DSA obligations under the GDPR fining methodology
The EDPB harmonises the GDPR fining methodology and finalises the DSA-GDPR guidelines. Here is how you link both regimes in one risk matrix and fine calculation.
You must now link each DSA obligation that processes personal data to a valid GDPR lawful basis, and model the fine exposure using the EDPB's five-step methodology: identify the processing and the relevant Article 83(3) category, set the starting amount from gravity and turnover, apply aggravating and mitigating factors, verify against the legal maximum, and test the result for deterrence. Document these steps for every processing operation.
The prompt is an analysis of 21 September 2026 of the harmonised GDPR fining methodology and final DSA–GDPR guidelines, which argues that the two instruments must be read together as a single enforcement framework rather than as separate regimes. The European Data Protection Board paired both in one announcement, signalling that DSA-mandated processes are subject to the full GDPR standard and assessed under the harmonised fine formula. In our assessment, the simultaneous publication makes it harder for national supervisory authorities to diverge in practice, and organisations that can demonstrate their fine exposure and DSA-GDPR link per processing operation will be better positioned in enforcement dialogue.
What does the EDPB's five-step methodology require you to do?
The harmonised fining methodology builds on earlier EDPB guidance and creates a structured process that all supervisory authorities must follow. The five steps are: identify the processing activity and the relevant Article 83(3) category; calculate a starting amount based on the gravity of the infringement and the organisation's turnover; apply aggravating factors (such as intentional conduct or prior breaches) and mitigating factors (such as timely remediation or cooperation); check the result against the legal maximum fine; and test whether the amount would deter the organisation and others from similar conduct. For organisations, this shift means compliance moves from reactive to calculable. Documenting mitigating factors—timely remedial measures, cooperation with the supervisory authority, a clean compliance history—becomes an explicit part of your compliance record rather than an argument raised only after investigation.
Which DSA obligations now fall under GDPR fining rules?
The EDPB states in its final guidelines that the Digital Services Act does not stand above the GDPR as a special case. Where a DSA obligation processes personal data, the full GDPR continues to apply and the DSA creates no new lawful basis. Processing operations such as trader verification, handling of notices about illegal content, transparency of recommender systems, and advertising rules all require a valid basis under Article 6 of the GDPR (and Article 9 where sensitive data is involved). The principles of data minimisation, purpose limitation and fairness remain in force even when a platform is carrying out a DSA obligation. This means DSA-mandated processes—notice-and-action workflows, transparency logs, ad libraries—are reviewed against the full GDPR standard, and infringements in those processes may be assessed under the GDPR fining methodology.
What failure modes and risk categories must you address?
- Absence of a valid GDPR basis — DSA processing lacking lawful basis under Article 6 or Article 9.
- Data minimisation breach — collecting or retaining personal data beyond what the DSA obligation requires.
- Purpose creep — using data collected for one DSA process for a different purpose without fresh consent or basis.
- Lack of transparency — failing to disclose to data subjects how their data is used in DSA-mandated workflows.
- Inadequate safeguards — processing high-risk data without appropriate technical or organisational measures.
- No documented assessment — inability to show how you determined gravity, turnover bracket and mitigating factors for a given processing activity.
What concrete controls must you be able to demonstrate?
- Map each DSA obligation to a GDPR Article 6 basis — document which lawful basis (consent, contract, legal obligation, vital interests, public task, or legitimate interest) applies to each DSA-mandated processing operation.
- Record the fine methodology assessment per processing activity — maintain a file showing how you identified the infringement category, calculated starting amount, applied aggravating and mitigating factors, and tested deterrence.
- Implement logging and audit trails for high-risk DSA workflows — capture who made which decision, when, on what data, and what safeguards were applied, especially for notice-and-action and recommender system processes.
- Document mitigating factors in real time — record remedial measures, supervisory authority cooperation, and compliance history as they occur, not retrospectively.
- Conduct a fine exposure model per major processing operation — calculate plausible fine ranges under the EDPB methodology to inform your risk appetite and remediation priorities.
How should you structure your compliance record?
A workable approach is to build an internal fine file per incident or investigation, showing how the case would play out under the EDPB methodology. That file steers early remedial measures and shapes the conversation with the supervisory authority. The substantiation of human oversight and decisions that accompanies it should be captured in a logging layer per high-risk decision and in session-bound GDPR accountability records for any autonomous processing. For organisations that fall only under the GDPR and do not qualify as a large online platform, the same discipline applies: model fine exposure per major processing activity and record your assessment of gravity, turnover bracket and mitigating factors. This record becomes your evidence of compliance intent and your basis for negotiating remediation if an investigation occurs.
Tooling can help you map processing operations to GDPR bases, calculate fine ranges under the EDPB formula, and maintain audit logs. What tooling cannot do is determine whether your organisation's specific business purpose justifies the data you are collecting, or whether your mitigating factors are genuine or merely asserted. That judgement remains yours.
Sources: This article draws on reporting and guidance from European Data Protection Board and Lewis Silkin.
Written by
Marit Halversen
Covers AI governance and regulatory design, with a focus on how compliance obligations land on architecture rather than on paperwork.