The verdict in three sentences
For a Berlin company commissioning a custom business app, GDPR compliance costs 8 to 15% of the development budget when designed in from the start, and two to three times more when bolted on after go-live. The unavoidable items are the data protection impact assessment (DPIA) for sensitive data, access logging and automatic deletion of data past its retention period. Hosting in Germany or the EU, with certifications such as C5 or ISO 27001 for health data, closes the file.
GDPR requirements translated into features
The GDPR does not ask for abstract paperwork: most articles translate into screens, scheduled jobs and technical settings. Here are the items a developer must price, as a 2026 order of magnitude.
| GDPR requirement | Concrete feature | Estimated cost |
|---|---|---|
| Data minimisation (Art. 5) | Review of collected fields, justified optional fields | EUR 500 to 1,500 |
| Storage limitation (Art. 5) | Scheduled automatic deletion or anonymisation | EUR 2,000 to 4,000 |
| Security (Art. 32) | Encryption, access logging, admin MFA | EUR 2,000 to 6,000 |
| Data subject rights (Art. 15 to 21) | Self-service export, rectification, deletion | EUR 1,500 to 4,000 |
| Consent (Art. 7) | Consent management and proof, compliant cookie banner | EUR 800 to 2,500 |
| Access control (Art. 25 and 32) | Fine-grained roles, need-to-know access | EUR 1,500 to 4,000 |
| Data breach (Art. 33) | Alerts, 72-hour notification procedure | EUR 500 to 1,500 |
On a EUR 60,000 app, these items usually total EUR 5,000 to 9,000, i.e. 8 to 15% of the budget.
The cost of compliance around the code
Compliance does not stop at development. Some items are legal or hosting matters and must be budgeted separately.
| Item | When it is required | 2026 cost |
|---|---|---|
| DPIA (impact assessment) | Health data, employee monitoring, profiling, large scale | EUR 2,000 to 6,000 |
| Outsourced DPO | Mandatory in Germany from 20 people regularly processing personal data | EUR 300 to 1,200 per month |
| Record of processing activities | Almost always | EUR 500 to 2,000 to set up |
| Standard EU hosting | Always recommended | EUR 80 to 400 per month |
| Certified health-grade hosting | Health data | EUR 300 to 1,500 per month |
| Processor agreements (Art. 28) | Every provider with data access | EUR 300 to 800 per contract |
| Annual compliance audit | Recommended | EUR 1,500 to 4,000 |
On the risk side, regulators can fine up to EUR 20 million or 4% of global turnover. For SMEs, fines from 2024 to 2026 mostly range from EUR 10,000 to 150,000, often for security failures or retention periods not respected, exactly the points handled in code.
Technical choices that make the difference
- Separating identifying data from the rest of the database makes anonymisation easier and reduces the impact of a leak.
- Logging reads, not just writes, lets you answer the question 'who viewed this record?'.
- Avoiding transfers outside the EU: US-hosted analytics, emailing or AI tools require an assessment and specific clauses. The Data Privacy Framework covers some vendors but remains legally fragile.
- Planning data export from day one: portability takes an hour with a button, a day without.
Mini case study
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Jonas, managing director of a 35-person Berlin occupational health services company, commissions an app to track medical visits and work restrictions for 12,000 monitored employees. Development budget: EUR 72,000. Privacy by design: EUR 8,500 (12%). DPIA: EUR 4,500. Certified health-grade hosting: EUR 600 per month, outsourced DPO: EUR 500 per month, i.e. EUR 13,200 per year. First-year compliance cost: EUR 26,200. Against a plausible fine of EUR 50,000 to 150,000 and the loss of a key account, the decision took one meeting.
FAQ
Is a DPIA mandatory for my app?
It is when processing carries a high risk: large-scale health data, employee monitoring, profiling, data on vulnerable people. Supervisory authorities publish lists of such cases, and a DPIA costs EUR 2,000 to 6,000.
Do I need to appoint a DPO?
In Germany, yes as soon as 20 people regularly process personal data, and always for large-scale sensitive data. An outsourced DPO costs EUR 300 to 1,200 per month depending on processing volume.
Can I host on AWS or Azure?
Yes, by choosing an EU region (Frankfurt, for instance) and signing their data processing addenda. For health data, choose hosting with the relevant certifications, starting around EUR 300 per month.
What does it cost to bring an app already in production into compliance?
Expect 15 to 30% of the original budget, versus 8 to 15% with privacy by design. Purging historical data and reworking access rights are the heaviest items.
How long should data be kept?
It depends on the purpose: 3 years after last contact for a prospect, 10 years for accounting records in Germany, a few years after the relationship ends for a customer. Each period must be coded into automatic deletion.
Let's scope your project. We build your business app with privacy by design, including records, deletion, logging and EU or health-grade hosting priced item by item. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.