Skip to content
Calcrivo

GDPR Compliance Calculator

Score GDPR accountability across records of processing, lawful basis, DSAR and 72-hour breach timelines, with Article 83 fine ceilings.

Inputs

days
hours

GDPR Accountability Score

71.7%

Tier 2 Fine Ceiling

$34,000,000

Greater of 4% of global turnover or €20 m

Tier 1 Fine Ceiling

$17,000,000

Greater of 2% of global turnover or €10 m

Residual Compliance Risk

High — an audit or a complaint would find reportable gaps

Article 33 Verdict

Outside the Article 33 window — a late notification is itself an infringement, so file a partial notification and supplement it in phases

Article 12(3) Verdict

Inside the Article 12(3) one-month deadline

Largest Gap

Article 35 DPIAs for high-risk processing — the most commonly skipped obligation

Step by step

  1. Values used

    Article 30 record of processing activities = Complete but more than a year stale — 70; Lawful basis documented per processing activity = Documented for most activities — 60; Typical data subject access request response time = 22 days; Time to notify the supervisory authority of a reportable breach = 96 hours; DPIAs completed for all high-risk processing (Article 35) = No; DPO or an equivalent named accountability owner = Yes; Chapter V safeguards for every international transfer = Yes; Article 28 contracts with every processor = Yes; Article 32 technical and organisational measures documented = Yes; Group annual worldwide turnover = 850,000,000 €

  2. GDPR Compliance

    Accountability score = weighted mean of nine obligations (records 15, lawful basis 15, breach timeline 13, DSAR timeline 12, DPIAs 10, transfers 10, processor contracts 8, Article 32 measures 12, DPO 5), each scored 0–100.

  3. Article 83 fine ceilings

    Tier 2 ceiling = max(4% × global annual turnover, €20 m); tier 1 ceiling = max(2% × turnover, €10 m).

  4. GDPR Accountability Score

    = 71.7

  5. Tier 2 Fine Ceiling

    = 34,000,000

  6. Tier 1 Fine Ceiling

    = 17,000,000

  7. Residual Compliance Risk

    = High — an audit or a complaint would find reportable gaps

  8. Article 33 Verdict

    = Outside the Article 33 window — a late notification is itself an infringement, so file a partial notification and supplement it in phases

  9. Article 12(3) Verdict

    = Inside the Article 12(3) one-month deadline

How it works

The weights follow where supervisory authorities actually issue fines: an absent record of processing and an undocumented lawful basis undermine every other claim you make, and the two clocks — 72 hours for breach notification, one month for a DSAR — are the obligations most often missed on the record. Fine ceilings are computed on the turnover of the whole undertaking, which is why a small local subsidiary can carry a group-sized exposure. The fine ceiling is what turns a compliance conversation into a budget conversation, and the two clocks are the ones that fail during a real incident rather than during an audit. These are management estimates, not legal advice or a regulator's assessment.

Formulas

GDPR Compliance

Accountability score = weighted mean of nine obligations (records 15, lawful basis 15, breach timeline 13, DSAR timeline 12, DPIAs 10, transfers 10, processor contracts 8, Article 32 measures 12, DPO 5), each scored 0–100.

30
Days allowed by Article 12(3) to answer a DSAR, extendable by two months
72
Hours allowed by Article 33 to notify the supervisory authority
4% / €20 m
Article 83(5) tier 2 ceiling, whichever is higher

Article 83 fine ceilings

Tier 2 ceiling = max(4% × global annual turnover, €20 m); tier 1 ceiling = max(2% × turnover, €10 m).

turnover
Worldwide annual turnover of the whole undertaking, not the local entity
tier 1
Infringements of controller and processor obligations such as Articles 25, 28 and 32
tier 2
Infringements of the principles, data subject rights and transfer rules

Frequently Asked Questions

How is GDPR Compliance calculated?

Accountability score = weighted mean of nine obligations (records 15, lawful basis 15, breach timeline 13, DSAR timeline 12, DPIAs 10, transfers 10, processor contracts 8, Article 32 measures 12, DPO 5), each scored 0–100. The weights follow where supervisory authorities actually issue fines: an absent record of processing and an undocumented lawful basis undermine every other claim you make, and the two clocks — 72 hours for breach notification, one month for a DSAR — are the obligations most often missed on the record. Fine ceilings are computed on the turnover of the whole undertaking, which is why a small local subsidiary can carry a group-sized exposure.

Why does GDPR Compliance matter?

The fine ceiling is what turns a compliance conversation into a budget conversation, and the two clocks are the ones that fail during a real incident rather than during an audit. These are management estimates, not legal advice or a regulator's assessment.

What values do I need to enter?

This calculator takes 10 inputs: Article 30 record of processing activities, Lawful basis documented per processing activity, Typical data subject access request response time, Time to notify the supervisory authority of a reportable breach, DPIAs completed for all high-risk processing (Article 35), DPO or an equivalent named accountability owner, Chapter V safeguards for every international transfer, Article 28 contracts with every processor, Article 32 technical and organisational measures documented, Group annual worldwide turnover. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Does the 72-hour clock start when the breach happens?

No — it starts when you become aware, meaning you have a reasonable degree of certainty that a personal data breach has occurred. That is why a short triage period is acceptable and an indefinite investigation is not; if you cannot supply all the detail in time, Article 33(4) lets you notify in phases.

Is the fine ceiling a realistic expectation?

No. It is a statutory maximum, and actual fines are set against the Article 83(2) factors — nature and gravity, intent, mitigation, cooperation and previous infringements. Use the ceiling to frame the size of the risk, not to forecast a penalty.

You might also need