GDPR fine calculator (Art. 83)
The GDPR has two fine tiers: up to EUR 10 million or 2 % of total worldwide group turnover, and up to EUR 20 million or 4 %. Which tier applies depends solely on which provision was infringed. Pick the type of infringement and enter the annual turnover to see the statutory ceiling — plus the criteria the supervisory authority uses to set the amount inside that range.
No signup · runs in your browser · nothing you enter is transmitted
The tier depends solely on which provision was infringed — not on turnover and not on severity.
Turnover of the whole economic unit, not of the entity that acted (Art. 101, 102 TFEU; CJEU C-807/21). Optional — without it only the fixed maximum is shown.
Tier 2 — Art. 83(5) GDPR: up to EUR 20 million or 4 % of total worldwide annual turnover, whichever is higher.
Without a turnover figure only the fixed maximum is shown. The percentage alternative only applies “in the case of an undertaking” in any event.
This is the statutory ceiling — the amount that may not be exceeded. It is not a forecast of the actual fine. Fines that are in fact imposed are overwhelmingly orders of magnitude lower.
Setting the amount within the range (Art. 83(2) GDPR)
- The nature, gravity and duration of the infringement — taking into account the nature, scope and purpose of the processing as well as the number of data subjects affected and the level of damage suffered
- The intentional or negligent character of the infringement
- Any action taken to mitigate the damage suffered by data subjects
- The degree of responsibility, taking into account the technical and organisational measures implemented under Art. 25 and 32 GDPR
- Any relevant previous infringements
- The degree of cooperation with the supervisory authority to remedy the infringement and mitigate its adverse effects
- The categories of personal data affected by the infringement
- The manner in which the infringement became known to the supervisory authority — in particular whether, and to what extent, it was self-reported
- Compliance with measures previously ordered against the same controller or processor on the same subject matter
- Adherence to approved codes of conduct under Art. 40 GDPR or approved certification mechanisms under Art. 42 GDPR
- Any other aggravating or mitigating factor, such as financial benefits gained or losses avoided, directly or indirectly, from the infringement
How that becomes an amount
The European Data Protection Board sets out a five-step method in Guidelines 04/2022: categorise the infringement, determine a starting amount from its seriousness and the undertaking's turnover, apply the aggravating and mitigating circumstances of Art. 83(2) GDPR, check the statutory maximum, and finally verify that the fine is effective, proportionate and dissuasive. In Germany the Datenschutzkonferenz (DSK) fining model of 2019, with its turnover-derived daily rates, previously governed; it is now only of supplementary relevance and was never binding on the courts. Where several infringements arise from the same or linked processing operations, Art. 83(3) GDPR caps the total at the range for the gravest infringement.
Art. 83 GDPR gives supervisory authorities two fine ranges. Under Art. 83(4) GDPR, infringements of the obligations of controllers and processors under Articles 8, 11, 25 to 39, 42 and 43 are subject to fines of up to EUR 10 million or — in the case of an undertaking — up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher. Under Art. 83(5) GDPR the range doubles to EUR 20 million or 4 % for infringements of the basic principles for processing including the conditions for consent (Articles 5, 6, 7, 9), of data subjects' rights (Articles 12 to 22), of the rules on transfers to third countries (Articles 44 to 49), and for non-compliance with an order of the supervisory authority — for which Art. 83(6) GDPR repeats the same range. The amount in the individual case is set using the criteria in Art. 83(2) GDPR and must be effective, proportionate and dissuasive.
Orientation only — not legal advice. This tool shows the statutory ceiling of the fine range, not a forecast of the fine you would actually receive. Fines that are in fact imposed are overwhelmingly orders of magnitude below the ceiling. Which tier applies, and how the amount is set within it, is decided by the competent supervisory authority case by case.
Frequently asked
- Does this calculate the fine I would actually get?
- No. It calculates the statutory ceiling of the fine range under Art. 83(4) or (5) GDPR — the amount that may not be exceeded. The actual amount is set by the supervisory authority using the criteria in Art. 83(2) GDPR and must, under Art. 83(1) GDPR, be effective, proportionate and dissuasive. In practice fines are regularly far below the ceiling; a forecast is not credible without knowing the specifics of the case.
- Whose turnover counts — my company's or the group's?
- The group's. The notion of "undertaking" in Art. 83 GDPR is to be understood in the sense of Articles 101 and 102 TFEU, i.e. as an economic unit, per recitals 150 and 37. The Court of Justice confirmed this in Deutsche Wohnen (C-807/21): the 2 % or 4 % share is calculated on the total worldwide turnover of the entire corporate group, not that of the subsidiary that acted. For a company in a group the turnover-based ceiling can therefore be many times the EUR 10 or 20 million figure.
- When does 2 % apply and when 4 %?
- The lower tier (EUR 10 million / 2 %, Art. 83(4) GDPR) covers the more organisational duties: records of processing activities, security of processing, data protection by design, processor arrangements, breach notification, data protection impact assessment, the data protection officer, and children's consent. The higher tier (EUR 20 million / 4 %, Art. 83(5) GDPR) covers the substantive core duties: the principles and lawfulness of processing including consent and special categories of data, data subjects' rights, and third-country transfers — as well as non-compliance with an order of the supervisory authority.
- How do authorities set the amount within the range?
- Using the eleven criteria in Art. 83(2) GDPR, among them the nature, gravity and duration of the infringement, whether it was intentional or negligent, mitigating action taken, previous infringements, cooperation with the supervisory authority, and the categories of personal data affected. For the methodology the European Data Protection Board issued Guidelines 04/2022 on the calculation of administrative fines, which set out a five-step approach applied across the EU — from categorising the infringement, through a turnover-dependent starting amount, to checking the statutory maximum. In Germany the Datenschutzkonferenz (DSK) had previously published its own 2019 fining model based on turnover-derived daily rates; since the EDPB guidelines it is only of supplementary relevance, and the courts never treated it as binding anyway.
- What if several infringements coincide?
- For the same or linked processing operations, Art. 83(3) GDPR caps the total amount of the fine at the amount specified for the gravest infringement. The ranges are not added up: where a tier 1 and a tier 2 infringement coincide, the tier 2 ceiling applies to the whole. Infringements arising from genuinely independent processing operations can, however, be sanctioned separately.
- Can public authorities and non-profits be fined too?
- The turnover-based alternative only applies "in the case of an undertaking". An entity that is not an undertaking in the competition-law sense can therefore only be fined up to the fixed maximum of EUR 10 or 20 million. Art. 83(7) GDPR also leaves it to Member States to decide whether and to what extent public authorities and bodies can be fined; Germany used that opening in section 43(3) BDSG and excluded fines against public authorities and other public bodies. State law may differ for state-level authorities.