Cost guide · evidence checked 29 July 2026

What does a GDPR audit actually cost?

Published offers run from a €49 automated tracker scan to consulting charged by the day. The label is the same; the work is not. Compare the observed scope, evidence, legal involvement, remediation, and retest before comparing price.

Engineering delivery session
On this page
  1. Short answer
  2. Published price snapshot
  3. First choose the product
  4. Quote drivers
  5. A quote-ready example
  6. Do not use the maximum fine as the budget
  7. Common questions
  8. Some Tech Work scope
Comparison of GDPR website scan, technical evidence audit, legal review, and multi-system programme scope
Short answer
  • There is no defensible single market average for “a GDPR audit” because the name covers automated scans, manual website tests, legal and organisational reviews, and multi-system programmes.
  • In a German-language price snapshot checked on 29 July 2026, published offers ranged from €49 including VAT for an automated tracker audit to €1,000–€1,800 consultant day rates. The product definitions differ, so their prices cannot form one low-to-high range.
  • Ask each supplier to price the same routes, consent states, forms, vendors, systems, access, evidence format, legal work, remediation, and retest.
  • Treat a price without exclusions and deliverables as a lead price. It cannot support a project budget.
Published price snapshot

What German-language providers publish—and what the number appears to buy.

Convenience sample checked 29 July 2026. Prices, tax treatment, availability, and scope can change. Inclusion carries no endorsement. The sample cannot establish a market average.
Provider and offerPublished priceVisible scopeComparison limit
FlowResults tracker audit ↗€49 incl. VATAutomated headless scan for known trackers, cookies, consent tool, HTTPS, and mixed content; HTML/PDF reportExternal automated scan; manual workflow, server-side, contract, and organisational review excluded
Globeria website audit ↗From €299 + VATWebsite, cookie banner, privacy notice, tracking, report, and recommendations“From” price; page does not define route count, test states, access, remediation, or retest
Wender Media compliance check ↗From €780Data-flow, cookies and tracking, third parties, consent, and document reviewBroader mixed technical/legal scope; final price and liability depend on the engagement
IITR privASSIST ↗€225–€2,000Web-based privacy-audit questionnaires, depending on the selected catalogueSelf-assessment product; IITR separately says on-site audits can charge this amount as a day rate over several days
Legiscope external audit guide ↗€1,000–€1,800 per consultant dayArticle benchmark for specialist privacy consultants and lawyersA vendor-published rate range with no representative market study or total project price
A €49 scan and a five-day evidence audit do not occupy the same price range. They answer different questions.
First choose the product

Four things sold under the name “GDPR audit.”

Automated external website scan
01

Automated external scan

Useful for discovering visible requests, cookies, storage, known trackers, HTTPS, and basic consent behavior. It cannot reliably see authenticated flows, server-side forwarding, internal deletion, contracts, or every conditional tag rule.

Manual technical GDPR evidence audit
02

Manual website evidence audit

Tests agreed routes and consent states, captures requests and storage, submits synthetic forms, traces selected workflows, documents reproduction steps, names technical owners, and defines retest criteria.

Legal and organisational privacy review
03

Legal and organisational review

Assesses notices, lawful bases, processor terms, transfer mechanisms, records, retention rules, rights procedures, DPIA need, and legal priority. That work belongs with a qualified DPO or counsel and needs its own scope.

Multi-system privacy programme
04

Multi-system privacy programme

Extends across products, entities, markets, internal systems, vendors, governance, implementation, training, monitoring, and repeated assurance. A programme budget cannot be inferred from a website-check price.

Quote drivers

The scope fields that determine the price.

Comparable proposals require the same input scope, artifacts, exclusions, and acceptance criteria.
Scope fieldLower effortHigher effortPut this in the RFQ
Routes and statesSelected public templates; one marketMany templates, languages, authenticated areas, and consent statesRoute list, markets, languages, and before/reject/accept/withdraw states
Forms and systemsOne contact form and endpointAccounts, checkout, CRM, marketing, support, and deletion workflowsForms, destinations, synthetic records, and workflow boundary
Tags and vendorsSmall documented stackConditional tag manager, server-side tags, embeds, and unknown endpointsTag manager, CMP, analytics, advertising, embeds, and vendor inventory
Access and evidencePublic browser test with supplied configuration exportStaging, test accounts, logs, code, and multiple ownersAccess type, evidence format, redaction, security, and verification limits
Legal involvementClient DPO/counsel reviews technical evidenceSupplier is asked to review notices, contracts, transfers, records, or DPIA needName legal decisions and who is qualified and accountable for them
After the reportFindings onlyImplementation, vendor changes, second evidence pass, and monitoringSeparate audit, remediation, retest, and recurring-monitoring prices
A quote-ready example

Describe the testable surface—not “please audit our GDPR.”

Example scope: one German and one English marketing site; twelve representative templates; first visit, reject all, accept analytics, accept marketing, and withdraw states; one tag manager; one consent platform; analytics, advertising, video, scheduling, and CRM vendors; three forms using synthetic records; public-browser testing plus read-only configuration exports.

Required artifacts: route/tag/vendor inventory, captured requests and storage by state, form-to-endpoint trace, finding cards with reproduction steps and technical owners, verification limits, and a post-fix retest. Separate options: engineering remediation, DPO/counsel review, additional authenticated products, and recurring monitoring.

That request can be priced and compared. “Full GDPR compliance audit” cannot, because each bidder will silently assume a different boundary.

Compliance next step

Get a compliance check on: GDPR audit cost Germany

Send us where your site stands today. We reply with the risks that carry real exposure, not a generic checklist.

Name the regulation, the page, or the deadline you are working against.

By submitting you agree to our privacy policy.

Do not use the maximum fine as the budget

Article 83 sets a legal ceiling. It cannot forecast your case.

The GDPR on EUR-Lex sets maximum administrative-fine tiers and lists factors authorities consider. It does not say that one complaint produces the maximum, or that multiplying turnover by four percent estimates likely exposure.

Budget the audit around the systems and evidence needed for a real decision. Ask your DPO or counsel to assess legal exposure, enforcement context, lawful basis, notices, contracts, transfers, retention, and DPIA requirements.

For consent, use the EDPB Guidelines 05/2020 to frame legal questions. A technical audit can record what happens before and after a choice or withdrawal; it does not decide legal validity by itself.

Common questions

Questions to settle before comparing GDPR audit prices.

How much does a GDPR website audit cost in Germany?

Published offers checked on 29 July 2026 include €49 including VAT for an automated tracker scan, website checks from €299 plus VAT and €780, a €225–€2,000 web-based self-audit product, and a vendor article citing €1,000–€1,800 consultant day rates. They are not comparable scopes. Use the table and RFQ fields above rather than treating the endpoints as a market range.

Why do two GDPR audit quotes differ so much?

One may be an external scan; another may include manual state testing, configuration access, synthetic workflows, legal review, remediation, and retesting. Compare routes, states, systems, evidence, exclusions, professional responsibility, and after-report work line by line.

Is legal advice included in a technical GDPR audit?

Not unless the proposal explicitly names qualified legal or DPO work. Technical evidence can show what was observed. Lawful basis, notices, contracts, transfers, retention rules, DPIA need, and legal priority require separate accountable review.

Should remediation be included in the audit price?

Keep audit, remediation, retest, and monitoring visible as separate lines even if one supplier performs all four. That makes proposals comparable and prevents a report-only price from being mistaken for a fixed implementation budget.

How long does a GDPR audit take?

The label does not determine duration. Ask suppliers to schedule the same route and state list, access, interviews, evidence package, review rounds, and retest. A scanner can run in minutes; manual and organisational work depends on the agreed surface and owner availability.

Some Tech Work scope

Our service is the manual technical evidence category.

We scope observable website and connected-workflow behavior: consent states, requests, storage, tags, forms, vendors, and a synthetic rights-request trace where safely agreed. The output is reproducible evidence, technical ownership, fixes, verification limits, and a retest—not a legal certification or scanner score.

Send the scope fields in this guide and we will return a proposal with assumptions, exclusions, access, artifacts, and whether remediation and a second evidence pass are included. See the technical GDPR audit service.

Start here

Ready to talk.Book a short diagnostic.

Tell us what needs fixing

A process, a tool, a decision that's stuck. One sentence is fine.

By submitting you agree to our privacy policy.

We read every brief and reply within one business day.

Prefer to talk first?or request a tech stack audit or email us directly

Not sure where to start? Send the stuck decision, workflow, or page. We will say whether you need a diagnostic call, a tech stack audit, or a different first step.