Cost guide · evidence checked 29 July 2026
What does a GDPR audit actually cost?
Published offers run from a €49 automated tracker scan to consulting charged by the day. The label is the same; the work is not. Compare the observed scope, evidence, legal involvement, remediation, and retest before comparing price.

Short answer
- There is no defensible single market average for “a GDPR audit” because the name covers automated scans, manual website tests, legal and organisational reviews, and multi-system programmes.
- In a German-language price snapshot checked on 29 July 2026, published offers ranged from €49 including VAT for an automated tracker audit to €1,000–€1,800 consultant day rates. The product definitions differ, so their prices cannot form one low-to-high range.
- Ask each supplier to price the same routes, consent states, forms, vendors, systems, access, evidence format, legal work, remediation, and retest.
- Treat a price without exclusions and deliverables as a lead price. It cannot support a project budget.
Published price snapshot
What German-language providers publish—and what the number appears to buy.
| Provider and offer | Published price | Visible scope | Comparison limit |
|---|---|---|---|
| FlowResults tracker audit ↗ | €49 incl. VAT | Automated headless scan for known trackers, cookies, consent tool, HTTPS, and mixed content; HTML/PDF report | External automated scan; manual workflow, server-side, contract, and organisational review excluded |
| Globeria website audit ↗ | From €299 + VAT | Website, cookie banner, privacy notice, tracking, report, and recommendations | “From” price; page does not define route count, test states, access, remediation, or retest |
| Wender Media compliance check ↗ | From €780 | Data-flow, cookies and tracking, third parties, consent, and document review | Broader mixed technical/legal scope; final price and liability depend on the engagement |
| IITR privASSIST ↗ | €225–€2,000 | Web-based privacy-audit questionnaires, depending on the selected catalogue | Self-assessment product; IITR separately says on-site audits can charge this amount as a day rate over several days |
| Legiscope external audit guide ↗ | €1,000–€1,800 per consultant day | Article benchmark for specialist privacy consultants and lawyers | A vendor-published rate range with no representative market study or total project price |
A €49 scan and a five-day evidence audit do not occupy the same price range. They answer different questions.
First choose the product
Four things sold under the name “GDPR audit.”
01
Automated external scan
Useful for discovering visible requests, cookies, storage, known trackers, HTTPS, and basic consent behavior. It cannot reliably see authenticated flows, server-side forwarding, internal deletion, contracts, or every conditional tag rule.
02
Manual website evidence audit
Tests agreed routes and consent states, captures requests and storage, submits synthetic forms, traces selected workflows, documents reproduction steps, names technical owners, and defines retest criteria.
03
Legal and organisational review
Assesses notices, lawful bases, processor terms, transfer mechanisms, records, retention rules, rights procedures, DPIA need, and legal priority. That work belongs with a qualified DPO or counsel and needs its own scope.
04
Multi-system privacy programme
Extends across products, entities, markets, internal systems, vendors, governance, implementation, training, monitoring, and repeated assurance. A programme budget cannot be inferred from a website-check price.
Quote drivers
The scope fields that determine the price.
| Scope field | Lower effort | Higher effort | Put this in the RFQ |
|---|---|---|---|
| Routes and states | Selected public templates; one market | Many templates, languages, authenticated areas, and consent states | Route list, markets, languages, and before/reject/accept/withdraw states |
| Forms and systems | One contact form and endpoint | Accounts, checkout, CRM, marketing, support, and deletion workflows | Forms, destinations, synthetic records, and workflow boundary |
| Tags and vendors | Small documented stack | Conditional tag manager, server-side tags, embeds, and unknown endpoints | Tag manager, CMP, analytics, advertising, embeds, and vendor inventory |
| Access and evidence | Public browser test with supplied configuration export | Staging, test accounts, logs, code, and multiple owners | Access type, evidence format, redaction, security, and verification limits |
| Legal involvement | Client DPO/counsel reviews technical evidence | Supplier is asked to review notices, contracts, transfers, records, or DPIA need | Name legal decisions and who is qualified and accountable for them |
| After the report | Findings only | Implementation, vendor changes, second evidence pass, and monitoring | Separate audit, remediation, retest, and recurring-monitoring prices |
A quote-ready example
Describe the testable surface—not “please audit our GDPR.”
Example scope: one German and one English marketing site; twelve representative templates; first visit, reject all, accept analytics, accept marketing, and withdraw states; one tag manager; one consent platform; analytics, advertising, video, scheduling, and CRM vendors; three forms using synthetic records; public-browser testing plus read-only configuration exports.
Required artifacts: route/tag/vendor inventory, captured requests and storage by state, form-to-endpoint trace, finding cards with reproduction steps and technical owners, verification limits, and a post-fix retest. Separate options: engineering remediation, DPO/counsel review, additional authenticated products, and recurring monitoring.
That request can be priced and compared. “Full GDPR compliance audit” cannot, because each bidder will silently assume a different boundary.
Compliance next step
Get a compliance check on: GDPR audit cost Germany
Send us where your site stands today. We reply with the risks that carry real exposure, not a generic checklist.
Do not use the maximum fine as the budget
Article 83 sets a legal ceiling. It cannot forecast your case.
The GDPR on EUR-Lex sets maximum administrative-fine tiers and lists factors authorities consider. It does not say that one complaint produces the maximum, or that multiplying turnover by four percent estimates likely exposure.
Budget the audit around the systems and evidence needed for a real decision. Ask your DPO or counsel to assess legal exposure, enforcement context, lawful basis, notices, contracts, transfers, retention, and DPIA requirements.
For consent, use the EDPB Guidelines 05/2020 to frame legal questions. A technical audit can record what happens before and after a choice or withdrawal; it does not decide legal validity by itself.
Common questions
Questions to settle before comparing GDPR audit prices.
How much does a GDPR website audit cost in Germany?
Published offers checked on 29 July 2026 include €49 including VAT for an automated tracker scan, website checks from €299 plus VAT and €780, a €225–€2,000 web-based self-audit product, and a vendor article citing €1,000–€1,800 consultant day rates. They are not comparable scopes. Use the table and RFQ fields above rather than treating the endpoints as a market range.
Why do two GDPR audit quotes differ so much?
One may be an external scan; another may include manual state testing, configuration access, synthetic workflows, legal review, remediation, and retesting. Compare routes, states, systems, evidence, exclusions, professional responsibility, and after-report work line by line.
Is legal advice included in a technical GDPR audit?
Not unless the proposal explicitly names qualified legal or DPO work. Technical evidence can show what was observed. Lawful basis, notices, contracts, transfers, retention rules, DPIA need, and legal priority require separate accountable review.
Should remediation be included in the audit price?
Keep audit, remediation, retest, and monitoring visible as separate lines even if one supplier performs all four. That makes proposals comparable and prevents a report-only price from being mistaken for a fixed implementation budget.
How long does a GDPR audit take?
The label does not determine duration. Ask suppliers to schedule the same route and state list, access, interviews, evidence package, review rounds, and retest. A scanner can run in minutes; manual and organisational work depends on the agreed surface and owner availability.
Some Tech Work scope
Our service is the manual technical evidence category.
We scope observable website and connected-workflow behavior: consent states, requests, storage, tags, forms, vendors, and a synthetic rights-request trace where safely agreed. The output is reproducible evidence, technical ownership, fixes, verification limits, and a retest—not a legal certification or scanner score.
Send the scope fields in this guide and we will return a proposal with assumptions, exclusions, access, artifacts, and whether remediation and a second evidence pass are included. See the technical GDPR audit service.
Written by
Vineet Talwar
Co-founder, Tech & Operations at Some Tech Work. WordCamp speaker across Europe and Asia, and host of the WP Shoutout podcast.
Start here
Ready to talk.Book a short diagnostic.
Tell us what needs fixing
We read every brief and reply within one business day.
Prefer to talk first?or request a tech stack audit →or email us directly →
Not sure where to start? Send the stuck decision, workflow, or page. We will say whether you need a diagnostic call, a tech stack audit, or a different first step.