Why use this calculator
The General Data Protection Regulation (GDPR) imposes some of the largest regulatory fines in the world, with penalties reaching up to 4% of global annual revenue or 20 million euros, whichever is greater. This calculator helps organizations estimate their potential fine exposure based on the nature and severity of a data protection violation. Understanding your risk helps prioritize compliance investments and data protection measures before a breach occurs.
How to use it
Enter your organization's global annual revenue, the number of data subjects potentially affected by a violation, the severity level of the violation, and whether your organization cooperated with data protection authorities. The calculator estimates a potential fine based on GDPR guidelines and adjusts for cooperation and scale of impact.
The formula
Maximum Fine = Greater of (4% of Annual Revenue) or 20 million EUR. Estimated Fine = Revenue x Severity Percentage, adjusted for cooperation (20% discount if cooperating) and scale of affected data subjects. Severity percentages: Minor = 1%, Significant = 2.5%, Major = 4% of revenue equivalent.
Worked examples
A company with $10M revenue affecting 50,000 data subjects with a significant violation and cooperation
Estimated fine of approximately $175,000 with maximum exposure of over $21.7 million
A large enterprise with $500M revenue and a major breach affecting 200,000 users without cooperation
Estimated fine of approximately $20 million, approaching the maximum 4% cap
When people use it
- Assessing financial risk of data protection non-compliance
- Justifying budget for data privacy and security investments
- Preparing board-level risk assessments for GDPR exposure
- Comparing cost of compliance programs versus potential fine exposure
Tips
- Cooperation with supervisory authorities is explicitly listed as a mitigating factor in GDPR Article 83 and can significantly reduce fines
- Demonstrating proactive compliance measures like Data Protection Impact Assessments can further reduce penalties
- Fines are determined by multiple factors including nature of the infringement, degree of negligence, and any previous violations
Questions people ask
- What is the difference between Article 83(4) and 83(5) fines?
- Article 83(4) covers less severe violations (like failing to maintain records) with fines up to 2% of revenue or 10 million EUR. Article 83(5) covers more severe violations (like unlawful processing or violating data subject rights) with fines up to 4% of revenue or 20 million EUR. This calculator uses the higher 83(5) tier.
- Has any company actually been fined the maximum amount?
- While no company has been fined the full 4%, large fines have been issued. Amazon was fined 746 million EUR in 2021, and Meta has received multiple fines exceeding 1 billion EUR. Most fines are significantly lower than the maximum but can still be substantial.
- Does GDPR apply to companies outside the EU?
- Yes. GDPR applies to any organization that processes the personal data of EU residents, regardless of where the company is based. This includes US companies serving EU customers.