The European Data Protection Board (EDPB) has introduced a structured methodology for Data Protection Authorities (DPAs) to decide on imposing administrative fines under the GDPR. This isn't just procedural housekeeping; it's a preview of the analytical framework that will be used when your organization is under investigation.
If you're responsible for compliance, you can now conduct the same five-step assessment internally before a DPA does it for you. This checklist translates the EDPB's methodology into a self-audit tool. Use it quarterly, or whenever you're evaluating a new processing activity that carries compliance risk.
What This Checklist Covers
This checklist mirrors the five-step methodology DPAs must follow when deciding on fines under GDPR. It includes: determining if your infringement is fineable, identifying who bears liability, assessing intent or negligence, weighing aggravating and mitigating factors, and evaluating proportionality. The guidelines also clarify how fines interact with other corrective measures like reprimands, orders, and processing bans.
These guidelines are open for public consultation until 13 November 2026, but the framework is already shaping how DPAs approach enforcement decisions. You don't need to wait for the final version to apply this structure internally.
Prerequisites
Before you begin:
- Identify the processing activity or incident you're evaluating. This could be a consent mechanism, a data breach response, a vendor relationship, or a cross-border transfer arrangement.
- Gather your documentation. You'll need records of decisions (Article 30 records, data protection impact assessments, vendor contracts, consent logs).
- Assign accountability. Clarify whether you're acting as controller or processor for the activity in question. This determines who carries liability.
- Know your national implementation. Some member states have enacted additional fining provisions beyond what GDPR specifies. Check your jurisdiction's national law.
Checklist Items
1. Is the infringement fineable under GDPR or national law?
What to check: Review whether the provision you've potentially breached carries an administrative fine under Article 83 GDPR or under your member state's implementing legislation.
Done state: You've confirmed that the specific obligation (e.g., Article 6 lawful basis, Article 13 transparency, Article 32 security) is listed in Article 83(4), 83(5), or 83(6), or is covered by national law that permits fines for this type of infringement.
What good looks like: You can point to the exact paragraph in Article 83 that authorizes a fine for this breach, or cite the relevant section of national law. If the provision isn't fineable, document why and move to evaluating other corrective measures (reprimand, order to cease processing, certification withdrawal).
2. Who is liable for this infringement?
What to check: Determine whether the controller or processor is bound by the breached provision. Some obligations (like lawful basis under Article 6) apply only to controllers. Others (like security measures under Article 32) bind both controllers and processors.
Done state: You've identified the party legally responsible for compliance with the breached provision and documented their role in your processing arrangement.
What good looks like: If you're the controller and the breach involves processor obligations (e.g., failure to maintain processing records under Article 30(2)), you've correctly assigned liability to the processor. If you're the processor and the breach involves controller-only obligations (e.g., failing to establish a lawful basis), you've documented that the controller bears responsibility. Joint controllers share liability according to their respective roles.
3. Was the infringement intentional or negligent?
What to check: The EDPB methodology requires culpability. A fine can't be imposed unless the infringement was committed intentionally or through negligence. Assess whether your organization knew about the obligation and chose not to comply (intentional), or should have known but failed to take reasonable steps (negligent).
Done state: You've documented evidence of intent or negligence, or confirmed that neither applies (in which case a fine isn't warranted under this framework).
What good looks like: You can demonstrate that staff responsible for the processing activity were trained on the relevant GDPR obligations, that internal controls existed to prevent the breach, and that the failure occurred despite reasonable precautions. If the breach resulted from a deliberate decision to delay compliance or ignore guidance, document that as intentional. If it resulted from inadequate training or missing controls, document that as negligent.
4. What aggravating and mitigating factors apply?
What to check: Article 83(2) lists factors DPAs must consider: nature and gravity of the infringement, duration, number of affected data subjects, level of damage, intentional or negligent character, actions taken to mitigate damage, degree of cooperation with the DPA, previous infringements, and financial situation (for natural persons).
Done state: You've systematically evaluated each Article 83(2) factor and documented whether it aggravates or mitigates your exposure.
What good looks like:
- Aggravating: You've identified that the breach involved special category data (Article 9), affected a large number of data subjects, persisted for months after you became aware of it, or occurred despite prior warnings from a DPA.
- Mitigating: You've documented that you self-reported the issue to the DPA, immediately suspended the non-compliant processing, implemented technical fixes within days, offered remediation to affected individuals, and cooperated fully with the investigation.
If the infringement is minor (limited scope, short duration, minimal harm, strong mitigating factors), the EDPB framework suggests a reprimand may replace a fine. If it's not minor, there's a strong presumption that a fine should be imposed.
5. Would a fine be effective, proportionate, and dissuasive?
What to check: Even if the first four steps point toward a fine, DPAs must assess whether imposing one would achieve the regulatory goals of effectiveness, proportionality, and dissuasiveness. This is where specific circumstances of your case matter.
Done state: You've evaluated whether a fine would be redundant (if you've already ceased the processing and implemented controls), disproportionate (if your organization is a small non-profit with limited resources), or ineffective (if the harm can't be undone by financial penalty).
What good looks like: You've documented any reason why a fine might not serve the regulatory purpose. For example: you've already invested significantly in remediation, the processing has been permanently discontinued, or the financial impact would threaten your ability to maintain necessary security controls. If none of these apply, acknowledge that a fine would likely be both proportionate and dissuasive.
Common Mistakes
Treating all GDPR violations as equally fineable. Not every breach triggers Article 83. Some provisions carry only other corrective measures. Check the specific paragraph in Article 83 before assuming a fine is on the table.
Confusing controller and processor liability. If you're a processor, you can't be fined for failing to establish a lawful basis (that's a controller obligation). But you can be fined for inadequate security or unauthorized sub-processing.
Ignoring the intent/negligence requirement. If you can demonstrate that the breach occurred despite reasonable precautions and wasn't the result of deliberate non-compliance or negligence, the EDPB framework suggests a fine may not be appropriate.
Overlooking minor infringement exceptions. The guidelines indicate that minor infringements should generally result in a reprimand rather than a fine. If your breach was limited in scope, duration, and impact, document why it qualifies as minor.
Failing to document mitigating actions. DPAs must consider what you did after discovering the breach. If you self-reported, remediated quickly, and cooperated fully, document it. These factors can shift the outcome from a fine to a warning.
Next Steps
Run this checklist quarterly for high-risk processing activities (Behavioural Advertising, cross-border transfers, automated decision-making, special category data). When you identify gaps in steps 1-4, treat them as compliance priorities before a DPA does the same analysis.
If you're currently under investigation, use this framework to anticipate which corrective measures the DPA is likely to impose. The five-step methodology is now the standard approach across EU member states, so understanding it gives you a preview of the decision-making process.
The public consultation period runs until 13 November 2026. If your organization has encountered edge cases where this methodology creates ambiguity, submit feedback to the EDPB. The final guidelines will shape enforcement for years.




