EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines

Brussels, 21 September – During its latest plenary, the EDPB has adopted guidelines on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR and the final version of its guidelines on the interplay between the Digital Services Act (DSA) and the GDPR. The new EDPB guidelines are a major step in further aligning how Data Protection Authorities decide whether an administrative fine should be imposed, either on its own or alongside other corrective measures. Data Protection Authorities (DPAs) should follow a five-step methodology when deciding whether to impose an administrative fine: The guidelines also provide an overview of the corrective powers within the remit of national DPAs and explain their purpose, scope, and how they relate to one another. The Board also provides 14 practical examples illustrating how DPAs can assess the specifics of a case and decide which corrective measures should be imposed, if any. The guidelines support the consistent application of both legal acts, particularly where DSA provisions concern the processing of personal data by intermediary service providers and refer to concepts and definitions laid down in the GDPR. * These Guidelines replace the WP29 guidelines on the application and setting of administrative fines for the purposes of the Regulation 2016/679 and complement the previously adopted guidelines on the calculation of administrative fines under the GDPR, which rather focus on the methodology for calculating the amount of an administrative fine.

This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.

Read original source