitor their behaviour there?
  • If it does, check that your Article 27 representative is appointed in writing, located in a member state where your users are, and named in your privacy notice.
  • If you run an online platform, hosting or other intermediary service used in the EU, check whether you need a DSA Article 13 legal representative and whether its details have gone to a Digital Services Coordinator.
  • Build a register of every reprimand, warning and regulator finding across all jurisdictions, because the EDPB draft treats repeats as the route from minor to finable.
  • Review your tracking pixels and software development kits for settings on the vendor's side that override your own data platform, using example 7 as the test case.
  • If you rely on legal advice for a contested processing position, make sure it is documented, addresses the regulator's published view and the majority opinion, and is kept on file.
  • For EU-facing platforms, check that profiling-based ads are off for users you know with reasonable certainty to be minors, and that age checks keep only a pass or fail result, not an age.
  • Map which UK regulator covers each service: the ICO for UK GDPR, and Ofcom for the Online Safety Act if you host user content or run search.
  • Decide whether to respond to the 04/2026 consultation before 13 November 2026, directly or through a trade body.
  • Diary the publication of the final DSA and GDPR guidelines and plan a gap analysis against the consultation version when they appear.

The question that exposes the gap

The EDPB's draft makes one thing clear: a minor breach that happens again stops being minor. So the question for any UK organisation serving EU customers is not how big an EU fine could be. It is this: if a regulator in Dublin, Paris or Stockholm asked for every complaint, reprimand and regulator contact you have had across Europe in the last three years, could you produce that list, and would it show a repeat?

Key facts

Sources

  1. PrimaryAnnouncement of 21 September 2026: five-step method, 14 examples, consultation deadline, DSA-GDPR final text pending linguistic checksEuropean Data Protection Boardaccessed 2026-09-21
  2. PrimaryGuidelines 04/2026 v1.0 on imposing administrative fines, read in full: steps, negligence, examples, outcomesEuropean Data Protection Boardaccessed 2026-09-21
  3. PrimaryConsultation page for Guidelines 04/2026: feedback period 21 September to 13 November 2026European Data Protection Boardaccessed 2026-09-21
  4. PrimaryGuidelines 04/2022 v2.1 on calculating fines, read in full: starting points, turnover bands, worked Example A, aggravation examplesEuropean Data Protection Boardaccessed 2026-09-21
  5. PrimaryGuidelines 3/2025 v1.1 on the DSA and GDPR (consultation version), read in full; consultation dates and respondentsEuropean Data Protection Boardaccessed 2026-09-21
  6. PrimaryOfficial Journal text of the Digital Services Act: Articles 2, 13, 26, 28, 38, 52 and 93Publications Office of the European Unionaccessed 2026-09-21
  7. PrimaryEU GDPR as adopted: Articles 3, 27 and 83 textlegislation.gov.ukaccessed 2026-09-21
  8. PrimaryData Protection Fining Guidance, all sections read: maximums, seriousness bands, turnover Table B, worked examples, growth dutyInformation Commissioner's Officeaccessed 2026-09-21
  9. PrimaryPublication date of the fining guidance, 18 March 2024Information Commissioner's Officeaccessed 2026-09-21
  10. PrimaryEnforcement procedural guidance consultation (31 October 2025 to 23 January 2026) confirming the fining guidance remains currentInformation Commissioner's Officeaccessed 2026-09-21
  11. PrimaryEU representative duty for UK organisations; renewed UK adequacy decisions of 19 December 2025 to 27 December 2031Information Commissioner's Officeaccessed 2026-09-21
  12. PrimaryOnline Safety Act explainer: scope for non-UK services and Ofcom penalties of £18m or 10% of qualifying worldwide revenueUK Government (DSIT)accessed 2026-09-21
  13. PrimaryOnline Safety Act 2023 Schedule 13 paragraph 4: maximum penaltylegislation.gov.ukaccessed 2026-09-21
  14. PrimaryDSA questions and answers: Commission powers and 6% fine ceilingEuropean Commissionaccessed 2026-09-21

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.