Form: Cost-of-Breach DisclosureSource: IBM 2025Filed: 28 Apr 2026
DataBreachCost.comOpen calc
Schedule 08 / By CountryIBM 2025, 14 country / regional brackets

Regional headline

US breach cost: 2.30x the global average.

US breaches now cost $10.22M on average (2025), a record high and up 9% on 2024. Brazil at the other end is $1.36M. The variance reflects regulatory regime, labour costs, litigation culture, and customer-churn expectations, not breach severity. Multinational organizations should weight regional exposure proportionally.

Global average

$4.44M

IBM 2025

US average

$10.22M

Record high, +9%

UK average

$4.21M

-2% YoY

Brazil average

$1.36M

Lowest in dataset

Section 08.1 / Country / region ranking

14 jurisdictions, 2025 figures

United States / State-by-state$10.22M (+9%)
Middle East / Varies$7.29M (+8%)
Canada / PIPEDA$5.13M (+3%)
Germany / GDPR / BDSG$4.85M (+2%)
Japan / APPI$4.53M (+1%)
United Kingdom / UK GDPR / DPA$4.21M (-2%)
France / GDPR / CNIL$4.08M (+4%)
Italy / GDPR / Garante$3.86M (+1%)
South Korea / PIPA$3.62M (+5%)
Australia / NDB / Privacy Act$3.41M (-1%)
South Africa / POPIA$2.87M (+7%)
ASEAN / Varies$2.71M (+3%)
India / DPDP Act$2.35M (+6%)
Brazil / LGPD$1.36M (-4%)

Primary source:IBM Cost of a Data Breach Report 2025 (regional sub-aggregates).

Section 08.2 / Multipliers & regulatory notes

What the multiplier represents

Multiplier values are computed from IBM 2025 country averages versus the global $4.44M baseline. They incorporate regulatory regime, labour costs for IR & legal, currency, and litigation culture. They do not reflect attack severity or company size.

Country / regionAvg costMultiplierYoYRegulation
United States$10.22Mx2.30+9%State-by-state
Middle East$7.29Mx1.64+8%Varies
Canada$5.13Mx1.16+3%PIPEDA
Germany$4.85Mx1.09+2%GDPR / BDSG
Japan$4.53Mx1.02+1%APPI
United Kingdom$4.21Mx0.95-2%UK GDPR / DPA
France$4.08Mx0.92+4%GDPR / CNIL
Italy$3.86Mx0.87+1%GDPR / Garante
South Korea$3.62Mx0.82+5%PIPA
Australia$3.41Mx0.77-1%NDB / Privacy Act
South Africa$2.87Mx0.65+7%POPIA
ASEAN$2.71Mx0.61+3%Varies
India$2.35Mx0.53+6%DPDP Act
Brazil$1.36Mx0.31-4%LGPD

Section 08.3 / GDPR impact on European breach costs

The 72-hour clock and the 4% revenue ceiling

GDPR's notification regime and supervisory-authority enforcement reshape European breach economics. Fine ceilings of 4% of global annual revenue or EUR 20M create asymmetric risk for global organizations. Enforcement pace has accelerated, the EUR 1.2B Meta fine (2023) and the multiple regulator-coordinated investigations of US tech firms make material exposure realistic for any organization processing EU personal data at scale.

Notification clock

72 hours

From awareness of a personal-data breach. Notify the lead supervisory authority. Failing the clock alone can trigger a separate fine.

Maximum fine

4% revenue

4% of global annual revenue or EUR 20M, whichever is higher. The Meta EUR 1.2B (2023) and Amazon EUR 746M (2021) figures sit within this ceiling.

Cross-border

One-stop shop

Cross-border incidents are coordinated through the lead authority but consultation with all affected authorities adds weeks to the resolution timeline.

Section 08.4 / US state notification map

Why US costs are so high

The US has no federal breach-notification law. All 50 states + DC have their own statute, with notification deadlines from 30 days (Florida, Washington, California from Jan 2026) to 'as soon as practicable' (Massachusetts). Multi-state breaches require simultaneous compliance with up to 50+ different statutes. This regulatory fragmentation drives the US to the top of the IBM cost ranking and shows no sign of changing.

Notable state regimes: California SB 446 (effective Jan 2026) requires notification within 30 days, the strictest in the US. New York SHIELD Act expanded the definition of personal information in 2019 and added security obligations. Texas expanded notification scope in 2025. Most states require AG notification on breaches affecting 500+ residents. See Schedule 09 for the full state-by-state register.

Index / Companion schedules

Schedule F / Reference Q&A

Frequently Asked Questions