This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.
Data Sovereignty
EDPB harmonizes enforcement methodology for fines and approves guidelines on the relationship between the Digital Services Act and GDPR
At its latest plenary session, the European Data Protection Board (EDPB) adopted guidelines on the application of enforcement powers regarding administrative fines in relation to other corrective measures under GDPR and finalized its guidelines on the interplay between the Digital Services Act and the General Data Protection Regulation (GDPR). "The new EDPB guidelines are a significant step towards further aligning how data protection authorities decide whether to impose an administrative fine, either independently or alongside other corrective measures. The guidelines reaffirm our commitment to ensuring greater clarity and uniform application of GDPR across Europe," said the data protection authorities. When deciding on imposing an administrative fine, authorities should follow a five-step methodology. The guidelines also provide an overview of corrective powers within the scope of national data protection authorities, explaining their purpose, scope, and relationships. The Board also includes 14 practical examples illustrating how authorities can assess case specifics and determine which corrective measures to impose. The guidelines on the relationship between the Digital Services Act (DSA) and GDPR were finalized after a public consultation. These guidelines replace the guidelines established by the Article 29 Working Party on the enforcement and setting of administrative fines under Regulation 2016/679 and complement earlier guidelines on calculating fines under GDPR, which focus more on the methodology for determining the amount of the fine.