EDPB Plenary — Draft Fining Methodology and Final DSA-GDPR Guidelines
At its 21 September 2026 plenary, the European Data Protection Board adopted two materially significant outputs:
Guidelines 04/2026 on administrative fines. The guidelines set out a five-step methodology for deciding whether to impose a GDPR fine and, if so, how to determine the amount. The steps cover: (1) whether the infringement is punishable by a fine; (2) whether the controller or processor can be sanctioned; (3) whether the infringement was committed intentionally or negligently; (4) the seriousness of the infringement; and (5) aggravating or mitigating circumstances. The guidelines include worked examples covering common infringement scenarios. They are open for public consultation until 13 November 2026.
Final Guidelines 03/2025 on the interplay between the DSA and the GDPR. Following the public consultation that closed on 31 October 2025, the EDPB adopted the final version of its guidelines on how the Digital Services Act and the GDPR apply together for platforms and intermediary services.
What it means for you
For any organisation processing personal data in the EU, the draft Guidelines 04/2026 are the closest the EDPB has come to a harmonised fine framework. The five-step test and its worked examples are now the practical reference points for assessing fine exposure and for understanding how a supervisory authority will decide between a fine and another corrective measure. If your organisation also operates an online platform, hosting service, or other intermediary caught by the DSA, the final Guidelines 03/2025 clarify which obligations run in parallel and which regime takes the lead for a given processing activity.
Sources
- EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines — EDPB (21.09.2026)
- Guidelines 04/2026 on the application of the power to impose administrative fines — EDPB (21.09.2026)
GPAI — No Verified Change in the 15–21 September Window
No new EU AI Act guidelines, delegated acts, harmonised standards, or confirmed enforcement decisions for GPAI providers were published during the 15–21 September 2026 monitoring window. The AI Office's Article 91 Requests for Information campaign to GPAI model providers remains ongoing; no investigation decision or financial penalty has been issued to date.
What it means for you
If you provide a general-purpose AI model (Article 3(63)), your immediate obligation is unchanged: maintain complete Article 53(1)(a)–(d) documentation. If you have built an AI system by integrating a third-party GPAI model API, your organisation is a downstream system provider of that AI system under Article 3(3) — not a deployer of the upstream GPAI model — and should continue to verify that you hold, and have date-stamped, the Article 53(1)(b) documentation from your upstream provider.
Sources
- Commission starts enforcing AI Act rules and new transparency requirements — 2 August 2026 — European Commission (02.08.2026)
- GPAI Model Obligations in Force and Final GPAI Code of Practice in Place — Latham & Watkins (10.07.2025)
ISO/IEC 42001 — No Verified Change in the 15–21 September Window
No new ISO/IEC 42001 editions, supplementary standards, or national transpositions beyond those already reported in prior weeks were confirmed during the 15–21 September 2026 monitoring window. ISO/IEC 42001:2023 remains the current base document.
What it means for you
If your organisation is working towards ISO/IEC 42001 certification, nothing changed this week. The standard does not confer AI Act presumption of conformity — no Official Journal citation has been issued. Certification remains optional and does not substitute for the AI Act's own Article 17 quality management obligations.
Sources
- ISO/IEC 42001:2023 — ISO (18.12.2023)
- ISO/IEC 42006:2025 — ISO (08.07.2025)
What to do this week
- Review the EDPB's draft Guidelines 04/2026 on fining methodology and assess whether your GDPR compliance programme reflects the five-step test and its worked examples.
- If your organisation operates a platform or intermediary service under the DSA, read the final EDPB Guidelines 03/2025 on DSA-GDPR interplay and map overlapping obligations.
- Consider submitting a response to the EDPB consultation on Guidelines 04/2026 before 13 November 2026.
- GPAI providers: maintain complete Article 53(1)(a)–(d) documentation in light of the ongoing Article 91 RFI campaign.
- Downstream system providers (Article 3(3)) integrating third-party GPAI models: verify you have received, retained, and date-stamped Article 53(1)(b) documentation from your upstream provider.
- No action is required on ISO/IEC 42001 this week.
Quick reference
| Topic | Change | Action |
|---|---|---|
| GDPR | EDPB adopts draft fining methodology (04/2026, five-step test with worked examples; consultation to 13 Nov 2026) and final DSA-GDPR Guidelines 03/2025 | Review fine-exposure models; platform operators map DSA-GDPR interplay; consider consultation response |
| EU AI Act — GPAI | No verified change; AI Office Article 91 RFI campaign continues | Maintain Art. 53 documentation; downstream providers retain Art. 53(1)(b) documentation |
| ISO/IEC 42001 | No verified change; ISO/IEC 42001:2023 remains current | No immediate action |
Every source in this issue
- EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines — EDPB (21.09.2026)
- Guidelines 04/2026 on the application of the power to impose administrative fines — EDPB (21.09.2026)
- Commission starts enforcing AI Act rules and new transparency requirements — 2 August 2026 — European Commission (02.08.2026)
- GPAI Model Obligations in Force and Final GPAI Code of Practice in Place — Latham & Watkins (10.07.2025)
- ISO/IEC 42001:2023 — ISO (18.12.2023)
- ISO/IEC 42006:2025 — ISO (08.07.2025)
Compiled by Relay Labs Ltd from the sources above, which remain the authoritative text. General information about EU law, not legal advice.
The EU AI governance brief
One email a week. Sourced and dated. Unsubscribe in one click, from any of them.
Relay Labs Ltd is the controller. Your address is used to send you this brief and nothing else. Privacy notice.