GDPR Compliance Calculator
Score GDPR accountability across records of processing, lawful basis, DSAR and 72-hour breach timelines, with Article 83 fine ceilings.
Inputs
GDPR Accountability Score
71.7%
Tier 2 Fine Ceiling
$34,000,000
Greater of 4% of global turnover or €20 m
Tier 1 Fine Ceiling
$17,000,000
Greater of 2% of global turnover or €10 m
Residual Compliance Risk
High — an audit or a complaint would find reportable gaps
Article 33 Verdict
Outside the Article 33 window — a late notification is itself an infringement, so file a partial notification and supplement it in phases
Article 12(3) Verdict
Inside the Article 12(3) one-month deadline
Largest Gap
Article 35 DPIAs for high-risk processing — the most commonly skipped obligation
Step by step
Values used
Article 30 record of processing activities = Complete but more than a year stale — 70; Lawful basis documented per processing activity = Documented for most activities — 60; Typical data subject access request response time = 22 days; Time to notify the supervisory authority of a reportable breach = 96 hours; DPIAs completed for all high-risk processing (Article 35) = No; DPO or an equivalent named accountability owner = Yes; Chapter V safeguards for every international transfer = Yes; Article 28 contracts with every processor = Yes; Article 32 technical and organisational measures documented = Yes; Group annual worldwide turnover = 850,000,000 €
GDPR Compliance
Accountability score = weighted mean of nine obligations (records 15, lawful basis 15, breach timeline 13, DSAR timeline 12, DPIAs 10, transfers 10, processor contracts 8, Article 32 measures 12, DPO 5), each scored 0–100.
Article 83 fine ceilings
Tier 2 ceiling = max(4% × global annual turnover, €20 m); tier 1 ceiling = max(2% × turnover, €10 m).
GDPR Accountability Score
= 71.7
Tier 2 Fine Ceiling
= 34,000,000
Tier 1 Fine Ceiling
= 17,000,000
Residual Compliance Risk
= High — an audit or a complaint would find reportable gaps
Article 33 Verdict
= Outside the Article 33 window — a late notification is itself an infringement, so file a partial notification and supplement it in phases
Article 12(3) Verdict
= Inside the Article 12(3) one-month deadline
How it works
The weights follow where supervisory authorities actually issue fines: an absent record of processing and an undocumented lawful basis undermine every other claim you make, and the two clocks — 72 hours for breach notification, one month for a DSAR — are the obligations most often missed on the record. Fine ceilings are computed on the turnover of the whole undertaking, which is why a small local subsidiary can carry a group-sized exposure. The fine ceiling is what turns a compliance conversation into a budget conversation, and the two clocks are the ones that fail during a real incident rather than during an audit. These are management estimates, not legal advice or a regulator's assessment.
Formulas
GDPR Compliance
Accountability score = weighted mean of nine obligations (records 15, lawful basis 15, breach timeline 13, DSAR timeline 12, DPIAs 10, transfers 10, processor contracts 8, Article 32 measures 12, DPO 5), each scored 0–100.
- 30
- Days allowed by Article 12(3) to answer a DSAR, extendable by two months
- 72
- Hours allowed by Article 33 to notify the supervisory authority
- 4% / €20 m
- Article 83(5) tier 2 ceiling, whichever is higher
Article 83 fine ceilings
Tier 2 ceiling = max(4% × global annual turnover, €20 m); tier 1 ceiling = max(2% × turnover, €10 m).
- turnover
- Worldwide annual turnover of the whole undertaking, not the local entity
- tier 1
- Infringements of controller and processor obligations such as Articles 25, 28 and 32
- tier 2
- Infringements of the principles, data subject rights and transfer rules
Frequently Asked Questions
How is GDPR Compliance calculated?
Accountability score = weighted mean of nine obligations (records 15, lawful basis 15, breach timeline 13, DSAR timeline 12, DPIAs 10, transfers 10, processor contracts 8, Article 32 measures 12, DPO 5), each scored 0–100. The weights follow where supervisory authorities actually issue fines: an absent record of processing and an undocumented lawful basis undermine every other claim you make, and the two clocks — 72 hours for breach notification, one month for a DSAR — are the obligations most often missed on the record. Fine ceilings are computed on the turnover of the whole undertaking, which is why a small local subsidiary can carry a group-sized exposure.
Why does GDPR Compliance matter?
The fine ceiling is what turns a compliance conversation into a budget conversation, and the two clocks are the ones that fail during a real incident rather than during an audit. These are management estimates, not legal advice or a regulator's assessment.
What values do I need to enter?
This calculator takes 10 inputs: Article 30 record of processing activities, Lawful basis documented per processing activity, Typical data subject access request response time, Time to notify the supervisory authority of a reportable breach, DPIAs completed for all high-risk processing (Article 35), DPO or an equivalent named accountability owner, Chapter V safeguards for every international transfer, Article 28 contracts with every processor, Article 32 technical and organisational measures documented, Group annual worldwide turnover. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Does the 72-hour clock start when the breach happens?
No — it starts when you become aware, meaning you have a reasonable degree of certainty that a personal data breach has occurred. That is why a short triage period is acceptable and an indefinite investigation is not; if you cannot supply all the detail in time, Article 33(4) lets you notify in phases.
Is the fine ceiling a realistic expectation?
No. It is a statutory maximum, and actual fines are set against the Article 83(2) factors — nature and gravity, intent, mitigation, cooperation and previous infringements. Use the ceiling to frame the size of the risk, not to forecast a penalty.
You might also need
- ISO 27001 Compliance CalculatorCommonly used together
- Compliance Cost CalculatorCommonly used together
- HIPAA Compliance CalculatorCommonly used together
- Disaster Recovery RTO CalculatorAlso in Compliance & GRC
- Security Investment ROI CalculatorAlso in Compliance & GRC
- Residual Risk CalculatorAlso in Compliance & GRC