The verdict in three sentences
Health data are sensitive data under GDPR: processing them requires certified hosting, a Data Protection Impact Assessment (DPIA) and strong encryption. Bringing an existing business application into compliance costs between 8,000 and 25,000 EUR over 6 to 12 weeks. Non-compliance risk is not theoretical: a regulator fine can reach several hundred thousand euros for an SME.
What GDPR requires for health data
Beyond consent, GDPR Article 9 strictly frames health data. Here are the obligations and their 2026 implementation cost.
| Obligation | Content | Cost | Timeline |
|---|---|---|---|
| Certified hosting | Migration to certified host | 2,000 - 6,000 EUR + monthly uplift | 2-4 weeks |
| DPIA (impact assessment) | Risk mapping, measures | 2,500 - 5,000 EUR | 2-3 weeks |
| Encryption at rest + transit | AES-256, TLS 1.3 | 1,500 - 3,500 EUR | 1-2 weeks |
| Access logging | Time-stamped logs, traceability | 1,500 - 4,000 EUR | 2 weeks |
| Register + retention policy | Documentation, auto-purge | 1,000 - 3,000 EUR | 1-2 weeks |
| Rights management (access, erasure) | User portal | 2,000 - 4,500 EUR | 2-3 weeks |
The uplift for certified health-data hosting is real: budget 150 to 600 EUR/month extra depending on volume, versus standard hosting.
Cost of a regulator fine and compliance maintenance
Non-compliance costs far more than compliance. Here are 2026 orders of magnitude for fines and the upkeep budget.
| Item | 2026 order of magnitude |
|---|---|
| SME regulator fine (security breach) | 20,000 - 150,000 EUR |
| Major fine (health data exposed) | up to 4 % of global turnover |
| Breach notification (legal deadline) | 72 h mandatory |
| Ongoing compliance maintenance | 500 - 1,200 EUR/month |
| Annual re-audit / review | 3,000 - 6,000 EUR/year |
| DPO / team training | 1,500 - 3,000 EUR/year |
A compliance maintenance of 500 to 1,200 EUR/month covers register updates, regulatory watch, sub-processor review and DPIA refresh when processing changes.
Mini case study
Dr. Byrne runs a teleconsultation software vendor in Dublin, 12 staff, processing data for 8,000 patients. Full compliance: certified hosting (4,000 EUR + 350 EUR/month), DPIA (3,500 EUR), encryption and logging (5,000 EUR), rights portal (3,000 EUR), i.e. 15,500 EUR + 350 EUR/month. He adds maintenance at 800 EUR/month. Year-one budget: 15,500 + (1,150 x 12) = 29,300 EUR. A regulator fine following a patient-record breach estimated at 80,000 - 150,000 EUR, plus loss of his commercial licence, made the investment non-negotiable.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
FAQ
Is certified hosting mandatory ?
Yes. As soon as an application hosts personal health data on behalf of a third party, the host must be certified. Budget 150 to 600 EUR/month uplift.
What is a DPIA and what does it cost ?
The Data Protection Impact Assessment is mandatory for high-risk health processing. It costs between 2,500 and 5,000 EUR and takes 2 to 3 weeks.
How long to become compliant ?
Between 6 and 12 weeks for an existing application, depending on the scale of hosting migration and encryption to catch up.
What is the real financial risk ?
An SME regulator fine ranges from 20,000 to 150,000 EUR; for a serious health-data breach it can reach 4 % of global turnover.
Do I have to log all access ?
Yes. Time-stamped logging of access to health data is a traceability requirement: budget 1,500 to 4,000 EUR at implementation.
Let's scope your project. Share your patient volume, current hosting state and regulatory deadline, and we'll frame the compliance work. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
