The EDPB's new fining guidelines make a fine the default: not minor means a strong presumption to fine
The European Data Protection Board adopted a five step method on 21 September for deciding whether to fine at all, separate from the existing method for calculating how much. Step four is the one that changes behaviour.
By Parminder Kumar Sharma · · 7 min read

The sentence that matters is in step four
On 21 September the European Data Protection Board adopted guidelines on when a data protection authority should impose an administrative fine, as opposed to some other corrective measure. They are separate from the existing guidelines on how to calculate the amount, which the Board says these complement, and they replace the old Article 29 Working Party guidelines on the same question.
The method has five steps. Four of them are the kind of thing a lawyer would have assumed anyway: is this infringement fineable, is this party the right one to fine, was it intentional or negligent, and would a fine be effective, proportionate and dissuasive.
Step four is the one that changes behaviour. In the Board's own words: "If the infringement is minor, there will generally be no fine and a reprimand may be issued instead; if it is not minor, there is a strong presumption that a fine should be imposed."
What that does not establish. It does not establish new law: the GDPR already set out the conditions for fines and the corrective powers, and guidelines interpret rather than legislate. It does not establish that fines will rise in number, because that depends on what regulators actually do. It does not establish anything about the size of fines, which is governed by the other set of guidelines. And, importantly, it is not yet settled: these guidelines are open to public consultation until 13 November 2026, fifty three days, so the text can change.
What it does establish is a stated default. Under the previous framing, a fine was one option among several corrective powers. Under this one, if your infringement is not minor, the starting position is that you will be fined, and the argument you have to win is the argument against that presumption.
The five steps, as written
The EDPB's five step methodology for deciding whether to impose a fine, from its announcement of 21 September 2026
| Step | What the authority does |
|---|---|
| 1 | Checks that the infringement can lead to a fine at all, with support either directly in the GDPR or in national law |
| 2 | Determines whether the party under investigation may be fined for that infringement, which depends on whether the controller or the processor is bound by the provision breached |
| 3 | Assesses whether the infringement was intentional or negligent, since a culpable infringement is a condition for imposing a fine |
| 4 | Assesses aggravating and mitigating factors. Minor infringement: generally no fine, and a reprimand may be issued instead. Not minor: a strong presumption that a fine should be imposed |
| 5 | Assesses whether a fine would be effective, proportionate and dissuasive, and may consider whether there is reason to deviate from the standard approach |
Steps one to three are gates. Each can end the matter: no legal basis for a fine, wrong party, no culpability. Step five is a check at the end, and it is where a regulator can step off the standard path if the circumstances justify it.
Step four is not a gate. It is a default setting, and it points one way. The word doing the work is "minor", and the announcement does not define it. Neither does this briefing, because the definition will be in the guidelines themselves and in how authorities apply them, which is exactly what the consultation period is for.
The Board also publishes an overview of the corrective powers available: warnings, reprimands, orders, limitations including bans, and withdrawal of certification, and fourteen practical examples of choosing between them.
Two sets of guidelines, doing different jobs
It is easy to conflate these with the fine calculation guidelines, and the distinction matters for anyone who has to brief a board.
The calculation guidelines, already in force, answer: given that a fine is being imposed, how much? They deal with starting amounts, turnover, and the adjustment factors that produce a figure.
These new guidelines answer a prior question: should there be a fine at all, or would a reprimand, an order or a limitation do? Historically that question was answered unevenly across member states, which is the inconsistency the Board says it is addressing. In the words of Deputy Chair Jelena Virant Burnik, quoted in the announcement: "The guidelines reaffirm our commitment to providing greater clarity and ensuring the consistent application of the GDPR across Europe."
Consistency cuts both ways. A regulator that was previously inclined to reprimand now has a stated presumption pointing the other way, and a regulator that was already inclined to fine has a methodology to point at.
What this changes for an organisation
Nothing today. Consultation runs to 13 November, the text may change, and guidelines are not directly binding on anyone in the way a regulation is.
What changes is the shape of the conversation you will have with a regulator later. Three things follow from the method as drafted.
First, step three makes culpability load bearing. Intentional or negligent is the condition, so the evidence that you took care before the incident is the evidence that matters, and it has to exist beforehand: records of decisions, assessments carried out, advice sought and acted on.
Second, step four means the useful argument is now about whether an infringement is minor, and about mitigation. Both are made of facts you either have or do not have on the day: how quickly you detected it, what you did, who you told, whether the people affected were harmed.
Third, step five is where cooperation and remediation do their work, since it is the step that allows a departure from the standard approach.
Take this with you
In the order worth doing
- Read the guidelines rather than the summaries, including this one, because the definition of minor is where the argument will happen and it is in the text.
- If you operate in the European Union or handle European personal data, respond to the consultation before 13 November. This is the cheapest point at which anyone outside the Board can influence the wording.
- Check that your incident records actually demonstrate care taken before an incident, not just actions taken after it, because step three turns on culpability.
- Rehearse the mitigation narrative you would rely on: detection time, containment, notification, remediation, and who decided what. Step four assesses those factors.
- Do not confuse this with the calculation guidelines when briefing anyone. One decides whether, the other decides how much.
- Note that the DSA and GDPR interplay guidelines are final, so if you are an intermediary service provider, that set is actionable now.
The question this leaves
Regulatory guidance is usually reported in the language of severity: fines are getting tougher, enforcement is stepping up. That is not quite what happened here. Nothing in this document raises a maximum or lowers a threshold.
What it does is move the default. A presumption is a quiet instrument. It does not tell anyone what the answer is; it tells them what the answer is unless somebody makes a case. In a regulator's office that changes who has to do the work of persuading, and it does it across twenty seven member states at once.
Which leaves a practical question for anyone who would have to make that case. If a regulator opened a file on you tomorrow and started at step three, what evidence exists today that your organisation took care before the thing happened, rather than only afterwards?
Sources
- PrimaryThe EDPB's own announcement of 21 September 2026, used for the five steps, the consultation deadline, the quoted remark and the note to editorsEuropean Data Protection Boardaccessed 2026-09-25
- PrimaryThe GDPR itself, used for Article 83 on the conditions for imposing administrative fines and Article 58 on corrective powersOfficial Journal of the European Unionaccessed 2026-09-25


