On 21 September 2026, the European Data Protection Board did something it had never done in GDPR's eight-year history: it told every national data protection authority, in one binding document, exactly how to calculate a fine. Until now, Ireland's DPC, Spain's AEPD, and Germany's sixteen regional regulators could each apply their own logic to the same violation and land on wildly different numbers. That inconsistency is now supposed to be gone.
For a small or mid-sized business, this isn't Brussels housekeeping. A standardised methodology means the fine your local DPA calculates is no longer a matter of which authority you happened to draw β it's a formula, applied the same way from Dublin to Warsaw. That's worth understanding before it's tested on you rather than after.
The Five-Step Test, Explained
The EDPB's new guidelines replace the old 2018 WP29 fining guidance with a standardised sequence every DPA must now work through before issuing a penalty. It comes with 14 worked examples covering real-world scenarios, and it's open for public consultation until 13 November 2026 before it's finalised.
| Step | What the DPA now must check |
|---|---|
| 1. Legal permissibility | Whether a fine is legally permitted at all for this particular finding, before any amount is discussed |
| 2. Liability | Who is legally responsible β the controller, the processor, or both β and to what extent |
| 3. Intent or negligence | Whether the violation was deliberate, reckless, or an honest process failure β this materially changes the starting point |
| 4. Aggravating & mitigating factors | Prior violations, cooperation with the investigation, remediation already taken, and the categories of data involved |
| 5. Proportionality check | A final test that the resulting fine is "effective, proportionate, and dissuasive" β not simply the largest number the formula allows |
Two things stand out for smaller businesses specifically. First, intent and negligence now sit explicitly at the centre of the calculation β meaning a documented, good-faith compliance effort that still fell short is treated differently from processing with no legal basis at all. Second, cooperation and remediation are formal mitigating factors, not just goodwill gestures. A business that self-reports, fixes the gap, and engages constructively with its DPA has a structurally better outcome under this methodology than one that stays silent.
The DSA-GDPR Guidelines Landed the Same Day
At the same plenary, the EDPB also finalised guidelines on how the Digital Services Act and GDPR interact where intermediary service providers handle personal data β think marketplaces, app stores, and hosting platforms moderating user content that includes personal data. If your business operates any kind of platform, listing service, or user-generated-content feature, this is the guidance that now governs which rulebook applies when the two overlap. Most SMBs won't be directly in scope, but any business selling through a marketplace or embedding third-party UGC widgets should check whether its platform partner's compliance posture has shifted.
Why the Timing Matters: A β¬403 Million Case Study, Same Week
Two days before the EDPB adopted its new methodology, Ireland's DPC closed a six-year inquiry into Google's Web & App Activity, Location History, and Location Accuracy features with a β¬403 million fine β one of the largest single GDPR penalties issued to date. The finding wasn't a dramatic breach: it was unlawful and unfair processing, inadequate transparency, and excessive retention of location data collected between May 2018 and February 2020. Google now has six months to bring its processing into compliance.
No hack, no leak, no dark pattern. Just data kept longer than the purpose required, and a notice that didn't say enough about it β the two failure modes that show up most often in DPA findings against businesses of every size.
That combination β excessive retention plus thin transparency β is exactly the kind of finding the new five-step test is built to standardise a penalty for. It's a useful preview of what "documented, proportionate processing" is now being measured against across the whole EU, not just for a company the size of Google.
Editable DPA pack, SAR response toolkit, and Article 30 RoPA register β the documents that demonstrate exactly the "intent," "mitigation," and "remediation" factors the new methodology weighs in your favour. β¬39ββ¬59 each or β¬99 for all three.
What to Actually Do Right Now
- Check your data retention schedule against your stated purpose. The single fastest way to fail the new test's proportionality step is retaining data past the point your privacy notice says you would. If you don't have a written retention schedule, that's the first document to write.
- Make sure your privacy notice matches what you actually collect and keep. Transparency failures are the second half of nearly every major 2026 fine, including Google's. A notice that was accurate in 2018 and hasn't been revisited since is a liability, not a formality.
- Document your compliance effort, not just your compliance state. Under the new methodology, a demonstrable good-faith process β audits run, gaps logged, fixes tracked β is a mitigating factor if something still goes wrong. An undocumented "we're basically fine" posture gets none of that credit.
- Submit feedback or watch the consultation if this affects your sector. The methodology is open for public comment until 13 November 2026 β trade bodies and industry groups are the usual channel for SMB input on exactly this kind of enforcement-shaping guidance.
- Run a quick self-check now rather than after a notification lands. Our free 30-second audit flags the retention and transparency gaps that show up most often in DPA findings.
The Bottom Line
A harmonised fining methodology cuts both ways. It removes the lottery of which DPA happens to investigate you, but it also means every authority in the EU is now working from the same playbook β and that playbook explicitly rewards documented, good-faith compliance over silence. The businesses best positioned under this new test are the ones that can show their work: what they collect, why, for how long, and what they did when they found a gap. That's a lower bar than perfect compliance, and a much more achievable one before 13 November.
Book a free consultation with GDPRGard β
Sources
- European Data Protection Board β EDPB Harmonises Fining Methodology and Adopts Final DSA-GDPR Guidelines
- Irish Data Protection Commission β DPC Fines Google β¬403 Million Following Inquiry into Google's Processing of Location Data
- CMS GDPR Enforcement Tracker
Also read:
- GDPR in 2026: record fines, a reform in motion, and what to do now
- GDPR & AI fines: the cases that matter for your business
- Inside the EU's Digital Omnibus: what's actually changing for GDPR