The verdict in three sentences
Making a web app GDPR-compliant means documenting the records of processing, applying data minimisation, implementing data subject rights (access, erasure, portability) and signing a DPA with each processor. Compliance costs in 2026 between 3,000 and 10,000 EUR excl. tax over a 3 to 6 week timeframe. The stakes are high: a regulator fine can reach 20M EUR or 4 % of global revenue.
The costed compliance checklist
Each GDPR requirement translates into a technical or organisational workstream. Here are the items and their 2026 indicative cost.
| Requirement | Deliverable | 2026 cost (EUR excl. tax) | Timeframe |
|---|---|---|---|
| Records of processing | Mapping document | 500 - 1,500 | 3-5 days |
| Data minimisation | DB schema review | 800 - 2,000 | 1 week |
| Right to erasure | Deletion feature | 1,000 - 2,500 | 1-2 weeks |
| Right of access / portability | Data export | 800 - 2,000 | 1 week |
| Cookie consent | Compliant banner | 400 - 1,200 | 3 days |
| Processor DPAs | Signed contracts | 300 - 800 | 1 week |
| Privacy policy | Legal drafting | 500 - 1,500 | 3-5 days |
| Encryption + access logs | Technical implementation | 800 - 2,500 | 1-2 weeks |
Full compliance for an SME application therefore falls between 3,000 and 10,000 EUR excl. tax depending on the starting maturity and the sensitivity of the data processed.
Sanctions and risks of non-compliance
Regulators scale sanctions by severity. In 2026, they favour formal notices but financial fines are rising, notably on cookies and non-EU transfers.
| Type of breach | Typical 2026 sanction | Additional risk |
|---|---|---|
| No records of processing | Formal notice | Aggravation on inspection |
| Non-compliant cookies | 5,000 - 100,000 EUR (SME) | Fine on repeat offence |
| Security failure | 20,000 - 250,000 EUR | Mandatory breach notification |
| Unlawful non-EU transfer | up to 4 % of revenue | Processing suspension |
| Non-respect of subject rights | 10,000 - 150,000 EUR | Complaint + reputation |
Beyond the fine, a breach exposes you to lost B2B contracts (customers audit their processors) and the obligation to notify a data breach within 72 hours.
Mini case study
Marc is an outsourced DPO for a 30-person edtech SME in Lille whose app handles learner data (including minors). He orders targeted compliance: records of processing, right to erasure, data export, compliant cookie banner and DPAs with the three processors, for 7,200 EUR excl. tax (5-week timeframe). As the app handles sensitive data, non-compliance exposed the company (3.2M EUR revenue) to a theoretical fine of 128,000 EUR (4 %). The compliance budget represents 5.6 % of that risk, while unlocking two large-account contracts conditioned on a passed GDPR questionnaire.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
FAQ
Are records of processing really mandatory?
Yes, for any organisation processing personal data (the under-250-employee exemption is very limited). It's the first document requested during an inspection. Its absence is an immediate non-compliance.
How long for full compliance?
Allow 3 to 6 weeks depending on the number of workstreams. Right to erasure and data export are the longest technical items. Documents (records, policy) are faster.
Do I need a DPO to be compliant?
A DPO is mandatory for large-scale processing of sensitive data or systematic monitoring. Many SMEs opt for an outsourced DPO (300-800 EUR/month) rather than an in-house role.
Is cookie consent a real risk?
Yes, it's the most inspected topic in 2026. A non-compliant banner (forced consent, no easy refusal) exposes you to fines of 5,000 to 100,000 EUR for an SME. Banner compliance costs 400-1,200 EUR.
What should I do in case of a data breach?
Notify the regulator within 72 hours and, if the risk is high, inform the affected individuals. A documented response plan and encryption in place strongly reduce the consequences and the potential fine.
Let's scope your project. Describe the data your app processes (nature, sensitivity, processors) and we'll build a costed compliance checklist with a prioritised action plan. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
