# DeFine is a calculator for GDPR fines based on method of the EDPB

- Type: News
- Source: Kromann Reumert
- Date: 2022-02-01
- Original: https://www.khlaw.com/define#entry-14
- Canonical: https://overview.legal/posts/6310
- Topics: Fines, Audit Logs, Administrative Fines on Union Institutions, Bodies, Offices and Agencies, IP Address, Prior Consultation, Integrity and Confidentiality Principle, Employees, Lawful Basis, Fairness & Transparency, Social Media

## Summary

> DeFine is a translation into a calculator of part of the methodology proposed by the European Data Protection Board to calculate GDPR fines (see EDPB, Guidelines 04/2022 on the calculation of administrative fines under the GDPR, 12 May 2022, available online; it was subject to a public consultation until 27 June 2022).

## Full text

[ Skip to main content](#main-content) 

[ Keller & Heckman ](https://www.khlaw.com/) 

![Celebrating 60 Years of Excellent: 1962 - 2022](/themes/khlaw_bootstrap/images/TaglineLogoWhite60Years.svg) 

[ Search ](#menu%5Fdrawer) [ Menu ](#menu%5Fdrawer) 

# DeFine 

## What is DeFine?

DeFine is a translation into a calculator of **part of the methodology proposed by the European Data Protection Board to calculate GDPR fines** (see EDPB, Guidelines 04/2022 on the calculation of administrative fines under the GDPR, 12 May 2022, [available online](https://edpb.europa.eu/our-work-tools/documents/public-consultations/2022/guidelines-042022-calculation-administrative%5Fen); it was subject to a public consultation until 27 June 2022).

These guidelines are only guidelines and do not guarantee any outcome, and due to the public consultation, they should also not be viewed as final.

To quote the EDPB:

_"The calculation of the amount of the fine is at the discretion of the supervisory authority, subject to the rules provided for in the GDPR. In that context, the GDPR requires that the amount of the fine shall in each individual case be effective, proportionate and dissuasive (Article 83(1) GDPR). Moreover, when setting the amount of the fine, supervisory authorities shall give due regard to a list of circumstances that refer to features of the infringement (its seriousness) or of the character of the perpetrator (Article 83(2) GDPR). Lastly, the amount of the fine shall not exceed the maximum amounts provided for in Articles 83(4) (5) and (6) GDPR. The quantification of the amount of the fine is therefore based on a specific evaluation carried out in each case, within the parameters provided for by the GDPR._

_Taking the abovementioned into account, the EDPB has devised the following methodology, consisting of five steps, for calculating administrative fines for infringements of the GDPR._

_Firstly, the processing operations in the case must be identified and the application of Article 83(3) GDPR needs to be evaluated (Chapter 3). Second, the starting point for further calculation of the amount of the fine needs to be identified (Chapter 4). This is done by evaluating the classification of the infringement in the GDPR, evaluating the seriousness of the infringement in light of the circumstances of the case, and evaluating the turnover of the undertaking. The third step is the evaluation of aggravating and mitigating circumstances related to past or present behaviour of the controller/processor and increasing or decreasing the fine accordingly (Chapter 5). The fourth step is identifying the relevant legal maximums for the different infringements. Increases applied in previous or next steps cannot exceed this maximum amount (Chapter 6). Lastly, it needs to be analysed whether the calculated final amount meets the requirements of effectiveness, dissuasiveness and proportionality. The fine can still be adjusted accordingly (Chapter 7), however without exceeding the relevant legal maximum._

_Throughout all abovementioned steps, it must be borne in mind that the calculation of a fine is no mere mathematical exercise. Rather, the circumstances of the specific case are the determining factors leading to the final amount, which can – in all cases – vary between any minimum amount and the legal maximum._

_These Guidelines and its proposed methodology will remain under constant review of the EDPB."_

DeFine helps anticipate what the "starting amount" might be, i.e. **Chapter 4** of Guidelines 04/2022 - and on the assumption that a supervisory authority takes into account all of the suggestions by the EDPB.

Because of all these caveats, it should not be seen as providing a full picture, but we hope it will be helpful to understand the proposed methodology better. For a comparison between this methodology and the top 250 GDPR fines imposed by August 2022 on companies with an identifiable turnover, read our separate article [here](https://www.khlaw.com/insights/thought-top-250-gdpr-fines-were-high-new-edpb-methodology-may-make-you-think-again).

_**Should you trust this website?**_

The calculations you make are carried out through your web browser only, and this website does not send information on the calculation to our servers. There is no use of cookies or trackers either in relation to this GDPR fine calculator.

## Parameters

| Turnover |
| -------- |

What is the annual turnover of the undertaking?  
\[Format: 12345678 + currency. Use integers, with no decimals. ,  
_Also, **this information never goes to any servers** so don't worry about confidentiality.\]_

"Undertaking"

The EDPB's guidelines include many considerations on what constitutes the **"undertaking"** whose turnover needs to be included. Notably:

_"120\. Accordingly, in cases where the controller or processor is (part of) an undertaking in the sense of Articles 101 and 102 TFEU, the combined turnover of such undertaking as a whole can be used to determine the dynamic upper limit of the fine (see Chapter 6.2.2), and to ensure that the resulting fine is in line with the principles of effectiveness, proportionality and dissuasiveness (Article 83(1) GDPR."_

_\[…\] 124\. In the specific case where a parent company holds 100% of shares or almost 100% of shares in a subsidiary which has infringed Article 83 GDPR and therefore is able to exercise decisive influence over the conduct of its subsidiary, a presumption arises that the parent company does in fact exercise this decisive influence over the conduct of its subsidiary (so-called Akzo presumption)_

_\[…\] 125\. However, the Akzo presumption is not an absolute one, but can be rebutted by other evidence_

_\[…\] 126\. If, on the other hand, the parent company does not hold all or almost all of the capital, additional facts must be evidenced by the supervisory authority to justify the existence of a \[single economic unit\]."_

"Turnover"

The EDPB's guidelines also define how to calculate the **"turnover"**:

_"128\. Turnover is taken from the annual accounts of an undertaking, which are drawn up with reference to its business year and provide an overview of the past financial year of a company or of a group of companies (consolidated accounts). Turnover is defined as the sum of all goods and services sold. The term turnover within the meaning of Article 83(4)–(5) GDPR is to be understood in terms of the net turnover of Directive 2013/34/EU. According to this directive, net turnover means the amount derived from the sale of products and the provision of services after deducting sales rebates and value added tax (VAT) and other taxes directly linked to turnover._

_129\. Turnover is taken from the presentation of the profit and loss account within the meaning of Annexes V or VI to Article 13(1) of Directive 2013/34/EU under the heading "net turnover". Net turnover includes revenue from the sale, rental and leasing of products and revenue from the sale of services less sales deductions (e.g. rebates, discounts) and VAT. Revenue therefore does not include items which are unrelated to the business object/sector of the company such as for example the proceeds from the sale of fixed assets, rental of unused parts of buildings, insurance premiums, commissions and interest income in case of an industrial company."_

| Infringements |
| ------------- |

Which are the (alleged) infringements, per relevant article of the GDPR?

_Notes: (i) multiple selections permitted but (ii) where an infringement concerns both a specific provision and a general one (e.g. one of the data protection principles) that the specific one embodies, the EDPB states that "\[a\] more specific provision (derived from the same legal act or different legal acts of the same force) supersedes a more general provision, although both pursue the same objective", in accordance with the principle of specialty (specialia generalibus derogant). Because the application or not of the principle cannot be assessed through this tool, only select relevant provisions that are not superseded._

| **Data protection principles**: Art. 5(1), 5(2); **Legal grounds**: Art. 6, 7 \[Lawfulness of processing; conditions for consent\] **Children's consent**: Art. 8 \[Child's consent in relation to information society services\] **Special categories of personal data**: Art. 9 \[Health, biometrics, politics, etc.\] **Anonymisation**: Art. 11 \[Processing which does not require identification\] **Data subject rights**: Art. 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22 \[Transparency, access, rectification, erasure, restriction, portability, objection, automated decision-making\] **Design and default**: Art. 25 \[Data protection by design and by default\] **Controller/processor roles**: Art. 26, 27, 28, 29 \[Joint controllers, processors, EU representatives\] **ROPA:** Art. 30 \[Records of processing activities\] **Cooperation**: Art. 31 \[Cooperation with the supervisory authority\] | **Security, breaches, DPIAs**: Art. 32, 33, 34, 35, 36 \[Security, personal data breach management and notification, data protection impact assessment and prior consultation\] **Data protection officer**: Art. 37, 38, 39 \[Data protection officer designation, position and tasks\] **Codes of conduct and certification**: Art. 41(4), 42, 43 \[Monitoring of code of conduct observance, certification observance and monitoring\] **Data transfers**: Art. 44, 45, 46, 47, 48, 49 \[Obligations in relation to international data transfers\] **Non-compliance with an order**: Art. 58(1), 58(2) \[Non-compliance with an order or a temporary or definitive limitation on processing or the suspension of data flows by the supervisory authority, non-provision of access requested by a supervisory authority\] **National obligations**: Art. 85, 86, 87, 88, 89, 90, 91 \[Obligations Member States can impose in relation to e.g. national identification numbers, employment-related processing, safeguards regarding statistics or research processing, etc.\] |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |

## Seriousness of the infringement

What is the likely level of "seriousness" the supervisory authority will give to the infringement(s)?  
\[There are three levels - low, medium and high. See explanations for more insights.\]

\-- select --Low level of seriousnessMedium level of seriousnessHigh level of seriousness

"Seriousness"

The EDPB's guidelines state clearly that the assessment of seriousness of an infringement is based on various factors that determine "the seriousness of the infringement as a whole. This assessment is no mathematical calculation in which the abovementioned factors are considered individually, but rather a thorough evaluation of the concrete circumstances of the case, in which all of the abovementioned factors are interlinked. Therefore, in reviewing the seriousness of the infringement, regard should be given to the infringement as a whole."".

The factors in question are the following:

### Nature, gravity, and duration of the infringement

_54\. \[…\] This assessment should therefore consider the following specific elements:_

_a) The **nature of the infringement**, assessed by the concrete circumstances of the case. In that sense, this analysis is more specific than abstract classification of Article 83(4)–(6) GDPR. The supervisory authority may review the interest that the infringed provision seeks to protect and the place of this provision in the data protection framework. In addition, the supervisory authority may consider the degree to which the infringement prohibited the effective application of the provision and the fulfilment of the objective it sought to protect._

_b) The **gravity of the infringement**, assessed on the basis of the specific circumstances. \[…\]_

_i. The **nature of the processing**, including the context in which the processing is functionally based (e.g. business activity, non-profit, political party, etc.) and all the characteristics of the processing. When the nature of processing entails higher risks, e.g. where the purpose is to monitor, evaluate personal aspects or to take decisions or measures with negative effects for the data subjects, depending on the context of the processing and the role of the controller or processor, the supervisory authority may consider to attribute more weight to this factor. Further, a supervisory authority may attribute more weight to this factor when there is a clear imbalance between the data subjects and the controller (e.g. when the data subjects are employees, pupils or patients) or the processing involves vulnerable data subjects, in particular children._

_ii. The **scope of the processing**, with reference to the local, national or cross-border scope of the processing carried out and the relationship between this information and the actual extent of the processing in terms of the allocation of resources by the data controller. This element highlights a real risk factor, linked to the greater difficulty for the data subject and the supervisory authority to curb unlawful conduct as the scope of the processing increases. The larger the scope of the processing, the more weight the supervisory authority may attribute to this factor._

_iii. The **purpose of the processing**, will lead the supervisory authority to attribute more weight to this factor. The supervisory authority may also consider whether the purpose falls within the so-called core activities of the controller. The more central the processing is to the controller’s or processor’s core activities, the more severe irregularities in this processing will be. The supervisory authority may attribute more weight to this factor in these circumstances. There may be circumstances though, in which the processing of personal data is further removed from the core business of the controller or processor, but significantly impacts the evaluation nonetheless (this is the case, for example, of processing concerning personal data of workers where the infringement significantly affects those workers’ dignity)._

_iv. The **number of data subjects** concretely but also potentially affected. The higher the number of data subjects involved, the more weight the supervisory authority may attribute to this factor. In many cases it may also be considered that the infringement takes on "systemic" connotations and can therefore affect, even at different times, additional data subjects who have not submitted complaints or reports to the supervisory authority. The supervisory authority may, depending on the circumstances of the case, consider the ratio between the number of data subjects affected and the total number of data subjects in that context (e.g. the number of citizens, customers or employees) in order to assess whether the infringement is of a systemic nature._

_v. The **level of damage** suffered and the extent to which the conduct may affect individual rights and freedoms. The reference to the "level" of damage suffered, therefore, is intended to draw the attention of the supervisory authorities to the damage suffered, or likely to have been suffered as a further, separate parameter with respect to the number of data subjects involved (for example, in cases where the number of individuals affected by the unlawful processing is high but the damage suffered by them is marginal). Following Recital 75 GDPR, the level of damage suffered refers to physical, material or non-material damage. The assessment of the damage, in any case, be limited to what is functionally necessary to achieve correct evaluation of the level of seriousness of the infringement as indicated in paragraph 61 below, without overlapping with the activities of judicial authorities as tasked with ascertaining the different forms of individual harm._

_c) The **duration of the infringement**, meaning that a supervisory authority may generally attribute more weight to an infringement with longer duration. Noting that a given conduct might have been illicit also within the previous regulatory framework, thus adding an additional element to assess the gravity of the infringement. The longer the duration of the infringement, the more weight the supervisory authority may attribute to this factor. If permitted by national law, both the period after the GDPR's effective date and the previous period may be taken into account when quantifying the fine, taking into account the conditions of that framework._

### Intentional or negligent character of the infringement

_57\. The intentional or negligent character of the infringement (Article 83(2)(b) GDPR) should be assessed taking into account the objective elements of conduct gathered from the facts of the case. The EDPB highlighted that “it is generally admitted that intentional \[infringements\], demonstrating contempt for the provisions of the law, are more severe than unintentional ones.”23 In case of an intentional infringement, the supervisory authority is likely to attribute more weight to this circumstance. Depending on the circumstances of the case, the supervisory authority may also attach weight to the degree of negligence. At best, negligence could be regarded as neutral._

### Categories of personal data affected

_58\. Concerning the requirement to take account of the categories of personal data affected (Article 83(2)(g) GDPR), the GDPR clearly highlights the types of data that deserve special protection and therefore a stricter response in terms of fines. This concerns, at the very least, the types of data covered by Articles 9 and 10 GDPR, and data outside the scope of these Articles the dissemination of which causes immediate damages or distress to the data subject (e.g. location data, data on private communication, national identification numbers, or financial data, such as transaction overviews or credit card numbers). In general, the more of such categories of data involved or the more sensitive the data, the more weight the supervisory authority may attribute to this factor._

_59\. Further, the amount of data regarding each data subject is of relevance, considering that the infringement of the right to privacy and protection of personal data increases with the amount of data regarding each data subject._

## "Starting amount"

On the basis of the parameters given, the EDPB's methodology suggests the following:

| **Likely fine range, before mitigating & aggravating factors:** between XXX and XXX EUR |
| --------------------------------------------------------------------------------------- |

**This GDPR fine calculator is based on the relevant guidelines of the European Data Protection Board, and the calculation is based on information provided by the user. This calculator is intended only to inform readers on how the EDPB's guidelines appear to work and does not create a lawyer-client relationship. It is not intended to be, and should not be used as, a substitute for taking legal advice in any specific situation. Keller and Heckman LLP will accept no responsibility for any actions taken or not taken on the basis of this calculator. This may qualify as "Lawyer Advertising" requiring notice in some jurisdictions. Prior results do not guarantee a similar outcome.**

[ Keller & Heckman ](https://www.khlaw.com/) 

## Footer Menu Primary

* [About Us](/about)
* [People](/people)
* [Practices](/practices)
* [Industries](/industries)
* [Contact Us](/contact-us)
* [Media Inquiries](/about/media)
* [Login](/client-login)
* [Member of Mackrell International](https://www.mackrell.net/)

[PackagingLaw.com](http://www.packaginglaw.com/)

[TSCA Reform Center](https://www.khlaw.com/tsca)

[ Linkedin ](https://www.linkedin.com/company/keller-and-heckman-llp/) [ Twitter ](https://twitter.com/kellerandheck?lang=en) 

## Footer Menu Bottom

* [Subscribe](/subscribe)
* [Legal Notice](/disclaimer)
* [Privacy and Cookies Policy](/privacy-policy)
* [Terms of Use](/terms)

 Copyright © 2022 Keller and Heckman LLP. All rights reserved. 

©2022 Keller and Heckman LLP | khlaw.com

## Site Menu

Submit

## Main navigation

* [Our Firm](/about)
* [Our People](/people)
* [Practice Areas](/practices)  
   * [All Practices](/practices "VIew all practices")  
   * [Advertising and Promotion](/practices/advertising)  
   * [Biotechnology](/practices/biotechnology)  
   * [California’s Proposition 65](/practices/california-proposition)  
   * [Chemical Control](/practices/chemical-control)  
   * [Employment and Labor](/practices/employment)  
   * [Environmental](/practices/environmental)  
   * [Food and Drug](/practices/food)  
   * [Food and Drug Packaging](/practices/food-and-drug-packaging "Our Packaging Practice Group provides legal advice on materials used to produce, store, hold, prepare, and package food, pharmaceuticals, cosmetics, and medical devices.  ")  
   * [Health and Safety Compliance Audit](/practices/safety-compliance-audit)  
   * [Insurance Coverage](/practices/insurance)  
   * [Intellectual Property](/practices/intellectual-property)  
   * [International Regulatory Affairs](/practices/international-regulatory-affairs)  
   * [Litigation](/practices/litigation)  
   * [Nanotechnology](/practices/nanotechnology)  
   * [Occupational Safety and Health](/practices/occupational-safety)  
   * [Pesticides](/practices/pesticides)  
   * [Privacy, Data Security, and Digital Media](/practices/privacy)  
   * [Product Safety](/practices/product-safety)  
   * [Product Stewardship and Sustainability](/practices/sustainability)  
   * [Telecommunications](/practices/telecommunications)  
   * [Tobacco and E-Vapor](/practices/food/tobacco)  
   * [Trade and Professional Associations](/practices/trade)  
   * [Transportation](/practices/transportation)
* [Industries](/industries)  
   * [All Industries](/industries)  
   * [Chemicals and Plastics](/industries/chemicals)  
   * [Consumer Products and Retail](/industries/consumer-products-and-retail)  
   * [Digital Media, Technology, and Telecommunications](/industries/digital-media-technology-and-telecommunications)  
   * [Energy, Infrastructure, and Transportation](/industries/energy-infrastructure-and-transportation)  
   * [Food and Life Sciences](/industries/food-life-sciences)  
   * [Packaging](/industries/packaging)  
   * [Tobacco and E-Vapor](/industries/tobacco-and-e-vapor)  
   * [Trade Associations](/industries/trade-associations)
* [Insights](/insights)
* [Events](/events)

## Secondary Navigation

* [In the News](/news)
* [Pro Bono](/about/pro-bono)
* [Contact Us](/contact-us)
* [Offices](/offices)
* [Diversity & Inclusion](/about/diversity-inclusion)
* [Login](/client-login)
* [Careers](/careers)
* [Subscribe](/subscribe)
* [Privacy Policy](/privacy-policy)

Close

## Cited law provisions (24)

### GDPR — gdpr-art-5-par-1-en

Personal data shall be:

### GDPR — gdpr-art-13-par-1-en

Where personal data relating to a data subject are collected from the data subject, the controller shall, at the time when personal data are obtained, provide the data subject with all of the following information:

### GDPR — gdpr-art-41-par-4-en

Without prejudice to the tasks and powers of the competent supervisory authority and the provisions of Chapter VIII, a body as referred to in paragraph 1 of this Article shall, subject to appropriate safeguards, take appropriate action in cases of infringement of the code by a controller or processor, including suspension or exclusion of the controller or processor concerned from the code. It shall inform the competent supervisory authority of such actions and the reasons for taking them.

### GDPR — gdpr-art-58-par-1-en

Each supervisory authority shall have all of the following investigative powers:

### GDPR — gdpr-art-83-par-1-en

Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive.

### GDPR — gdpr-art-83-par-2-en

Administrative fines shall, depending on the circumstances of each individual case, be imposed in addition to, or instead of, measures referred to in points (a) to (h) and (j) of Article 58(2). When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to the following:

### GDPR — gdpr-art-83-par-2-pnt-b-en

the intentional or negligent character of the infringement;

### GDPR — gdpr-art-83-par-2-pnt-g-en

the categories of personal data affected by the infringement;

### GDPR — gdpr-art-83-par-3-en

If a controller or processor intentionally or negligently, for the same or linked processing operations, infringes several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the gravest infringement.

### GDPR — gdpr-art-83-par-4-en

Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 10 000 000 EUR, or in the case of an undertaking, up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher:

### GDPR — gdpr-art-6-en

Lawfulness of processing

### GDPR — gdpr-art-8-en

Conditions applicable to child's consent in relation to information society services

### GDPR — gdpr-art-9-en

Processing of special categories of personal data

### GDPR — gdpr-art-11-en

Processing which does not require identification

### GDPR — gdpr-art-12-en

Transparent information, communication and modalities for the exercise of the rights of the data subject

### GDPR — gdpr-art-25-en

Data protection by design and by default

### GDPR — gdpr-art-26-en

Joint controllers

### GDPR — gdpr-art-30-en

Records of processing activities

### GDPR — gdpr-art-31-en

The controller and the processor and, where applicable, their representatives, shall cooperate, on request, with the supervisory authority in the performance of its tasks.

### GDPR — gdpr-art-32-en

Security of processing

### GDPR — gdpr-art-37-en

Designation of the data protection officer

### GDPR — gdpr-art-44-en

Any transfer of personal data which are undergoing processing or are intended for processing after transfer to a third country or to an international organisation shall take place only if, subject to the other provisions of this Regulation, the conditions laid down in this Chapter are complied with by the controller and processor, including for onward transfers of personal data from the third country or an international organisation to another third country or to another international organisation. All provisions in this Chapter shall be applied in order to ensure that the level of protection of natural persons guaranteed by this Regulation is not undermined.

### GDPR — gdpr-art-83-en

General conditions for imposing administrative fines

### GDPR — gdpr-art-85-en

Processing and freedom of expression and information

---
Generated by overview.legal · https://overview.legal/posts/6310 · 2026-08-22
