The verdict in three sentences
A business application that stores sensitive client data must go through a GDPR audit and a penetration test before go-live, not after the first incident. The budget sits between EUR 8,000 and 18,000 excl. VAT for both, plus a DPIA if the app processes health data. That is small next to a regulatory fine of up to 4% of worldwide turnover or a data breach that typically costs an SME several hundred thousand euros.
What the audit covers and what it costs in 2026
The audit breaks down into building blocks you can order separately depending on how sensitive the data is.
| Service | Scope | 2026 budget excl. VAT | Lead time |
|---|---|---|---|
| GDPR audit and record | Processing map, legal bases, retention periods, record of processing | EUR 3,000 to 6,000 | 1 to 2 weeks |
| DPIA (impact assessment) | Mandatory for health data or large-scale processing | EUR 2,500 to 5,000 | 1 to 2 weeks |
| Code and configuration review | Authentication, encryption, secrets management, dependencies | EUR 2,500 to 6,000 | 1 week |
| Application penetration test | Grey-box tests based on OWASP Top 10, report and evidence | EUR 5,000 to 12,000 | 1 to 2 weeks |
| Remediation plan | Prioritised fixes, effort estimate | Included or EUR 1,000 to 2,000 | 2 to 3 days |
| Retest after fixes | Verification of critical and major findings | EUR 1,000 to 2,500 | 2 to 3 days |
For a client case-management app, the usual scope (GDPR audit, code review, pentest, retest) costs EUR 11,500 to 26,500 excl. VAT, completed in 3 to 5 weeks.
The quantified risks of launching without an audit
| Risk | 2026 reference | Possible impact for an SME |
|---|---|---|
| Regulatory fine (serious breach) | Up to EUR 20M or 4% of worldwide turnover | Recent SME amounts: EUR 10,000 to 150,000 |
| Lower-tier fine | Up to EUR 10M or 2% of turnover | Common for inadequate security |
| Breach notification | 72 h to notify the Data Protection Commission | Crisis management cost: EUR 15,000 to 60,000 |
| Customer churn | Data subjects must be informed if risk is high | 5 to 15% cancellations after a public incident |
| Emergency remediation | Fixes after go-live | 2 to 3 times more expensive than before launch |
| Excluded from tenders | Security clauses required by large accounts | Lost contracts |
The most frequent flaws we see before go-live: weak access control between clients (one user can see another's file), no robust password policy, logs containing personal data, unencrypted backups.
The typical 5-week schedule
| Week | Activity | Deliverable |
|---|---|---|
| 1 | Interviews, data mapping, access to the staging environment | Record of processing v1 |
| 2 | DPIA if needed, code review | GDPR compliance report |
| 3 | Penetration test | Technical report with severity levels |
| 4 | Fixes by the development team | Tracked remediation plan |
| 5 | Retest, final documentation | Retest certificate, go or no-go |
Mini case study
Aoife runs a 35-person SME in Dublin that is launching a case-management app for social support services, including health data. She orders a GDPR audit (EUR 4,500), DPIA (EUR 3,500), penetration test (EUR 8,000) and retest (EUR 1,500): EUR 17,500 excl. VAT.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
The pentest reveals a critical flaw: by changing the ID in the URL, a user could open another beneficiary's file. Fixed in 3 days before launch, it could have exposed 12,000 files. Crisis management at EUR 40,000 and even a moderate EUR 50,000 fine would have cost more than five times the audit.
FAQ
How much does a GDPR audit of a business app cost in 2026?
Budget EUR 3,000 to 6,000 excl. VAT for the audit and record, plus EUR 2,500 to 5,000 if a DPIA is needed. The full scope with a pentest sits between EUR 11,500 and 26,500.
Is a DPIA mandatory?
It is when processing is likely to result in high risk: health data, large-scale data, profiling, vulnerable people. Supervisory authorities, including Ireland's DPC, publish lists of processing types where it is always required.
Is a penetration test legally required?
Not explicitly, but GDPR Article 32 requires regular testing of security measures. In an inspection, a pentest report less than 12 months old is the best evidence of diligence.
How much time should we allow before go-live?
Allow 3 to 5 weeks including fixes. Schedule the audit as soon as staging is stable, about 6 weeks before launch.
Do we need a new audit for every release?
No, an annual pentest is enough for most SMEs, with a targeted retest at EUR 1,000 to 2,500 for a major change such as a new payment module.
Let's scope your project. Describe your application, the data it processes and your launch date: we will price a GDPR and security audit between EUR 8,000 and 26,500, completed in 3 to 5 weeks. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
