GDPR Fine Calculator

For organizations estimating GDPR administrative fine exposure under Article 83

Calculate potential GDPR fines using the official EDPB 5-step methodology. Estimate penalties based on your annual turnover, violation type (Tier 1 or Tier 2), severity factors, and aggravating or mitigating circumstances as outlined in EDPB Guidelines 04/2022.

Fine Estimate

Estimated Fine

3.00M

% of Turnover

6.00%

Severity Level

Medium

Aggravating Factors (increase fine)

Mitigating Factors (reduce fine)

Want this on your website?

We'll white-label it, match your brand, and set up lead capture. You just copy-paste one line of code.

No engineering requiredNo design neededDeploy in days
Let's Chat

No pressure. Just a friendly conversation.

Formula

Estimated Fine = min(Starting Point × Adjustment Factor, Legal Maximum)

This calculator implements the European Data Protection Board's official 5-step methodology from Guidelines 04/2022. It first establishes the legal maximum based on violation type and turnover, then calculates a severity score (0-100) from factors like data subjects affected, data categories, duration, and damage level. This determines a starting point bracket. Finally, aggravating and mitigating factors create an adjustment multiplier (0.3x to 2.5x), capped at the legal maximum.

Variables

  • Annual Turnover(EUR)Organization's global annual revenue from the preceding financial year
  • Violation Type(category)GDPR article violated, determining Tier 1 (2%/€10M) or Tier 2 (4%/€20M) maximum
  • Data Subjects Affected(people)Number of individuals whose personal data was impacted by the violation
  • Data Categories(category)Type of personal data: standard, sensitive (Article 9), or children's data
  • Violation Duration(time period)How long the violation persisted before detection or correction
  • Damage Level(assessment)Severity of harm experienced by affected data subjects
  • Aggravating Factors(factors)Circumstances that increase fine: intent, prior violations, obstruction, non-cooperation
  • Mitigating Factors(factors)Circumstances that decrease fine: self-reporting, corrective action, cooperation, certifications

Assumptions

  • Legal maximum is the greater of the fixed amount (€10M or €20M) or percentage of turnover (2% or 4%)
  • Severity scoring uses EDPB-aligned brackets: Low (0-10%), Medium (10-20%), High (20-100%) of maximum
  • Aggravating factors increase the starting point, mitigating factors decrease it
  • Final fine is always capped at the legal maximum for the violation tier
  • Calculation uses the midpoint of each severity bracket for the starting point estimate

Sources

Limitations

  • Estimates are based on the EDPB methodology but actual fines depend on case-specific supervisory authority discretion
  • Does not account for national variations in DPA enforcement approaches across EU member states
  • Cannot model complex multi-violation scenarios where different tiers may apply
  • Severity scoring is simplified from the nuanced assessment supervisory authorities perform
  • Does not include potential civil damages from affected data subjects separate from regulatory fines

Tips for Accurate Results

  • Use global annual turnover from your most recent financial year - GDPR fines are calculated on worldwide revenue
  • Tier 2 violations (processing principles, consent, data subject rights) carry higher maximum fines than Tier 1
  • Self-reporting breaches and demonstrating corrective action can significantly reduce fine amounts
  • Previous GDPR infringements are a major aggravating factor that can multiply your starting point
  • Data protection authorities consider cooperation throughout the investigation when setting final amounts

How to Use the GDPR Fine Calculator

  1. 1Enter your organization's annual global turnover in EUR to establish legal maximum fine thresholds
  2. 2Select the violation type based on which GDPR article was breached (Tier 1 vs Tier 2)
  3. 3Input the number of data subjects affected by the violation
  4. 4Specify the category of data involved (standard personal data, sensitive Article 9 data, or children's data)
  5. 5Select the duration of the violation from days to years
  6. 6Assess the damage level experienced by affected data subjects
  7. 7Check any aggravating factors that apply (intentional conduct, prior violations, obstruction)
  8. 8Check any mitigating factors that apply (self-reporting, corrective action, cooperation, certifications)
  9. 9Review your estimated fine, percentage of turnover, and comparison against the legal maximum

Why GDPR Fine Estimation Matters

GDPR administrative fines under Article 83 can reach €20 million or 4% of global annual turnover for serious violations. The European Data Protection Board (EDPB) published Guidelines 04/2022 establishing a harmonized 5-step methodology for calculating fines across EU member states. Understanding this methodology helps organizations assess regulatory risk, justify data protection investments, and prepare for potential enforcement actions.

Data protection authorities determine fine amounts by establishing the legal maximum based on violation type, then calculating a starting point based on violation severity, and finally adjusting for aggravating and mitigating factors. Factors like intentional conduct, previous infringements, and obstruction can significantly increase fines, while self-reporting, cooperation, and demonstrating corrective action can reduce them.

Proactive GDPR fine estimation supports informed decision-making about data protection program investments. Organizations can model worst-case scenarios based on their turnover and violation risk profile, evaluate whether cyber insurance coverage aligns with potential exposure, and demonstrate regulatory risk awareness to leadership and board members. This calculator implements the official EDPB methodology to provide realistic fine estimates.


Common Use Cases & Scenarios

Large Enterprise - Consent Violation

Multinational corporation found collecting user data without valid GDPR consent

Inputs:
  • Annual Turnover:€500,000,000
  • Violation Type:Tier 2 - Consent violations
  • Data Subjects Affected:1,000,000
  • Data Categories:Standard personal data
  • Violation Duration:Months
  • Damage Level:Moderate
  • Aggravating:None
  • Mitigating:Self-reported, took corrective action
Expected Results:

Multi-million euro fine estimate, reduced by self-reporting and corrective action

SME - Data Subject Rights Violation

Mid-size company failing to respond to data subject access requests

Inputs:
  • Annual Turnover:€10,000,000
  • Violation Type:Tier 2 - Data subject rights
  • Data Subjects Affected:500
  • Data Categories:Standard personal data
  • Violation Duration:Weeks
  • Damage Level:Minimal
  • Aggravating:Failed to cooperate
  • Mitigating:None
Expected Results:

Moderate fine estimate, increased by lack of cooperation with authorities

Healthcare Organization - Sensitive Data Breach

Hospital with inadequate security measures exposing patient health records

Inputs:
  • Annual Turnover:€75,000,000
  • Violation Type:Tier 1 - Controller obligations (security)
  • Data Subjects Affected:50,000
  • Data Categories:Sensitive (Article 9)
  • Violation Duration:Days
  • Damage Level:Significant
  • Aggravating:None
  • Mitigating:Fully cooperated, has certification
Expected Results:

Elevated fine estimate due to sensitive health data, reduced by cooperation

Repeat Offender - International Transfer Violation

Company with prior GDPR violation found transferring data without adequate safeguards

Inputs:
  • Annual Turnover:€200,000,000
  • Violation Type:Tier 2 - International transfers
  • Data Subjects Affected:100,000
  • Data Categories:Standard personal data
  • Violation Duration:Years
  • Damage Level:Moderate
  • Aggravating:Previous infringements, intentional
  • Mitigating:None
Expected Results:

Substantial fine estimate significantly increased by prior violations and intent


Frequently Asked Questions

What is the EDPB 5-step methodology for GDPR fines?

The European Data Protection Board (EDPB) Guidelines 04/2022 establish a 5-step methodology: (1) Identify the processing operations and applicable maximum fine; (2) Evaluate the gravity of the infringement to determine a starting point; (3) Adjust for aggravating or mitigating circumstances; (4) Identify the applicable legal maximum; (5) Verify the final amount meets requirements of effectiveness, proportionality, and dissuasiveness. This calculator implements this methodology.

What is the difference between Tier 1 and Tier 2 GDPR violations?

Tier 1 violations (Article 83(4)) carry a maximum fine of €10 million or 2% of global annual turnover and cover obligations of controllers and processors, certification bodies, and monitoring bodies. Tier 2 violations (Article 83(5)) carry a maximum of €20 million or 4% of turnover and cover core principles including lawfulness, consent, data subject rights, and international transfers. The higher of the fixed amount or percentage-based amount applies.

How does annual turnover affect GDPR fine calculations?

GDPR fines are calculated as a percentage of global annual turnover from the preceding financial year. For Tier 2 violations, the maximum is 4% of turnover or €20 million (whichever is higher). For Tier 1, it is 2% or €10 million. Small organizations may face the fixed euro amounts, while large enterprises face percentage-based maximums. The EDPB methodology uses turnover to establish both the legal ceiling and the starting point for calculations.

What factors can increase a GDPR fine?

Aggravating factors include: intentional or deliberate nature of the infringement; failure to take steps to mitigate damage; previous infringements of GDPR or prior supervisory orders; failure to cooperate with the supervisory authority; and obstruction of the investigation. Multiple aggravating factors can significantly multiply the starting point, sometimes doubling or tripling the initial estimate.

What factors can reduce a GDPR fine?

Mitigating factors include: voluntary notification of the infringement to the supervisory authority (self-reporting); immediate corrective action to stop and address the violation; full cooperation with the authority throughout the investigation; adherence to an approved code of conduct; and holding relevant certifications. Strong mitigating circumstances can reduce fines by 50% or more from the starting point.

How does data sensitivity affect GDPR fines?

Violations involving special category data under Article 9 (health, biometric, genetic, racial/ethnic origin, political opinions, religious beliefs, sexual orientation) or children's data receive higher severity assessments. This increases the starting point bracket from low (0-10% of maximum) to medium (10-20%) or high (20-100%). Sensitive data cases also more easily qualify for the upper end of any bracket.

Can I appeal a GDPR fine?

Yes. GDPR Article 78 grants data subjects and controllers the right to an effective judicial remedy against supervisory authority decisions. Appeals typically go through national administrative courts. Organizations can challenge both the finding of a violation and the fine amount. Appeals may result in reduced fines if proportionality or procedural issues are identified.

Does this calculator predict actual GDPR fine amounts?

This calculator provides estimates based on the official EDPB methodology, but actual fines depend on numerous case-specific factors that only supervisory authorities can fully evaluate. Precedent cases, the specific DPA involved, organizational cooperation quality, and detailed violation circumstances all influence outcomes. Use this calculator for planning and risk assessment, not as a prediction of enforcement outcomes.


Related Calculators

GDPR Fine Calculator | Article 83 Penalty Estimator (EDPB Methodology)