The European Data Protection Board adopted Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR on 17 September and announced them on 21 September. The document sets a five-step method for deciding whether a breach should end in a fine, a reprimand, or another corrective measure, backed by 14 worked examples. One of them is a martech scenario: a tracking pixel, a function in the platform’s developer tool that overrode the SME’s own settings, and an Article 32 security failure that the supervisory authority in the example rated minor. Public consultation runs until 13 November 2026, so none of this is final yet.
The Five-Step Method for Deciding on a Fine
The guidelines walk supervisory authorities through the same sequence every time:
- Check that the infringement can support a fine under the GDPR or national law.
- Establish who may be fined, controller or processor, depending on which one is bound by the breached provision.
- Confirm the conduct was intentional or negligent: “a culpable infringement is a condition for the imposition of an administrative fine.”
- Weigh the Article 83(2) factors to decide whether the infringement is minor.
- Ask whether a fine would be effective, proportionate and dissuasive, a step where the authority may still deviate from its general practice.
GRC Report sums up the fourth step this way: “A minor infringement will generally not attract a fine and may instead result in a reprimand.” The guidelines replace the WP29 fining guidelines and complement the separate Calculation Guidelines, which cover fine amounts.
What Do the EDPB Fine Guidelines Change?
If the Article 83(2) factors show an infringement is minor, the EDPB’s Guidelines 04/2026 say a fine should generally not be imposed and a reprimand may be issued instead; if the infringement is not minor, the guidelines set a “strong presumption” that a fine follows. The guidelines are open for public consultation until 13 November 2026, so the five-step method is still a draft, not a final text.
Example 7: A Pixel, a Vendor Setting, and 50,000 Users
Among the EDPB’s 14 worked examples, Example 7 is titled “Failure to implement systematic procedures for third-party tracking tools”. An SME used a tracking pixel from a social media provider on a webpage for “a service used for video conferencing meetings between businesses and their customers”, and the pixel sent the hashed emails and phone numbers of roughly 50,000 users to the platform over a two-year period. The transfer happened “because a certain technical function was activated in the social media provider’s developer tool, which took precedence over the data protection settings the organisation had configured in its own Customer Data Platform.” The SME “lacked the systematic procedures required to identify such unintentional changes,” and the incident “was only discovered following a report from a third party.”
The example lists several mitigating facts together. The authority noted that “the transferred data was hashed, and thus unusable”, that it did not include special-category data or information about the meetings, that the SME had other measures in place limiting the scope of collection, and that there was no uncontrolled public disclosure. On those combined facts it rated the Article 32(1) infringement minor and issued a reprimand under Article 58(2)(b), not a fine. Hashing is not always part of the picture in pixel setups: the ChatGPT measurement pixel ships four of its nine fields unhashed.
Why “Minor” Doesn’t Stay Minor
A minor rating isn’t permanent. Example 5 describes a recruitment agency that kept emailing people after they exercised their right to erasure; a first reprimand followed two complaints, then three more similar complaints arrived, and the example concludes: “Considering the recurring nature of the infringement the supervisory authority deemed that the infringement could no longer be considered minor and fined the controller.” In Example 10, a small telecom answered a data subject’s request for information a month late; the authority at first considered the infringement minor and a reprimand appropriate, but while handling that complaint it found further identical cases and initiated administrative fine proceedings, reasoning that “the accumulation of many cases suggests that the delayed response is not an exception, but rather a fundamental problem or pattern”.
Real security failures don’t always land as gently as Example 7. The Irish DPC’s decision on Permanent TSB over contact-centre security and 72-hour breach notification ended in a €277,500 fine. Example 7’s minor rating rests on the example’s full set of facts, not on hashing alone.
“The new EDPB guidelines are a major step in further aligning how Data Protection Authorities decide whether an administrative fine should be imposed, either on its own or alongside other corrective measures. The GDPR significantly increased the corrective powers of DPAs, with fines serving as an important instrument for effective enforcement. The guidelines reaffirm our commitment to providing greater clarity and ensuring the consistent application of the GDPR across Europe.”
— Jelena Virant Burnik, Deputy Chair, EDPB
The same plenary finalised the EDPB’s separate DSA-GDPR interplay guidelines after their own consultation. The fining guidelines stay open for comment until 13 November 2026; until then, Example 7 shows how the EDPB proposes to weigh a vendor-side setting change, not a settled rule.
