For organizations estimating GDPR administrative fine exposure under Article 83
Calculate potential GDPR fines using the official EDPB 5-step methodology. Estimate penalties based on your annual turnover, violation type (Tier 1 or Tier 2), severity factors, and aggravating or mitigating circumstances as outlined in EDPB Guidelines 04/2022.
Aggravating Factors (increase fine)
Mitigating Factors (reduce fine)
Estimated Fine
€3.00M
% of Turnover
6.00%
Severity Level
Medium
Based on €50.0M annual turnover with a medium severity Tier 2 violation, your estimated GDPR fine is €3,000,000 (6.00% of turnover). The legal maximum for this violation is €20,000,000.
GDPR fines are calculated using the European Data Protection Board (EDPB) 5-step methodology under Article 83. Fines can reach up to 4% of annual global turnover or €20 million for serious violations (Tier 2), or 2% / €10 million for procedural violations (Tier 1). The actual fine depends on violation severity, aggravating and mitigating factors, and the principle of proportionality.
Key factors that regulators consider include: the nature and gravity of the violation, number of data subjects affected, whether the violation was intentional or negligent, actions taken to mitigate damage, cooperation with authorities, prior infringements, and how the authority learned of the violation. Organizations that self-report breaches and cooperate fully typically receive lower fines.
Aggravating Factors (increase fine)
Mitigating Factors (reduce fine)
Estimated Fine
€3.00M
% of Turnover
6.00%
Severity Level
Medium
Based on €50.0M annual turnover with a medium severity Tier 2 violation, your estimated GDPR fine is €3,000,000 (6.00% of turnover). The legal maximum for this violation is €20,000,000.
GDPR fines are calculated using the European Data Protection Board (EDPB) 5-step methodology under Article 83. Fines can reach up to 4% of annual global turnover or €20 million for serious violations (Tier 2), or 2% / €10 million for procedural violations (Tier 1). The actual fine depends on violation severity, aggravating and mitigating factors, and the principle of proportionality.
Key factors that regulators consider include: the nature and gravity of the violation, number of data subjects affected, whether the violation was intentional or negligent, actions taken to mitigate damage, cooperation with authorities, prior infringements, and how the authority learned of the violation. Organizations that self-report breaches and cooperate fully typically receive lower fines.
We'll white-label it, match your brand, and set up lead capture. You just copy-paste one line of code.
No pressure. Just a friendly conversation.
Estimated Fine = min(Starting Point × Adjustment Factor, Legal Maximum)
This calculator implements the European Data Protection Board's official 5-step methodology from Guidelines 04/2022. It first establishes the legal maximum based on violation type and turnover, then calculates a severity score (0-100) from factors like data subjects affected, data categories, duration, and damage level. This determines a starting point bracket. Finally, aggravating and mitigating factors create an adjustment multiplier (0.3x to 2.5x), capped at the legal maximum.
GDPR administrative fines under Article 83 can reach €20 million or 4% of global annual turnover for serious violations. The European Data Protection Board (EDPB) published Guidelines 04/2022 establishing a harmonized 5-step methodology for calculating fines across EU member states. Understanding this methodology helps organizations assess regulatory risk, justify data protection investments, and prepare for potential enforcement actions.
Data protection authorities determine fine amounts by establishing the legal maximum based on violation type, then calculating a starting point based on violation severity, and finally adjusting for aggravating and mitigating factors. Factors like intentional conduct, previous infringements, and obstruction can significantly increase fines, while self-reporting, cooperation, and demonstrating corrective action can reduce them.
Proactive GDPR fine estimation supports informed decision-making about data protection program investments. Organizations can model worst-case scenarios based on their turnover and violation risk profile, evaluate whether cyber insurance coverage aligns with potential exposure, and demonstrate regulatory risk awareness to leadership and board members. This calculator implements the official EDPB methodology to provide realistic fine estimates.
Multinational corporation found collecting user data without valid GDPR consent
Multi-million euro fine estimate, reduced by self-reporting and corrective action
Mid-size company failing to respond to data subject access requests
Moderate fine estimate, increased by lack of cooperation with authorities
Hospital with inadequate security measures exposing patient health records
Elevated fine estimate due to sensitive health data, reduced by cooperation
Company with prior GDPR violation found transferring data without adequate safeguards
Substantial fine estimate significantly increased by prior violations and intent
The European Data Protection Board (EDPB) Guidelines 04/2022 establish a 5-step methodology: (1) Identify the processing operations and applicable maximum fine; (2) Evaluate the gravity of the infringement to determine a starting point; (3) Adjust for aggravating or mitigating circumstances; (4) Identify the applicable legal maximum; (5) Verify the final amount meets requirements of effectiveness, proportionality, and dissuasiveness. This calculator implements this methodology.
Tier 1 violations (Article 83(4)) carry a maximum fine of €10 million or 2% of global annual turnover and cover obligations of controllers and processors, certification bodies, and monitoring bodies. Tier 2 violations (Article 83(5)) carry a maximum of €20 million or 4% of turnover and cover core principles including lawfulness, consent, data subject rights, and international transfers. The higher of the fixed amount or percentage-based amount applies.
GDPR fines are calculated as a percentage of global annual turnover from the preceding financial year. For Tier 2 violations, the maximum is 4% of turnover or €20 million (whichever is higher). For Tier 1, it is 2% or €10 million. Small organizations may face the fixed euro amounts, while large enterprises face percentage-based maximums. The EDPB methodology uses turnover to establish both the legal ceiling and the starting point for calculations.
Aggravating factors include: intentional or deliberate nature of the infringement; failure to take steps to mitigate damage; previous infringements of GDPR or prior supervisory orders; failure to cooperate with the supervisory authority; and obstruction of the investigation. Multiple aggravating factors can significantly multiply the starting point, sometimes doubling or tripling the initial estimate.
Mitigating factors include: voluntary notification of the infringement to the supervisory authority (self-reporting); immediate corrective action to stop and address the violation; full cooperation with the authority throughout the investigation; adherence to an approved code of conduct; and holding relevant certifications. Strong mitigating circumstances can reduce fines by 50% or more from the starting point.
Violations involving special category data under Article 9 (health, biometric, genetic, racial/ethnic origin, political opinions, religious beliefs, sexual orientation) or children's data receive higher severity assessments. This increases the starting point bracket from low (0-10% of maximum) to medium (10-20%) or high (20-100%). Sensitive data cases also more easily qualify for the upper end of any bracket.
Yes. GDPR Article 78 grants data subjects and controllers the right to an effective judicial remedy against supervisory authority decisions. Appeals typically go through national administrative courts. Organizations can challenge both the finding of a violation and the fine amount. Appeals may result in reduced fines if proportionality or procedural issues are identified.
This calculator provides estimates based on the official EDPB methodology, but actual fines depend on numerous case-specific factors that only supervisory authorities can fully evaluate. Precedent cases, the specific DPA involved, organizational cooperation quality, and detailed violation circumstances all influence outcomes. Use this calculator for planning and risk assessment, not as a prediction of enforcement outcomes.
Estimate the total cost and impact of a data breach
Calculate the total financial impact and cost of a ransomware attack on your organization including downtime, recovery, and ransom decisions
Calculate the total cost of achieving and maintaining HIPAA compliance for your healthcare organization
Calculate total cost of achieving and maintaining FEDRamp authorization for government cloud services
Estimate total costs for achieving and maintaining SOC compliance