GDPR Compliance Penalty Exposure Estimator

This estimator models GDPR administrative-fine exposure as a scenario, using annual worldwide turnover, the Article 83 fine tier, a user-selected fraction of the statutory ceiling, and an assumed probability that the scenario results in a fine. It is intended for risk budgeting and sensitivity analysis, not for predicting what a supervisory authority will impose.

Article 83 provides two principal maximum fine tiers: up to €10 million or 2% of preceding-year worldwide annual turnover, whichever is higher, and up to €20 million or 4%, whichever is higher, depending on the infringement. Actual fines are case-specific and consider factors such as nature, gravity, duration, intent or negligence, mitigation, prior infringements, cooperation, and other circumstances.

Model a GDPR penalty-exposure scenario

EUR
%
%
Result
Modeled expected penalty exposure
Selected statutory ceiling
Modeled fine if imposed
Fine probability assumption
Modeled fine / turnover
  1. Enter worldwide annual turnover

    Use the relevant preceding financial-year turnover basis for the organization being modeled.

  2. Select the Article 83 tier

    Choose the lower or upper maximum tier that matches the type of infringement being stress tested.

  3. Set a ceiling fraction

    Enter what percentage of the maximum ceiling you want to use as the modeled fine if a fine is imposed.

  4. Set a scenario probability

    Enter a risk-management assumption for the chance that the scenario results in a fine.

  5. Review expected exposure and ceiling

    The main result probability-weights the modeled fine; the breakdown keeps the statutory ceiling separate from the scenario assumption.

Formula:

Ceiling = max(Fixed tier cap, Turnover × Tier rate); Scenario fine = Ceiling × Ceiling fraction; Expected exposure = Scenario fine × Fine probability

Where:

  • Fixed tier cap: €10m for the lower tier or €20m for the upper tier
  • Tier rate: 2% for the lower tier or 4% for the upper tier
  • Ceiling fraction: user-entered scenario severity as a percentage of the ceiling
  • Fine probability: user-entered probability assumption

Assumptions: The calculator models Article 83 ceiling mechanics but does not determine infringement classification, liability, or an actual fine. Supervisory authorities assess statutory factors case by case.

What the result means

The main result is a probability-weighted scenario amount, not a legal forecast or expected enforcement outcome.

Confirm current law and obtain legal advice before relying on a penalty estimate for a specific matter.

Given:

  • Worldwide annual turnover: €50,000,000
  • Upper tier: €20m or 4%, whichever is higher
  • Assumed fine: 25% of ceiling
  • Fine probability: 10%

Calculation:
4% of turnover = €2,000,000, so the €20,000,000 fixed cap is the higher ceiling. Scenario fine = €20,000,000 × 25% = €5,000,000. Expected exposure = €5,000,000 × 10% = €500,000.

Result: Modeled expected penalty exposure: €500,000.

Interpretation: The €20 million figure is the selected statutory maximum ceiling in this example, while €500,000 is only a risk-modeling expected value built from user assumptions.

Is the statutory ceiling the amount a company will be fined?

No. Article 83 sets maximum levels, while the actual decision depends on the circumstances and statutory factors of the individual case.

Which tier should I select?

Select the tier only after identifying the provisions potentially implicated. Different GDPR infringements fall under different Article 83 paragraphs, and legal classification should be confirmed for a real matter.

Why use a ceiling fraction?

It separates the legal maximum from your internal scenario severity. This avoids treating the maximum fine as the default expected outcome.

Can multiple GDPR violations simply be added together?

Not always. Article 83 contains rules for several infringements connected to the same or linked processing operations, so simple multiplication can overstate a legal maximum.

Does this include damages paid to individuals?

No. The model covers only the selected administrative-fine scenario. Compensation claims, litigation costs, remediation, business loss, and other penalties are separate exposures.