The verdict in three sentences
Securing a web app that handles personal data combines two workstreams: technical security (pentest, OWASP, encryption) and GDPR compliance (records, DPAs, minimisation). In 2026, a pentest costs 4,000 to 15,000 EUR and is ideally renewed yearly or on each major change. With a regulator fine reaching up to 4 % of worldwide turnover, these amounts are insurance, not expense.
The security budget line by line
Security is managed by line item and frequency. This table gives 2026 orders of magnitude for a business app handling customer data.
| Line item | 2026 cost (EUR) | Frequency |
|---|---|---|
| Application pentest | 4,000 - 15,000 | Yearly + major change |
| Code audit | 3,000 - 9,000 | At delivery |
| Encryption (in transit + at rest) | included in build | Continuous |
| Logging & monitoring | 100 - 500/month | Continuous |
| EU / health-grade hosting | 300 - 2,000/month | Continuous |
| Encrypted backups | 50 - 300/month | Continuous |
| Outsourced DPO | 400 - 1,500/month | Continuous |
The GDPR compliance checklist
Compliance is not only about code: it rests on documents and processes. Here are the items to cover before an audit.
| Requirement | What to produce | Target status |
|---|---|---|
| Records of processing | List of processing, purposes, legal bases | Mandatory |
| Data minimisation | Collect only what is needed | Mandatory |
| Retention period | Automatic purge policy | Mandatory |
| Processor contracts (DPA) | Signed DPA with each provider | Mandatory |
| Consent & information | Banners, notices, opt-in | Mandatory |
| Data subject rights | Access, rectification, erasure | Mandatory |
| Security (OWASP Top 10) | Fixes for critical vulnerabilities | Mandatory |
| Suitable hosting | EU, health-grade for health data | Data-dependent |
Mini case study
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Karim is CTO of a 60-person e-health company that hosts patient data. A regulator audit is possible: he commissions a pentest at 11,000 EUR, migrates to a health-grade certified host (1,400 EUR/month), formalises his records and signs DPAs with his three processors. First-year compliance cost: about 28,000 EUR (audit + migration + DPO support). Compare that with the risk: on 6M EUR turnover, a fine at 4 % would reach 240,000 EUR, not counting reputational damage among his healthcare-institution clients. The ROI of compliance is immediate here.
FAQ
How often is a pentest needed? At least once a year and after each major change (new exposed feature, architecture change). A pentest costs 4,000 to 15,000 EUR depending on scope.
Is health-grade hosting mandatory? Yes, as soon as you process personal health data in the EU. Budget 300 to 2,000 EUR/month depending on volume and service level.
What is the concrete risk of non-compliance? A fine can reach 4 % of annual worldwide turnover or 20M EUR, whichever is higher, on top of reputational damage.
Is GDPR mostly legal or technical? Both: documents and processes (records, DPAs, retention) on one side, technical measures (encryption, OWASP, logging) on the other. One without the other is not enough.
Do we need a DPO? It is mandatory for large-scale processing of sensitive data. An outsourced DPO costs 400 to 1,500 EUR/month, far less than a fine.
Let's scope your project. Tell us the nature of your data and your current application, and we'll cost a security audit and a GDPR compliance roadmap. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.


