The European Data Protection Board (EDPB) has adopted a five-step method for administrative fines, prompting a critical question for your team: should every GDPR violation result in a financial penalty? The answer influences how you allocate compliance resources, report incidents, and interpret supervisory authority actions.
The question at hand
When you identify a potential violation, the immediate question isn't just "did we breach?" but "will this result in a fine?" The EDPB's new guidelines formalize a framework for deciding whether to impose a penalty, issue a reprimand, or require corrective action without financial consequences. This matters because your internal response depends on which outcome you're preparing for.
The case for presuming fines
Some argue that you should assume every violation will result in a fine. The EDPB's method creates a strong presumption that fines will be imposed for non-minor infringements. If you can't demonstrate that a violation is minor, you're likely facing financial exposure.
This approach has practical benefits. Your incident response becomes more rigorous when you assume financial consequences. Documentation improves because you're building a defense from the start. Remediation happens faster because leadership understands the stakes in monetary terms.
The framework supports this view. Step three requires supervisory authorities to establish that a violation was intentional or negligent before imposing a fine. Most violations stem from process failures or insufficient oversight, often classified as negligent. If you failed to implement appropriate measures or processed data without a compatibility assessment, you were negligent.
Step four's aggravating and mitigating factors also lean toward enforcement. Factors like the categories of data subjects affected and the degree of cooperation determine fine amounts, not whether a fine is warranted. By the time you're discussing mitigation, you're already in penalty territory.
For governance leads, this means investing in controls that prevent violations entirely, because remediation rarely eliminates financial exposure. Document your compliance program comprehensively to demonstrate a good faith effort to reduce the final amount.
The case for proportionate enforcement
Others believe supervisory authorities have the discretion to use corrective measures other than fines, especially for first-time violations or when controllers demonstrate genuine cooperation.
The EDPB guidelines list alternative corrective measures: warnings, reprimands, processing limitations, certification withdrawals. These exist because Article 58(2) gives supervisory authorities a range of powers, emphasizing enforcement that is "effective, proportionate and dissuasive." Proportionality doesn't mean "always maximum penalty."
Step four's evaluation of minor character provides a genuine off-ramp. If your violation is minor, the guidelines state there will "generally" be no fine. A reprimand may be issued instead. Supervisory authorities issue warnings and reprimands regularly, particularly when the controller self-reported, immediately remediated, and the impact on data subjects was negligible.
The guidelines include 14 practical examples illustrating how supervisory authorities evaluate cases. Enforcement is contextual, not mechanical. A controller that discovers an unauthorized disclosure, notifies the supervisory authority within hours, implements technical controls to prevent recurrence, and voluntarily notifies affected data subjects demonstrates a different compliance posture than one that waits for a complaint.
This perspective leads to different resource decisions. Invest in detection and response capabilities, not just prevention. Build relationships with your supervisory authority through transparency and cooperation. Develop escalation protocols that prioritize speed and candor over legal defensiveness.
Where practitioners actually land
Most governance teams operate between these approaches. You treat violations seriously but calibrate your response based on the violation's characteristics.
For processing without a valid lawful basis or failures to implement appropriate measures, assume financial exposure. These aren't edge cases, they're core obligations. The violation signals systemic weakness.
For transparency obligations or procedural requirements where you can demonstrate immediate remediation and minimal data subject impact, focus on documentation and cooperation. You're building the record that supports a warning or reprimand rather than a fine.
The five-step method enables this calibration. Step five requires supervisory authorities to assess whether imposing a fine would be effective, proportionate, and dissuasive. If you've implemented comprehensive corrective measures, demonstrated they're working, and shown that your compliance program has matured, you're providing evidence that a fine isn't necessary to achieve regulatory objectives.
Our take
The EDPB's framework doesn't resolve whether every violation should result in a fine, because there's no universal answer. The guidelines formalize what experienced practitioners already knew: enforcement depends on violation severity, controller conduct, and regulatory context.
Your compliance strategy should reflect this reality. Build controls that prevent violations, but invest equally in detection and response. When violations occur, evaluate them using the five-step method from the supervisory authority's perspective. Is this violation minor? Was it negligent? What aggravating factors exist? What have you already done to remediate?
The consultation period running until November 13, 2026, offers an opportunity to review these guidelines against your actual violation history. Map past incidents to the five-step framework. Where would you have landed under this methodology? That analysis will tell you whether your current approach to compliance risk is calibrated correctly or whether you're over-investing in unlikely scenarios or under-preparing for probable ones.
The guidelines won't eliminate enforcement uncertainty, but they provide the clearest picture yet of how supervisory authorities will exercise their discretion. Use that clarity to make better decisions about where your compliance resources actually matter.





