The verdict in three sentences
In 2026, designing a web application that is GDPR compliant by design adds 8 to 15% to the development budget, data protection impact assessment (DPIA) included. Fixing the same application after launch costs in practice two to three times more, before counting the risk of a regulator fine (Autoriteit Persoonsgegevens in the Netherlands, CNIL in France) and lost user trust. The most cost-effective method is to put a 20-requirement checklist in the specification, so every item is priced in the initial quote.
The real extra cost, line by line
For an appointment-booking app handling names, phone numbers, visit reasons and history, the extra cost splits between documentation deliverables and technical work. Basis: an EUR 80,000 application, ex. VAT.
| Item | Content | 2026 cost (ex. VAT) | Share of budget |
|---|---|---|---|
| Data mapping and records of processing | Purposes, legal bases, recipients | EUR 1,500 to 3,000 | 2 to 4% |
| DPIA | Mandatory for sensitive or large-scale data | EUR 3,000 to 8,000 | 4 to 10% |
| Encryption and access control | Encryption at rest, roles, logging | EUR 2,500 to 5,000 | 3 to 6% |
| Automated retention periods | Scheduled purge and anonymisation | EUR 1,500 to 3,500 | 2 to 4% |
| Data subject rights | Self-service export, correction, deletion | EUR 2,000 to 4,500 | 2.5 to 5.5% |
| Consent management | Cookie banner, proof of consent | EUR 800 to 2,000 | 1 to 2.5% |
| Total built in from design | Shared with development | EUR 6,500 to 12,000 | 8 to 15% |
The total is lower than the sum of the rows because several items share the same technical foundation (logging, roles, data model).
By design or retrofitted: the comparison
| Criterion | Privacy by design | Compliance after launch |
|---|---|---|
| Extra cost on an EUR 80,000 app | EUR 6,500 to 12,000 | EUR 18,000 to 35,000 |
| Added time | 2 to 3 weeks built into the plan | 6 to 12 weeks of rework |
| Data model | Designed for purge and minimisation | Migration of existing data |
| Legal risk in the meantime | Low | Exposed until fixed |
| French CNIL simplified procedure cap | Not applicable if compliant | Fines up to EUR 20,000 |
| GDPR ordinary ceiling | Not applicable if compliant | 4% of global turnover or EUR 20 million |
European regulators issue dozens of fines every year, a growing share aimed at SMBs and mid-sized companies, with amounts ranging from a few thousand to a few tens of thousands of euros as an order of magnitude. The most frequent breaches remain weak security, excessive retention and failure to honour data subject rights.
The 20-point checklist for your specification
- Records of processing kept up to date, one entry per purpose.
- Legal basis identified for each data item collected.
- Minimisation: no form field without a documented use.
- DPIA completed before development if health data or profiling.
- TLS 1.2 minimum in transit, encryption at rest for sensitive data.
- Hashed passwords (Argon2 or bcrypt), two-factor authentication for admins.
- Least-privilege role management.
- Logging of access to personal data, kept 6 to 12 months.
- Configured retention periods and automatic purge.
- Anonymisation of data used for statistics.
- User data export in a readable format (JSON or CSV).
- Self-service account deletion.
- Cookie banner where refusing is as easy as accepting.
- Timestamped proof of consent.
- Hosting in the European Union, or documented transfer safeguards.
- Processor agreements (Article 28) with every vendor.
- Test environments without real data.
- Breach notification procedure within 72 hours.
- Clear privacy policy, updated with every new purpose.
- Penetration test before go-live.
Mini case study
Sanne, DPO of an occupational health services company in Amsterdam (900 staff), is launching a booking app for 120,000 employees of client companies. Development budget: EUR 95,000 ex. VAT.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
- Privacy by design: DPIA EUR 6,500, dedicated development EUR 7,800, so EUR 14,300 (15% of budget).
- Alternative scenario: launch without a DPIA, then retrofit after an audit. Estimated rework EUR 32,000, plus 8 weeks with no new features.
- Saving: EUR 17,700 and two months of roadmap preserved, before even factoring in fine risk.
FAQ
How much does a DPIA cost for a web app?
Between EUR 3,000 and 8,000 ex. VAT in 2026, depending on the number of processing operations and data sensitivity. It is mandatory for health data processed at scale.
Is privacy by design mandatory?
Yes, GDPR Article 25 requires data protection by design and by default. The 8 to 15% extra cost is therefore a legal requirement to budget, not an option.
Can a GDPR app be hosted outside the EU?
It is possible with safeguards (adequacy decision, standard contractual clauses), but EU hosting simplifies the DPIA. European hosting costs EUR 50 to 300 a month for an SMB application.
What is the fine risk for a mid-sized company?
The French CNIL simplified procedure caps fines at EUR 20,000, while the ordinary procedure anywhere in the EU can reach 4% of global turnover. Add compliance costs and reputational damage.
How much time does GDPR add to the schedule?
As a 2026 order of magnitude, 2 to 3 weeks if requirements are in the specification, versus 6 to 12 weeks of rework after launch.
Let's scope your project. Share your specification or app idea: we build in the GDPR checklist, price the DPIA and the real extra cost within a firm schedule. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
