Free tool

GDPR fine calculator

Enter your company's annual worldwide turnover to see the maximum fine the GDPR or UK GDPR allows for your business, and whether the fixed cap or the percentage of turnover applies. It runs in your browser; nothing is sent to us and no signup is needed.

Which law?

Use the total worldwide annual turnover of the preceding financial year, for the whole group of companies if you belong to one.

Standard maximum

Article 83(4): for example, failing to keep records, secure processing or appoint a DPO where required

10 000 000 €

The fixed cap of 10 000 000 € applies, because 2 % of your turnover is only 40 000 €.

Higher maximum

Article 83(5): for example, breaching the basic principles, the conditions for consent or data subject rights

20 000 000 €

The fixed cap of 20 000 000 € applies, because 4 % of your turnover is only 80 000 €.

These are legal maximums, not predictions. Regulators set the actual amount case by case, and most fines are far below the maximum.

Worked examples

Maximum fines under the EU GDPR at different turnover levels, calculated with the same formula as the calculator.

Annual turnoverStandard maximum (Art. 83(4))Higher maximum (Art. 83(5))
500 000 €10 000 000 €20 000 000 €
5 000 000 €10 000 000 €20 000 000 €
50 000 000 €10 000 000 €20 000 000 €
500 000 000 €10 000 000 €20 000 000 €
5 000 000 000 €100 000 000 €200 000 000 €

The percentage starts to exceed the fixed cap at a turnover of 500 000 000 € for the standard tier and 500 000 000 € for the higher tier.

How the maximum is calculated

Article 83 of the GDPR sets two tiers. The standard tier allows up to EUR 10 million or 2% of total worldwide annual turnover, whichever is higher. The higher tier allows up to EUR 20 million or 4%, whichever is higher. The UK GDPR uses the same structure with GBP 8.7 million or 2%, and GBP 17.5 million or 4%.

Consent failures, such as setting tracking cookies without valid consent, fall under the conditions for consent and the basic principles, which belong to the higher tier. Cookie rules also come from national ePrivacy laws, which have their own penalties; regulators such as France's CNIL have fined cookie violations under those laws.

What decides the actual fine

Article 83(2) lists what regulators weigh when they set the amount. Most fines are far below the maximum because of these factors:

  • Nature, gravity and duration

    How serious the infringement is, how many people it affected and for how long.

  • Intent or negligence

    Whether the infringement was deliberate or careless.

  • Mitigation

    What you did to limit the damage once you knew.

  • Responsibility and safeguards

    The technical and organizational measures you had in place.

  • History and cooperation

    Previous infringements, and how well you cooperated with the regulator.

  • Data categories and how it came to light

    Whether sensitive data was involved, and whether you reported it yourself.

Lower your cookie risk

The most common cookie problem is trackers that fire before the visitor has agreed. Start with a scan of your site: the free cookie scanner lists what loads, and GetCookies can block non-essential scripts until consent and log every decision as proof. Our GDPR compliance overview explains what the rules require.

Try GetCookies on your own site

Start on the Free plan: one domain, a cookie scan and a consent banner, no credit card required. Upgrade only when you need more.

Start gratis