The verdict in three sentences
GDPR compliance for a website protects the business against a real financial risk: the Irish DPC can impose fines up to 4 % of global turnover or EUR 20 million. In Dublin in 2026, an audit costs EUR 1,500 to 5,000 and remediation EUR 2,000 to 8,000 over 3 to 6 weeks. It's a modest investment against the legal and reputational exposure.
What a GDPR audit covers
The audit maps the gap between the site's current state and legal requirements. It examines cookie consent, the legal notices and privacy policy, the record of processing activities, processor contracts (DPAs) and data security. Each gap is ranked by priority and costed.
| Compliance item | Priority | Remediation cost |
|---|---|---|
| Compliant cookie consent banner | Critical | EUR 800-2,500 |
| Up-to-date privacy policy | Critical | EUR 400-1,200 |
| Complete legal notices | High | EUR 300-800 |
| Record of processing activities | High | EUR 500-1,500 |
| DPA with processors | Medium | EUR 400-1,000 |
| Access/erasure rights (process) | Medium | EUR 300-1,000 |
| Form encryption & security | High | EUR 500-2,000 |
The financial risk: order of magnitude
DPC sanctions are not theoretical. The legal cap is high, but even reprimands and small fines involve emergency remediation costs, pricier than a planned approach. Here is a 2026 estimate of the stakes.
| Scenario | Estimated impact | Handling time |
|---|---|---|
| DPC reprimand | Urgent remediation EUR 3,000-8,000 | 1-3 months |
| SME fine (cookie breach) | EUR 5,000-50,000 | -- |
| Cap fine (4 % of turnover) | up to millions EUR | -- |
| Loss of customer trust | hard to quantify | lasting |
| Planned audit + remediation | EUR 3,500-13,000 total | 3-6 weeks |
Mini case study
Nadia, DPO at a digital services SME in Dublin (turnover EUR 4.2 M), finds the site's cookie banner drops trackers before consent — a classic breach. She commissions an audit at EUR 2,800 then remediation at EUR 5,400, i.e. EUR 8,200 over 4 weeks. Against the theoretical risk (up to 4 % of EUR 4.2 M = EUR 168,000) and a realistic cookie fine of EUR 20,000-40,000, the investment is insurance at under 5 % of the potential loss.
FAQ
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
How much does a GDPR website audit cost?
Between EUR 1,500 and 5,000 depending on site size and number of processing activities. A simple brochure site sits at the low end; a site with a client portal, multiple forms and marketing tools moves up.
What's the real fine risk?
The legal cap is 4 % of global turnover or EUR 20 M. In practice, for an SME, cookie breaches draw fines of EUR 5,000 to 50,000, plus emergency remediation and reputational harm.
How long does remediation take?
Usually 3 to 6 weeks: a few days for the cookie banner and notices, longer for the record of processing and data-subject rights processes.
Is cookie consent really mandatory?
Yes. Non-essential trackers may only be set after free, informed and revocable consent. A banner that drops trackers before a click or without an easy refuse option is non-compliant.
Do I need a DPO to be compliant?
Not always: a DPO is mandatory for certain bodies (public sector, large-scale processing). Even without a designated DPO, GDPR obligations apply and an audit is still recommended.
Let's scope your project. Tell us the nature of your site, your data processing and your marketing tools: we run your GDPR audit and remediation in 3 to 6 weeks. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
