Prefer to listen? Click play for AI narration

On 21 September 2026, the European Data Protection Board did something it had never done in GDPR's eight-year history: it told every national data protection authority, in one binding document, exactly how to calculate a fine. Until now, Ireland's DPC, Spain's AEPD, and Germany's sixteen regional regulators could each apply their own logic to the same violation and land on wildly different numbers. That inconsistency is now supposed to be gone.

For a small or mid-sized business, this isn't Brussels housekeeping. A standardised methodology means the fine your local DPA calculates is no longer a matter of which authority you happened to draw β€” it's a formula, applied the same way from Dublin to Warsaw. That's worth understanding before it's tested on you rather than after.

The Five-Step Test, Explained

The EDPB's new guidelines replace the old 2018 WP29 fining guidance with a standardised sequence every DPA must now work through before issuing a penalty. It comes with 14 worked examples covering real-world scenarios, and it's open for public consultation until 13 November 2026 before it's finalised.

5
Mandatory steps in the new test
14
Worked examples published alongside it
€403M
Google's Ireland DPC fine, same week
13 Nov
2026 consultation deadline
StepWhat the DPA now must check
1. Legal permissibilityWhether a fine is legally permitted at all for this particular finding, before any amount is discussed
2. LiabilityWho is legally responsible β€” the controller, the processor, or both β€” and to what extent
3. Intent or negligenceWhether the violation was deliberate, reckless, or an honest process failure β€” this materially changes the starting point
4. Aggravating & mitigating factorsPrior violations, cooperation with the investigation, remediation already taken, and the categories of data involved
5. Proportionality checkA final test that the resulting fine is "effective, proportionate, and dissuasive" β€” not simply the largest number the formula allows

Two things stand out for smaller businesses specifically. First, intent and negligence now sit explicitly at the centre of the calculation β€” meaning a documented, good-faith compliance effort that still fell short is treated differently from processing with no legal basis at all. Second, cooperation and remediation are formal mitigating factors, not just goodwill gestures. A business that self-reports, fixes the gap, and engages constructively with its DPA has a structurally better outcome under this methodology than one that stays silent.

The DSA-GDPR Guidelines Landed the Same Day

At the same plenary, the EDPB also finalised guidelines on how the Digital Services Act and GDPR interact where intermediary service providers handle personal data β€” think marketplaces, app stores, and hosting platforms moderating user content that includes personal data. If your business operates any kind of platform, listing service, or user-generated-content feature, this is the guidance that now governs which rulebook applies when the two overlap. Most SMBs won't be directly in scope, but any business selling through a marketplace or embedding third-party UGC widgets should check whether its platform partner's compliance posture has shifted.

Why the Timing Matters: A €403 Million Case Study, Same Week

Two days before the EDPB adopted its new methodology, Ireland's DPC closed a six-year inquiry into Google's Web & App Activity, Location History, and Location Accuracy features with a €403 million fine β€” one of the largest single GDPR penalties issued to date. The finding wasn't a dramatic breach: it was unlawful and unfair processing, inadequate transparency, and excessive retention of location data collected between May 2018 and February 2020. Google now has six months to bring its processing into compliance.

No hack, no leak, no dark pattern. Just data kept longer than the purpose required, and a notice that didn't say enough about it β€” the two failure modes that show up most often in DPA findings against businesses of every size.

That combination β€” excessive retention plus thin transparency β€” is exactly the kind of finding the new five-step test is built to standardise a penalty for. It's a useful preview of what "documented, proportionate processing" is now being measured against across the whole EU, not just for a company the size of Google.

πŸ“‹
GDPRGard Toolkit
Retention and transparency are step-one fixes, not six-year investigations

Editable DPA pack, SAR response toolkit, and Article 30 RoPA register β€” the documents that demonstrate exactly the "intent," "mitigation," and "remediation" factors the new methodology weighs in your favour. €39–€59 each or €99 for all three.

Get the Templates β†’

What to Actually Do Right Now

  1. Check your data retention schedule against your stated purpose. The single fastest way to fail the new test's proportionality step is retaining data past the point your privacy notice says you would. If you don't have a written retention schedule, that's the first document to write.
  2. Make sure your privacy notice matches what you actually collect and keep. Transparency failures are the second half of nearly every major 2026 fine, including Google's. A notice that was accurate in 2018 and hasn't been revisited since is a liability, not a formality.
  3. Document your compliance effort, not just your compliance state. Under the new methodology, a demonstrable good-faith process β€” audits run, gaps logged, fixes tracked β€” is a mitigating factor if something still goes wrong. An undocumented "we're basically fine" posture gets none of that credit.
  4. Submit feedback or watch the consultation if this affects your sector. The methodology is open for public comment until 13 November 2026 β€” trade bodies and industry groups are the usual channel for SMB input on exactly this kind of enforcement-shaping guidance.
  5. Run a quick self-check now rather than after a notification lands. Our free 30-second audit flags the retention and transparency gaps that show up most often in DPA findings.

The Bottom Line

A harmonised fining methodology cuts both ways. It removes the lottery of which DPA happens to investigate you, but it also means every authority in the EU is now working from the same playbook β€” and that playbook explicitly rewards documented, good-faith compliance over silence. The businesses best positioned under this new test are the ones that can show their work: what they collect, why, for how long, and what they did when they found a gap. That's a lower bar than perfect compliance, and a much more achievable one before 13 November.

Book a free consultation with GDPRGard β†’

Sources

Share this article

Also read:

⚠️ This article is for informational purposes only and does not constitute legal advice. For complex compliance situations, consult a qualified data protection professional. GDPR and EU AI Act requirements are subject to ongoing regulatory guidance β€” verify current obligations with your legal adviser.