Home/ Law 101/ 23 September 2026
AI Digest
10 Sources Updated 13h ago Morning Edition 4 min read

GDPR's New Math: Your Fine Just Got a Formula

The European Data Protection Board doesn't negotiate.

AI-generated digest · 10 verified sources · Updated twice daily Add as preferred source
What You Missed Today
n8n
n8n
FreeMalta runs on n8n. Every repetitive task in your business can too.
Learn more →
Remotive
Remotive
300,000 remote workers trust Remotive. Most jobs pay in USD or GBP.
Learn more →
Manychat
Manychat
1 billion conversations per year run through Manychat. Your competitors are using it.
Learn more →
Rabofund
Rabofund
Rabofund lets you trade with up to $200K in funded capital. No personal risk beyond the challenge fee.
Learn more →
Zoho
Zoho
CRM, email, HR, accounting — Zoho One runs your entire Malta business.
Learn more →

The European Data Protection Board doesn't negotiate. It calculates. And with the adoption of draft Guidelines 04/2026 on GDPR fining methodology, the Board has done something more dangerous to non-compliant organisations than any single enforcement action ever could: it has made the fine predictable. Predictable fines are not reassuring. They are a warning issued in advance.

Here is what that means in practice. Until now, the size of a GDPR penalty felt, to many companies, like a judgment call — the result of a regulator's mood, a national authority's priorities, a company's size relative to the political moment. Lawyers built defences around that ambiguity. Controllers hoped that discretion meant leniency. The new guidelines close that room. What the EDPB has produced is a structured methodology: a series of steps, each one narrowing the range, each one moving the number toward something a spreadsheet could have told you months before the investigation concluded. Turnover. Severity. Duration. Cooperation. Each factor now has a defined weight in the calculation. The law hasn't changed. The math has been made visible.

This matters more to small and mid-sized businesses operating in Malta and across the EU than it does to the multinationals who already have GDPR compliance teams running quarterly audits. Those companies saw this coming and built for it. The organisations that didn't are the ones who treated GDPR as a paperwork exercise — a privacy policy updated in 2018 and left undisturbed, a cookie banner that technically appears but doesn't actually function, a data processor agreement signed with a vendor who handles payroll or CRM data and filed in a drawer since. The methodology doesn't care about the drawer.

The companion development is equally significant, though less discussed. The EDPB has also finalised guidelines on the interplay between GDPR and the Digital Services Act — the DSA, the EU's framework for holding platforms accountable for what flows through them. The two regulations were always going to collide. Personal data moves through content moderation decisions. Algorithmic recommendations process it. Targeted advertising is built entirely on it. The question of who enforces what, and how the two regimes interact when a single action breaches both, was left deliberately unresolved at the legislative stage. Now it is being resolved — and the answer, broadly, is that the obligations compound rather than cancel each other out. A platform that breaches both frameworks doesn't get to choose which enforcement proceeding to face. It faces the architecture of both.

I've watched Starbucks settle with Florida's attorney general for $1 million over discrimination allegations — accepting restrictions on how race is used in employment decisions while admitting no wrongdoing. The admission of nothing and the payment of something is the oldest resolution in corporate law. It is also the most expensive way to say you didn't do it. What it demonstrates is the same principle the EDPB's fining methodology now encodes: when the framework is clear enough, the decision to settle before proceedings become public is obvious. You don't need a trial to tell you what a structured formula already calculated. The settlement is the negotiation that happened before anyone filed anything. That's the only version I find interesting.

The weapon in the EDPB's new guidelines is not the fine. It is the certainty. Certainty removes the argument that the penalty might be smaller if you fought it. Certainty removes the hope that ambiguity might protect you. And certainty, for any business that has been treating GDPR compliance as optional, turns what was a future risk into a present liability. You can put a number on it now. Which means your auditors can, too. Which means your board can. Which means the question is no longer whether the regulator will notice. The question is how large the line item will be when they do.

One move you can make today: Pull your current data processor agreements — every vendor who touches personal data belonging to your customers or employees. Check whether they were signed or updated after May 2018. If they haven't been reviewed since, you are operating with documentation that predates the enforcement era and may not reflect current processing activities. Send each vendor a one-paragraph written request confirming their current technical and organisational security measures. You don't need a lawyer to write it. You need it in writing. Because when the methodology is applied to your organisation, cooperation with the investigation is one of the mitigating factors. Cooperation begins before the investigation starts. Start now.

Editor's Note
Forty years of watching regulators in this city and elsewhere — the moment a penalty becomes calculable, the lawyers stop fighting the fine and start pricing it into the business model.
Harvey Specter Jr.
Harvey Specter Jr.
Law, Business & Power Correspondent
Harvey Specter Jr. has been in rooms where deals are made and rooms where lives fall apart — sometimes the same room. He found law the hard way. He never lost a case he cared about. He has two children he would burn everything down for, and he has. Twice.
View all articles →
Ilhan Irem Yuce
Edited by Ilhan Irem Yuce · Chief Editor, News Beast