EDPB's new fining guidelines decide whether to fine, not how much, and they are still a draft
The EDPB's Guidelines 04/2026 set a five-step test for whether EU regulators should fine at all, leaving the 2023 calculation untouched and open for consultation until 13 November. Its final DSA and GDPR guidance is adopted but unpublished. UK firms with EU users are still in scope.
By Parminder Kumar Sharma · · 23 min read

Three fines in fourteen examples
The European Data Protection Board's new fining guidelines contain 14 worked examples. Count how they end and only three finish with a fine. Five end in a reprimand, three end with the regulator taking no corrective measure at all, and the remaining three are there to show that a controller was negligent rather than to show an outcome. The Board announced the document on 21 September 2026 under the headline that it had harmonised fining methodology.
That count does not establish that EU regulators are going soft. The Board says plainly that its examples are imaginary cases that cannot be treated as precedents, and the same document sets a strong presumption that any infringement which is not minor should be fined. What the count does show is the shape of the document. It is about the decision to fine at all, the step before any number is calculated. It does not touch the calculation, which still sits in Guidelines 04/2022, unchanged since 2023.
There are two other things to know before reading any summary of this announcement. The fining guidelines are a draft, open for consultation until 13 November 2026. And the other document announced the same day, the "final" guidelines on the interplay between the Digital Services Act (DSA) and the GDPR, has not been published: the Board says it will undergo linguistic checks first. Everything this briefing says about the DSA and GDPR overlap therefore comes from the consultation version, 3/2025 version 1.1, and the final text may differ.
What was actually adopted
The announcement bundles two documents with different status. The table separates what each document is from what the headline implies.
Status of the two EDPB documents announced on 21 September 2026. Source: EDPB announcement, document pages and version histories.
| Document | What it is | Stated | Not stated or not yet true |
|---|---|---|---|
| Guidelines 04/2026 on imposing fines | Version 1.0, adopted 17 September 2026 for public consultation | Consultation 21 September to 13 November 2026; replaces the WP29 fining guidelines (WP253); complements 04/2022 | Not final. No date for the post-consultation version |
| Guidelines 04/2022 on calculating fines | Version 2.1, final after consultation (v2.0 adopted 24 May 2023, minor correction 29 June 2023) | Still the method for the amount; 04/2026 tells regulators to refer to it | Any change to starting points, turnover bands or factors |
| Guidelines 3/2025 on the DSA and GDPR | Final version adopted after consultation, per the announcement | Consultation ran 12 September to 31 October 2025 on version 1.1 | Final text: not published; awaiting linguistic checks. Adoption date of the final version not given |
Two arithmetic points. The fining consultation runs for 53 days (21 September to 13 November 2026). The DSA consultation ran for 49 days, and 375 days separate the adoption of the DSA draft (11 September 2025) from the announcement that it is final.
The five steps that come before any number
Guidelines 04/2026 give regulators a five-step test for whether to fine. The first three steps are legal preconditions and the last two are judgement.
Step 1: can this infringement be fined at all? The regulator must find support in Article 83(4) to (6) GDPR or in national law. The Board notes that Articles 10 and 24 are missing from Article 83's lists, but says a breach of Article 24 may amount to a breach of the accountability principle in Article 5(2), which is finable.
Step 2: who is liable? The addressee of the provision that was breached. The Board restates direct corporate liability as the Court of Justice set it out in Deutsche Wohnen: management need not have acted or known, and no individual needs to be identified. A controller answers for its processor unless the processor went off on its own purposes.
Step 3: intent or negligence? A culpable infringement is required, but the bar is low. Negligence needs only that the organisation "could not be unaware" of the infringing nature of its conduct. Legal advice does not rescue it: the examples reject an external opinion that went against the majority view, internal advice that contradicted the regulator's known position, and advice the company could not document. One sentence deserves attention from anyone who relies on reading the rules their own way: where EDPB guidelines exist, the Board says, an error is always avoidable and therefore at least negligent.
Step 4: is it minor? The regulator weighs the Article 83(2) factors (nature, gravity and duration, intent, mitigation, responsibility, previous infringements, cooperation, data categories, how the regulator found out, compliance with earlier orders, codes of conduct, and anything else). If the infringement is minor, as a general rule there is no fine and a reprimand may be issued instead. If it is not minor, there is "a strong presumption to impose an administrative fine".
Step 5: would a fine be effective, proportionate and dissuasive? This is where the regulator may depart from the presumption either way. A minor breach can still be fined. A serious breach can still end in a reprimand where a fine would be a disproportionate burden, and the Board extends that to legal persons, not only the natural persons mentioned in Recital 148. In exceptional cases a regulator can decline to use any corrective power, following the Court of Justice's Land Hessen judgment.
The draft also sets out what each corrective power is for, and that affects which ones can be combined. A warning under Article 58(2)(a) is issued before any infringement has occurred, so it cannot be combined with a fine for the same conduct. A reprimand and a fine share a purpose, deterrence, so both are not normally needed for the same infringement, although the GDPR does not rule out combining them. Orders and fines can be combined freely because orders restore compliance while fines punish.
How the fourteen examples end
Outcomes of the 14 practical examples in EDPB Guidelines 04/2026 v1.0, counted by this briefing. The Board states the examples are imaginary and not precedents.
| Outcome | Examples | Count |
|---|---|---|
| Fine (with a warning in example 1) | 1 (AI productivity monitoring despite a warning), 5 (repeated erasure failures after a reprimand), 10 (delayed access responses, repeated) | 3 |
| Reprimand, infringement minor | 6 (missed access request in spam), 7 (tracking pixel sent hashed data of about 50,000 users for two years), 8 (refused CCTV access), 9 (sports club transparency) | 4 |
| Reprimand, infringement not minor | 14 (health data published under a certificate of publication) | 1 |
| No corrective measure | 11 (employee snooping at a savings bank), 12 (raffle notice not updated), 13 (driving licence emailed in error) | 3 |
| Negligence illustrations, no outcome | 2 (changed law), 3 (one-person company), 4a to 4c (legal advice) | 3 |
Two of the three fines follow the same pattern: a problem first treated as minor becomes finable once it repeats. In example 5 a recruitment agency is reprimanded over two erasure complaints and fined after three more arrive. In example 10 a small telecoms company is first reprimanded for a one-month delay in answering an access request, then fined once further identical cases turn up. The lesson for a compliance team is that a reprimand is not the end of a matter. It becomes the record against which the next complaint is judged.
The calculation did not change
The request most readers will have is how 04/2026 changes the starting points, the turnover adjustments and the aggravating and mitigating factors in 04/2022. The answer, from reading both documents, is that it does not change the numbers at all. Chapter 4 of 04/2022 still sets them, and 04/2026 twice tells regulators to go to the Calculation Guidelines once they decide to fine. For reference, those numbers are:
Starting point for a fine under EDPB Guidelines 04/2022 v2.1, paragraphs 60, 65 and 66. Percentages apply to the legal maximum, then to the result.
| Stage | Rule in 04/2022 | Range |
|---|---|---|
| Seriousness: low | Share of the applicable legal maximum | 0 to 10% |
| Seriousness: medium | Share of the applicable legal maximum | 10 to 20% |
| Seriousness: high | Share of the applicable legal maximum | 20 to 100% |
| Turnover up to EUR 2m | Multiply the starting amount by | 0.2 to 0.4% |
| EUR 2m to 10m | Multiply by | 0.3 to 2% |
| EUR 10m to 50m | Multiply by | 1.5 to 10% |
| EUR 50m to 100m | Multiply by | 8 to 20% |
| EUR 100m to 250m | Multiply by | 15 to 50% |
| EUR 250m to 500m | Multiply by | 40 to 100% |
| Above EUR 500m | No adjustment; the 2% or 4% turnover maximum already scales the fine | None |
What 04/2026 does change is how the same Article 83(2) factors are read at the earlier stage. The text is largely carried over from 04/2022 and adapted to the question "is this minor?", but a few points are new or sharper.
The same Article 83(2) factors in the two sets of guidelines. Source: 04/2022 v2.1 chapters 4 and 5; 04/2026 v1.0 section 5.2.
| Factor | 04/2022: effect on the amount | 04/2026: effect on whether to fine |
|---|---|---|
| Intent or negligence | Intent weighs more; negligence at best neutral | Culpability is a precondition (step 3); higher negligence points away from minor |
| Previous infringements | Aggravating; absence is neutral | Same, plus only infringements established before preliminary findings need count, citing Regulation (EU) 2025/2518 |
| Failure to heed a warning | Not addressed | Not a previous infringement, but may count as ignoring an earlier measure; proceeding despite a warning points to intent |
| Mitigation of damage | May reduce the fine; timing matters | May help show the breach is minor; early, unprompted action counts most |
| Cooperation | Ordinary cooperation neutral | Same; only cooperation beyond the legal duty that limited harm counts |
| Codes of conduct | May mitigate | Regulator may refrain from further measures if the monitoring body acted |
| Profit from the breach | Aggravating | A strong indication that the breach is not minor and a fine is needed |
The new material is procedural. The previous-infringements cut-off follows the EU's GDPR Procedural Rules Regulation, (EU) 2025/2518 of 26 November 2025, which 04/2026 cites repeatedly. The Board also says the 04/2026 method should be considered, where appropriate, when regulators draft the summary of key issues and the preliminary findings under that regulation, not only final decisions. The practical effect is that the decision whether to fine starts to take shape early in a cross-border case.
A worked fine, using the EDPB's own numbers
The Board's calculation annex includes a complete worked example (Example A in 04/2022). It is reproduced here step by step with the arithmetic checked. It is the EDPB's hypothetical, not a real case.
EDPB Guidelines 04/2022, Annex, Example A: a social media company with EUR 200m turnover sold users' sensitive data, infringing Article 9. Arithmetic checked by this briefing.
| Step | Decision in the example | Result |
|---|---|---|
| Legal maximum | Article 9 falls under Article 83(5); turnover is under EUR 500m, so the static maximum applies | EUR 20m |
| Seriousness | High: range 20 to 100% of EUR 20m, which is EUR 4m to 20m | Set at EUR 10m (50%) |
| Turnover adjustment | EUR 200m falls in the EUR 100m to 250m band (15 to 50%); chosen at 40% | EUR 10m x 40% = EUR 4m |
| Sanity check | Annex table range for high seriousness in this band: EUR 600,000 to 10m | EUR 4m is inside the range |
| Next | Aggravating and mitigating factors, legal maximum, effectiveness check | Not calculated in the example |
The example stops at the starting point. For a sense of what the next step can do, the Board's aggravation examples in chapter 5 move starting amounts by between minus 13% and plus 33%: example 7a goes from EUR 2m to EUR 2.6m for a repeat offence (plus 30%), 7b from EUR 260,000 to EUR 225,000 for mitigation (about minus 13%), 7c from EUR 100,000 to EUR 130,000 and 7d from EUR 150,000 to EUR 200,000 for profiting from the breach. The Board warns that these percentages are illustrations and must not be read as rates for real cases, so this briefing does not apply them to Example A.
To compare the EU and UK methods, take the ICO's own Example A: a medium-seriousness breach of a higher-tier provision by an undertaking with £30 million turnover, a 16% seriousness starting point and a 5% size adjustment. The ICO works it through to £140,000 (£17.5m x 16% x 5%). Feed the same percentages into the EDPB method and the result is EUR 160,000 (EUR 20m x 16% x 5%), within the EDPB's range for that band. The two figures are in different currencies and this briefing has not converted them. The point is structural: both regulators use the same three multiplications, and the gap comes from the size of the statutory maximum and slightly different turnover bands.
What the DSA and GDPR guidelines say about the overlap
The final text has not been published, so what follows is taken from the consultation version (3/2025, version 1.1). The Board describes the final version as adopted "after public consultation" and has not said what changed. Read this section as the Board's stated direction, not as final guidance.
The starting point is that the DSA does not override the GDPR. Article 2(4)(g) DSA says the DSA is without prejudice to the GDPR and the ePrivacy Directive, and the Board concludes that the DSA is not a lex specialis that derogates from data protection rules. Where the two overlap they must be applied consistently, and the Board says consistency must not lower the level of protection.
Where the DSA and GDPR meet, per EDPB Guidelines 3/2025 v1.1 (consultation version) and the DSA text in the Official Journal.
| Topic | DSA rule | GDPR overlay per the EDPB draft |
|---|---|---|
| Targeted ads with sensitive data | Art 26(3): no ads based on profiling using Article 9 special category data | Prohibition applies even with a lawful basis and an Article 9(2) exception; inferred data counts |
| Ads and minors | Art 28(2): no profiling-based ads when the platform is aware with reasonable certainty the user is a minor | Art 28(3): no duty to collect extra data to find out; Art 28(1) and (2) can be an Article 6(1)(c) legal basis if necessary and proportionate |
| Age assurance | Art 28(1): high level of privacy, safety and security for minors | Avoid mechanisms that identify users unambiguously, such as government ID, on Art 28 alone; do not store age or age range, only whether the user qualifies |
| Ad transparency | Art 26(1): real-time information on each ad, including main targeting parameters | DSA information arrives after processing; GDPR Article 13 information is due at collection, before it |
| Recommender systems | Art 38: very large platforms must offer at least one option not based on profiling | Present options equally, no nudging; no profiling at all while the non-profiling option is on; a recommendation can be an Article 22 decision |
| Content moderation | Art 7: voluntary detection of illegal content | Legitimate interests is the likely basis; solely automated removals may fall under Article 22; a DPIA is likely |
| Systemic risk | Arts 34 and 35: very large platforms assess and mitigate | If a systemic risk to data protection is found, a DPIA is likely to be mandatory |
Which authority acts. The draft is clear that enforcing the GDPR belongs only to data protection authorities. The European Commission alone supervises the extra obligations on very large online platforms and search engines in Section 5 of Chapter III DSA, while national Digital Services Coordinators handle other providers. Neither law sets out a formal consultation duty between DSA enforcers and data protection authorities. The Board relies instead on the principle of sincere cooperation as the Court of Justice applied it in Meta Platforms (C-252/21): an authority examining conduct under the other regime should consult its counterpart, especially where the counterpart has already ruled on similar conduct, partly to avoid breaching the rule against being punished twice for the same conduct (ne bis in idem).
Deceptive design. Article 25(2) DSA switches off the DSA's dark-pattern ban for practices covered by the GDPR. The Board's test is whether personal data are processed and whether the pattern influences behaviour related to that processing. A "few left in stock" banner is a consumer or DSA matter. The same banner asking for an email address to reserve the item is a GDPR matter for the data protection authority.
What changes for a UK firm with EU customers
None of these EDPB documents binds the UK. The ICO says EDPB decisions and guidance have no legal force in the UK, though it may have regard to them where relevant. For a UK organisation, what matters is whether it falls under the EU regimes directly.
It does if it offers goods or services to people in the EU, or monitors their behaviour there. That is Article 3(2) GDPR. In that case Article 27 requires a written appointment of a representative in the EU, in a member state where affected people are located, unless the processing is occasional, low-risk and involves no large-scale special category or criminal data, or the organisation is a public authority. The ICO's guidance tells UK organisations the same thing and adds that having a representative does not affect the organisation's own liability. The DSA has an equivalent: Article 2(1) applies it to intermediary services offered to recipients in the EU wherever the provider is established, and Article 13 requires a provider with no EU establishment to appoint a legal representative, who can be held liable and whose details go to a Digital Services Coordinator.
For a UK organisation offering services to people in the EU. Sources: GDPR Arts 3 and 27; DSA Arts 2, 13 and 52; EDPB 04/2026; ICO guidance; UK Online Safety Act explainer.
| Area | What changes | What does not change |
|---|---|---|
| EU GDPR enforcement | EU regulators get a draft common test for whether to fine; repeat minor breaches point more clearly to a fine | Whether EU GDPR applies (Art 3(2)); the Art 27 representative duty; the 04/2022 amounts |
| Which EU regulator | 04/2026 envisages that, with no lead authority (controller not in the EU), any authority may count infringements found by others | Without an EU establishment there is no lead authority under the one-stop shop (inference from the text) |
| Negligence | Where EDPB guidelines exist, the Board treats an error as avoidable, so 3/2025 raises the bar for EU-facing platforms | The ICO is not bound by the EDPB |
| DSA (if an intermediary) | EDPB's view on ads, minors, recommenders and age assurance now final, text pending | Art 13 legal representative; fines up to 6% of worldwide turnover (Art 52(3)) |
| UK regime | Nothing in this announcement | UK GDPR under the ICO's March 2024 fining guidance; Online Safety Act under Ofcom, fines up to £18m or 10% of qualifying worldwide revenue |
The inference in the second row needs stating plainly. The GDPR's one-stop shop gives a single lead authority to controllers with a main establishment in the EU. The 04/2026 draft discusses the case where there is "no lead supervisory authority (for example, in case the controller or processor is not established in the European Union)" and says authorities could then take account of infringements found by other authorities. A UK firm with customers across several member states should therefore plan to be dealing with more than one regulator, and assume that a reprimand in one country can count against it in another. That is this briefing's reading, not a statement the Board makes about UK firms.
On the UK side, the rules have not moved. The ICO's Data Protection Fining Guidance was published on 18 March 2024, 917 days before this announcement. The version online on 21 September 2026 still uses the March 2024 method, and the ICO's October 2025 enforcement consultation describes it as the current statutory guidance. No revised version was found. The ICO's published plan of general data protection guidance being updated for the Data (Use and Access) Act 2025 does not list the fining guidance. The EU also renewed the UK's adequacy decisions on 19 December 2025, running to 27 December 2031 according to the ICO, so data can still flow from the EEA to the UK without extra safeguards.
EDPB and ICO fining approaches side by side
The ICO's method was clearly built alongside the EDPB's: the same Article 83(2) factors, the same three seriousness bands, the same idea of turnover bands for smaller firms. The differences are in the detail, and one is a difference of philosophy.
EDPB (04/2026 draft and 04/2022) compared with the ICO Data Protection Fining Guidance (March 2024). Figures as published; not converted between currencies.
| Point | EDPB | ICO |
|---|---|---|
| Status | 04/2022 final; 04/2026 draft to 13 November 2026 | Statutory guidance under s160 DPA 2018, laid before Parliament |
| Whether to fine | Minor: as a rule no fine. Not minor: strong presumption of a fine | Serious: likely a penalty notice unless mitigation outweighs; finely balanced cases may still be fined |
| Minor-breach concept | Explicit, from Recital 148, with 14 examples | No equivalent presumption in the guidance |
| Growth | Not a stated factor | Must have regard to promoting economic growth (s108 Deregulation Act 2015) |
| Legal maximum | EUR 10m or 2%; EUR 20m or 4% | £8.7m or 2%; £17.5m or 4% |
| Turnover-based maximum applies above | EUR 500m | £435m (standard) or £437.5m (higher) |
| Seriousness bands | 0 to 10, 10 to 20, 20 to 100% of maximum | Same |
| Turnover band, 10m to 50m | 1.5 to 10% | 2 to 10% |
| Turnover band, 250m to cap | 40 to 100% | 50 to 100% |
| Reporting to other bodies | No equivalent in 04/2026 | Proactive reporting to NCSC and following its advice can mitigate |
| Legal advice as a defence | Rejected in the examples; EDPB guidelines make errors avoidable | Human error without training cited as negligence |
The turnover bands matter for mid-sized firms. For every band between 2 million and the turnover cap, the ICO's lower bound is higher than the EDPB's: 0.4% against 0.3%, 2% against 1.5%, 10% against 8%, 20% against 15% and 50% against 40%. The upper bounds are the same. Applied to the same infringement and turnover, the ICO's floor for the starting point is higher, but its statutory maximum is lower. Which regime produces a bigger number depends on where in each band the regulator lands.
Comfortable labels that are not controls
"Harmonised". The fining methods were already harmonised in 2023. What 04/2026 harmonises is the decision to fine, and it is still a draft. A board paper that says "EU fines harmonised" and moves the budget line is reading the headline, not the document.
"Final". The DSA and GDPR guidelines are final in the sense that the Board has adopted them. Nobody outside can read the final text yet. Build compliance work on the consultation version and expect changes.
"Only a reprimand". In the Board's own examples a reprimand is the first step on the path to a fine. Treat a reprimand as the first strike.
"We have an EU representative". The ICO is explicit that a representative does not change your own liability under EU GDPR, and Article 13(3) DSA makes the DSA representative liable as well as you. A representative is a point of contact, not a shield.
"We offer a non-profiling feed". For very large platforms, the EDPB draft says that while that option is on, the provider cannot keep collecting data to profile the user for later. A toggle that switches the display but not the data collection does not meet the Board's reading.
Method, not accusation
The EDPB is the collective of the EU's data protection regulators, so these are enforcers writing guidance for themselves. That is the point of them, and it is also why the negligence passages lean firmly towards the regulator: legal advice rarely helps, and published EDPB guidance makes errors avoidable. Consultation is the check on that. The DSA consultation drew responses from trade associations in the advertising and digital sectors, a civil society group and a national media regulator, among others, and industry will have a similar chance on 04/2026 until 13 November. Firms that sell EU representative services or age assurance tools have an obvious interest in how these texts are read. None of that makes the Board's reasoning wrong. It means compliance teams should read the documents rather than the vendor summaries.
What to do, in order
Take this with you
Actions for UK organisations with EU users
- Confirm in writing whether Article 3(2) GDPR catches you: do you offer goods or services to people in the EU, or monitor their behaviour there?
- If it does, check that your Article 27 representative is appointed in writing, located in a member state where your users are, and named in your privacy notice.
- If you run an online platform, hosting or other intermediary service used in the EU, check whether you need a DSA Article 13 legal representative and whether its details have gone to a Digital Services Coordinator.
- Build a register of every reprimand, warning and regulator finding across all jurisdictions, because the EDPB draft treats repeats as the route from minor to finable.
- Review your tracking pixels and software development kits for settings on the vendor's side that override your own data platform, using example 7 as the test case.
- If you rely on legal advice for a contested processing position, make sure it is documented, addresses the regulator's published view and the majority opinion, and is kept on file.
- For EU-facing platforms, check that profiling-based ads are off for users you know with reasonable certainty to be minors, and that age checks keep only a pass or fail result, not an age.
- Map which UK regulator covers each service: the ICO for UK GDPR, and Ofcom for the Online Safety Act if you host user content or run search.
- Decide whether to respond to the 04/2026 consultation before 13 November 2026, directly or through a trade body.
- Diary the publication of the final DSA and GDPR guidelines and plan a gap analysis against the consultation version when they appear.
The question that exposes the gap
The EDPB's draft makes one thing clear: a minor breach that happens again stops being minor. So the question for any UK organisation serving EU customers is not how big an EU fine could be. It is this: if a regulator in Dublin, Paris or Stockholm asked for every complaint, reprimand and regulator contact you have had across Europe in the last three years, could you produce that list, and would it show a repeat?
Key facts
Sources
- PrimaryAnnouncement of 21 September 2026: five-step method, 14 examples, consultation deadline, DSA-GDPR final text pending linguistic checksEuropean Data Protection Boardaccessed 2026-09-21
- PrimaryGuidelines 04/2026 v1.0 on imposing administrative fines, read in full: steps, negligence, examples, outcomesEuropean Data Protection Boardaccessed 2026-09-21
- PrimaryConsultation page for Guidelines 04/2026: feedback period 21 September to 13 November 2026European Data Protection Boardaccessed 2026-09-21
- PrimaryGuidelines 04/2022 v2.1 on calculating fines, read in full: starting points, turnover bands, worked Example A, aggravation examplesEuropean Data Protection Boardaccessed 2026-09-21
- PrimaryGuidelines 3/2025 v1.1 on the DSA and GDPR (consultation version), read in full; consultation dates and respondentsEuropean Data Protection Boardaccessed 2026-09-21
- PrimaryOfficial Journal text of the Digital Services Act: Articles 2, 13, 26, 28, 38, 52 and 93Publications Office of the European Unionaccessed 2026-09-21
- PrimaryEU GDPR as adopted: Articles 3, 27 and 83 textlegislation.gov.ukaccessed 2026-09-21
- PrimaryData Protection Fining Guidance, all sections read: maximums, seriousness bands, turnover Table B, worked examples, growth dutyInformation Commissioner's Officeaccessed 2026-09-21
- PrimaryPublication date of the fining guidance, 18 March 2024Information Commissioner's Officeaccessed 2026-09-21
- PrimaryEnforcement procedural guidance consultation (31 October 2025 to 23 January 2026) confirming the fining guidance remains currentInformation Commissioner's Officeaccessed 2026-09-21
- PrimaryEU representative duty for UK organisations; renewed UK adequacy decisions of 19 December 2025 to 27 December 2031Information Commissioner's Officeaccessed 2026-09-21
- PrimaryOnline Safety Act explainer: scope for non-UK services and Ofcom penalties of £18m or 10% of qualifying worldwide revenueUK Government (DSIT)accessed 2026-09-21
- PrimaryOnline Safety Act 2023 Schedule 13 paragraph 4: maximum penaltylegislation.gov.ukaccessed 2026-09-21
- PrimaryDSA questions and answers: Commission powers and 6% fine ceilingEuropean Commissionaccessed 2026-09-21


