EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines
The European Data Protection Board has adopted two sets of guidelines: one standardizing how national data protection authorities decide when and how to impose fines under the GDPR, and another clarifying how the Digital Services Act and the GDPR interact with each other.
Why this matters: Until now, whether a company got a fine or just a warning depended partly on which country's regulator came knocking. That inconsistency let companies treat enforcement as a geographic lottery. These guidelines push DPAs toward a common framework, so the decision to fine should look less like a local judgment call and more like a predictable rule. The DSA-GDPR overlap guidance matters too — both laws can apply to the same platform behavior, and companies need to know which obligations take precedence and who is responsible for enforcing what.
Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.