Skip to content
VITI Security

ePrivacy Directive + GDPR

Cookie Consent Fine Calculator

Estimate your cookie-consent enforcement exposure and get a prioritized fix list based on CNIL practice.

How this is calculated

  1. Each issue you tick has a weight: 3 for cookies set before consent; 2 for no first-layer reject button, pre-ticked boxes, cookie walls or undisclosed third-party trackers; 1 for no granular choice or no consent records. The weights add up to a score.
  2. Two multipliers apply: supervisory risk (0.5 low, 1 medium, 2 high) and audience (1 under 10,000 monthly EU visitors, 2 from 10,000, 4 from 100,000, 8 from 1,000,000).
  3. Low end = EUR 2,000 x score x risk x audience, rounded to the nearest EUR 100, with a floor of EUR 1,000. High end = 25 x the low end, capped at EUR 20 million.
  4. Fixes are listed heaviest-weight first, so the top of the list is where risk falls fastest.

Constants the tool uses

Unless a value names a study, it is VITI Security's working estimate for budgeting - not taken from a statute or a dated study - so treat it as an adjustable assumption.

Issue weights
3 / 2 / 1 as described above
Base amount per score point
EUR 2,000
Supervisory risk multiplier
0.5 / 1 / 2
Audience multiplier
1 / 2 / 4 / 8
High end
25x the low end, capped at EUR 20 million
Floor
EUR 1,000

Worked example

The calculator run on its default inputs:

Monthly EU visitors
50,000 visitors
Consent issues found on your site (select all that apply)
Non-essential cookies set before consent
Supervisory attention risk
Medium - active market, some complaints possible

Indicative exposure band

€12,000 - €300,000

Issues selected
1
Exposure band (indicative)
€12,000 - €300,000
Fix #1
Block all non-essential cookies and tags until consent is given (prior-consent requirement, ePrivacy Art. 5(3)).

One issue (non-essential cookies before consent, weight 3), medium supervisory risk (x1) and 50,000 monthly EU visitors (x2) give EUR 2,000 x 3 x 1 x 2 = EUR 12,000 at the low end, and 25 times that, EUR 300,000, at the high end.

Sources

Sources last checked September 2026.

Limitations

The band is a heuristic, not a prediction: cookie rules are enforced under each country’s ePrivacy law, with its own ceilings and procedures, and the reference fines above involved very large companies. The EUR 20 million cap is a modelling choice - fines on large companies have gone well above it (Google, EUR 325 million in 2025). This is an indicative estimate for education and planning, not legal advice. Laws and published figures change, and regulators and courts apply discretion no calculator can model - confirm with a qualified legal or compliance professional before acting on a result.