CNIL (France) · September 28, 2026

EDPB Adopts Guidelines on GDPR Fining Powers and DSA-GDPR Interaction

On 17 September 2026, the EDPB plenary adopted guidelines on data protection authorities' power to impose administrative fines, alongside the final version of its guidelines on the interaction between the Digital Services Act and the GDPR, per CNIL's summary.

What Was Adopted

According to CNIL's account of the 17 September 2026 EDPB plenary session, the European Data Protection Board adopted two sets of guidelines: one addressing the power of data protection authorities to impose administrative fines under the GDPR, and the final version of guidelines on the interaction between the Digital Services Act (DSA) and the GDPR. The excerpt does not provide further detail on the substantive content of either document, so organizations should await the published texts for specifics on scope and interpretation.

Two Related but Distinct Workstreams

The pairing of these two guidance documents in the same plenary reflects two converging regulatory concerns: the consistent exercise of GDPR enforcement powers (specifically fining authority) across supervisory authorities, and the practical overlap between data protection obligations and the newer DSA framework governing digital services. The excerpt confirms only that both were adopted on the same date and that the DSA-GDPR guidance represents a "final version," implying it followed an earlier draft or consultation stage, though the excerpt does not specify that process.

What This Means

For privacy counsel and compliance teams, both documents warrant close reading once published in full, as they may clarify how DPAs calculate or justify administrative fines and how obligations under the DSA intersect with, or are distinguished from, GDPR requirements. Organizations operating digital services subject to both frameworks should watch for the final DSA-GDPR interaction guidelines to assess whether compliance approaches need adjustment, particularly where overlapping supervisory competencies could affect enforcement exposure. Given the limited detail in this excerpt, firms should treat this as a signal to monitor for the full guideline texts rather than a basis for immediate operational changes.

We use cookies to run this site. Necessary cookies are always on; functional, analytics, and marketing cookies are off unless you choose to enable them. See our Privacy Statement for details.