The verdict in three sentences
A compliant client portal is built with privacy by design, not patched after launch. In 2026, baking in GDPR compliance from the design stage costs 3,000 to 12,000 EUR depending on scope, while a retrofit often costs double, with technical debt on top. The financial stake is clear: a regulator fine can reach 4 % of global turnover, plus the loss of customer trust.
Privacy by design or retrofit
Anticipating is always cheaper than fixing. A portal built with no retention logic or consent management will need deep rework, often a partial rebuild.
| Criterion | Privacy by design | Retrofit |
|---|---|---|
| 2026 cost | 3,000 – 12,000 EUR | 6,000 – 24,000 EUR |
| Timeline | Built into project | +4 to 8 weeks |
| Technical debt | Low | High |
| Sanction risk | Controlled | High until fixed |
| Customer trust | Reinforced | Weakened |
| Reversibility / data export | Native | To rebuild |
The retrofit premium comes mainly from reworking existing data schemas and regression testing.
The compliance items to budget
GDPR requires concrete mechanisms, not just a privacy policy. Here are the items to build in from the design stage.
| Item | GDPR requirement | 2026 order of magnitude |
|---|---|---|
| Processing register | Article 30 | 800 – 2,500 EUR |
| Consent management | Legal basis, opt-in | 1,000 – 3,000 EUR |
| Retention & auto-purge | Minimization | 700 – 2,000 EUR |
| Right to erasure | Article 17 | 800 – 2,500 EUR |
| Data export (portability) | Article 20 | 600 – 1,800 EUR |
| Logging & security | Article 32 | Included in dev |
Right to erasure and portability are the functions most often missing in portals not built for GDPR.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Mini case study
Julie, DPO of an e-health SME in Berlin, is rolling out a client portal for 12,000 users. The vendor prices privacy by design at 8,500 EUR built into development. The alternative quote for a post-launch retrofit is 17,000 EUR with a 6-week delay. Julie picks privacy by design: she saves 8,500 EUR and six weeks. Above all, she prices the avoided risk: a complaint followed by a sanction, even capped at an order of magnitude of 20,000 EUR for an SME, plus crisis-management costs, would far exceed the initial investment. Native compliance becomes a sales argument with her institutional clients.
FAQ
Does GDPR apply to a small internal portal? Yes, as soon as it processes personal data, even internally. Portal size does not change the obligation, only the scale of the measures required.
Do you have to appoint a DPO? A DPO is mandatory for large-scale processing of sensitive data or systematic monitoring. Many SMEs appoint one as a precaution, even without a strict obligation.
What does compliance cost in 2026? Budget 3,000 to 12,000 EUR for a portal built privacy by design; roughly double for a retrofit.
What is the processing register? It is the document listing each data processing activity, its purpose, legal basis and retention period. It is required by Article 30 and requested first in an audit.
What is the sanction for non-compliance? The regulator can impose fines up to 4 % of annual global turnover or 20 million EUR, whichever is higher.
Let's scope your project. Tell us about your portal, user volume and the data processed: we frame privacy-by-design compliance (3,000-12,000 EUR). Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.

