Websites11 min read

GDPR and security audit of a business app before launch in Dublin: 2026 pricing

Mohamed Bah·Fondateur, Kolonell
October 7, 2026
Share:
GDPR and security audit of a business app before launch in Dublin: 2026 pricing

GDPR and security audit of a business app before launch in Dublin: 2026 pricing

Websites

The verdict in three sentences

A business application that stores sensitive client data must go through a GDPR audit and a penetration test before go-live, not after the first incident. The budget sits between EUR 8,000 and 18,000 excl. VAT for both, plus a DPIA if the app processes health data. That is small next to a regulatory fine of up to 4% of worldwide turnover or a data breach that typically costs an SME several hundred thousand euros.

What the audit covers and what it costs in 2026

The audit breaks down into building blocks you can order separately depending on how sensitive the data is.

ServiceScope2026 budget excl. VATLead time
GDPR audit and recordProcessing map, legal bases, retention periods, record of processingEUR 3,000 to 6,0001 to 2 weeks
DPIA (impact assessment)Mandatory for health data or large-scale processingEUR 2,500 to 5,0001 to 2 weeks
Code and configuration reviewAuthentication, encryption, secrets management, dependenciesEUR 2,500 to 6,0001 week
Application penetration testGrey-box tests based on OWASP Top 10, report and evidenceEUR 5,000 to 12,0001 to 2 weeks
Remediation planPrioritised fixes, effort estimateIncluded or EUR 1,000 to 2,0002 to 3 days
Retest after fixesVerification of critical and major findingsEUR 1,000 to 2,5002 to 3 days

For a client case-management app, the usual scope (GDPR audit, code review, pentest, retest) costs EUR 11,500 to 26,500 excl. VAT, completed in 3 to 5 weeks.

The quantified risks of launching without an audit

Risk2026 referencePossible impact for an SME
Regulatory fine (serious breach)Up to EUR 20M or 4% of worldwide turnoverRecent SME amounts: EUR 10,000 to 150,000
Lower-tier fineUp to EUR 10M or 2% of turnoverCommon for inadequate security
Breach notification72 h to notify the Data Protection CommissionCrisis management cost: EUR 15,000 to 60,000
Customer churnData subjects must be informed if risk is high5 to 15% cancellations after a public incident
Emergency remediationFixes after go-live2 to 3 times more expensive than before launch
Excluded from tendersSecurity clauses required by large accountsLost contracts

The most frequent flaws we see before go-live: weak access control between clients (one user can see another's file), no robust password policy, logs containing personal data, unencrypted backups.

The typical 5-week schedule

WeekActivityDeliverable
1Interviews, data mapping, access to the staging environmentRecord of processing v1
2DPIA if needed, code reviewGDPR compliance report
3Penetration testTechnical report with severity levels
4Fixes by the development teamTracked remediation plan
5Retest, final documentationRetest certificate, go or no-go

Mini case study

Aoife runs a 35-person SME in Dublin that is launching a case-management app for social support services, including health data. She orders a GDPR audit (EUR 4,500), DPIA (EUR 3,500), penetration test (EUR 8,000) and retest (EUR 1,500): EUR 17,500 excl. VAT.

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Prefer a call back?

Leave your WhatsApp number and a Kolonell expert will get back to you within 1 business day. Free, no strings attached.

The pentest reveals a critical flaw: by changing the ID in the URL, a user could open another beneficiary's file. Fixed in 3 days before launch, it could have exposed 12,000 files. Crisis management at EUR 40,000 and even a moderate EUR 50,000 fine would have cost more than five times the audit.

FAQ

How much does a GDPR audit of a business app cost in 2026?

Budget EUR 3,000 to 6,000 excl. VAT for the audit and record, plus EUR 2,500 to 5,000 if a DPIA is needed. The full scope with a pentest sits between EUR 11,500 and 26,500.

Is a DPIA mandatory?

It is when processing is likely to result in high risk: health data, large-scale data, profiling, vulnerable people. Supervisory authorities, including Ireland's DPC, publish lists of processing types where it is always required.

Is a penetration test legally required?

Not explicitly, but GDPR Article 32 requires regular testing of security measures. In an inspection, a pentest report less than 12 months old is the best evidence of diligence.

How much time should we allow before go-live?

Allow 3 to 5 weeks including fixes. Schedule the audit as soon as staging is stable, about 6 weeks before launch.

Do we need a new audit for every release?

No, an annual pentest is enough for most SMEs, with a targeted retest at EUR 1,000 to 2,500 for a major change such as a new payment module.

Let's scope your project. Describe your application, the data it processes and your launch date: we will price a GDPR and security audit between EUR 8,000 and 26,500, completed in 3 to 5 weeks. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.

Tags:#GDPR audit#application security#go-live#Dublin#penetration test#Data Protection Commission
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.