GDPR AUDIT · PRICE · RATE

GDPR audit pricing.
Scope before numbers.

A useful audit does not include only documents. It checks salaries, decisions, contracts and practices to produce defensible gaps and a prioritized roadmap.

From 1 200 € tax excl.
Starting price €1,200 excluding tax
Indicative duration 2 to 4 weeks
Review meeting Variations + priorities
Format Interviews & evidence
Estimate After scoping
BUDGET

Why the price
It varies as much.

The cost depends on the number of entities and processing, the availability of evidence, the number of interlocutors, sensitive data, transfers and the expected level of detail.

PERIMETER

Organization

Entities, professions, tools, sites and countries examined.

PROFOUNDER

Sampling

Number of processes, contracts and proofs to verify.

RISK

Critical treatment

Health, HR, profiling, monitoring or large volumes.

PROCEDURE

Four steps.
A workable decision.

The scope and criteria are validated before start-up to avoid a generic report or an uncontrolled budget.

01

Frame

Objectives, activities, contacts, benchmarks, samples and calendar.

02

Examine

Interviews, register, contracts, policies, tracers, technical evidence and procedures.

03

Qualify

Gaps, risks, dependencies, quick action and management decisions.

04

Return

Report, roadmap, managers, priorities and exchange of feedback.

DELIVERY

What you
must receive.

The quote specifies the deliverables. A standard mission includes at least a trace of the perimeter, findings, criticality and recommendations.

Deliverable Targeted audit SME audit Complex audit
Framework note Included Included Included
Gap mapping Targeted scope Multi-process Multi-entity
Prioritization Essential Detailed Control program
Review meeting 1 meeting Project committee Management + professions
Support after audit Optional Optional Customised
FAQ PRICES

Before
compare estimates.

How much does a GDPR audit cost?

RCM displays a starting price of €1,200 excluding tax. This level corresponds to a limited and prepared perimeter. A multi-entity audit, involving numerous processing operations, sensitive data or international flows, requires a specific quote.

Can we only audit a site or a process? +

Yes. A targeted audit can relate to a site, an HR process, an application, a supplier or a transfer. The report must then clearly indicate what was not examined.

Does the audit ensure compliance? +

No. It describes a situation over a given area and on a given date. Compliance then depends on the implementation, maintenance of measures and developments in the activity.

How much time should you allow? +

A standard mission usually takes two to four weeks, subject to the availability of teams and evidence. The calendar is confirmed at scoping.

Get a price based on your scope.

Forward the entities, activities, main tools, number of interlocutors and your deadline. We will offer you a scoping and suitable deliverables.

Scoping my audit →
Request a quote