Risk · GDPR Fines

    What is the cost of a personal data incident?

    When an attack exfiltrates personal data, it is no longer just an IT event. It is a regulatory event with notification obligations, supervision, and fines under GDPR. Calculate your exposure below.

    Art. 83(5) GDPR
    4 %

    of total global annual turnover can be imposed for serious infringements.

    Statutory cap
    20 M EUR

    The higher amount of 4% and 20 M EUR is the cap.

    Calculator

    Calculate your exposure.

    Enter turnover, number of affected individuals, and circumstances. The result is an indicative estimate based on Art. 83 GDPR and practice from IMY, CNIL, and Ireland DPC.

    Step 1 of 4

    Company size

    Annual turnover sets the legal cap

    SEK250,000,000 kr
    Probable outcome
    4,452,914 kr
    ≈ 387,210 EUR
    0Statutory cap 230,000,000 kr
    1.9 % of statutory cap
    Lowest probable
    2,449,103 kr
    Probable
    4,452,914 kr
    Worst case
    10,261,494 kr
    How we got here
    1. 1
      Formula 1 - Statutory cap
      Higher of 4% of 250 M or 20M EUR
      230,000,000 kr
    2. 2
      Formula 2 - Base amount
      Turnover × 0.3% × scale for 25,000 affected
      3,298,455 kr
    3. 3
      Formula 3 - Data category
      Regular personal data · ×1.0
      3,298,455 kr
    4. 4
      Formula 4 - Aggravating & mitigating
      +35 % · ±0 %
      4,452,914 kr
    5. 5
      Likely outcome
      Below statutory cap
      4,452,914 kr
    Indicative estimate based on Art. 83 GDPR and practice. Actual outcome is determined by the supervisory authority (in Sweden IMY) and is affected by many more factors than those shown here. Exchange rate 11.5 SEK/EUR.
    Real fines

    This is what has actually been imposed.

    2023
    1.2 bn EUR
    Meta (Ireland DPC)
    Unlawful data transfers EU-US
    2021
    746 M EUR
    Amazon (CNPD Luxemburg)
    Processing without valid basis
    2022
    405 M EUR
    Instagram (Ireland DPC)
    Children's data exposed
    2022
    150 M EUR
    Google (CNIL France)
    Cookie design without clear choice
    2023
    58 Mkr
    Spotify (IMY Sweden)
    Deficiencies in data subject access requests
    2022
    7.5 Mkr
    Klarna (IMY Sweden)
    Unclear information during processing
    2026
    6 Mkr
    SportAdmin (IMY Sverige)
    Inadequate security - children's data exposed
    What GDPR says

    Two categories of sanctions.

    Art. 83(4) - Lower category
    10 M EUR or 2 %

    Of total global annual turnover. The higher amount applies.

    • - Security deficiencies (Art. 32)
    • - Insufficient incident notification (Art. 33-34)
    • - Missing data protection impact assessment (Art. 35)
    • - Missing or incorrect DPO (Art. 37-39)
    Art. 83(5) - Higher category
    20 M EUR or 4 %

    Of total global annual turnover. The higher amount applies.

    • - Unlawful processing (Art. 5-7, 9)
    • - Infringement of data subjects' rights (Art. 12-22)
    • - Unlawful transfers to third countries (Art. 44-49)
    • - Breach of supervisory decisions
    Art. 83(2) - Factors that weigh in
    ·Nature, gravity, and duration of the infringement
    ·Number of affected data subjects and extent of damage
    ·Data category (sensitive data weighs more)
    ·Intent or negligence
    ·Measures taken to mitigate damage
    ·Previous infringements
    ·Cooperation with supervisory authority
    ·Manner in which the infringement became known
    ·Technical and organizational measures
    Indirect costs

    Fines are just a part of the bill.

    Damages from data subjects

    Art. 82 GDPR gives every affected individual the right to claim damages. Class actions are becoming more common.

    Notification obligation and PR

    Affected individuals and supervisory authorities must be informed. Media image costs time, agency fees, and brand.

    Customer losses

    B2B customers require SOC2/ISO and terminate contracts. B2C customers quietly leave.

    Insurance premiums up

    Cyber insurance becomes more expensive or conditions are stricter after an incident.

    DPO, lawyer, and consultant hours

    Forensics, legal, and supervisory dialogue easily take 6-12 months of external time.

    Brand value

    Long-term effect on trust-score, NPS, and lead conversion.

    Methodology and sources

    How the calculator works.

    The model is a transparent estimate - not a legal forecast. Each figure is a calibration against practice from IMY, CNIL, Ireland DPC, and CNPD, not an official benchmark.

    Formula 1 - Statutory cap

    The cap is the higher of 4% of total global annual turnover or 20 M EUR (Art. 83(5) GDPR)[1]. We use an exchange rate of 11.5 SEK/EUR to compare the two in SEK[5].

    cap = max(omsättning × 0,04, 20 000 000 × 11.5)
    Formula 2 - Base amount

    The base is derived from 0.3% of turnover, multiplied by a logarithmic scale of the number of affected individuals[2]. 100 affected individuals gives ~0.3×, 10,000 gives ~1×, 1 million gives ~1.5× of the base factor. The total base factor is scaled by 4 so typical realistic outcomes are in the same ballpark as actual supervisory decisions.

    skala = max(0,3, log10(max(100, drabbade)) / 4)
    bas = omsättning × 0,003 × skala × 4
    Formula 3 - Data category

    Sensitive data (Art. 9) and children's data weigh more in the supervisory authority's assessment[3]. The multipliers are calibrated against published decisions.

    • Regular personal data×1.0
    • Sensitive data (Art. 9)×1.7
    • Children's data×1.4
    Formula 4 - Aggravating & mitigating

    Aggravating circumstances add to the base. Mitigating circumstances deduct[4]. Mitigating circumstances can never lower the outcome below 40% of the base.

    agg  = 1 + Σ(försvårande %)
    mit  = max(0,4, 1 - Σ(förmildrande %))
    utfall = min(cap, bas × agg × mit)
    Range (lowest / probable / worst)
    • Probable: the result of the formula above, clamped to the statutory cap.
    • Lowest probable: 55% of probable outcome - reflects that supervision often results in lower figures at the first infringement.
    • Worst case: the statutory cap according to Art. 83(5).
    Assumptions and limitations
    • - Static exchange rate 11.5 SEK/EUR, no daily update.
    • - We use the higher category (Art. 83(5)) as the cap, as exfiltration of personal data is practically handled there.
    • - The model does not consider group structure, sector (healthcare, finance), or if the incident is repeated.
    • - Damages under Art. 82, civil claims, and indirect costs are not included.
    • - Swedish sanctions from IMY have historically been below the EU average - the outcome may be lower in Sweden.
    • - The result is indicative and does not replace legal advice.
    Sources and references

    Click on an assumption to see exact references to GDPR, EDPB, and IMY. Footnotes [1]-[7] in the text above link here.

    Free playbook
    Screenshot of the Akira ransomware group's terminal screen. Green monospace text on a black background with the AKIRA title in pixel art. The text reads: Well, you are here. It means that you're suffering from cyber incident right now. Think of our actions as an unscheduled forced audit of your network for vulnerabilities. Keep in mind that there is a fair price to make it all go away. Do not rush to assess what is happening - we did it to you. The best thing you can do is to follow our instructions to get back to your daily routine. Those who choose different path will be shamed here publicly. Remember. You are unable to recover without our help. Your data is already gone. Below is a command list: leaks, news, contact, help, clear.

    Avoid the fine: a ransomware response that satisfies the regulator

    Documented containment, notification timelines and evidence trail. Pick the edition that matches your jurisdiction.

    Choose your region
    Lower the risk

    Lower the risk before IMY calls.

    The Acronis stack stops exfiltration at an early stage, and Skyddad arbetsplats provides you with the documentation supervision asks for. Book a review and we will go through your current situation.