Enter your turnover and the type of violation to see the statutory fine ceiling under Article 83 GDPR, and an indicative risk range based on the safeguards you already have in place.
Share this
1Your business
The statutory cap is based on your total worldwide annual turnover, not just EU revenue.
2Safeguards already in place
Under Art. 83(2), regulators weigh these when deciding where in the range a fine actually lands. Check what's true for you.
Your estimate
Statutory maximum
—The absolute legal ceiling for this violation and turnover
Indicative risk range
—
—
This range models where the enforcement pattern of most GDPR fines actually falls for cases like this one — it moves as you check off safeguards above. It is an illustrative estimate, not a prediction of any specific case outcome.
How GDPR fines actually work
Article 83 GDPR splits infringements into two tiers, each with its own statutory ceiling. The fine is always whichever figure is higher: the fixed amount, or the percentage of the company's total worldwide annual turnover from the previous financial year.
Lawful basis, consent, special category data, data subject rights, international transfers, ignoring DPA orders
The cap is a ceiling, not a typical outcome. Most fines issued to small and medium businesses land well below the statutory maximum — regulators weigh the ten Art. 83(2) factors (duration, intent, mitigation, cooperation, prior history, and more) before setting the actual figure. That's what the checklist above is modelling.
Want to know exactly where your gaps are?
This calculator estimates exposure. The free GDPR Audit tells you precisely which controls are missing and what to fix first.
This tool provides an illustrative, educational estimate based on the statutory fine tiers in Article 83 GDPR and general enforcement patterns. It is not legal advice, does not use any real case data, and cannot predict the outcome of any specific investigation. Actual fines are set case-by-case by the competent supervisory authority. For a real risk assessment, consult a qualified data protection professional or lawyer.
Prefer to listen? Click play for AI narration
Why It Matters
GDPR fines scale with your turnover, not your intent
Article 83 GDPR sets statutory maximums of up to €20 million or 4% of global annual turnover, whichever is higher, for the most serious violations — and 2% or €10 million for less severe ones. Where an actual fine lands within that ceiling depends on factors like the nature and duration of the breach, how many people were affected, whether you cooperated with the regulator, and what safeguards you already had in place.
This calculator estimates the statutory ceiling that applies to your turnover and violation type, then narrows it to an indicative risk range based on the safeguards you tell it you already have — so you can see roughly where you'd sit, and what reduces that exposure.
1
Enter turnover and violation type
Your annual global turnover, and the category of GDPR violation involved.
2
Ceiling calculated under Article 83
The statutory maximum fine that applies at your turnover level.
3
Get an indicative risk range
Narrowed based on the safeguards and mitigating factors you already have in place.
Common Questions
Before you calculate
Is this the exact fine I'd actually pay?▼
No — it's an indicative range, not a prediction. Actual fines are set case-by-case by the relevant supervisory authority, weighing factors this calculator can only approximate from the details you provide.
Why do some violations have a lower ceiling than others?▼
Article 83 splits violations into two tiers. Less severe breaches (like inadequate record-keeping) are capped at €10 million or 2% of turnover; more serious ones (like violating core data-processing principles or data subject rights) are capped at €20 million or 4%.
What safeguards actually reduce risk?▼
Having documented policies, a designated point of contact for data protection, evidence of prompt breach response, and a track record of cooperating with regulators are all factors that typically weigh in your favour when a fine is assessed.
Where do the €20M / 4% figures come from?▼
Directly from Article 83(5) and (6) GDPR, which set the statutory maximum penalties supervisory authorities can impose — this calculator applies those thresholds to the turnover figure you enter.
Is the information I enter stored?▼
No. Your inputs are processed to generate the estimate, then discarded — nothing is retained on our servers. See the note below for the full legal basis.
Should I use this if I'm actually facing a regulatory investigation?▼
Use it to understand the scale of exposure, but get a data protection lawyer involved immediately for anything beyond a hypothetical estimate — an active investigation needs real legal representation, not a calculator.
🍪 We use necessary cookies to run this site (no tracking scripts run without your consent). Optional analytics cookies only load if you accept them — we currently have none active. No non-essential data leaves your browser until you choose "Accept All."
See our Cookie Policy and Privacy Policy for details.