A GDPR Infringement Is Established. Should a Fine Follow?
Before calculating a penalty, a supervisory authority has to explain why a fine is the appropriate response. The EDPB’s new consultation draft makes that decision explicit.

A company has infringed the rules on processing personal data. The facts are established and the responsible party identified. The next question is which measure the supervisory authority should choose. The finding of an infringement does not settle the question of a fine.
On 17 September 2026, the European Data Protection Board adopted Guidelines 04/2026 on imposing administrative fines in relation to other corrective powers. As of this article’s date, 24 September, the document is version 1.0, adopted for public consultation. It proposes a decision process and complements the guidance on calculating the amount of a fine. EDPB, version 1.0.
Imagine two companies with the same type of established infringement. The first immediately stopped the processing, investigated the cause and changed its procedures. The second continued after learning about the problem. This is a hypothetical example, not a prediction of either outcome. It illustrates why choosing a measure requires a history of what happened, beyond a box marked “infringement confirmed”.
That approach already has a judicial foundation. In Case C-768/21, a bank employee repeatedly accessed a customer’s data without authorisation. The bank took measures and notified the supervisory authority. The customer sought action, including a fine. On 26 September 2024, the Court of Justice held that the authority need not exercise a corrective power where doing so is unnecessary to remedy the shortcoming and ensure full enforcement of the GDPR. Measures taken by the organisation itself to end the infringement and prevent recurrence can matter. It remained for the national court to check whether the authority had respected the limits of its discretion. Court of Justice, summary of the judgment.
Remediation therefore does not automatically secure an exemption from a fine. It becomes part of the evidence the authority must assess.
The new EDPB guidance organises the decision into five steps:
| Step | Question |
|---|---|
| 1 | Can the established infringement lead to an administrative fine? |
| 2 | Can this particular party be fined for it? |
| 3 | Was the infringement committed intentionally or negligently? |
| 4 | Do the circumstances indicate a minor infringement? |
| 5 | Would a fine be effective, proportionate and dissuasive in this case? |
The first three steps address legal preconditions; the last two address the choice of measure. For minor infringements, the guidance points generally towards not imposing a fine. For other infringements, it sets out a strong presumption in favour of one. The final assessment can justify departing from either starting point. EDPB, executive summary and section 2.
Step three is easy to misread: an absence of intent does not establish an absence of grounds for a fine. Negligence also matters. In its judgments of 5 December 2023 in Cases C-683/21 and C-807/21, the Court of Justice confirmed the requirement for an intentional or negligent infringement. Where the controller is a legal person, the infringement need not have been committed by its management, nor must management have known about it. Court of Justice, summary of the judgments.
Preparing the decision requires more than identifying the provision infringed. Article 83(2) requires consideration of the nature, gravity and duration of the infringement, the people affected and damage suffered, intent or negligence, mitigation, previous infringements and the other listed factors. Article 83(1) requires a fine to be effective, proportionate and dissuasive. GDPR, Article 83.
For an engineer building a system to support this decision, a separate design problem follows: preserve the distinction between an event and its assessment.
“Access was revoked on 18 September” is an event that evidence can establish. “The measures are sufficient to prevent recurrence” is a conclusion that needs reasons. Recording both as identical switches hides an important part of the reasoning. A user may see a confident answer without seeing where an assessment entered the process.
Arxo’s GDPR model reflects this distinction in its rules on fines. It represents the applicable fine tier and statutory maximum, checks an amount against the ceiling, and separately records the factors in Article 83(2). Weighing those factors remains with the competent authority. This describes the existing Article 83 model; applying the EDPB’s new five-step methodology is a separate mapping exercise.
The useful output of such a system is a decision record that a reader can follow. Which obligation was infringed? Why did it apply to this party? What establishes fault? Which circumstances were considered? Who assessed their significance? Why does the chosen measure fit the case?
Return to the two companies. The same infringed provision provides a common legal starting point. Their case records then diverge: chronology, response, consequences and evidence. The system should preserve those differences and show how they affected the decision.
Before calculating the amount, open the draft reasons. If they do not explain why a fine was chosen in this case, a more precise calculator will not solve the problem.