- Enter the potential violation counts
Separate standard violations from intentional or qualifying under-16 violations for the scenario you are testing.
- Check the per-violation rates
The defaults use the California Privacy Protection Agency’s 2025 inflation-adjusted amounts; update them if the official amounts change.
- Set a modeled percentage of maximum
Use this as an internal scenario factor rather than assuming the maximum is the likely outcome.
- Set an enforcement probability
Enter a risk-management assumption for the chance of monetary enforcement in the scenario.
- Review the scenario values
The breakdown shows the mathematical maximum at entered rates, the factored fine scenario, and the probability-weighted expected exposure.
CCPA Compliance Penalty Exposure Estimator
This estimator models a CCPA administrative-fine scenario from the number of standard violations, the number of intentional or qualifying under-16 violations, current per-violation maximum rates entered in the calculator, and a user-defined probability and settlement factor. It is intended for internal risk sensitivity analysis rather than predicting an enforcement outcome.
California law provides per-violation administrative maximums that are periodically adjusted for inflation. As of the current 2025 adjustment, the published amounts are $2,663 for each violation and $7,988 for each intentional violation or qualifying violation involving personal information of consumers under 16. Actual enforcement outcomes depend on the facts, legal theories, discretion, settlement, and other remedies.
Model a CCPA penalty-exposure scenario
Formula:
Maximum scenario = (Standard count × Standard rate) + (Aggravated count × Aggravated rate); Scenario fine = Maximum × Settlement factor; Expected exposure = Scenario fine × Enforcement probabilityWhere:
- Standard rate: entered maximum rate per standard violation
- Aggravated rate: entered maximum rate per intentional or qualifying under-16 violation
- Settlement factor: user-entered percentage of the mathematical maximum
- Enforcement probability: user-entered probability assumption
Assumptions: The formula is a scenario model only. The number of legally cognizable violations, classification, available remedies, and final amount are legal and factual questions.
What the result means
The main result is a probability-weighted internal risk estimate based on the rates and assumptions you entered.
Fine amounts are periodically adjusted; confirm current official figures before using this model for a live matter.
Given:
- 100 standard violations at $2,663 each
- 10 aggravated violations at $7,988 each
- Modeled amount: 40% of maximum
- Monetary-enforcement probability: 15%
Calculation:
Standard subtotal = 100 × $2,663 = $266,300. Aggravated subtotal = 10 × $7,988 = $79,880. Maximum = $346,180. Scenario fine = $346,180 × 40% = $138,472. Expected exposure = $138,472 × 15% = $20,770.80.
Result: Modeled expected exposure: about $20,771.
Interpretation: The expected value is an internal scenario metric. It is not a statement that an agency would count violations this way or impose that amount.
Are the default rates current statutory base amounts?
The defaults reflect the California Privacy Protection Agency’s inflation-adjusted amounts effective January 1, 2025: $2,663 and $7,988. Because the statute provides periodic adjustments, confirm the current official amounts before relying on them.
What belongs in the aggravated-violation count?
The statute provides the higher maximum for intentional violations and certain violations involving personal information of consumers the violator actually knows are under 16. Classification in a real matter requires legal analysis.
Can I multiply every affected consumer by a penalty rate?
Do not assume that affected-person count automatically equals the legally countable number of violations. Violation counting can be contested and depends on the facts and enforcement theory.
Does this include private damages for a data breach?
No. CCPA private-action damages for qualifying security incidents are a separate remedy with different requirements and are not included in this administrative-fine model.
Why are the rates editable?
California adjusts certain CCPA monetary thresholds periodically. Editable rates let you keep the scenario model current without changing the calculator logic.