Alessandro Del Ninno
News
EDPB Guidelines 04/2026: when supervisory authorities should impose gdpr administrative fines and when other corrective measures may apply.
DATA PROTECTION
21/09/2026

The European Data Protection Board (EDPB) has adopted the new Guidelines 04/2026 on the exercise of the power to impose administrative fines in relation to the other corrective powers provided for under the GDPR, which were subsequently published for public consultation from 21 September to 13 November 2026.

The document addresses an issue that is distinct from the mere calculation of the amount of fines: it clarifies when a Data Protection Authority should impose an administrative fine and when, instead, it may rely on other corrective powers under Article 58(2) GDPR, such as warnings, reprimands, orders to bring processing operations into compliance, restrictions or bans on processing, and the withdrawal of certifications. On this point, the new Guidelines replace the previous guidance of the Article 29 Working Party and complement the Guidelines 04/2022, which concern the methodology for calculating the amount of administrative fines.

The objective is to promote greater consistency in enforcement across the European Union through a five-step methodology.

irst, the Supervisory Authority must verify that the infringement identified is in fact punishable by an administrative fine under the GDPR or, where permitted, under national law. It must then determine which entity may be held liable – for example, the controller, processor, certification body or monitoring body – and establish that the infringement was committed intentionally or negligently. Only after completing these preliminary assessments does the Authority consider, on the basis of the criteria laid down in Article 83(2) GDPR, whether the infringement may be classified as “minor” and, finally, whether the imposition of an administrative fine would be effective, proportionate and dissuasive in the circumstances of the particular case.

Of particular relevance to businesses is the clarification concerning corporate liability. Referring to the case law of the Court of Justice, the EDPB states that controllers and processors may be held directly liable for infringements committed by directors, employees or other persons acting within the scope of the organisation’s activities and on its behalf: it is not necessary to establish that the management body was aware of the conduct, nor is it necessarily required to identify the individual natural person to whom the infringement may materially be attributed.

The Guidelines also devote particular attention to the requirement of fault. At least negligent conduct must be established before an administrative fine may be imposed, but the threshold identified by the EDPB is relatively low: the relevant question is whether the entity was in a position to be aware of the unlawfulness of its conduct and ought to have been aware of it had it exercised the ordinary degree of diligence required in the circumstances. Mere ignorance of the applicable legal framework is therefore not sufficient to exclude negligence.

Nor does the existence of an internal or external legal opinion automatically have exculpatory effect. Among the examples set out in the Guidelines, the EDPB considers that negligence may still be established where an undertaking has followed legal advice that departs from settled or well-known guidance issued by the Supervisory Authority or from established legal doctrine; similarly, undocumented external advice, or advice based on incomplete information, is not in itself sufficient to exclude liability.

A central part of the Guidelines concerns the distinction between minor and non-minor infringements. The Supervisory Authority must carry out an overall assessment of the aggravating and mitigating factors referred to in Article 83(2), taking into account, inter alia, the nature, gravity and duration of the infringement, the number of data subjects affected, the damage suffered, the degree of fault, the measures taken to mitigate the consequences, previous infringements, the degree of cooperation with the Authority, the categories of data concerned and any financial benefits obtained.

Where an infringement is classified as minor, the general rule identified by the EDPB is that no administrative fine should be imposed and that another corrective measure, such as a reprimand, may instead be appropriate. This is not, however, an automatic rule: depending on the specific circumstances, a fine may still be imposed for a minor infringement. Conversely, where the infringement is not minor, the Guidelines identify a strong presumption – and, in general terms, the rule – in favour of imposing an administrative fine, without prejudice to the Authority’s ability to decide otherwise where required by the principles of effectiveness, proportionality and dissuasiveness. In exceptional circumstances, it may even be unnecessary to exercise any corrective power at all.

The EDPB further emphasises that compliance measures already required under the GDPR do not automatically qualify as mitigating factors. When assessing the degree of responsibility, the Authority will instead consider whether the controller or processor did what could reasonably be expected in light of the nature, purposes and scale of the processing, and whether the measures implemented under Articles 24, 25 and 32 GDPR effectively reduced the residual risks to data subjects.

The conduct adopted after the infringement is also relevant. Prompt mitigation of the damage, effective cooperation with the Supervisory Authority and the voluntary adoption of measures capable of preventing recurrence may influence the overall assessment. Conversely, the existence of previous infringements – particularly infringements of the same type – or the repetition of conduct initially capable of being classified as minor may reveal a systemic organisational deficiency and make the imposition of a fine more likely.

rom an operational perspective, the Guidelines 04/2026 therefore reinforce the importance of effective and demonstrable GDPR compliance. For businesses, it becomes particularly important to be able to demonstrate not only the formal existence of policies and procedures, but also the effective implementation of accountability measures; to retain evidence of legal assessments and decisions taken; to document the consideration and implementation of the DPO’s recommendations; to maintain procedures for the prompt remediation of infringements; and to monitor any previous incidents or recurring compliance weaknesses that could cause isolated events to be regarded as evidence of structural organisational shortcomings.

The new Guidelines therefore complete the EDPB’s framework on administrative fines: the Guidelines 04/2022 explain how the amount of a fine should be calculated, whereas the Guidelines 04/2026 address when such a fine should be imposed in relation to the other corrective measures available to Supervisory Authorities.