The European Data Protection Board (EDPB) has adopted guidelines for a consultation on when national data protection authorities should impose administrative fines under the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR), alongside or instead of other corrective measures. The guidelines set out a five-step methodology requiring authorities to establish that an infringement is finable, identify the liable party, assess intention or negligence, consider aggravating and mitigating factors, and determine whether a fine would be effective, proportionate and dissuasive. They explain the relationship between fines and measures such as warnings, reprimands, orders, processing limitations or bans, and withdrawal of certification, and include 14 practical examples. The EDPB has also adopted the final guidelines on the interaction between the EU Digital Services Act and the EU GDPR, following consultation, to support consistent application where intermediary services process personal data. The consultation closes on 13 November 2026.