GDPR Penalty Estimator

Estimate the potential fine your organisation could face for a GDPR violation. Enter your annual global revenue, select the violation type (standard or serious), and indicate any mitigating factors. The tool calculates your maximum penalty exposure under GDPR Article 83, which caps fines at 4% of annual global turnover or €20 million for serious violations, and 2% or €10 million for standard violations, whichever is higher.

Ad Space

How GDPR Penalty Estimator Works

Estimate the potential GDPR fine for a data protection violation. Enter annual revenue, violation type, and mitigating factors. calculator. Use the tool above to get your results instantly — everything runs in your browser with no data sent to any server.

GDPR Fines Explained

The General Data Protection Regulation (GDPR) introduced a two-tier system of administrative fines to ensure that penalties are proportionate, effective, and dissuasive. The lower tier (Article 83(4)) allows fines of up to 2% of annual worldwide turnover or €10 million, whichever is greater, for violations relating to obligations of controllers and processors, certification bodies, and monitoring bodies. The upper tier (Article 83(5)) permits fines of up to 4% of annual worldwide turnover or €20 million, whichever is greater, for more serious violations including breaches of the basic principles of processing, conditions for consent, data subjects' rights, and international transfer provisions.

It is important to understand that these are maximum penalties. The actual fine imposed by a supervisory authority will depend on a careful assessment of the specific circumstances of the case. Article 83(2) sets out a list of factors that authorities must consider when determining both whether to impose a fine and the amount of that fine. These include the nature, gravity, and duration of the infringement; whether the violation was intentional or negligent; actions taken to mitigate damage; the degree of cooperation with the supervisory authority; and any relevant previous infringements.

How Supervisory Authorities Set Fines

In practice, GDPR fines have ranged from a few thousand euros for small organisations with minor violations to hundreds of millions of euros for large technology companies found to have committed systematic breaches. The European Data Protection Board (EDPB) published Guidelines 04/2022 on the calculation of administrative fines, which provide a five-step methodology for determining the appropriate fine amount. This methodology starts with identifying the processing operations concerned, then finding the starting point for the fine calculation based on the nature of the violation and the turnover of the undertaking, before adjusting for aggravating and mitigating factors.

This tool provides a simplified estimate of maximum exposure and the potential impact of mitigating factors. It is intended for awareness and planning purposes only and does not predict actual enforcement outcomes. Real-world fines depend on many factors that cannot be captured in a simple calculator, including the specific supervisory authority involved, the political and enforcement climate, and the quality of the organisation's data protection programme overall.

Frequently Asked Questions

What is the maximum GDPR fine?

The maximum GDPR fine depends on the type of violation. For serious violations (breaches of basic processing principles, consent conditions, data subject rights, or international transfers), the maximum is 4% of annual global turnover or \u20ac20 million, whichever is higher. For standard violations (obligations of controllers/processors, certification, or monitoring bodies), the maximum is 2% of annual global turnover or \u20ac10 million, whichever is higher.

Does the fine apply to the entire corporate group or just the entity that violated GDPR?

GDPR fines are calculated based on the total worldwide annual turnover of the preceding financial year of the "undertaking," which can mean the entire corporate group, not just the specific legal entity that committed the violation. This is intended to prevent large companies from limiting their exposure by placing data processing activities in low-revenue subsidiaries.

What mitigating factors can reduce a GDPR fine?

Mitigating factors include prompt action to address the infringement and reduce harm to data subjects, proactive cooperation with the supervisory authority, voluntary notification of the breach before it was discovered by the authority, implementation of approved codes of conduct or certification mechanisms, and any other mitigating circumstances such as financial hardship. The degree of mitigation depends on the specific case.

Can a company receive a GDPR fine even without a data breach?

Yes. GDPR fines can be imposed for any violation of the regulation, not just data breaches. Common non-breach violations that have attracted fines include processing personal data without a valid legal basis, failing to obtain proper consent, insufficient transparency in privacy notices, failure to honour data subject access requests, and inadequate data protection impact assessments.

Is GDPR Penalty Estimator free to use?

Yes, GDPR Penalty Estimator is completely free with no sign-up, no login, and no hidden fees. The tool runs entirely in your browser — your data never leaves your device.