Data Breach Regulatory Fine Calculator

JJ Ben-Joseph headshot JJ Ben-Joseph

What this calculator does

Regulatory penalties after a data breach can be assessed in very different ways depending on the legal framework. This calculator provides a simplified estimate of potential maximum administrative fines under two commonly discussed regimes:

Important: outputs are high-level estimates intended for planning and context, not a prediction of what a regulator will actually assess in a real case.

Inputs explained

Annual global revenue (GDPR)

For GDPR tiers, the relevant baseline is the organization’s worldwide annual revenue/turnover (typically the prior financial year). The calculator uses this to compute the percentage-based cap.

Affected records

This is the number of impacted individuals/consumers (or records) involved in the incident. For CCPA/CPRA penalty estimates, the calculator treats this value as the count of potential “violations” for a rough upper-bound style estimate.

Regulation and severity

Select the tier/severity that best matches the scenario you’re exploring. For GDPR, the “lower” vs “upper” tier corresponds to different statutory maximums. For CCPA, “unintentional” vs “intentional” corresponds to different per-violation penalty ceilings.

Formulas used (simplified statutory maxima)

GDPR maximum fine (tiered cap)

GDPR administrative fines are commonly summarized as the maximum of a percentage cap and a fixed euro cap:

F = max ( p·R , M )

CCPA/CPRA civil penalty estimate (per-record approximation)

This calculator uses a straightforward multiplication model:

F = c × N

How to interpret the results

Worked example

Assume:

Example A: GDPR upper tier (4% or €20M, whichever is higher)

  1. Percentage cap: 4% × €50,000,000 = €2,000,000
  2. Fixed cap: €20,000,000
  3. Maximum (higher of the two): €20,000,000

Interpretation: at this revenue level, the fixed cap dominates; the upper-tier statutory maximum is €20M, even though 4% of revenue is smaller.

Example B: CCPA/CPRA intentional ($7,500 per record)

  1. Penalty estimate: $7,500 × 10,000 = $75,000,000

Interpretation: the per-record model scales rapidly with record count. Actual assessed penalties may differ depending on enforcement approach and how violations are counted.

Quick comparison

Framework What the calculator models Primary driver(s) Output currency
GDPR (Lower tier) max(2% × revenue, €10M) Revenue-based cap vs fixed cap EUR (€)
GDPR (Upper tier) max(4% × revenue, €20M) Revenue-based cap vs fixed cap EUR (€)
CCPA/CPRA (Unintentional) $2,500 × affected records Record/violation count USD ($)
CCPA/CPRA (Intentional) $7,500 × affected records Record/violation count USD ($)

Assumptions and limitations (read before relying on the estimate)

Sources (starting points)

For compliance decisions, consult primary legal text and qualified counsel for your jurisdiction and facts.

Embed this calculator

Copy and paste the HTML below to add the Data Breach Regulatory Fine Calculator to your website.