GDPR fines: the EDPB sets a five-step method (17/09/2026)
Before writing an amount, a data protection authority will now have to work through five questions in order. The text is open for public feedback until 13 November 2026. Here is what an SME in the four countries should take from it, and what it can prepare this week.
In brief
On 17 September 2026 the European Data Protection Board (EDPB) adopted guidelines on the power of authorities to impose a GDPR fine, together with the final version of its guidelines on the interplay between the Digital Services Act (DSA) and the GDPR[1][2][4]. The EDPB published the announcement on 21 September 2026 and the French CNIL relayed it on 23 September 2026[1][3]. The part that matters for an SME: before writing an amount, an authority will have to work through a five-step method, and a minor infringement is expected to end in a reprimand rather than a fine[1][3].
The five steps, as written
Guidelines 04/2026 cover the application of the power to impose administrative fines in relation to other corrective powers under the GDPR[2]. They do not set the amount: they deal with the question that comes first, namely whether a fine or another tool is the right response. The authorities agreed on this sequence[1][3]:
- check that the infringement can lead to a fine, relying either directly on the GDPR or on national law;
- determine whether the organisation under investigation may be fined for that infringement, depending on who is bound by the provision breached;
- assess whether the infringement was committed intentionally or negligently — fault is a condition for a fine;
- weigh aggravating and mitigating factors, on the understanding that a minor infringement calls for a reprimand instead;
- check that the fine would be effective, proportionate and dissuasive.
The EDPB adds 14 practical examples and restates the range of other corrective powers: warning, reprimand, order, limitation of processing, withdrawal of a certification[1]. In other words, a fine is not the reflex: it is the last link in a chain the authority has to justify.
One plenary, two different statuses
Two documents came out of the same meeting, and they do not carry the same weight. The fining guidelines are a version 1 open for public feedback until 13 November 2026[1]: the method shows the direction authorities are taking, but it can still change. The DSA–GDPR guidelines are adopted in final form and go through no further consultation[1][4].
Practical consequence: treat the five-step method as a firm orientation, not as settled law. If your sector is affected, the consultation is also a window — a trade association can file a contribution before 13 November 2026.
What it changes for an SME
The argument moves to fault. Step three makes intent or negligence a condition for a fine[1][3]. For an SME, the question in an inspection will no longer be only "did you fail?" but "what had you put in place, and what did you do once you found out?". What defends you there is written down: a maintained record of processing activities, a dated retention policy, a ticket showing the fix, an exchange with the processor.
Minor does not mean invisible. A reprimand is still an authority decision. In the Netherlands it can even be published (see below). An enterprise client auditing you will find it.
The ceilings do not move. Article 83 GDPR keeps its two tiers, up to EUR 10 million or 2% of total worldwide annual turnover, and up to EUR 20 million or 4% depending on the provision breached, whichever is higher[6]. The method frames the decision to fine, not the statutory cap.
The four countries: who decides where you operate
The EDPB brings the national authorities together, but it is your national authority that inspects and sanctions. For the markets CyberNovaLabs.io covers:
| Country | Authority | Country-specific point |
|---|---|---|
| France | CNIL | Relayed the plenary on 23 September 2026[3]; a simplified sanction procedure is in use for low-complexity cases. |
| Belgium | APD / GBA (Data Protection Authority) | Litigation Chamber handles corrective measures; the same five-step method is intended to apply. |
| Netherlands | Autoriteit Persoonsgegevens (AP) | Since 1 September 2026 the AP publishes its enforcement decisions as a matter of principle — fines, orders subject to a penalty payment, processing bans[5]. |
| Luxembourg | CNPD | Competent for controllers established in Luxembourg; same European framework. |
The Dutch shift deserves its own line. The new Article 21b UAVG, in force since 1 September 2026, makes publication the default under an "open, unless" logic[5]. A Belgian or French SME handling data on Dutch customers therefore carries a visibility risk on top of the financial one. If your activity also falls under NIS2, read this alongside our pages on NIS2 in Belgium and our analysis of NIS2 in the Netherlands for transport and logistics: two distinct regimes, two distinct authorities, one organisation facing both.
The most exposed ground: prospecting
In our files, the failures that surface most often in SMEs are not break-ins: they are prospecting lists with no clear legal basis, objection rights handled late, no information given to the person at first contact. Those are exactly the cases where step three is decided — negligence, or a documented process. Our guide to B2B prospecting and the GDPR in France, Belgium and the Netherlands sets out what is accepted country by country, and our B2B appointment setting page describes how we frame that processing for clients. For the technical inventory, our cybersecurity page lists the controls we check first.
- Pull out your record of processing activities and date it. If it has not been touched in twelve months, that is the first thing an authority will look at under step three.
- Take your last three data subject requests (access, objection, erasure) and measure the real response time. The GDPR speaks of one month.
- Check that every prospecting email carries a working opt-out, and test it yourself.
- If you process data on Dutch customers, brief your management on the 1 September 2026 change: an AP decision can now be published by default[5].
- Diary 13 November 2026: the close of the public consultation on Guidelines 04/2026[1]. If your association is contributing, send it your concrete cases.
At CyberNovaLabs.io
We work with SMEs in the Netherlands, Belgium, France and Luxembourg, and we keep seeing the same scene: the measures exist, but nothing is written down, so nothing can be demonstrated on inspection day. Our job is to make that evidence available in an hour instead of three weeks — record kept current, rights requests traced, prospecting process compliant and measurable. If you want to know where you stand before an authority asks, book a meeting with us: we review your processing and tell you plainly what would hold and what would not.
Sources
- CEPD — EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines (21/09/2026)
- CEPD — Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR, adoptées le 17/09/2026
- CNIL — Amendes RGPD et interaction avec le règlement sur les services numériques : retour sur la plénière du CEPD du 17 septembre 2026 (23/09/2026)
- CEPD — Guidelines 3/2025 on the interplay between the DSA and the GDPR (version finale)
- Autoriteit Persoonsgegevens — AP maakt AVG-sancties voortaan verplicht openbaar (01/09/2026)
- Règlement (UE) 2016/679 (RGPD), article 83
Qualified meetings, no lock-in.
Criteria in writing before launch, pay per meeting or monthly, stop with a simple email.
Read next
Data breach at FWB: three weeks before it was confirmed (05/10)
Flagged from outside in mid-September, confirmed on 5 October 2026: the EAD-online.be data breach shows where the GDPR's 72 hours are really lost, and why the weak link is so often a supplier.
Read the article →October 7, 2026 · 7 min readNIS2 France: are hotels and tourism in scope?
Tourist accommodation is absent from the NIS2 annexes, and France's transposition was still in parliament on 7 October 2026. Yet in May 2026 three French tourism operators lost their reservation databases within 72 hours. Here is what actually applies to you.
Read the article →October 6, 2026 · 7 min readDGFiP breach: stolen logins, no MFA, no detection (29/09/2026)
On 29 September 2026 France's cyber agency ANSSI published its incident report on the cyberattacks against the tax administration. No rare technique: passwords stolen from personal computers, a second factor sent by email, sensitive applications reachable without segmentation, and a portal nobody was watching. All four links exist in most SMEs.
Read the article →