When Will GDPR Breaches Lead to Fines? Insights from the EDPB’s New Draft Guidelines
The European Data Protection Board (the “EDPB”) has published draft Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR for public consultation. The guidelines aim to harmonise the methodology for determining whether an administrative fine should be imposed in addition to, or instead of, other corrective measures available to data protection authorities (“DPAs”) under Article 58(2) GDPR and complement previous EDPB guidelines on the calculation of administrative fines. In addition to setting out the methodology that the EDPB proposes should be followed by DPAs, the guidelines also contain some noteworthy indications of how DPAs are likely to deal with organisations believed to have infringed the GDPR.
The guidelines set out a five-step methodology that DPAs should follow when determining whether an administrative fine should be imposed.
STEP ONE: Check that the established infringement can lead to an administrative fine.
STEP TWO: Establish that the party under investigation can be fined for the infringement in question.
STEP THREE: Assess whether the infringement was committed intentionally or negligently, since a culpable infringement is a precondition for the imposition of an administrative fine (albeit the EDPB asserts that the threshold for negligence is very low).
STEP FOUR: Establish whether aggravating or mitigating factors indicate that the infringement is minor since, as a general rule, an administrative fine will not be imposed in the case of a minor infringement.
STEP FIVE: Assess whether the imposition of an administrative fine would be effective, proportionate and dissuasive in the individual case in accordance with Article 83(1) GDPR.
In setting out this methodology, the EDPB addresses some mistaken assumptions that some organisations might make. Below, we highlight four takeaways from the draft guidelines that organisations should have on their radar.
Legal Advice Is Not a Shield Against Liability
One significant aspect of the guidelines is the EDPB's treatment of legal advice as a factor in assessing negligence. Through a series of worked examples (examples 4a–c at pages 18-19), the EDPB makes it clear that obtaining a legal opinion does not, by itself, exculpate a controller from a finding of negligent infringement. Where contrary positions were available from data protection authorities, EDPB guidance, or mainstream legal commentary, a controller is expected to have appreciated that a particular processing activity was legally questionable, regardless of whether external counsel advised otherwise.
The message is clear that organisations cannot "blindly" rely on legal advice as a proxy for compliance. A legal opinion favouring supporting a particular approach is not an insurance policy. Controllers must be able to demonstrate genuine engagement with their obligations under the GDPR, including awareness of the broader regulatory landscape and any divergent interpretive positions. For businesses, this reinforces the importance of making informed decisions grounded in a real understanding of the rules and their interpretation, rather than treating outside counsel's sign-off as a “shield” from potential liability.
A Clean Track Record is an Expectation, not a Bonus
The guidelines also dispel any assumption that a record of previous compliance will count in an organisation's favour when things go wrong. At paragraph 88 page 25 of the Guidance, the EDPB states explicitly that "the mere absence of previous infringements … cannot, in itself, be considered a mitigating factor, as compliance with the GDPR is the norm." In other words, not having been fined before is simply the baseline expectation and so earns no credit if infringement arises.
The same logic is applied to cooperation with DPAs. Ordinary cooperation under Article 31 GDPR is a legal obligation, not a discretionary act, and therefore carries no weight in mitigation. Only cooperation that goes above and beyond what the law requires may be treated as a mitigating circumstance. Where cooperation has the effect that negative consequences on the rights of data subjects did not occur, this could be a mitigating factor.
Compliance with legal obligations is a baseline expectation and not something that will earn an organisation any leniency.
Group Liability and the TikTok Preliminary Reference
The guidelines state (at paragraph 45, page 15) that national law may extend liability for the payment of GDPR fines to parent companies, successors, and other group affiliates.
Questions in relation to the extent to which, and in what manner, DPAs may have regard to a parent entity’s revenue in calculating the size of fines are currently before the CJEU, having been referred by the Irish High Court in the context of TikTok’s challenge to the DPC’s imposition of a €530 million fine for the transfer by TikTok of EEA users’ personal data to China, which was calculated by reference to the wider ByteDance group's turnover. The questions before the CJEU include asking whether a DPA may have regard to a parent entity's revenue when calculating the size of a fine imposed on a subsidiary, without imputing liability for the underlying GDPR infringement to that parent, and whether the parent is entitled to its own right to be heard in the proceedings.
Organisations operating through a multi-entity group structure will be watching this CJEU reference closely in terms of what it means for the calculation of fines going forward.
Controller Liability for Processor Conduct
The guidelines underscore the EDPB’s view that a controller's exposure is not confined to the acts of its own employees and that the principle of direct corporate liability extends to any other person acting in the course of their business and on the controller’s behalf, including a controller's processors, unless the processor acted so far outside its instructions that it was effectively processing data for its own purposes or in a manner the controller cannot reasonably be taken to have authorised.
Even in that scenario, a controller may still face separate liability under Article 32 GDPR for failing to implement adequate technical and organisational security measures, including measures that might have prevented or detected the processor's unauthorised conduct. Given the volume of data processing now outsourced to third-party service providers, this guidance carries significant practical weight for businesses. Organisations should consider whether their processor agreements, audit rights, and due diligence of vendors are sufficiently robust having regard to the risk that a processor's breach may result in a fine for the controller.
What This Means for Your Organisation
The EDPB guidelines are still in draft and are open for public consultation until 13 November 2026. Even in draft form they provide valuable guidance for organisations in terms of what may or may not give rise to an administrative fine and circumstances in which a fine may be avoided or mitigated. They may help inform an organisation’s approach to negotiating contracts involving the processing of personal data with third parties and strategic decisions regarding the processing of personal data.
Also contributed to by Gabrielle Wall
This content has been prepared by McCann FitzGerald LLP for general guidance only and should not be regarded as a substitute for professional advice. Such advice should always be taken before acting on any of the matters discussed.


Select how you would like to share using the options below