What Happened
In May 2026, the European Data Protection Board (EDPB) issued Binding Decision 1/2026, resolving a dispute submitted by the Belgian supervisory authority concerning Vlaamse Radio-en Televisieomroeporganisatie (VRT). This decision was accompanied by Guidelines 04/2026, which clarify how data protection authorities should apply administrative fines in relation to other corrective powers under the GDPR.
This case and the accompanying guidelines mark a shift in enforcement philosophy. Data protection authorities (DPAs) are now instructed to use the full range of corrective measures, not just fines, as deterrents. This approach focuses on effectiveness rather than leniency.
Timeline
September 2026: The EDPB published Guidelines 3/2025 on the interplay between the Digital Services Act and GDPR, establishing how overlapping regulatory regimes should coordinate enforcement actions.
May 2026: Binding Decision 1/2026 resolved the Belgian SA's dispute regarding VRT under Article 65 GDPR, demonstrating how cross-border enforcement decisions incorporate the new fines-plus-orders framework.
Current: Guidelines 04/2026 now provide the authoritative framework for how all EU supervisory authorities must balance fines against other corrective powers when addressing GDPR violations.
Which Controls Failed or Were Missing
The new guidance on balancing corrective powers highlights a gap in compliance programs: preparation for enforcement outcomes beyond monetary penalties.
Most compliance teams have focused on avoiding fines. They calculated maximum penalties under Article 83, estimated likelihood based on precedent, and presented financial exposure scenarios to leadership. However, they weren't prepared for supervisory authorities ordering them to rebuild consent infrastructure, suspend processing operations, or undergo mandatory audits.
Your compliance controls might be solid, but your enforcement-response readiness may not be. You've tested your systems against regulatory requirements, but have you planned for a DPA issuing a binding order that requires architectural changes to your CMP or immediate cessation of certain tracking practices?
Consider the VRT dispute. The Belgian SA escalated to the EDPB because the case involved cross-border processing and required coordination among multiple supervisory authorities. The binding decision didn't just impose a fine; it set a precedent for how DPAs must coordinate when issuing corrective orders affecting data subjects across the EU.
What the Relevant Standard Requires
Article 58(2) GDPR grants supervisory authorities eight distinct corrective powers beyond fines:
- Issue warnings for likely infringements
- Issue reprimands for actual violations
- Order compliance with data subject requests
- Order processing operations brought into compliance within a specified timeframe
- Order processing operations limited, suspended, or banned
- Order rectification, erasure, or restriction of processing
- Order certification withdrawal
- Impose temporary or definitive limitations including bans on processing
Article 83 establishes fines as one tool among many, not the default response. The new guidelines make this explicit: DPAs must evaluate which combination of corrective powers will most effectively address the violation and prevent recurrence.
The Guidelines 04/2026 framework requires supervisory authorities to consider:
Effectiveness: Will a fine alone change the controller's behavior, or does the violation require operational changes that only a binding order can enforce?
Proportionality: Does the severity of the violation warrant processing bans, or would a compliance order with monitoring achieve the same outcome?
Deterrence: Will other controllers learn from this enforcement action, and which corrective powers send the clearest signal about what's unacceptable?
For your team, this means Article 58(2) compliance orders are no longer theoretical edge cases. They're becoming standard enforcement outcomes, often paired with fines.
Lessons and Action Items for Your Team
Map your processing operations to potential corrective orders. Don't just identify GDPR risks. Identify which processing operations a DPA could order you to suspend or modify. If your Consent Management Platform fails to meet EDPB Guidelines 05/2020 requirements, what would happen if a supervisory authority ordered you to cease all non-essential cookie placement until you achieve compliant configuration? Do you have the technical capability to execute that order within 48 hours?
Build operational resilience for compliance orders. Create runbooks for rapid processing suspension by category: Behavioural Advertising, cross-context tracking, third-party data sharing. Your incident response plan should include "DPA issues Article 58(2) order" as a scenario alongside "data breach" and "ransomware attack."
Document your corrective-power exposure in risk assessments. When you brief leadership on GDPR risk, present both fine exposure and operational-disruption exposure. The €20 million fine gets attention, but the order to rebuild your consent infrastructure and halt all marketing automation for three months is what will actually cost you revenue.
Prepare for hybrid enforcement outcomes. The Belgian SA's escalation to the EDPB for binding decision signals that complex cases now routinely involve multiple supervisory authorities coordinating enforcement. If you operate across EU member states, you face coordinated corrective orders that could require simultaneous operational changes in multiple jurisdictions.
Review your consent infrastructure against order-worthiness. Ask yourself: if a DPA audited your CMP configuration tomorrow, which violations would warrant a compliance order rather than just a fine? Pre-ticked boxes, missing granularity, asymmetric choice architecture, consent walls for non-essential cookies. These aren't fine-only violations anymore. They're order-worthy failures that could force you offline.
Establish DPA communication protocols. The VRT case went to binding decision because it required cross-border coordination. Your legal team needs clear escalation paths for responding to supervisory authority inquiries that might trigger Article 65 dispute resolution. Delayed or inadequate responses increase the likelihood of corrective orders.
The message from Guidelines 04/2026 is clear: fines are table stakes. The real enforcement risk is operational disruption through binding orders. Prepare accordingly.





