Websites11 min read

GDPR requirements checklist for a custom business app in Berlin (2026)

Mohamed Bah·Fondateur, Kolonell
October 7, 2026
Share:
GDPR requirements checklist for a custom business app in Berlin (2026)

GDPR requirements checklist for a custom business app in Berlin (2026)

Websites

The verdict in three sentences

GDPR added after development costs on average two to three times more than GDPR written into the specification. For a custom client tracking app, the checklist fits in about a dozen requirements, including a DPIA billed at EUR 2,000 to 5,000 of support, configurable retention periods, access logging and Article 28 processor clauses. The risk to avoid is well known: fines of up to 4% of worldwide annual turnover, and above all an application that has to be rebuilt.

The checklist to put in the specification

Each requirement below must appear as a testable requirement with an acceptance criterion. The cost shown is the extra development cost versus an app without these features.

GDPR requirementWording in the specificationIndicative extra cost
Data minimisationEach field justified by a purpose, free-text fields limitedEUR 0 to 1,000 (scoping)
Retention periodsRetention configurable per data type, automatic purge or anonymisationEUR 2,500 to 5,000
Data subject rightsExport, rectification and erasure within 30 days from the UIEUR 3,000 to 6,000
LoggingRead and write audit trail, kept 6 to 12 monthsEUR 2,000 to 4,500
Access controlRoles per team and branch, quarterly reviewEUR 2,500 to 5,000
EncryptionTLS 1.2 minimum, encryption at rest for attachmentsEUR 1,000 to 2,500
HostingEU host, EU backups, signed DPADepends on offer
Pseudonymised test environmentsAnonymised acceptance dataEUR 1,500 to 3,000

In total, allow EUR 12,000 to 27,000 for a client tracking app costing EUR 60,000 to 120,000: 15 to 25% of the budget, invested once.

Documents and roles to prepare on the client side

The vendor builds, but controller responsibility stays with you. The DPO should drive the following deliverables, ideally before the development contract is signed.

DeliverableOwnerLead timeCost if outsourced
Entry in the records of processingDPO1 to 2 daysEUR 500 to 1,000
DPIA (if high-risk processing)DPO + business + vendor3 to 6 weeksEUR 2,000 to 5,000
Article 28 processing agreementLegal1 to 2 weeksEUR 800 to 2,000
Client privacy noticesLegal + marketing1 weekEUR 400 to 900
Retention policyDPO + business2 weeksEUR 600 to 1,500
Breach procedure (72 h)DPO + IT1 weekEUR 500 to 1,200

A DPIA is mandatory when processing meets at least two criteria from the EDPB list: profiling or scoring, sensitive data, dataset matching, systematic monitoring, vulnerable people, large scale. A client tracking app with sales scoring and interaction history often qualifies. In Germany, the state data protection authorities, such as the Berlin commissioner, also publish their own mandatory DPIA lists.

Article 28 clauses not to forget

The contract with the agency must specify the subject and duration of processing, the duty to act only on instructions, confidentiality of staff, the list of sub-processors (host, email delivery, support tool) with a right to object, assistance with rights requests and DPIAs, breach notification within 24 to 48 h so you can meet the 72 h deadline, return and deletion of data at the end of the contract, and an audit right. Without these clauses, you carry the risk alone.

Mini case study

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Prefer a call back?

Leave your WhatsApp number and a Kolonell expert will get back to you within 1 business day. Free, no strings attached.

Anna, head of legal and DPO of a 2,300-client business services mid-cap (the same figures apply in Nice or Berlin, with 140 sales and field staff), commissions a client tracking app for EUR 85,000. Adding the checklist at specification stage adds EUR 17,000 of development and EUR 4,000 of DPIA support, EUR 21,000 in total. The same work done after go-live had been quoted at EUR 46,000 by a second vendor, as it required reworking the data model and the purge logic. Savings reach EUR 25,000, before counting the fine risk: on EUR 60 million of turnover, the theoretical 4% cap is EUR 2.4 million.

FAQ

Is a DPIA mandatory for a client tracking app?

It is if at least two risk criteria apply, such as scoring and large scale. Support costs EUR 2,000 to 5,000 and it must be completed before go-live.

Who is liable if the agency causes a breach?

You remain the controller, the agency is a processor with its own liability under Article 28. A precise contract allocates obligations and penalties.

How long can prospect data be kept?

The French CNIL recommends 3 years after the last contact for a prospect; German authorities apply similar purpose-based limits. For a client, the relationship plus 3 years, and 10 years for accounting records.

Must hosting be in Germany?

GDPR requires the EU or a country with adequate safeguards. An EU host avoids documenting transfers, for EUR 150 to 600 per month for this type of app.

What happens during a regulator audit?

The authority asks for the records, the DPIA, processor contracts and logging evidence. Sanctions range from a warning to 4% of worldwide turnover or EUR 20 million.

Let's scope your project. We write a testable GDPR specification with your DPO for your client tracking app, with a costed compliance budget and a DPIA schedule. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.

Tags:#specification#GDPR#business application#Berlin#DPIA#DPO
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.