The verdict in three sentences
A custom business app that processes European clients' data must satisfy the EU GDPR AND the local data-protection law (in Singapore, the PDPA). The compliance project represents in 2026 an order of magnitude of 2-6 million FCFA equivalent depending on complexity, plus recurring costs (EU hosting, DPO). Non-compliance loses European contracts and exposes you to penalties: it is a commercial investment as much as a risk to cover.
GDPR vs local law: two frameworks to reconcile
The two texts share a close philosophy (consent, purpose, security) but differ on the competent authority and formalities. An app targeting Europe must aim for the stricter standard.
| Obligation | GDPR (EU) | Local law (PDPA) |
|---|---|---|
| Supervisory authority | CNIL and peers | PDPC |
| Legal basis for processing | Mandatory | Mandatory |
| Processing register | Required | Recommended |
| Prior notification | No (unless DPIA) | Case-by-case |
| DPO | Required in some cases | Data Protection Officer required |
| Max penalty | Order of magnitude: millions EUR | Significant fines |
The 2026 compliance budget
Beyond the one-off compliance work, plan for recurring costs. The most structural item is often EU hosting, required by European clients.
| Item | 2026 range | Type |
|---|---|---|
| Compliance (audit + docs) | 2,000,000 - 6,000,000 FCFA eq. | One-off |
| EU hosting (OVH/Scaleway) | 30 - 150 EUR/month | Recurring |
| Outsourced DPO | 300 - 800 EUR/month | Recurring |
| Processing register | Included in compliance work | One-off |
| Consent + retention policy | 500,000 - 1,500,000 FCFA eq. | One-off |
| Annual follow-up audit | 800,000 - 2,000,000 FCFA eq. | Annual |
The 12-point minimum checklist: documented legal basis, processing register, DPA with the host, EU hosting, explicit consent, retention policy, access/erasure rights, encryption in transit and at rest, logging, breach procedure, DPO or referent, compliant legal notices.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Mini case study
Wei, founder of a software SME in Singapore, sells a management tool to distributors in France. A European prospect requires proof of GDPR compliance before signing. Wei invests 3,500,000 FCFA equivalent in compliance (audit, register, policies), migrates to EU hosting at 90 EUR/month and hires an outsourced DPO at 400 EUR/month. First-year cost: roughly 3,500,000 FCFA + ~5,880,000 FCFA recurring equivalent. He signs a blocked European contract worth 12,000 EUR/year and secures two more compliance-sensitive prospects.
FAQ
Does GDPR apply to a non-EU company? Yes, as soon as it processes data of individuals located in the EU. GDPR has extraterritorial reach: the client's location matters, not just the company's.
Is a DPO always mandatory? Not always, but strongly recommended once you process data at scale or sensitive data. An outsourced DPO costs 300-800 EUR/month in 2026.
Can I host locally and stay compliant? For European clients, EU hosting is often contractually required. EU hosting at 30-150 EUR/month removes this blocker.
How long does compliance take? Expect 4 to 10 weeks depending on the app's complexity and existing documentation maturity.
What is the risk of non-compliance? Loss of European contracts, local-authority penalties and, on the EU side, high-order-of-magnitude fines. Compliance cost remains far below that of an incident.
Let's scope your project. Tell us what data types you process and your target markets, and we will frame the GDPR + local compliance and an indicative budget. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
