Websites11 min read

GDPR Compliance for a Website or App: Checklist and Cost (2026)

Mohamed Bah·Fondateur, Kolonell
September 12, 2026
Share:
GDPR Compliance for a Website or App: Checklist and Cost (2026)

GDPR Compliance for a Website or App: Checklist and Cost (2026)

Websites

The verdict in three sentences

GDPR compliance for a site rests on five pillars: cookies and consent, records of processing, EU hosting, processor agreements (DPAs) and security. An audit costs 3,000 to 9,000 EUR by size; a sanction can reach 4 % of global revenue or 20 M EUR. The maths is simple: compliance is almost always cheaper than the risk.

Operational GDPR checklist

Here are the items checked during an audit and their priority. Tick what is missing.

ItemWhat is requiredPriority
Cookie bannerFree consent, refusing as easy as acceptingCritical
Trackers blockedNo non-essential cookie before consentCritical
Privacy policyUp to date, accessible, completeHigh
Records of processingList of processing and purposesHigh
Legal noticePublisher, host, DPOHigh
FormsPurpose, consent, retentionMedium
Data subject rightsAccess, erasure, portabilityMedium
SecurityEncryption, access, logsHigh

The cookie banner concentrates most recent fines: making refusal harder than acceptance is the number-one grounds for a formal notice.

Hosting, processors and security

Compliance does not stop at the visible site: it covers the whole data-processing chain.

Control point2026 requirementIndicative cost
EU hostingServers in the EU, no unframed non-EU transfer25 - 150 EUR/mo
Processor DPAsContract with each tool (analytics, mailing)Included in contract
Compliant analyticsConsent-free or anonymised tool0 - 100 EUR/mo
EncryptionHTTPS, sensitive data encryptedIncluded
Secure backupsEncrypted, restricted accessIncluded in maintenance
Records & DPOInternal or outsourced200 - 800 EUR/mo if external

Every third-party tool that processes data (mailing, CRM, chat, analytics) must have a signed data processing agreement (DPA).

Audit cost and sanction risk

2026 orders of magnitude for the EU market, in EUR ex. VAT. The risk is not theoretical: regulators issue dozens of sanctions per year.

Service2026 cost (EUR ex. VAT)
GDPR audit, brochure site3,000 - 5,000
Audit, site + application5,000 - 9,000
Cookie compliance fix800 - 2,500
Policy + records drafting1,500 - 4,000
Compliance maintenance/yr1,500 - 6,000
Sanction (cap)up to 20 M or 4 % of revenue

Even a "moderate" sanction of a few tens of thousands of euros, plus negative publicity, far exceeds the cost of full compliance.

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Prefer a call back?

Leave your WhatsApp number and a Kolonell expert will get back to you within 1 business day. Free, no strings attached.

Mini case study

Nadia, DPO of a B2B distribution group in Bordeaux, inherits a site with no tracker blocking and a banner where "accept all" is far more visible than "refuse". She orders a 6,000 EUR audit, a 2,000 EUR cookie fix and a 2,500 EUR privacy policy rewrite, totalling 10,500 EUR. In parallel she quantifies the risk: a formal notice followed by a sanction, even capped at 50,000 EUR, plus reputational impact on her enterprise clients. Compliance represents 21 % of that single low scenario: the decision is immediate.

FAQ

Is a simple cookie banner enough?

No. The banner must block trackers before consent and make refusal as easy as acceptance. A purely decorative banner is exactly what regulators sanction.

Is Google Analytics compliant?

Only with consent and proper configuration, or via a privacy-friendly alternative. Without prior consent, dropping its cookies is unlawful.

Is a DPO mandatory?

Mandatory for public bodies and organisations whose activity involves large-scale monitoring. For others it is strongly recommended; outsourcing costs 200 to 800 EUR/month.

How long does compliance take?

Budget 3 to 8 weeks: audit, technical fixes (cookies, hosting), documentation, then setting up the records. Tracker blocking is often the fastest to fix.

Is non-EU hosting forbidden?

Not forbidden but framed: any non-EU transfer must rely on safeguards (standard clauses, adequacy decision). The simplest route is EU hosting and EU processors.

Let's scope your project. Send us your site URL and your third-party tools (analytics, mailing, CRM) for a GDPR audit and a costed compliance plan. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.

Tags:#GDPR compliance#GDPR checklist#cookie consent#EU hosting#records of processing#GDPR audit#security#compliance quote
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.