Regulatory compliance is a numbers game: every security control an organization enables measurably shifts breach probability, the number of records a breach would expose, and the statutory fine that follows. This simulator renders a real four-stage data pipeline — Collection, Storage, Processing and Third-Party Transfer — as a live 3D particle flow, and lets you toggle four documented controls (encryption, MFA/access control, audit logging, data minimization) plus the organization's record volume, annual turnover and external attack pressure. Every change recomputes annual breach probability, records exposed per incident, the GDPR Article 83 statutory fine cap (the greater of €20M or 4% of global turnover) and the resulting expected annual fine exposure, using published risk-reduction factors instead of made-up sliders.