Estimate your potential GDPR fine based on violation type, company revenue, and aggravating/mitigating factors. Uses real enforcement data and Article 83 guidelines.
How GDPR Fines Are Calculated
Under the General Data Protection Regulation, administrative fines are not arbitrary — they follow a structured framework in Article 83. A supervisory authority works through two tiers of maximum penalties and then applies a set of ten mitigating and aggravating factors to land on an actual figure. Understanding that framework lets you use this gdpr fine calculator meaningfully rather than treating the output as a black box.
Lower Tier: Article 83(4) — Up to €10 Million or 2% of Global Annual Turnover
The lower tier covers procedural and organizational obligations rather than substantive data rights. Violations that fall here include:
- Failure to implement appropriate technical and organizational security measures (Article 25, 32)
- Breach notification failures — not telling the supervisory authority within 72 hours, or not notifying affected individuals when required (Articles 33–34)
- Inadequate data protection impact assessments (Article 35)
- Failure to appoint a Data Protection Officer where required (Article 37)
- Insufficient records of processing activities (Article 30)
The ceiling is €10 million or 2% of the undertaking’s total worldwide annual turnover in the preceding financial year, whichever is higher. For large multinationals the revenue-based ceiling dominates; for small companies the flat cap often applies.
Upper Tier: Article 83(5) — Up to €20 Million or 4% of Global Annual Turnover
The upper tier covers violations of the core principles of the regulation — the rules that define whether data is processed lawfully at all. These include:
- Violations of the basic principles for processing: lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality (Article 5)
- Processing without a lawful basis or without valid consent where consent is required (Articles 6–9)
- Violating data subjects’ rights — access, erasure, portability, objection (Articles 15–22)
- Unlawful international data transfers (Articles 44–49)
- Failing to comply with an order issued by a supervisory authority (Article 58)
The ceiling doubles to €20 million or 4% of annual turnover, whichever is higher. This is the tier that generates the headline fines.
The Article 83(2) Mitigating and Aggravating Factors
The actual fine a supervisory authority imposes sits somewhere between zero and the tier ceiling. Article 83(2) lists ten factors that pull the number up or down:
| Factor | Aggravates | Mitigates |
|---|---|---|
| Nature, gravity, duration of infringement | Intentional, systematic, long-running | Minor, isolated, short-lived |
| Number of data subjects affected | Millions of records | Limited scope |
| Damage suffered by data subjects | Financial loss, identity harm | No material damage |
| Degree of responsibility | Deliberate disregard of controls | Negligence without intent |
| Previous infringements | Repeat offender | Clean enforcement history |
| Degree of cooperation | Obstruction, concealment | Proactive notification, full disclosure |
| Categories of personal data | Special categories (health, biometric, children) | Non-sensitive ordinary data |
| Notification of breach by controller | Authority learned from third party | Self-reported promptly |
| Adherence to approved codes of conduct | None | Certified, code-compliant |
| Financial benefit gained from infringement | Monetised the violation | No economic gain |
For deeper context on how regulators use these factors in practice, see our guide on how GDPR enforcement actually works.
How to Use This Calculator
The calculator above walks you through the same logic a DPA applies when sizing a fine. Here is what each input means:
- Violation tier — choose whether your issue falls under Article 83(4) (procedural) or 83(5) (substantive principles and rights). If you are not sure, the lower tier is the safer starting assumption for planning purposes.
- Global annual revenue — enter the worldwide turnover of the entire corporate group, not just the local entity. Under GDPR, “undertaking” follows EU competition-law logic and can capture a parent company’s full revenue.
- Mitigating / aggravating factors — adjust the sliders for each Article 83(2) factor. The tool weights them proportionally. Moving all factors to maximum aggravation approaches the tier ceiling; strong mitigation can bring the estimate below 5% of the maximum.
- Affected individuals — the number of data subjects influences severity weighting. A breach touching 500 people is treated differently from one exposing five million records.
The output is an estimate — not legal advice. Actual fines depend on the specific DPA, the quality of your cooperation during the investigation, and case law that develops over time. Use the figure for risk-quantification, insurance conversations, and budget-setting for compliance programmes. Then run our GDPR compliance self-assessment to identify where your exposure is highest.
Real GDPR Fine Examples by Violation Type
Enforcement data from across the EU makes the Article 83 logic concrete. The following cases are drawn from publicly reported decisions.
Consent and lawful basis (Upper tier, Art. 83(5)): Amazon was fined €746 million by Luxembourg’s CNPD in 2021 for processing personal data for advertising without a valid lawful basis — the largest single GDPR fine on record at the time. Meta received a €1.2 billion fine from Ireland’s DPC in 2023 for transferring EU user data to the United States without an adequate transfer mechanism, an Article 46 violation. TikTok was fined €345 million by Ireland’s DPC in 2023 for failures in children’s data protection, including default-public settings and family pairing weaknesses.
Cookie consent (Upper tier where principles are violated, Lower tier for procedural failures): France’s CNIL fined Google €150 million and Facebook €60 million in early 2022 for making it harder for users to refuse cookies than to accept them — a transparency and consent principle violation under Article 5(1)(a).
Data breach and security failures (Lower or upper tier depending on root cause): British Airways was initially issued a notice of intent for £183 million (later settled at £20 million) by the UK ICO for a 2018 breach affecting approximately 500,000 customers. The reduction reflected significant cooperation and the economic impact of the pandemic.
Data subject rights failures (Upper tier, Art. 83(5)): Multiple fines in the range of €5,000–€500,000 have been issued across EU member states for simply failing to respond to access or erasure requests within the required one-month window.
Identity and Personal Data Violations: The Highest-Risk Category
Article 5 of GDPR — the lawfulness, fairness, and transparency principle — sits at the heart of the upper tier. For identity-related processing, this matters acutely. Any operation that touches authentication credentials, biometric templates, government identifiers, or detailed behavioural profiles linked to a natural person falls into the category where regulators have shown the least tolerance.
The reason is straightforward: identity data violations cause harms that are difficult or impossible to reverse. A leaked password can be changed. A leaked biometric cannot. A stolen government ID number can enable years of downstream fraud. Regulators reflect this asymmetry in their use of the Article 83(2) factors, particularly “damage suffered by data subjects” and “categories of personal data processed.”
If your organisation processes identity-layer data — digital identities, sign-on credentials, KYC records, or behavioural profiles used for authentication — the realistic fine exposure is typically modelled at 40–70% of the Article 83(5) ceiling rather than the 10–20% range that applies to lower-sensitivity use cases. Use the calculator accordingly, and ensure you have reviewed your consent obligations for each processing purpose.
Frequently Asked Questions
What is the maximum GDPR fine?
The absolute ceiling under Article 83(5) is €20 million or 4% of the undertaking’s total worldwide annual turnover in the preceding financial year, whichever is higher. For a company with €30 billion in global revenue, the 4% upper-tier ceiling would be €1.2 billion. In practice regulators rarely impose the maximum — most fines land far below it.
How is a GDPR fine actually calculated?
Supervisory authorities start by determining which tier applies (Art. 83(4) or 83(5)), establish the ceiling based on the higher of the flat amount or the revenue percentage, and then work through the ten factors in Article 83(2) to land on a specific figure. The European Data Protection Board’s guidelines on Article 83 (adopted 2023) formalise a five-step methodology: classify the infringement, set a starting amount, adjust for aggravating/mitigating factors, apply the ceiling, and check proportionality.
What is the difference between the 2% and 4% tiers?
The 2% tier (Art. 83(4)) covers organisational and procedural violations — record-keeping, DPO appointment, data protection by design, breach notification. The 4% tier (Art. 83(5)) covers violations of the substantive principles: lawful basis, consent, data subject rights, and international transfers. A breach that began as a security failure (2% tier) can escalate to the 4% tier if the investigation reveals the underlying processing lacked a lawful basis.
Has any company actually hit the maximum GDPR fine?
No company has been fined the literal mathematical maximum, but several have been fined close to 4% of their global annual turnover. Meta’s €1.2 billion fine in 2023 represented roughly 1% of Meta’s annual revenue — large in absolute terms, but still well below the 4% ceiling, which is typical of even the biggest GDPR penalties. The theoretical maximum for a company the size of Amazon would exceed €17 billion.
Can individuals claim compensation under GDPR?
Yes. Article 82 GDPR gives any person who has suffered material or non-material damage as a result of a GDPR infringement the right to claim compensation from the controller or processor responsible. “Non-material damage” includes distress, loss of control over personal data, and reputational harm. Class-action style representative actions are becoming more common in Germany, the Netherlands, and Austria.
Which supervisory authority issues the most GDPR fines?
By number of fines, Spain’s AEPD has issued more decisions than any other DPA. By total value, Ireland’s DPC dominates because the major US tech companies (Meta, Google, Apple, TikTok) have their EU establishments in Ireland, making it the lead supervisory authority for cross-border cases under the one-stop-shop mechanism. Luxembourg’s CNPD holds the record for the single largest fine (Amazon, €746 million, 2021).