Websites11 min read

DPIA for a health app under GDPR: when it is required and its cost (2026)

Mohamed Bah·Fondateur, Kolonell
October 8, 2026
Share:
DPIA for a health app under GDPR: when it is required and its cost (2026)

DPIA for a health app under GDPR: when it is required and its cost (2026)

Websites

The verdict in three sentences

A health app that monitors patients almost always meets at least two of the nine EDPB criteria, which makes a DPIA mandatory before going live. With an external DPO and support from the tech team, the budget ranges from 3,000 to 12,000 EUR excl. VAT for 3 to 8 weeks of work. Doing it during design costs far less than fixing the architecture after a regulator audit.

When is a DPIA mandatory?

Article 35 of the GDPR requires a data protection impact assessment (DPIA) when processing is likely to result in a high risk to individuals. France's CNIL publishes a list of processing operations that require one, and the European guidelines set nine criteria: as soon as two are met, a DPIA is in principle required.

EDPB criterionPatient monitoring appCounts
Sensitive data (health)Yes, vitals, diagnoses, treatmentsYes
Vulnerable peoplePatients, sometimes elderly or minorsYes
Large-scale processingFrom a few thousand patientsOften
Systematic monitoringRemote monitoring, connected devicesOften
Matching datasetsPatient record + sensors + calendarSometimes
Innovative useAI triage, risk scoringSometimes
Automated decision with effectAlert that triggers careRarely

The CNIL list explicitly covers health data processed by health or social care institutions for patient care, and large-scale health data processing. In practice, a vendor selling its app to clinics or healthcare professionals must plan for it from the design stage.

The 4-step PIA method and budget

The CNIL method, supported by the free PIA software, runs in four stages: context description, review of core principles, security risk assessment, action plan and sign-off.

StepContentDPO/consultant daysIndicative cost excl. VAT (2026)
1. ContextPurposes, data, flows, actors, processors1 to 3700 to 2,700 EUR
2. Core principlesLegal basis, minimisation, retention, rights1 to 3700 to 2,700 EUR
3. RisksIllegitimate access, modification, loss2 to 41,400 to 3,600 EUR
4. Action plan and sign-offMeasures, residual risk, DPO opinion1 to 2700 to 1,800 EUR
Tech team workshopsArchitecture, encryption, logs1 to 3 internal daysInternal time
Prior consultation with the CNIL (if residual risk is high)File and exchanges1 to 2700 to 1,800 EUR

Day rates for an external DPO or specialist firm range from 700 to 1,200 EUR excl. VAT. A small, well-documented app stays under 4,000 EUR excl. VAT; a platform with AI and connected devices often exceeds 10,000 EUR excl. VAT.

DPIA, HDS hosting and penalty risks

The DPIA and HDS certification are two separate obligations. In France, hosting health data on behalf of a third party requires an HDS-certified host (20 to 60 % more than standard cloud, often 300 to 1,500 EUR a month for an early-stage app). The DPIA documents this choice as a security measure, along with encryption, access logging and strong authentication for clinicians.

During an audit, failing to carry out a mandatory DPIA can be fined up to 10 million euros or 2 % of worldwide turnover. The CNIL also uses a simplified procedure for fines from a few thousand to 20,000 EUR, and hospital buyers increasingly ask for the DPIA in tenders.

Mini case study

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Prefer a call back?

Leave your WhatsApp number and a Kolonell expert will get back to you within 1 business day. Free, no strings attached.

Thomas, founder of a post-operative follow-up app in Bordeaux, plans a launch with 4 clinics and 6,000 patients in year one. His external DPO bills 6 days at 850 EUR excl. VAT, i.e. 5,100 EUR, and the tech team spends 3 internal days on it. The DPIA reveals that wound photos are stored unencrypted in a bucket: the fix takes 2 development days, about 1,200 EUR, instead of a redesign estimated at 15,000 EUR had the issue surfaced after go-live. The DPIA file also lets Thomas answer the first clinic's security questionnaire within 48 hours.

FAQ

Is a DPIA needed for an MVP tested with 50 patients?

If the MVP processes real health data, in practice yes, because the sensitive data and vulnerable people criteria are already met. A lighter version at 2,000 to 3,000 EUR excl. VAT is possible and can be expanded before scaling.

Who must carry out the DPIA: the vendor or the clinic?

The controller, often the healthcare institution. The vendor, as processor, must supply the technical input, and many vendors provide a template DPIA to speed up sales.

Does it need to be redone regularly?

Yes, whenever a significant change occurs (new AI feature, new processor), and at least a review every 3 years. An update usually costs 30 to 50 % of the initial cost.

Is the CNIL PIA software enough?

It is a free and recognised structuring tool, but it does not replace the analysis. Without GDPR and security expertise, the risk is a box-ticking document the regulator will find insufficient.

When must the CNIL be consulted?

If residual risk remains high after the planned measures. The CNIL then has 8 weeks, extendable by 6, to give its opinion.

Let's scope your project. We build your health app with an architecture ready for the DPIA and HDS hosting, and support you with a partner DPO for a budget of 3,000 to 12,000 EUR excl. VAT. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.

Tags:#DPIA#impact assessment#health data#CNIL#GDPR#e-health
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.