Link each DSA obligation that processes personal data to a valid GDPR basis and model the fine risk with the EDPB's five-step methodology: identify the processing and Article 83(3), base the starting amount on gravity and turnover, apply aggravating and mitigating factors, check the legal maximum and test for deterrence. Document these steps per processing operation.
On 21 September 2026 the European Data Protection Board (EDPB) announced a headline describing harmonised fining methodology and final DSA–GDPR guidelines. That these two actions coincide in a single announcement is significant: the EDPB is pairing fining methodology with DSA–GDPR guidance in one enforcement message.
Our editorial assessment: the sources name both instruments separately, but leave the practical link open. It is precisely that link — DSA processing operations reviewed through the harmonised fine formula — that providers and large deployers must now work out.
What does it mean that the EDPB harmonises the fining methodology?
The harmonised methodology builds on the Guidelines 04/2022 on the calculation of administrative fines, version 2.1. Those guidelines describe a structured process that all supervisory authorities must follow. The five steps are:
- Identify the relevant processing operations and establish whether Article 83(3) (multiple infringements) applies.
- Determine a starting amount based on the legal category of the infringement, the gravity (low, medium or high) and the turnover of the undertaking.
- Adjust the amount for aggravating and mitigating factors.
- Check that the calculated amount does not exceed the legal maximum.
- Assess whether the fine is effective, proportionate and dissuasive.
For organisations, the emphasis thereby shifts from reactive to calculable. In our assessment, documenting mitigating factors — timely remedial measures, cooperation with the supervisory authority, a clean history — becomes an explicit part of compliance rather than an argument raised only after the fact.
Why do DSA obligations fall under full GDPR review?
The EDPB states in Guidelines 3/2025 that the Digital Services Act does not stand above the GDPR as lex specialis. Where a DSA obligation processes personal data, the full GDPR continues to apply. The DSA creates no new legal basis.
In concrete terms, according to the EDPB, this means that processing operations such as trader verification, the handling of notices about illegal content, transparency of recommender systems and advertising rules need a valid basis under Article 6 (and where necessary Article 9) of the GDPR. The principles of minimisation, purpose limitation and fairness remain in force, even when a platform is merely carrying out a DSA obligation.
The analysis by law firm Lewis Silkin on these guidelines underlines that platforms cannot treat the DSA and the GDPR as separate silos. DSA-mandated processes — notice-and-action workflows, transparency logs, ad libraries — are reviewed against the full GDPR standard. Our inference: infringements in those processes may be assessed under the GDPR fining methodology where GDPR enforcement applies.
How do I link DSA obligations and GDPR bases in one risk matrix?
The practical task is to bring two regimes together in one overview. A workable approach, built from what the EDPB guidelines require:
- Map, per DSA obligation, which processing operations it triggers and which personal data are processed in the process.
- Assign a valid GDPR basis to each processing operation and record how minimisation and purpose limitation are safeguarded.
- Assess, per processing operation, the gravity (low, medium, high) and the relevant turnover basis as the fining methodology prescribes.
- Record, per processing operation, which mitigating measures have been taken and which documentation substantiates them.
- Prepare for coordinated oversight: the guidelines envisage cooperation between Digital Services Coordinators and data protection authorities.
For controllers that fall only under the GDPR and do not qualify as a platform, the first half remains relevant: model fine exposure per major processing activity and record the assessment of gravity, turnover bracket and mitigating factors. Useful background on that recording can be found in our topic hub on AI privacy and GDPR and in the article on traceable personal data in embeddings and vector databases.
What must oversight and legal teams record now?
A concrete step is to build an internal fine file per incident or investigation, showing how the case would play out under the EDPB methodology. That file steers early remedial measures and the conversation with the supervisory authority. The substantiation of human oversight and decisions that goes with it we work out in a logging layer per high-risk decision and in session-bound GDPR accountability for autonomous processing.
Our assessment: the simultaneous publication of the harmonised methodology and the final DSA–GDPR guidelines may make fragmentation between national practices harder to sustain. Organisations that can make their fine exposure and their DSA-GDPR link visible per processing operation stand stronger in an environment where the calculation has become known and traceable in advance.
Sources and references
- Guidelines 04/2022 on the calculation of administrative fines under the GDPR (Version 2.1)
- Guidelines 3/2025 on the interplay between the DSA and the GDPR
- EDPB guidelines on the DSA-GDPR interplay: what platforms, advertisers and researchers need to know
- EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines
Sources: The article draws on the official EDPB Guidelines 04/2022 and 3/2025, the EDPB news announcement of 21 September 2026 and the analysis by Lewis Silkin.