GDPR Fine Calculator 💶
Supervisory authorities do not publish a formula. What they publish is decisions. This tool takes the published decisions where the fined organisation's turnover is known, finds the ones closest to your own size and circumstance, and shows what those organisations actually paid as a proportion of turnover. It is a benchmark drawn from enforcement practice, not a prediction and not a legal opinion.
How to use this
- Enter your annual turnover. Use the whole undertaking, not one legal entity. Art. 83 refers to the undertaking, which the Court of Justice reads as the whole economic unit, and it is the same basis used for every organisation in the comparison set. You can type
20bn,450mor a plain number. - Pick what went wrong. The categories come from the enforcement tracker's own classification, one per decision. The number beside each is how many comparable cases carry a known turnover, which tells you how much weight the answer can bear.
- Narrow by sector if it helps. Optional. The tool widens the search automatically if too few peers match, and tells you when it did.
- Read all three numbers. The typical outcome, the realistic range and the statutory ceiling. The range matters more than the midpoint: fines for the same conduct vary by orders of magnitude, and any single figure hides that.
Nothing you type is sent anywhere. The calculation runs entirely in your browser and no figure leaves this page.
Your organisation
Worldwide, most recent full financial year.
Narrows the peer set. Dropped automatically if too few peers match.
How the number is worked out
The index
For every published decision where the organisation's turnover is known, the index is the fine divided by that turnover. It is the only figure that lets a EUR 3,000 fine in Romania and a EUR 225 million fine in Ireland sit on the same scale.
Choosing the peers
Peers are the cases in the same violation category whose turnover is within 50% of yours, optionally in the same sector. If fewer than eight organisations match, the turnover band widens in defined steps, then the sector filter is dropped, then the violation filter. The tool always says which step it ended on. It never quietly averages a handful of rows and presents the result as an answer.
The turnover band is not decoration. Fines scale far less than proportionally with size: across this data the fitted elasticity is about 0.35, meaning a company ten times larger draws a fine only about twice as large. A small company's index is therefore not comparable with a large one's, and an average taken across sizes is meaningless.
One vote per organisation
Some regulators fine the same operator repeatedly, in one case more than sixty times. Each organisation is collapsed to a single index, the median of its own cases, before percentiles are taken. Without that step one heavily fined operator would decide the answer for its whole size band.
Median and percentiles, not an average
The index distribution is heavily skewed: a few small organisations paid a large share of their turnover, which drags any mean upwards by an order of magnitude. The headline is the median across peer organisations, and the range is the 25th to the 90th percentile. Across the whole dataset the 25th percentile is about 0.0009% of turnover and the 90th about 0.98%, a spread of three orders of magnitude for the same statute.
The statutory ceiling
Art. 83(4) caps the relevant infringements at 2% of total worldwide annual turnover or EUR 10 million, whichever is higher. Art. 83(5) caps the rest at 4% or EUR 20 million. The absolute floor is the part usually forgotten: an organisation needs roughly EUR 500 million of turnover before 4% of it exceeds EUR 20 million. Below that, the ceiling is a flat EUR 20 million and turnover does not enter into it, which is why small organisations occasionally pay a double-digit percentage of revenue entirely lawfully.
Cookie fines are not GDPR fines
Five of the largest decisions in this data, including the CNIL's fines of EUR 200 million and EUR 125 million against Google and EUR 60 million against Facebook, cite Art. 82 of the French loi Informatique et Libertes rather than any GDPR Article. They are national ePrivacy enforcement about cookies and trackers, not Art. 83 cases, even though they are routinely quoted as GDPR records. They are kept in the comparison because they are real privacy enforcement at a known turnover, they are marked in the peer table, and the toggle above removes them.
Where the data comes from
Fines, dates, countries, cited Articles and the violation classification come from the public GDPR enforcement tracker. Turnover is not in that source and had to be attached separately, from annual reports, statutory filings and national company registers. Each peer row shows the confidence attached to its turnover figure, and the peer set can be restricted to rows with a recorded source.
Coverage: carry both a fine and a turnover. That is a minority of all published decisions, because most fined organisations are public bodies, micro-entities or private companies whose accounts are not published for free.
To explore the enforcement record itself rather than benchmark against it, the GDPR Fines Dashboard covers every published decision, refreshed from the tracker, with breakdowns by country, sector, Article and year.
What this tool cannot tell you. Turnover explains under 10% of the variation in fine size across this data. Everything a regulator actually weighs under Art. 83(2): how many people were affected, whether the conduct was negligent or deliberate, what was done to mitigate it, how the organisation behaved during the investigation, whether it had been fined before, all of it is absent from these figures because it is not in any structured source. Two organisations of identical size doing identical things can and do receive fines an order of magnitude apart. Treat the range as the scale of exposure, not as a number to put in a risk register without a caveat beside it.
Categories with too few peers. Information obligations, breach notification, DPO involvement and processing agreements are marked thin. Those violations are enforced overwhelmingly against public bodies and very small organisations, which have no published turnover, so no amount of further research will make them benchmarkable. The tool will still calculate, but the warning it shows should be believed.
This is not legal advice and not a prediction of what any authority would do.