Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
EDPB Fine Guidelines: Five Compliance Mistakes You're Already MakingLaws and Regulations
5 min readFor Compliance Managers

EDPB Fine Guidelines: Five Compliance Mistakes You're Already Making

The European Data Protection Board adopted new guidelines on September 17, 2026, outlining a five-step method for data protection authorities to impose administrative fines under GDPR. Many compliance teams think they understand this framework, yet they often make preventable mistakes that can turn minor infractions into hefty penalties.

Here's why these errors persist and how to fix them before your next audit.

Why These Mistakes Keep Happening

The new guidelines don't radically change GDPR enforcement. They formalize what data protection authorities have been doing: evaluating fault, weighing circumstances, and deciding if a fine serves a corrective purpose. The issue isn't complexity; it's that compliance teams treat the framework as a checklist instead of a decision tree.

You're focusing on the wrong question. Instead of asking, "Can we be fined for this?", ask, "What evidence would demonstrate fault if we were investigated?" The five-step method shows how authorities think, yet many organizations overlook steps three and four entirely.

Mistake 1: Assuming Non-Essential Processing Is Low-Risk

Why it happens: Your team classifies Behavioural Advertising and analytics as "non-essential" cookies, requires consent, and considers the matter closed. You've met the technical requirement, so you assume enforcement risk is minimal.

The consequence: When a data protection authority investigates your Consent Management Platform (CMP) configuration, they don't stop at whether you asked for consent. They evaluate whether the processing was intentional and if there was negligence in consent collection. If your CMP shows rejected cookies firing anyway, or if consent records lack detail, you've demonstrated fault under step three of the methodology.

The fix: Audit your CMP's actual behavior, not just its configuration. Use browser developer tools to verify that rejected third-party cookies don't load. Ensure your consent records include timestamps, specific purposes, and withdrawal mechanisms. The guidelines state that fault is a condition for imposing a fine. Your job is to eliminate evidence of negligence.

Mistake 2: Treating Corrective Measures as Separate from Fines

Why it happens: The guidelines list warnings, reprimands, injunctions, processing limitations, and certification withdrawals as distinct corrective measures. Your legal team sees this as a menu of options and assumes minor infractions will only receive warnings.

The consequence: Data protection authorities can impose multiple corrective measures at once. A reprimand doesn't rule out a fine. The guidelines clarify that if an infraction isn't minor, there's a strong presumption of a fine. Assuming you'll get a warning first isn't supported by the methodology.

The fix: Evaluate your processing activities using step four of the framework: aggravating and mitigating circumstances. If you're processing children's data, operating at scale, or have a history of similar infractions, those are aggravating factors. Document your mitigating circumstances proactively: cooperation with authorities, swift remediation, and technical measures that show Data Protection by Design. Don't wait for an investigation to compile this evidence.

Mistake 3: Ignoring the DSA-GDPR Interaction Guidelines

Why it happens: Your organization isn't a Very Large Online Platform, so you assume the Digital Services Act doesn't apply to you. Or you're an intermediary service provider who thinks DSA compliance is separate from GDPR obligations.

The consequence: The finalized guidelines on DSA-GDPR interaction clarify that when DSA provisions concern personal data processing by intermediary service providers, GDPR concepts and definitions apply. If you're an internet access provider, hosting service, or online platform processing user data, you're subject to both frameworks. Treating them as parallel obligations rather than intersecting ones creates compliance gaps.

The fix: Map your DSA obligations to GDPR legal bases for processing. If you're required to collect and retain certain data under DSA, identify whether you're relying on legal obligation (Article 6(1)(c)) or legitimate interests (Article 6(1)(f)) as your legal basis. Ensure your privacy notices explain both the DSA requirement and the GDPR legal basis. This isn't redundant documentation. It's demonstrating that you understand how the frameworks interact.

Mistake 4: Failing to Participate in Public Consultation

Why it happens: The guidelines entered public consultation until November 13, 2026. Your compliance team is already overloaded, and submitting comments feels like optional homework.

The consequence: Public consultation isn't just an opportunity to influence final guidelines. It's a mechanism to clarify ambiguities before they become enforcement precedents. If you operate in a niche sector or have legitimate questions about how the five-step method applies to your processing activities, silence during consultation means you'll be interpreting finalized guidelines with no input on edge cases.

The fix: Identify one specific scenario where the guidelines create uncertainty for your operations. Draft a focused comment that describes the scenario, explains the compliance challenge, and proposes clarification language. You don't need to submit a comprehensive response. A single well-reasoned question can influence how authorities interpret the framework when they investigate organizations like yours.

Mistake 5: Misunderstanding "Effective, Proportionate, and Dissuasive"

Why it happens: Step five of the methodology states that authorities evaluate whether imposing a fine would be effective, proportionate, and dissuasive. Your team interprets this as discretionary leniency.

The consequence: These criteria aren't leniency cards. "Effective" means the fine must correct the behavior. "Proportionate" means it must match the severity of the infraction. "Dissuasive" means it must deter future violations. If your organization has revenue in the hundreds of millions, a €50,000 fine might not be dissuasive. Authorities can and will scale penalties to ensure they meet all three criteria.

The fix: Calculate your maximum potential fine under Article 83(4) and 83(5) before an investigation happens. For most processing violations, that's up to €20 million or 4% of global annual turnover, whichever is higher. Now evaluate whether your current compliance posture would survive scrutiny under the five-step method. If the answer is no, you're not looking at a warning. You're looking at a penalty designed to be dissuasive for an organization your size.

Prevention Checklist

Before your next audit or investigation, verify:

  • CMP behavior matches configuration (rejected cookies don't load)
  • Consent records include timestamps, specific purposes, and withdrawal evidence
  • Processing activities are documented with clear legal bases under GDPR
  • DSA obligations (if applicable) are mapped to GDPR legal bases
  • Privacy notices explain both regulatory requirements and legal bases
  • Mitigating circumstances are documented (cooperation, remediation, technical measures)
  • Aggravating factors are identified and addressed (children's data, scale, repeat infractions)
  • Public consultation opportunities are monitored and used strategically
  • Maximum potential fines are calculated and understood by leadership
  • Compliance posture is evaluated against all five steps of the methodology

The guidelines don't change what you should be doing. They clarify how authorities will evaluate what you've already done. Use that clarity to eliminate evidence of fault before it becomes evidence in an investigation.

Application Security Isn’t Optional Anymore.

You Might Also Like