EUComply

EUComplycompliance checklist › GDPR Fine Calculator

GDPR Fine Calculator

What could a GDPR violation actually cost your business? Enter your annual turnover and see both penalty tiers under Article 83 — plus the ranges regulators hand out to small sites in practice.

Lower tier — Art. 83(4): higher of €10M or 2% of turnover

Typical violations: inadequate records of processing, insufficient security measures, missing data breach notification.

Upper tier — Art. 83(5): higher of €20M or 4% of turnover

Typical violations: no lawful basis for tracking, invalid cookie consent, unlawful data transfers outside the EU.

The cheapest fix: most small-site fines come from cookie consent and tracking failures you can find yourself in two minutes.

Run a free compliance scan on your site →

This calculator shows theoretical maximums under Regulation (EU) 2016/679 Art. 83 and typical published enforcement outcomes. It is indicative only and not legal advice. Actual fines depend on the Art. 83(2) factors: nature and duration of the infringement, intent, mitigation, and cooperation with the supervisory authority.

How GDPR fines are calculated

GDPR has two penalty tiers. The tier depends on which article was violated, not on how much harm was done:

TierCapTypical violations for websites
Lower — Art. 83(4)€10M or 2% of annual worldwide turnover, whichever is higherInadequate processing records, weak security, failure to notify a data breach within 72 hours
Upper — Art. 83(5)€20M or 4% of annual worldwide turnover, whichever is higherNo valid consent for cookies or advertising pixels, unlawful transfers of EU data abroad, violating core data-subject rights

Note the word higher: a company with €100,000 turnover faces the same €10M / €20M flat caps as everyone else. The percentage only matters once it exceeds the cap — from €500M turnover up, in practice.

What small businesses actually get fined

Data protection authorities rarely impose anything near the caps on first-time offenders. Published decisions show a consistent pattern:

The practical takeaway: the violations that actually reach small websites — consent setup, pixels, policies — are all technical checks you can run yourself before any regulator ever looks at you.

Frequently asked questions

Can I be fined if my business is outside the EU?
Yes. GDPR applies to any business offering goods or services to people in the EU or monitoring their behaviour — regardless of where the business is registered.

Is the UK different?
The structure is identical: UK GDPR caps at £17.5M or 4% (upper tier) and £8.75M or 2% (lower tier), enforced by the ICO.

Does one fine cover everything?
No — each distinct violation can be fined separately. A single website with broken consent, unlawful transfers, and missing records can accumulate multiple fines from one investigation.

How do I check whether my site has these problems?
Our free scanner checks cookie banner behavior, tracking scripts loaded without consent, and other common violation triggers on any website — WordPress, Shopify, Wix, Webflow, or hand-coded HTML.

Keep reading