The verdict in three sentences
A custom web app handling customer data must satisfy the security baseline and the regulatory one at once: GDPR applies as soon as you process EU residents' data, on top of local data-protection law. The security foundation is quotable: initial audit EUR 4,000-9,000, annual pentest EUR 5,000-12,000, compliant EU hosting EUR 100-350/month. The good news: these requirements can be scoped in the spec and documented with a records-of-processing register.
The minimum technical baseline in 2026
Security is not "added" afterwards: it is designed in. Here are the building blocks expected for a B2B custom app and their budget ballpark.
| Security block | 2026 requirement | Budget |
|---|---|---|
| Encryption in transit | TLS 1.3 everywhere | included |
| Encryption at rest | Encrypted DB + backups | EUR 1,000-3,000 |
| RBAC (roles & permissions) | Least privilege | EUR 3,000-7,000 |
| Audit logging | Access traceability | EUR 2,000-5,000 |
| Initial security audit | Code + config review | EUR 4,000-9,000 |
| Annual pentest | Penetration test | EUR 5,000-12,000 |
| Compliant EU hosting | EU region, backups | EUR 100-350/month |
RBAC and audit logging are the two blocks most often missing from cheap quotes — and the first two demanded in a data-protection audit or a customer security review. Encryption at rest also protects your backups, a frequent breach target.
GDPR compliance: the checklist
GDPR compliance is procedural as much as technical. These obligations must be documented and demonstrable.
| Obligation | Requirement | Practical action |
|---|---|---|
| Records of processing | Mandatory | Single living register |
| Legal basis / consent | Mandatory | Documented per purpose |
| Access / rectification | Mandatory | Self-service or process |
| Breach notification | Within 72 h | To the supervisory authority |
| Cross-border transfer | Standard clauses | SCCs + risk assessment |
| DPO / contact point | Case by case | Named contact |
| Data minimisation | Mandatory | Collect only what's needed |
In practice, host EU customers' data in an EU region, keep a single records-of-processing register, and formalise 72-hour breach notification. For transfers outside the region, plan standard contractual clauses and a transfer risk assessment.
Mini case study
Aoife, managing director of a services SME in Dublin, runs an app with 12,000 customer records, 3,000 of them across the EU. Compliance quote: initial audit EUR 6,000, RBAC + audit logging EUR 8,000, migration to compliant EU hosting EUR 250/month, annual pentest EUR 7,000. Upfront investment: EUR 21,000, plus EUR 10,000/year recurring (pentest + hosting). Against a GDPR fine of up to 4% of turnover and the reputational risk of a breach, the risk calculation justifies the investment in year one.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
FAQ
Does GDPR apply to a small custom app?
Yes, as soon as you process data of individuals in the EU (customers, prospects, staff). Size does not exempt you; obligations scale with the volume and sensitivity of the data.
Is an annual pentest really necessary?
For an app handling customer data, yes. A penetration test (EUR 5,000-12,000) reveals flaws before attackers do and reassures enterprise customers during vendor audits.
Where should I host to be compliant?
For EU customers, an EU region of a recognised cloud (EUR 100-350/month) simplifies compliance. Document the location in your register and secure backups with encryption.
How much is initial compliance?
Allow a 2026 ballpark of EUR 15,000 to 25,000 for a medium-sized custom app, depending on data volume and the level of RBAC required.
Who maintains the records of processing?
The data controller (your company). It is a living document listing each processing activity, its purpose, legal basis and retention period; it must be produced on request during an audit.
Let's scope your project. Tell us your data volume, the share of EU customers and your integrations: we frame a costed compliance plan (audit, RBAC, hosting). Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
