Digital Africa11 min read

GDPR & Security for a Custom Web App: A Dublin Checklist (2026)

Mohamed Bah·Fondateur, Kolonell
September 12, 2026
Share:
GDPR & Security for a Custom Web App: A Dublin Checklist (2026)

GDPR & Security for a Custom Web App: A Dublin Checklist (2026)

Digital Africa

The verdict in three sentences

A custom web app handling customer data must satisfy the security baseline and the regulatory one at once: GDPR applies as soon as you process EU residents' data, on top of local data-protection law. The security foundation is quotable: initial audit EUR 4,000-9,000, annual pentest EUR 5,000-12,000, compliant EU hosting EUR 100-350/month. The good news: these requirements can be scoped in the spec and documented with a records-of-processing register.

The minimum technical baseline in 2026

Security is not "added" afterwards: it is designed in. Here are the building blocks expected for a B2B custom app and their budget ballpark.

Security block2026 requirementBudget
Encryption in transitTLS 1.3 everywhereincluded
Encryption at restEncrypted DB + backupsEUR 1,000-3,000
RBAC (roles & permissions)Least privilegeEUR 3,000-7,000
Audit loggingAccess traceabilityEUR 2,000-5,000
Initial security auditCode + config reviewEUR 4,000-9,000
Annual pentestPenetration testEUR 5,000-12,000
Compliant EU hostingEU region, backupsEUR 100-350/month

RBAC and audit logging are the two blocks most often missing from cheap quotes — and the first two demanded in a data-protection audit or a customer security review. Encryption at rest also protects your backups, a frequent breach target.

GDPR compliance: the checklist

GDPR compliance is procedural as much as technical. These obligations must be documented and demonstrable.

ObligationRequirementPractical action
Records of processingMandatorySingle living register
Legal basis / consentMandatoryDocumented per purpose
Access / rectificationMandatorySelf-service or process
Breach notificationWithin 72 hTo the supervisory authority
Cross-border transferStandard clausesSCCs + risk assessment
DPO / contact pointCase by caseNamed contact
Data minimisationMandatoryCollect only what's needed

In practice, host EU customers' data in an EU region, keep a single records-of-processing register, and formalise 72-hour breach notification. For transfers outside the region, plan standard contractual clauses and a transfer risk assessment.

Mini case study

Aoife, managing director of a services SME in Dublin, runs an app with 12,000 customer records, 3,000 of them across the EU. Compliance quote: initial audit EUR 6,000, RBAC + audit logging EUR 8,000, migration to compliant EU hosting EUR 250/month, annual pentest EUR 7,000. Upfront investment: EUR 21,000, plus EUR 10,000/year recurring (pentest + hosting). Against a GDPR fine of up to 4% of turnover and the reputational risk of a breach, the risk calculation justifies the investment in year one.

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Prefer a call back?

Leave your WhatsApp number and a Kolonell expert will get back to you within 1 business day. Free, no strings attached.

FAQ

Does GDPR apply to a small custom app?

Yes, as soon as you process data of individuals in the EU (customers, prospects, staff). Size does not exempt you; obligations scale with the volume and sensitivity of the data.

Is an annual pentest really necessary?

For an app handling customer data, yes. A penetration test (EUR 5,000-12,000) reveals flaws before attackers do and reassures enterprise customers during vendor audits.

Where should I host to be compliant?

For EU customers, an EU region of a recognised cloud (EUR 100-350/month) simplifies compliance. Document the location in your register and secure backups with encryption.

How much is initial compliance?

Allow a 2026 ballpark of EUR 15,000 to 25,000 for a medium-sized custom app, depending on data volume and the level of RBAC required.

Who maintains the records of processing?

The data controller (your company). It is a living document listing each processing activity, its purpose, legal basis and retention period; it must be produced on request during an audit.

Let's scope your project. Tell us your data volume, the share of EU customers and your integrations: we frame a costed compliance plan (audit, RBAC, hosting). Detailed quote within 48 h. WhatsApp +221 77 596 93 33.

Tags:#web app security#GDPR custom app#data protection#security audit#pentest#compliant hosting#data encryption#2026
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.