Blog
October 5, 2026
4 mins
GDPR
Privacy Laws

New EDPB GDPR Fine Guidelines: What Businesses Should Know in 2026

The EDPB adopted Guidelines 04/2026 in September 2026, setting out a five-step method for deciding whether to impose a GDPR fine. Here is what the draft guidelines say and which GDPR checks Shopify merchants can run now.
GDPR Fines 2026: What the EDPB’s new guidance means for enforcement and how regulators decide when fines should be imposed.

Key Takeaways

  • On 17 September 2026, the European Data Protection Board (EDPB) adopted Guidelines 04/2026, which tell data protection authorities (DPAs) how to decide whether to impose an administrative fine. The EDPB announced them on 21 September.
  • DPAs should follow a five-step method. A minor infringement generally leads to no fine, and a reprimand may be issued instead. A non-minor infringement creates a strong presumption in favour of a fine.
  • The guidelines are open for public consultation until 13 November 2026, so the text may still change.
  • Fines are not the only risk, but the guidelines reward businesses that can show what they did and how quickly they fixed problems. For Shopify merchants, that means keeping clear records of consent, tracker behavior and privacy requests.

What changed in September 2026

On 17 September 2026, the EDPB adopted Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR. The Board announced the outcome in a press release on 21 September.

The guidelines answer a question that comes before any calculation: should a fine be imposed at all, on its own or alongside other corrective measures? They sit next to the EDPB's earlier guidelines on calculating the amount of a fine. They also replace the older WP29 guidelines on applying and setting administrative fines.

The EDPB says the aim is to align how DPAs across Europe make this decision. The guidelines also include 14 practical examples of how a DPA can assess a case and choose a corrective measure, if any.

The five-step methodology

According to the EDPB, DPAs should work through five steps:

  1. Can this infringement lead to a fine? The DPA looks for a legal basis in the GDPR or in national law. Not every infringement can be fined.
  2. Can this party be fined for it? Liability depends on who the breached provision applies to, the controller or the processor.
  3. Was it intentional or negligent? A fine requires culpability.
  4. Is the infringement minor? The DPA weighs aggravating and mitigating factors. If it is minor, there will generally be no fine. If it is not, there is a strong presumption that a fine should be imposed.
  5. Would a fine be effective, proportionate and dissuasive? The DPA checks whether there is a reason to depart from the standard approach in this case.

Steps 1 to 3 are legal preconditions. Steps 4 and 5 are where most of the practical judgment happens, according to Pearl Cohen's summary.

In step 4, the factors a DPA weighs include:

  • the nature, gravity and duration of the infringement (a longer duration weighs against calling it minor);
  • how culpable the business was;
  • measures taken to reduce harm to the people affected, including whether they were adopted before the business knew about an investigation;
  • whether the business "did what it could be expected to do" about the remaining risk;
  • previous infringements and cooperation with the authority;
  • the categories of data involved and how the infringement came to light;
  • whether the business followed approved codes of conduct or certification.

A GDPR violation does not automatically mean a fine

The guidelines separate two situations.

1. Minor infringements. As a general rule, no fine is imposed and a reprimand may be issued instead. The EDPB also notes that in some minor cases it may not be necessary to use any corrective power. One example is a controller that ends the infringement and prevents it from recurring as soon as it becomes aware of it.

2. Non-minor infringements. As a general rule, a fine is imposed. The DPA keeps some discretion, for example to issue a reprimand if a fine would place a disproportionate burden on the business.

Two points follow for merchants. First, a violation does not lead to a fine by default, because the DPA still has to assess whether a fine is effective, proportionate and dissuasive. Second, a longer-running problem that is not corrected leans toward a fine. How quickly a business notices and fixes an issue appears to carry real weight in the assessment.

Why evidence of compliance matters

Nothing in the guidelines says a particular tool prevents a fine, and no consent platform can promise that. What the framework does is make the facts of your situation central: how long an issue lasted, what you did about it, and whether you acted before anyone complained.

You can only show those facts if you have records. For a store that uses cookies and tracking, a business should be able to answer:

  • How is consent collected, and what did the visitor see?
  • Which preferences did each visitor choose?
  • When did a visitor's consent change?
  • How do trackers on the site behave before and after a choice is made?
  • How are privacy requests received, handled and closed?

If a DPA asks any of these, "we believe it works" is a weaker answer than a dated record.

Practical GDPR checks for Shopify merchants

Use this list as a recurring review, not a one-time setup.

  1. Check your regional settings. Confirm that consent requirements apply to the right regions, so EU and UK visitors see the correct experience.
  2. Test that non-essential trackers wait for consent. Where consent is required, analytics and marketing scripts should not fire until the visitor agrees. Test in a clean browser session, not just in your admin.
  3. Scan for new cookies and trackers regularly. Every new app, pixel or theme change can add a script. A scan after each change catches problems early, which matters when duration is a factor.
  4. Keep consent records. Retain logs of consent choices so you can show what a visitor selected and when.
  5. Make changing or withdrawing consent easy. Visitors should be able to reopen their preferences at any time, using a visible and accessible control.
  6. Keep a process for privacy requests. Decide who receives data-subject requests, where they are tracked and how they are closed.

Consentmo covers several of these checks for Shopify stores. Smart Geotargeting shows the appropriate banner based on visitor location. Script blocking and pixel controls can hold tracking until consent is given, while Tracker Manager scans the store for cookies, scripts, and trackers.

Consent Records keep a history of visitor choices, and the cookie preference widget lets visitors update their settings later.

Keep in mind: you still need to review your own setup, vendors, and internal processes. The legal responsibility remains with the business.

These guidelines are still under consultation

Guidelines 04/2026 are not final. The EDPB has opened them to public consultation until 13 November 2026, so wording and details may change after feedback.

Treat them as a clear signal of how DPAs are expected to think, not as a final rulebook. Individual DPAs and national laws still apply, and this article is general information, not legal advice. For decisions about your business, check with a qualified privacy professional.

A short note on the DSA and GDPR guidelines

In the same announcement, the EDPB adopted the final version of its guidelines on the interplay between the Digital Services Act (DSA) and the GDPR. These were finalised after a public consultation.

They matter mainly where DSA obligations involve personal data processing by intermediary service providers, such as online platforms and marketplaces, and where the DSA refers to GDPR concepts and definitions. Most Shopify merchants selling their own products do not fall into that category, so these guidelines are unlikely to change much for a typical store. If you run a marketplace or host content from other users, they are worth a closer read.

Conclusion

The EDPB's five-step method gives businesses a clearer picture of how fining decisions are meant to work. A short, well-documented, quickly fixed issue sits in a very different place from a long-running one that nobody noticed. A regular review of regions, trackers, consent records and privacy request handling is a sensible way to be ready to explain your choices, whatever the final text of the guidelines looks like.

Mariya Petrova
Growth & Product Marketing
With over 7 years of experience in advertising across agencies and e-commerce brands, Mariya has made marketing her core element. Today, she supports Consentmo users by guiding them through the realms of compliance, Shopify, and all things marketing.