TLDR: Free GDPR fine calculator that estimates your enforcement risk based on revenue, traffic, industry, and cookie violations. Input your numbers, get a range estimate, and understand which factors matter most—before a regulator calculates it for you.
Read full summary
An interactive tool that estimates potential GDPR fine exposure based on company revenue, website traffic, industry sector, cookie count, consent implementation status, and pre-consent violations. Uses the official GDPR fine calculation methodology (up to €20M or 4% of global turnover) with risk multipliers for various factors.
*Summary by Claude AI*
## The Number That Changed the Budget Meeting
A marketing director walked into a quarterly review with confidence. Their website was driving €2.3 million in annual revenue. The compliance budget request: €15,000 for a proper consent management implementation.
The CFO asked: "Why should we spend €15,000 on cookie compliance?"
The marketing director opened the GDPR Fine Calculator, entered the company details, and showed the screen: **Estimated fine exposure: €340,000 - €920,000**.
The compliance budget was approved before lunch.
Numbers win arguments. Especially when they come from official fine calculation methodology.
## How GDPR Fines Are Actually Calculated
The GDPR defines two fine tiers:
### Lower Tier (Article 83(4))
- Up to **€10 million** or **2%** of global annual turnover
- Applies to: Technical violations, incomplete records, failure to notify
### Upper Tier (Article 83(5))
- Up to **€20 million** or **4%** of global annual turnover
- Applies to: Consent violations, unlawful processing, cross-border transfers
Cookie consent violations typically fall under Article 83(5)—the higher tier. Processing personal data (including through cookies) without valid consent is classified as unlawful processing.
### The Calculation Factors
Regulators consider:
1. **Nature, gravity, and duration**: How bad, for how long?
2. **Intentional vs negligent**: Did you know, or should you have known?
3. **Actions to mitigate**: Did you try to fix it?
4. **Technical and organizational measures**: What was your setup?
5. **Previous infringements**: Repeat offender?
6. **Cooperation level**: Did you work with the regulator?
7. **Data categories affected**: Sensitive data involved?
8. **How the violation was discovered**: Self-reported vs complaint?
9. **Certifications**: Any compliance programs in place?
10. **Aggravating/mitigating factors**: Everything else relevant
## How the Calculator Works
### Input: Your Details
**Company Information**
- Annual global revenue
- Industry sector (affects risk multiplier)
- Number of EU website visitors/month
**Cookie Compliance Status**
- Do you have a consent mechanism?
- Are there pre-consent cookie violations?
- Total cookie count on your site
### Output: Fine Range Estimate
The calculator returns:
- **Lower bound estimate**: Conservative scenario
- **Upper bound estimate**: Aggressive enforcement scenario
- **Risk level**: Low, Medium, High, or Critical
- **Contributing factors**: What's driving your risk
### Industry Risk Multipliers
Some industries face higher scrutiny:
| Industry | Multiplier | Reason |
|----------|------------|--------|
| Healthcare | 1.5x | Sensitive data, high public interest |
| Finance | 1.4x | Financial data, regulated sector |
| Government | 1.3x | Public accountability expectations |
| E-commerce | 1.2x | Scale of data processing |
| Technology | 1.1x | Should know better |
| Media | 1.1x | High traffic, advertising focus |
| Education | 1.0x | Baseline |
| Other | 1.0x | Baseline |
## Real Calculation Examples
### Example 1: Mid-Size E-commerce
**Inputs:**
- Annual revenue: €5 million
- Industry: E-commerce (1.2x)
- Monthly EU visitors: 200,000
- Cookies: 25
- Has consent banner: Yes
- Pre-consent violations: Yes
**Result:**
- Risk Level: **High**
- Estimated Range: **€80,000 - €200,000**
- Key Factors:
- Pre-consent cookie violations detected
- High number of cookies (25)
- Moderate traffic volume
### Example 2: Small SaaS Company
**Inputs:**
- Annual revenue: €800,000
- Industry: Technology (1.1x)
- Monthly EU visitors: 50,000
- Cookies: 8
- Has consent banner: Yes
- Pre-consent violations: No
**Result:**
- Risk Level: **Low**
- Estimated Range: **€3,200 - €8,000**
- Key Factors:
- Moderate cookie count
- Consent mechanism in place
- No detected pre-consent violations
### Example 3: Large Healthcare Platform
**Inputs:**
- Annual revenue: €50 million
- Industry: Healthcare (1.5x)
- Monthly EU visitors: 1,000,000+
- Cookies: 40
- Has consent banner: No
- Pre-consent violations: Yes
**Result:**
- Risk Level: **Critical**
- Estimated Range: **€1,500,000 - €2,000,000**
- Key Factors:
- No consent mechanism
- Pre-consent violations
- High cookie count
- High traffic volume
- Healthcare multiplier
## What Drives Fine Amounts
### Pre-Consent Violations (+40% base risk)
This is the single biggest factor. Cookies that fire before consent represent clear evidence of unlawful processing. Regulators can prove this with a single automated scan.
### No Consent Mechanism (+30% base risk)
No banner at all? That's not negligence—regulators may view it as intentional non-compliance.
### High Cookie Count (+10-15% base risk)
More cookies mean more processing, more third parties, and more potential violations. Sites with 20+ cookies face higher scrutiny.
### Traffic Volume (+10-20% base risk)
High-traffic sites affect more data subjects. A violation on a site with 1M monthly visitors is worse than the same violation on a 10K visitor site.
### Industry Sector (multiplier)
Healthcare and finance face higher expectations due to data sensitivity and existing regulations.
## Using the Calculator for Business Cases
### Budget Justification
Compare estimated fine exposure to compliance costs:
| Item | Cost |
|------|------|
| Potential Fine (low) | €80,000 |
| Potential Fine (high) | €200,000 |
| GetCookies Annual License | €1,200 |
| Implementation Time | 4 hours |
ROI is clear when you show the alternative.
### Risk Prioritization
Run the calculator for each of your domains to prioritize:
1. Highest exposure sites first
2. Highest traffic sites second
3. Remaining sites by revenue
### Stakeholder Communication
Technical teams understand compliance requirements. Executives understand financial risk. The calculator translates one to the other.
## Limitations and Caveats
### Estimates, Not Predictions
This calculator provides directional guidance based on publicly documented fine methodology. Actual fines depend on:
- Specific regulator discretion
- Complete investigation findings
- Company cooperation level
- Public vs private enforcement
### Worst-Case Orientation
Fine estimates assume the regulator finds violations. If your consent implementation is solid, actual enforcement risk may be lower.
### Not Legal Advice
The calculator is an educational tool. For specific situations, consult qualified legal counsel familiar with your jurisdiction and circumstances.
## Next Steps After Calculation
### If Risk Level is Low
- Maintain current practices
- Schedule periodic compliance scans
- Document your consent implementation
### If Risk Level is Medium
- Audit your cookie implementation
- Verify consent is properly blocking tracking
- Review third-party scripts
### If Risk Level is High or Critical
- Immediate remediation recommended
- Consider professional consent management
- Document timeline of fixes
- Prepare response plan
## Try the Calculator
1. Go to [getcookies.co/tools/fine-calculator](https://getcookies.co/tools/fine-calculator)
2. Enter your company details
3. Get instant risk assessment
Understanding your exposure is the first step to reducing it.
The regulators have their calculators. Now you have yours.