Free GDPR fine calculator

GDPR fine calculator
under Article 83.

Article 83 puts every GDPR obligation in one of two tiers: up to €10 million or 2% of worldwide turnover, or up to €20 million or 4%, whichever is higher. Tick what would be infringed, enter your turnover, and see the ceiling for each tier and for the case, with the factors that decide the real number.

Which obligations would be infringed?

Each one sits in a tier of Article 83. Tick every one that applies; the result shows the ceiling for each tier and for the case as a whole.

Higher tier: up to €20 million or 4% of turnover

Lower tier: up to €10 million or 2% of turnover

Your turnover

The whole undertaking, which can mean the whole group (see below). Digits only; commas are fine.
How the amount is set
This is the statutory maximum under Article 83 GDPR, not a forecast. The supervisory authority sets the actual fine, case by case, using the Article 83(2) factors, and it can be far below the ceiling, or no fine at all.
01

The two tiers of Article 83

Article 83 of the GDPR sets two ceilings and assigns every obligation in the Regulation to one of them. Both are expressed as a fixed sum or a percentage of the total worldwide annual turnover of the preceding financial year, whichever is higher. For a small company the fixed sum is the ceiling; above €500 million of turnover the percentage takes over.

TierWhat is in itMaximum
LowerArticle 83(4)Controller and processor obligations in Articles 8, 11, 25 to 39, 42 and 43: children's consent, privacy by design, processor contracts, records, security, breach notification, DPIAs, the DPO. Also the obligations of certification bodies (Articles 42 and 43) and monitoring bodies (Article 41(4))€10m or 2%whichever is higher
HigherArticle 83(5)The principles and lawful bases (Articles 5, 6, 7 and 9), data subjects' rights (Articles 12 to 22), international transfers (Articles 44 to 49), national law under Chapter IX, and ignoring an authority's order or refusing it access (Article 58)€20m or 4%whichever is higher
OrdersArticle 83(6)Non-compliance with an order of the supervisory authority under Article 58(2)€20m or 4%whichever is higher

Percentages are of total worldwide annual turnover of the preceding financial year. Read on EUR-Lex, Regulation (EU) 2016/679, October 2026.

The split is deliberate. The lower tier is mostly the machinery of compliance: the records, contracts, assessments and security that make the rules work. The higher tier is the rules themselves: whether you had a lawful basis at all, whether you honoured people's rights, and whether data left the EEA lawfully. Breach notification and security sit in the lower tier, which surprises people, but a breach rarely comes alone: an insecure system usually also breaches the Article 5(1)(f) integrity and confidentiality principle, which is in the higher one.

02

How the actual amount is set

Article 83(1) requires every fine to be effective, proportionate and dissuasive, and Article 83(2) lists what the authority must give due regard to when it decides whether to fine and how much. The ceiling is where that exercise stops, not where it starts.

  • The nature, gravity and duration of the infringement, the purpose of the processing, the number of people affected and the damage they suffered
  • Whether it was intentional or negligent
  • What you did to mitigate the damage to the people affected
  • Your degree of responsibility, given the measures you had in place under Articles 25 and 32
  • Relevant previous infringements
  • How far you cooperated with the authority to remedy it
  • The categories of personal data affected
  • How the authority found out, and in particular whether you notified it
  • Compliance with any earlier corrective measures, adherence to approved codes of conduct or certification, and any other aggravating or mitigating factor, such as financial benefit gained or losses avoided

Most of those are facts you create before anything goes wrong: the security measures you can show were in place, the records that let you scope an incident, and a notification made on time. That is why the same infringement can end in a reprimand for one company and a large fine for another.

03

Turnover, groups and several infringements

Whose turnover. The percentage limb applies to an undertaking, and Recital 150 says an undertaking is to be understood as in Articles 101 and 102 TFEU, the competition law concept. In competition law an undertaking can be a whole group under common control, so a subsidiary's ceiling may be calculated on its group's worldwide turnover rather than its own. Enter the figure that would apply to you, and check with counsel which that is.

Several infringements. Article 83(3) says that where a controller or processor infringes several provisions, intentionally or negligently, for the same or linked processing operations, the total fine cannot exceed the amount for the gravest infringement. That is why the calculator shows one overall ceiling, set by the highest tier you ticked, rather than adding the tiers together.

Not an undertaking. For a person who is not an undertaking only the fixed sums apply, and Recital 150 asks the authority to take account of the general level of income in the member state and the person's economic situation. Whether public authorities can be fined at all is left to each member state by Article 83(7).

04

The UK GDPR

Since Brexit the UK has its own copy of the Regulation, the UK GDPR, with the ceilings converted to sterling. Section 157 of the Data Protection Act 2018 sets the higher maximum at £17,500,000 or 4% of total annual worldwide turnover in the preceding financial year, and the standard maximum at £8,700,000 or 2%, whichever is higher in each case for an undertaking. The obligations fall into the same two tiers, and the Information Commissioner sets the amount. A company selling into both markets can face both regimes for the same processing.

05

Sources

For what the GDPR requires in the first place, see the GDPR guide and does GDPR apply to my company?. If you also process data of people in India, the DPDP penalty calculator does the same for the DPDP Act's fixed-rupee schedule.

Questions

The things people ask us

What is the maximum GDPR fine?

€20 million or 4% of the total worldwide annual turnover of the preceding financial year, whichever is higher, under Article 83(5) and (6). That tier covers the processing principles, lawful bases, consent, special category data, data subjects' rights, international transfers and ignoring an authority's order. Other controller and processor obligations carry up to €10 million or 2%, under Article 83(4).

Is the GDPR fine the higher or the lower of the two figures?

The higher. For an undertaking, each tier is the fixed amount or the percentage of worldwide turnover, whichever is higher, so the percentage only matters once turnover passes €500 million. There is no lower-of rule for small companies in the GDPR, unlike the EU AI Act's Article 99(6).

Are GDPR fines added up for each infringement?

Not for the same or linked processing operations. Article 83(3) caps the total at the amount specified for the gravest infringement. Infringements arising from unrelated processing can be fined separately, each up to its own ceiling.

Does the 4% apply to the subsidiary or the whole group?

Recital 150 says an undertaking is to be understood as in Articles 101 and 102 TFEU, the competition law concept, which can cover a whole group under common control. So the percentage can be calculated on the group's worldwide turnover. Which entity's turnover applies to you is a question for counsel.

How does a supervisory authority decide the amount?

Using the Article 83(2) factors: the nature, gravity and duration of the infringement, intent or negligence, mitigation, the technical and organisational measures in place, previous infringements, cooperation, the categories of data, how the authority learned of it, compliance with earlier orders, codes of conduct or certification, and any financial benefit gained or loss avoided.

What are the UK GDPR fines?

Up to £17.5 million or 4% of total annual worldwide turnover, whichever is higher, for the higher tier, and up to £8.7 million or 2% for the standard tier, under section 157 of the Data Protection Act 2018. The Information Commissioner's Office sets the amount.

Is the result a prediction of our fine?

No. It is the statutory maximum for the obligations you ticked. The authority may issue a reprimand or an order instead of a fine, and where it does fine, the Article 83(2) factors usually put the amount well below the ceiling.

Book a walkthrough

A fine is set by what you can show.

Article 83(2) weighs the measures you had in place and how you responded. The platform keeps that evidence current, control by control, so it exists before anyone asks for it.