Data Breach Cost by Country and Region (2025)

US breaches cost $10.22M — 2.3x the global average and 7.5x more than Brazil. Geography is one of the strongest cost predictors.

Most Expensive

$10.22M

United States

Least Expensive

$1.36M

Brazil

Global Average

$4.44M

Across 17 countries

Cost Range

7.5x

Between highest and lowest

Regional Cost Ranking

IBM's 2025 report covers 17 countries and regions, revealing dramatic variation in breach costs that reflects differences in regulatory environment, litigation culture, labour costs, and customer expectations. The United States has been the most expensive country for data breaches for every year of IBM's study, driven by class action litigation, complex multi-state regulatory requirements, and the highest incident response labour costs globally. The 7.5x cost difference between the US ($10.22M) and Brazil ($1.36M) underscores how critical geographic context is when modelling breach impact.

United States (+9% YoY)$10.22M
Middle East (+8% YoY)$7.29M
Canada (+3% YoY)$5.13M
Germany (+2% YoY)$4.85M
Japan (+1% YoY)$4.53M
United Kingdom (-2% YoY)$4.21M
France (+4% YoY)$4.08M
Italy (+1% YoY)$3.86M
South Korea (+5% YoY)$3.62M
Australia (-1% YoY)$3.41M
South Africa (+7% YoY)$2.87M
ASEAN (+3% YoY)$2.71M
India (+6% YoY)$2.35M
Brazil (-4% YoY)$1.36M

Source: IBM Cost of a Data Breach Report 2025

Complete Country Data

Country/RegionAvg CostMultiplierYoY ChangePrimary Regulation
United States$10.22M2.3x+9%State-by-state
Middle East$7.29M1.64x+8%Varies
Canada$5.13M1.16x+3%PIPEDA
Germany$4.85M1.09x+2%GDPR / BDSG
Japan$4.53M1.02x+1%APPI
United Kingdom$4.21M0.95x-2%UK GDPR / DPA
France$4.08M0.92x+4%GDPR / CNIL
Italy$3.86M0.87x+1%GDPR / Garante
South Korea$3.62M0.82x+5%PIPA
Australia$3.41M0.77x-1%NDB / Privacy Act
South Africa$2.87M0.65x+7%POPIA
ASEAN$2.71M0.61x+3%Varies
India$2.35M0.53x+6%DPDP Act
Brazil$1.36M0.31x-4%LGPD

Why Costs Vary So Dramatically

Regulatory environment: Countries with strict data protection regulations and active enforcement have higher breach costs. GDPR countries face fines up to 4% of global revenue or 20 million EUR, plus mandatory 72-hour notification. The US, despite lacking a federal privacy law, has the world's most complex regulatory landscape with all 50 states plus DC maintaining separate breach notification laws, each with different definitions, timelines, and penalties. This state-by-state compliance burden adds significant legal and administrative costs to every US breach.

Litigation culture: The United States has the most active class action litigation environment for data breaches. Almost every significant breach triggers multiple class action lawsuits, with settlements ranging from $30 million to $700 million for mega-breaches. By contrast, class action mechanisms are limited or non-existent in many countries, dramatically reducing post-breach legal exposure. European countries, while having strong regulatory penalties through GDPR, have less class action activity than the US.

Labour costs for remediation: The cost of incident response professionals varies enormously by market. US-based forensic investigators, breach response attorneys, and security consultants command rates of $300-$1,000 per hour, while comparable professionals in India or Brazil may charge $50-$200 per hour. Since forensic investigation and legal response are labour-intensive activities consuming hundreds to thousands of professional hours, this cost differential has a large impact on total breach cost. Organizations in high-cost markets should consider pre-negotiated retainer arrangements with IR firms to lock in rates before an incident occurs.

Customer churn expectations: Customer tolerance for data breaches varies by market. US and European consumers have the highest expectations for data protection and the greatest willingness to switch providers after a breach. In markets with fewer competitive alternatives or lower data privacy awareness, customer churn rates are lower, reducing the lost business component of breach cost. However, this is changing globally as data privacy awareness increases and privacy regulations expand.

Currency and purchasing power: IBM normalizes all costs to US dollars, but purchasing power parity means that the same dollar amount represents different real impacts in different markets. A $1.36M breach cost in Brazil represents a proportionally larger burden relative to typical Brazilian corporate revenues than a $4.85M breach cost in Germany. Organizations should consider breach cost relative to their market-specific revenue benchmarks rather than comparing raw dollar amounts across countries.

Source: IBM Cost of a Data Breach Report 2025, World Bank economic data

GDPR Impact on European Breach Costs

The General Data Protection Regulation (GDPR), enforceable since May 2018, has significantly impacted breach costs for organizations operating in the European Economic Area. The regulation's 72-hour notification requirement compresses the response timeline, often requiring expensive rapid mobilization of incident response resources. Fines up to 4% of global annual revenue or 20 million EUR (whichever is higher) create enormous regulatory exposure — Meta/Facebook's $1.6 billion fine in 2023 demonstrates that regulators are willing to impose near-maximum penalties for serious violations.

Cross-border breach complications add another cost layer. When a breach involves data subjects in multiple EU member states, the organization must navigate the "one-stop-shop" mechanism, identifying the lead supervisory authority and coordinating with concerned supervisory authorities in other affected states. This cross-border coordination extends timeline, increases legal complexity, and multiplies compliance costs. A multinational breach affecting customers in 10 EU countries requires far more legal and regulatory effort than a single-jurisdiction incident.

Despite the increase in regulatory costs, GDPR has also driven significant improvement in breach detection and response capabilities across European organizations. The 72-hour notification requirement forced companies to invest in detection infrastructure and incident response planning, leading to faster identification and containment of breaches. This investment in preparedness partially offsets the increased regulatory costs — European organizations now detect breaches significantly faster than they did before GDPR implementation.

For organizations subject to GDPR, understanding the full fine landscape is critical for breach cost planning. Visit gdprfine.com for a comprehensive database of GDPR fines and enforcement actions, including sector-specific analysis and penalty trend data.

US State-by-State Landscape

The United States presents the world's most complex breach notification landscape, with all 50 states plus the District of Columbia maintaining separate breach notification laws. There is no federal data breach notification law, meaning organizations that experience a breach affecting customers in multiple states must comply with potentially dozens of different notification requirements simultaneously. This regulatory fragmentation is a primary driver of the US's $10.22M average breach cost.

California leads with the most comprehensive framework. SB 446 (effective January 2026) reduces the notification deadline to 30 days, the shortest of any state. Combined with the CCPA/CPRA, which imposes fines of $2,500-$7,500 per violation and grants consumers a private right of action for data breaches, California creates the highest per-state compliance burden for any US breach.

New York's SHIELD Act (2019) expanded the definition of private information and required businesses to implement "reasonable safeguards." Penalties of $5,000 per violation plus potential AG enforcement actions make New York another high-exposure state.

Texas expanded its notification requirements in 2025 with a 60-day deadline, mandatory AG notification for breaches affecting 250+ residents, and penalties of $100,000-$250,000 per breach. The state's AG has been increasingly active in enforcement.

For a complete mapping of all 50 state requirements, see our notification requirements page.

Calculate for Your Region

Select your country in the calculator for region-specific estimates.

Notification by Country

Complete notification requirements for every major jurisdiction.

Industry Costs in Your Region

How industry and geography interact to determine breach costs.

Frequently Asked Questions

The United States has the highest data breach cost at $10.22 million average in 2025, according to IBM's report. This is 2.3x the global average of $4.44 million and has been the most expensive country for every year of IBM's study. US costs are driven by class action litigation (nearly every significant breach triggers lawsuits), complex multi-state regulatory compliance (all 50 states have separate notification laws), and high labour costs for incident response professionals ($300-$1,000/hour). The Middle East is second at $7.29M, followed by Canada at $5.13M.
GDPR data breaches carry both direct regulatory fines and indirect compliance costs. Fines can reach 4% of global annual revenue or 20 million EUR, whichever is higher. Meta/Facebook received a $1.6 billion GDPR fine in 2023, the largest to date. Beyond fines, GDPR compliance costs include mandatory 72-hour notification (requiring rapid IR mobilization), Data Protection Impact Assessments, cross-border coordination with multiple supervisory authorities, and mandatory breach documentation. German breaches average $4.85M and UK breaches $4.21M, both influenced by GDPR requirements. The regulation has also driven significant investment in detection infrastructure, which partially offsets costs through faster breach identification.
US breach costs ($10.22M) are the highest globally due to several compounding factors: (1) Litigation culture — nearly every significant breach triggers class action lawsuits, with settlements ranging from $30M-$700M. (2) Regulatory complexity — with 50 separate state notification laws plus sector-specific regulations (HIPAA, GLBA, PCI DSS), compliance costs multiply. (3) Labour costs — US IR professionals charge $300-$1,000/hour, 3-5x rates in lower-cost markets. (4) Customer expectations — US consumers have high expectations for data protection and strong willingness to switch providers after breaches. (5) No federal preemption — the absence of a federal privacy law means organizations cannot satisfy all obligations with a single compliance framework.
US breaches ($10.22M) cost approximately twice as much as major European markets: Germany ($4.85M), UK ($4.21M), France ($4.08M), and Italy ($3.86M). The difference is primarily driven by the US litigation environment (class actions are far more common and costly than European equivalents) and the fragmented US regulatory landscape (50+ jurisdictions versus GDPR's one-stop-shop mechanism). However, European costs have been rising since GDPR implementation, and GDPR fines can be more severe than any individual US state penalty. The enforcement of GDPR fines like Meta's $1.6B penalty suggests that the gap between US and European breach costs may narrow over time as European regulators become more aggressive.