Free tool
GDPR fine calculator
Enter your company's annual worldwide turnover to see the maximum fine the GDPR or UK GDPR allows for your business, and whether the fixed cap or the percentage of turnover applies. It runs in your browser; nothing is sent to us and no signup is needed.
Use the total worldwide annual turnover of the preceding financial year, for the whole group of companies if you belong to one.
Standard maximum
Article 83(4): for example, failing to keep records, secure processing or appoint a DPO where required
€10,000,000
The fixed cap of €10,000,000 applies, because 2% of your turnover is only €40,000.
Higher maximum
Article 83(5): for example, breaching the basic principles, the conditions for consent or data subject rights
€20,000,000
The fixed cap of €20,000,000 applies, because 4% of your turnover is only €80,000.
These are legal maximums, not predictions. Regulators set the actual amount case by case, and most fines are far below the maximum.
Worked examples
Maximum fines under the EU GDPR at different turnover levels, calculated with the same formula as the calculator.
| Annual turnover | Standard maximum (Art. 83(4)) | Higher maximum (Art. 83(5)) |
|---|---|---|
| €500,000 | €10,000,000 | €20,000,000 |
| €5,000,000 | €10,000,000 | €20,000,000 |
| €50,000,000 | €10,000,000 | €20,000,000 |
| €500,000,000 | €10,000,000 | €20,000,000 |
| €5,000,000,000 | €100,000,000 | €200,000,000 |
The percentage starts to exceed the fixed cap at a turnover of €500,000,000 for the standard tier and €500,000,000 for the higher tier.
How the maximum is calculated
Article 83 of the GDPR sets two tiers. The standard tier allows up to EUR 10 million or 2% of total worldwide annual turnover, whichever is higher. The higher tier allows up to EUR 20 million or 4%, whichever is higher. The UK GDPR uses the same structure with GBP 8.7 million or 2%, and GBP 17.5 million or 4%.
Consent failures, such as setting tracking cookies without valid consent, fall under the conditions for consent and the basic principles, which belong to the higher tier. Cookie rules also come from national ePrivacy laws, which have their own penalties; regulators such as France's CNIL have fined cookie violations under those laws.
What decides the actual fine
Article 83(2) lists what regulators weigh when they set the amount. Most fines are far below the maximum because of these factors:
Nature, gravity and duration
How serious the infringement is, how many people it affected and for how long.
Intent or negligence
Whether the infringement was deliberate or careless.
Mitigation
What you did to limit the damage once you knew.
Responsibility and safeguards
The technical and organizational measures you had in place.
History and cooperation
Previous infringements, and how well you cooperated with the regulator.
Data categories and how it came to light
Whether sensitive data was involved, and whether you reported it yourself.
Lower your cookie risk
The most common cookie problem is trackers that fire before the visitor has agreed. Start with a scan of your site: the free cookie scanner lists what loads, and GetCookies can block non-essential scripts until consent and log every decision as proof. Our GDPR compliance overview explains what the rules require.
Try GetCookies on your own site
Start on the Free plan: one domain, a cookie scan and a consent banner, no credit card required. Upgrade only when you need more.
無料で始める