Websites11 min read

GDPR compliance checklist for a web app (2026)

Mohamed Bah·Fondateur, Kolonell
September 4, 2026
Share:
GDPR compliance checklist for a web app (2026)

GDPR compliance checklist for a web app (2026)

Websites

The verdict in three sentences

Making a web app GDPR-compliant means documenting the records of processing, applying data minimisation, implementing data subject rights (access, erasure, portability) and signing a DPA with each processor. Compliance costs in 2026 between 3,000 and 10,000 EUR excl. tax over a 3 to 6 week timeframe. The stakes are high: a regulator fine can reach 20M EUR or 4 % of global revenue.

The costed compliance checklist

Each GDPR requirement translates into a technical or organisational workstream. Here are the items and their 2026 indicative cost.

RequirementDeliverable2026 cost (EUR excl. tax)Timeframe
Records of processingMapping document500 - 1,5003-5 days
Data minimisationDB schema review800 - 2,0001 week
Right to erasureDeletion feature1,000 - 2,5001-2 weeks
Right of access / portabilityData export800 - 2,0001 week
Cookie consentCompliant banner400 - 1,2003 days
Processor DPAsSigned contracts300 - 8001 week
Privacy policyLegal drafting500 - 1,5003-5 days
Encryption + access logsTechnical implementation800 - 2,5001-2 weeks

Full compliance for an SME application therefore falls between 3,000 and 10,000 EUR excl. tax depending on the starting maturity and the sensitivity of the data processed.

Sanctions and risks of non-compliance

Regulators scale sanctions by severity. In 2026, they favour formal notices but financial fines are rising, notably on cookies and non-EU transfers.

Type of breachTypical 2026 sanctionAdditional risk
No records of processingFormal noticeAggravation on inspection
Non-compliant cookies5,000 - 100,000 EUR (SME)Fine on repeat offence
Security failure20,000 - 250,000 EURMandatory breach notification
Unlawful non-EU transferup to 4 % of revenueProcessing suspension
Non-respect of subject rights10,000 - 150,000 EURComplaint + reputation

Beyond the fine, a breach exposes you to lost B2B contracts (customers audit their processors) and the obligation to notify a data breach within 72 hours.

Mini case study

Marc is an outsourced DPO for a 30-person edtech SME in Lille whose app handles learner data (including minors). He orders targeted compliance: records of processing, right to erasure, data export, compliant cookie banner and DPAs with the three processors, for 7,200 EUR excl. tax (5-week timeframe). As the app handles sensitive data, non-compliance exposed the company (3.2M EUR revenue) to a theoretical fine of 128,000 EUR (4 %). The compliance budget represents 5.6 % of that risk, while unlocking two large-account contracts conditioned on a passed GDPR questionnaire.

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Prefer a call back?

Leave your WhatsApp number and a Kolonell expert will get back to you within 1 business day. Free, no strings attached.

FAQ

Are records of processing really mandatory?

Yes, for any organisation processing personal data (the under-250-employee exemption is very limited). It's the first document requested during an inspection. Its absence is an immediate non-compliance.

How long for full compliance?

Allow 3 to 6 weeks depending on the number of workstreams. Right to erasure and data export are the longest technical items. Documents (records, policy) are faster.

Do I need a DPO to be compliant?

A DPO is mandatory for large-scale processing of sensitive data or systematic monitoring. Many SMEs opt for an outsourced DPO (300-800 EUR/month) rather than an in-house role.

Is cookie consent a real risk?

Yes, it's the most inspected topic in 2026. A non-compliant banner (forced consent, no easy refusal) exposes you to fines of 5,000 to 100,000 EUR for an SME. Banner compliance costs 400-1,200 EUR.

What should I do in case of a data breach?

Notify the regulator within 72 hours and, if the risk is high, inform the affected individuals. A documented response plan and encryption in place strongly reduce the consequences and the potential fine.

Let's scope your project. Describe the data your app processes (nature, sensitivity, processors) and we'll build a costed compliance checklist with a prioritised action plan. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.

Tags:#GDPR#compliance#web application#DPO#records of processing#right to erasure#GDPR checklist#data protection
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.