GDPR Fine Exposure Calculator
Work out which GDPR fining cap applies to an infringement, what the statutory maximum is for your turnover, and where the EDPB fining methodology would place a starting amount before aggravating and mitigating factors.
Last reviewed by the Radiatus Cloud team
Going for ISO 27001, SOC 2, HIPAA or GDPR?
Radiatus runs end-to-end compliance & GRC programs.
Two caps, and the one that applies is fixed by the article breached
Article 83(4) sets a maximum of ten million euro or two percent of worldwide annual turnover, whichever is higher, for obligations on controllers and processors such as security, records and impact assessments. Article 83(5) sets twenty million or four percent for breaches of the principles, of lawful basis, of data subject rights and of the transfer rules. Which cap applies is not a matter of severity; it is fixed by which provision was infringed, and a minor breach of a 83(5) obligation carries the higher cap while a serious breach of a 83(4) obligation does not.
Turnover means the undertaking, not the legal entity
The percentage is calculated on the worldwide annual turnover of the undertaking in the preceding financial year, and the Court of Justice has confirmed that undertaking carries its competition-law meaning: the whole economic unit, including a parent. A subsidiary with modest revenue that belongs to a large group is exposed to a percentage of the group's turnover, which is usually the difference between a nominal cap and a substantial one.
The EDPB method starts from the cap, not from the harm
The EDPB's fining guidelines set a starting amount as a proportion of the applicable cap based on the seriousness of the infringement, then adjust for the size of the undertaking, then apply the aggravating and mitigating factors in Article 83(2), and finally check the result against the cap and against effectiveness, proportionality and dissuasiveness. Reproducing that structure shows why turnover dominates the outcome, but it produces a range rather than a number, and no methodology predicts what a particular authority will do.
Related tools
- SOC 2 Evidence Readiness — Interactive checklist to gauge your SOC 2 evidence readiness.
- Privacy Policy Checker — Check if your policy covers standard requirements (GDPR/CCPA basics).
- Compliance Req Finder — Find which standards (ISO, SOC2, HIPAA) apply to your industry/region.
- Audit Readiness Planner — Plan your compliance audit timeline (SOC2, ISO) backwards from deadline.
Frequently Asked Questions
Which cap applies to my infringement?
It depends on the article breached, not on how serious it was. Article 83(4) obligations carry the 10 million or 2 percent cap; Article 83(5) obligations, including the principles, lawful basis, data subject rights and transfers, carry 20 million or 4 percent.
Is the percentage based on my company or my group?
On the undertaking, which the Court of Justice has confirmed carries its competition-law meaning: the whole economic unit including a parent. A small subsidiary of a large group is exposed to a percentage of group turnover.
Does the cap mean the fine will be that large?
No. The cap is the maximum. The EDPB methodology starts at a proportion of the cap based on seriousness and adjusts from there, and most fines land far below the maximum.
Can this predict my fine?
No, and nothing can. It shows the statutory maximum, which is arithmetic, and where the published methodology would place a starting point, which is a range. What a supervisory authority actually decides depends on facts no calculator holds.
What reduces the amount?
Article 83(2) lists the factors, including the degree of cooperation, measures taken to mitigate damage, whether the infringement was reported voluntarily, and adherence to approved codes of conduct. Voluntary notification and demonstrable remediation are the two that most consistently matter.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Select the infringement type and enter your turnover to see the applicable cap.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
SOC 2 Evidence Readiness
ComplianceInteractive checklist to gauge your SOC 2 evidence readiness.
Privacy Policy Checker
ComplianceCheck if your policy covers standard requirements (GDPR/CCPA basics).
Compliance Req Finder
ComplianceFind which standards (ISO, SOC2, HIPAA) apply to your industry/region.