Answer 9 questions. Get a brutally honest dollar figure.
Takes about 3 minutes.
This drives how many Data Subject Access Requests you're likely fielding — and how expensive each one is to process.
Select all that apply. If you operate under multiple frameworks, the calculator will use the most stringent to determine your DSAR obligations and penalty exposure.
A ballpark is fine. This affects your breach exposure and Data Subject Access Request (DSAR) volume.
Be honest. Nobody's watching. This affects how quickly your team can respond to privacy issues.
Select all that apply. Higher-sensitivity data = higher breach cost multiplier.
Select all that apply. Encryption gaps directly increase your breach probability score.
Select all that exist in some shape or form — they don't need to be fully formalised. Gaps here = compliance overhead hours. Leaving this blank is a valid (and expensive) answer.
Bugs, incidents, near-misses, Data Subject Access Request (DSAR) bottlenecks — anything that touched privacy. Round up if unsure.
Not the time to notice it — the time from "we know about this" to "it's fixed."