GDPR Data Breach Fine Estimator
Legal & ComplianceEstimate a potential GDPR fine based on annual global turnover and violation tier.
Realistic Fine Estimate
A disclosed approximation using the EDPB's own published severity and company-size bands (Guidelines 04/2022), calibrated against real cases (BA, Marriott, H&M, TIM all landed at roughly 3-4% of their theoretical maximum). This is an educational estimate, not a legal prediction — real fines depend on facts and regulator discretion no formula can fully capture.
Statutory Maximum Fine
$10,000,000
The absolute legal ceiling under GDPR Article 83 for your selected tier — real regulators almost never impose this maximum in practice.
Found this calculator useful?
From Scratch To $10K/Month In 60 Days
This is a proven money making system that takes students by the hand to make at least $10,000 per month, every month. Students get 12 weeks of guided coaching in addition to the "MPS Super Funnel" and tools.
We value your privacy and promise not to sell or misuse your information. Here's our privacy policy.
Calculator Stats
Creators
Odeh AhwalBased on 3 sources
0people find this calculator helpful
Views
Helpful
Saved
Embeds
Calculator Stats
Creators
Odeh AhwalBased on 3 sources
0people find this calculator helpful
Views
Helpful
Saved
Embeds
Legal & Compliance calculators
This calculator estimates what a GDPR fine might actually look like for a data breach or compliance violation, based on your company's annual global turnover, the severity tier of the violation under Article 83, and factors regulators weigh when setting a penalty, such as how many people were affected, whether special category data was involved, how long the violation lasted, and whether you self-reported and cooperated with the investigation.
It produces two numbers. The first is the statutory maximum, the absolute legal ceiling of 10 million euros or 2 percent of global turnover for lower tier violations, and 20 million euros or 4 percent for higher tier violations. Most articles about GDPR fines stop there, which is misleading, because regulators almost never impose the maximum. The second number, and the one this tool treats as primary, is a realistic estimate built from the same severity and size bands the European Data Protection Board sets out in its Guidelines 04/2022, then checked against how real fines have actually landed. Several of the largest GDPR fines on record, including British Airways, Marriott, H and M, and TIM, settled at roughly 3 to 4 percent of the company's theoretical maximum exposure, not the headline percentage.
Be clear about what this tool is not. It is not a legal opinion, and it cannot replicate the judgment a data protection authority applies to the specific facts of a real case, including precedent, aggravating conduct, or political pressure in a given jurisdiction. Treat the output as an educated, transparent approximation for budgeting, risk assessment, or board reporting, not a prediction you can rely on in place of advice from a qualified data protection lawyer. If you are facing an actual investigation or breach notification deadline, this calculator is a starting point for understanding scale, not a substitute for counsel.
How GDPR fines are calculated under Article 83
GDPR splits violations into two severity tiers under Article 83. Lower tier violations, things like inadequate record-keeping or missing a breach notification deadline, cap at 10 million euros or 2 percent of global annual turnover, whichever figure is higher. Higher tier violations, which cover core failures like processing personal data without a lawful basis or ignoring a data subject's rights, cap at 20 million euros or 4 percent of global annual turnover. That turnover figure is worldwide revenue for the entire corporate group, not just revenue earned inside the EU, which is why the fine exposure for a large multinational can run into the hundreds of millions even for a single incident.
Within that statutory ceiling, the assigned data protection authority has wide discretion. It weighs the nature and duration of the violation, the number of people affected, whether the data involved was sensitive, and how the company behaved once the violation came to light. This calculator applies those same inputs to move from a bare percentage cap toward a number that reflects how enforcement actually works.
| Tier | Statutory Cap | Example Violations |
|---|---|---|
| Lower tier (Art. 83(4)) | 10 million euros or 2 percent of turnover | Record-keeping failures, missed breach notification, inadequate contracts with processors |
| Higher tier (Art. 83(5) and (6)) | 20 million euros or 4 percent of turnover | No lawful basis for processing, violating core data subject rights, ignoring a regulator order |
Why real GDPR fines land well below the statutory maximum
The 2 percent and 4 percent figures get quoted constantly, but they describe a ceiling, not a typical outcome. Regulators size a fine to be effective, proportionate, and dissuasive for the specific facts in front of them, and in practice that produces numbers far smaller than the theoretical maximum. Some of the largest GDPR fines ever issued illustrate this clearly.
- British Airways was initially facing a fine close to the statutory maximum before the final penalty was reduced to a fraction of that figure.
- Marriott's fine followed a similar pattern, settling well under the 4 percent ceiling despite the scale of the breach.
- H and M and TIM, two of the largest fines issued by European regulators, also landed at roughly 3 to 4 percent of each company's theoretical maximum exposure rather than the full cap.
- Across these and other large enforcement actions, self-reporting, cooperation, and swift remediation were consistently cited as reasons the final fine sat well below the statutory ceiling.
This is exactly why the calculator's realistic fine estimate exists alongside the statutory maximum. Quoting only the maximum overstates real exposure for most companies, especially smaller ones with turnover under a few million dollars, where the calculated maximum is often the flat euro floor rather than the percentage figure at all.
What counts as a reportable GDPR violation or data breach
A GDPR violation is any failure to meet an obligation set out in the regulation, which is broader than most people assume. A personal data breach specifically means an accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. Both can trigger a fine, but a breach additionally triggers a notification obligation: controllers generally must notify their supervisory authority within 72 hours of becoming aware of a breach that risks the rights and freedoms of the people affected, and must notify those individuals directly when the risk is high.
Scale and sensitivity both move the needle on severity. A breach affecting a few hundred people is treated very differently from one affecting hundreds of thousands, and special category data, meaning health records, biometric identifiers, genetic data, or information about a child, pushes a violation toward the higher end of the severity scale regardless of how many records were involved. This calculator's data subjects affected and special category data inputs exist because both factors are explicitly called out in the EDPB's own guidance on setting fine amounts.
Data protection failures often start with weak contractual terms between a company and the vendors or partners it shares data with. If you are drafting or reviewing an agreement that touches personal data, the Contract Value Calculator can help you think through the value and risk on the table before you sign.
Factors that increase or reduce a GDPR penalty
Beyond the statutory tier, a handful of factors consistently move a real GDPR penalty up or down, and this calculator's inputs mirror them directly.
| Factor | Effect on Fine |
|---|---|
| Self-reported the violation to the regulator | Reduces the estimate; regulators credit voluntary disclosure |
| Cooperated fully with the investigation | Reduces the estimate further |
| Violation was intentional rather than negligent | Increases the estimate substantially |
| Weak or no technical security measures in place | Increases the estimate |
| Ongoing or systemic violation rather than a brief one | Increases severity and the resulting estimate |
None of these factors operate in isolation. A company that self-reports an intentional violation still faces a materially higher penalty than one that self-reports simple negligence, and a company with strong encryption and access controls in place going into an incident is treated more leniently than one with none, even when the breach itself was identical in scale. The realistic fine estimate this calculator produces combines all of these inputs at once, the same way a regulator's own severity assessment does.
GDPR breach notification and how it affects your fine
A data breach and a breach notification failure are two separate things a regulator can penalize. Article 33 requires a controller to notify its supervisory authority within 72 hours of becoming aware of a breach that risks people's rights and freedoms, and to notify the affected individuals directly when that risk is high. Missing the 72-hour window, understating the scope of a breach, or failing to notify at all is treated as its own aggravating factor layered on top of whatever caused the breach in the first place.
This is where the self-reported input in this calculator does most of its work. A company that meets its notification obligation and comes forward voluntarily is, in practice, treated meaningfully better than one a regulator discovers through a complaint, a journalist, or a competitor. Combined with full cooperation once an investigation opens, timely notification is one of the few factors within a company's control after a breach has already happened, which is why it moves the realistic fine estimate down rather than the statutory maximum, which stays fixed regardless of how the company responds.
If your organization relies heavily on confidentiality agreements to protect the personal or proprietary data you handle, the NDA Value Calculator is a useful companion for putting a number on what that confidentiality is actually worth.
Frequently Asked Questions
Is a GDPR fine based on global turnover or just EU revenue?
Global turnover. The percentage caps in Article 83 apply to the annual worldwide turnover of the entire undertaking, meaning the whole corporate group, not just the revenue a company earns inside the European Union. This is why multinational companies face fine exposure in the hundreds of millions even when the affected EU operation is relatively small.
Does the GDPR fine calculation use revenue or profit as turnover?
Revenue. Turnover under Article 83 means gross annual turnover, the total revenue the undertaking generates, not net profit after costs and taxes. A company can have thin margins or even a loss and still face a fine calculated against its full revenue figure, which is why turnover-based exposure can look large relative to actual profitability.
Does GDPR apply to companies based outside the EU?
Yes. GDPR has extraterritorial reach and applies to any organization, regardless of location, that offers goods or services to people in the EU or monitors the behavior of people located there. A company with no EU office can still be fined.
Who actually enforces and issues GDPR fines?
Each EU member state has its own independent data protection authority, such as Ireland's Data Protection Commission or Germany's regional authorities, which investigates complaints and issues fines within its jurisdiction. The European Data Protection Board coordinates consistency across these national regulators for cross-border cases.
What is considered special category data under GDPR?
Special category data includes health information, biometric or genetic data used for identification, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation, and any data concerning children. A breach involving this data is treated more severely than a breach of ordinary contact details, which is why it is a separate input in this calculator.
Can individuals sue for compensation after a GDPR breach, separate from the regulatory fine?
Yes. Article 82 gives individuals a separate right to claim compensation for material or non-material damage caused by a GDPR violation, pursued through the courts rather than the regulator. This is independent of, and in addition to, any administrative fine a data protection authority imposes on the company.
How can a business reduce its GDPR fine risk before an incident happens?
The practices regulators consistently credit include minimizing the personal data collected in the first place, documenting a clear lawful basis for every processing activity, running data protection impact assessments for higher-risk processing, training staff on breach recognition, and maintaining the technical security measures, such as encryption and access controls, that this calculator asks about directly.
Is this estimate a guarantee of what a regulator would actually charge?
No. It is a transparent approximation built from the EDPB's published severity and size bands and calibrated against documented cases, useful for budgeting and risk planning. A real fine depends on the specific facts of an investigation and the discretion of the assigned regulator, so treat this as a starting point rather than a legal prediction.
Sources
- Regulation (EU) 2016/679 (General Data Protection Regulation) - full text, incl. Article 83 on administrative fines, EUR-Lex (Publications Office of the European Union)
- Guidelines 04/2022 on the calculation of administrative fines under the GDPR (final version), European Data Protection Board (EDPB)
- General Data Protection Regulation (GDPR) - Summary, EUR-Lex (Publications Office of the European Union)
Spot a mistake? Tell us what's wrong.
Request a calculator. The most-requested ones get built first in our monthly batch.
Request a calculatorWant this calculator on your website?
Embed the GDPR Data Breach Fine Estimator on any site — no code needed. Customize colors, remove branding, and track usage.
