Regulatory  ·  2026-09-25

EDPB adopts Guidelines 04/2026 harmonising GDPR administrative-fine decisions (five-step test)

RegulatoryMedium impactEuropean Union
At its plenary of 21 September 2026 (reported 22-23 September), the European Data Protection Board adopted Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR, and finalised its guidelines on the DSA–GDPR interplay. The fining guidelines replace the seven-year-old Article 29 Working Party guidance and set a single five-step test every national DPA must follow when deciding whether to fine, with 14 worked examples; public consultation runs to 13 November 2026.
This is the enforcement-framework layer under which AI-related GDPR breaches (agents mishandling personal data, unlawful profiling, AI voice/bot deception) will be sanctioned across all 27 DPAs. It makes the 'fine vs other corrective power' decision predictable and harmonised — directly relevant to organisations facing AI-data-protection investigations, including the growing agentic-AI breach caseload.
Organisations facing or anticipating GDPR enforcement over AI systems should map the five-step fining test into their risk posture; stakeholders can submit comments to the EDPB consultation by 13 November 2026.
Insight EU — EDPB sets five-step test for GDPR finesObsidian Regulatory Intelligence — EDPB harmonises GDPR fining powersEuropean Data Protection Board (EDPB) home
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →