The EDPB has released draft guidelines on fining under GDPR. The guidelines address the question of whether to fine rather than the amount of the fine itself, breaking the decision down into five steps:
1. Is the infringement subject to a fine? – Not all infringements lead to a fine.
2. Who is liable for the infringement? – If, for example, controllers and processors are involved, who is at fault?
3. Is the infringement negligent or intentional and what is the outcome of the assessment of the factors listed in Article 83(2)(a)-(k)? – Such as degree of co-operation by the organisation, mitigation/aggravation, adherence to codes etc.
4. Do the aggravating/mitigating factors suggest the infringement is minor? – If this is the case, a fine will usually not be imposed.
5. Would the imposition of an administrative fine be effective, proportionate, and dissuasive in the individual case? – Is there a reason to deviate from standard practice?
The consultation is open until 13 November 2026 and the full draft guidelines can be found here.