Score GDPR accountability across records of processing, lawful basis, DSAR and 72-hour breach timelines, with Article 83 fine ceilings.
The weights follow where supervisory authorities actually issue fines: an absent record of processing and an undocumented lawful basis undermine every other claim you make, and the two clocks — 72 hours for breach notification, one month for a DSAR — are the obligations most often missed on the record. Fine ceilings are computed on the turnover of the whole undertaking, which is why a small local subsidiary can carry a group-sized exposure. The fine ceiling is what turns a compliance conversation into a budget conversation, and the two clocks are the ones that fail during a real incident rather than during an audit. These are management estimates, not legal advice or a regulator's assessment.
GDPR Compliance
Accountability score = weighted mean of nine obligations (records 15, lawful basis 15, breach timeline 13, DSAR timeline 12, DPIAs 10, transfers 10, processor contracts 8, Article 32 measures 12, DPO 5), each scored 0–100.
Article 83 fine ceilings
Tier 2 ceiling = max(4% × global annual turnover, €20 m); tier 1 ceiling = max(2% × turnover, €10 m).
Accountability score = weighted mean of nine obligations (records 15, lawful basis 15, breach timeline 13, DSAR timeline 12, DPIAs 10, transfers 10, processor contracts 8, Article 32 measures 12, DPO 5), each scored 0–100. The weights follow where supervisory authorities actually issue fines: an absent record of processing and an undocumented lawful basis undermine every other claim you make, and the two clocks — 72 hours for breach notification, one month for a DSAR — are the obligations most often missed on the record. Fine ceilings are computed on the turnover of the whole undertaking, which is why a small local subsidiary can carry a group-sized exposure.
The fine ceiling is what turns a compliance conversation into a budget conversation, and the two clocks are the ones that fail during a real incident rather than during an audit. These are management estimates, not legal advice or a regulator's assessment.
This calculator takes 10 inputs: Article 30 record of processing activities, Lawful basis documented per processing activity, Typical data subject access request response time, Time to notify the supervisory authority of a reportable breach, DPIAs completed for all high-risk processing (Article 35), DPO or an equivalent named accountability owner, Chapter V safeguards for every international transfer, Article 28 contracts with every processor, Article 32 technical and organisational measures documented, Group annual worldwide turnover. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
No — it starts when you become aware, meaning you have a reasonable degree of certainty that a personal data breach has occurred. That is why a short triage period is acceptable and an indefinite investigation is not; if you cannot supply all the detail in time, Article 33(4) lets you notify in phases.
No. It is a statutory maximum, and actual fines are set against the Article 83(2) factors — nature and gravity, intent, mitigation, cooperation and previous infringements. Use the ceiling to frame the size of the risk, not to forecast a penalty.