What a GDPR audit actually costs.
“GDPR audit” covers three distinct exercises with ranges that differ by an order of magnitude. The SERP routinely conflates them. We split internal audit, external advisory audit, and certification audit (ISO 27701 / Europrivacy) cleanly.
Three audit shapes
Cross-functional team time plus tooling. SME first cycle. Output: gap report and remediation plan. Defensible if conducted by someone independent of the controls being audited.
Third-party assurance, not certification. Day-rate or fixed-scope. Driven by processor count, jurisdiction count, prior maturity. Output: written report with findings and recommendations.
ISO 27701 or Europrivacy. Accredited certification body. Initial certification plus surveillance audits at 70-80% of initial cost recurring annually. Output: a certificate with defined scope.
What drives the number
- Data volume: number of data subjects, processing activities, and special-category records.
- Processor count: sub-processor inventory length is one of the strongest cost drivers; 50+ processors typically pushes audit days into the mid-market range.
- Jurisdiction count: UK plus three EU countries adds two-three audit days per jurisdiction beyond the second.
- Prior maturity: an organisation with a maintained ROPA, signed-off DPIAs, and a current policy bundle is audited in roughly half the days of one without.
- Scope agreement: audit scope creep is the single biggest in-engagement cost inflator. A specific signed scope before kickoff matters.
What teams underestimate
Mid-audit remediation discoveries (auditor finds a control gap that must be fixed before report sign-off) are the single most common overrun pattern. Evidence collection time during the audit window (the team is asked to produce records in three days that take three weeks to assemble) is the second. Surveillance audit budget under- allocation in years 2-3 is the third; the surveillance fee is rarely included in initial procurement, and 70-80% of year 1 cost recurring is a non-trivial line.
Sanity check scenarios
40-person UK SaaS, partial maturity, 12 sub-processors, UK only. 8-12 audit days at £1,200-£1,500 / day, scope-locked, single jurisdiction, written report with prioritised findings.
200-person UK retailer, prior ISO 27001, 35 sub-processors, UK plus two EU countries. Initial certification including stage 1 and stage 2. Surveillance audits in years 2-3 at 70-80% of initial cost. Recertification at three years.
ISO 27001 overlap
Organisations with existing ISO 27001 certification typically reduce GDPR external audit days by 25-35% on the technical-and-organisational layer because the auditor can rely on the ISMS evidence. The privacy-specific layer (lawful basis, DSAR, transfer mechanisms, DPIA framework) is unaffected and remains the bulk of the audit effort. Detail on the control overlap sits at /iso-27001-overlap.
Audit cost questions
How much does a GDPR audit cost?
It depends which of three exercises is meant. An internal audit runs £2,000 to £15,000 in loaded team time and tooling. An external advisory audit (third-party assurance, not certification) runs £5,000 to £70,000 depending on processor count, jurisdiction count, and prior maturity. A certification audit (ISO 27701 or Europrivacy) runs £12,000 to £80,000+ initial, with surveillance audits at 70 to 80 percent of initial cost recurring annually.
How much does GDPR certification cost?
There is no single official 'GDPR certificate' a business can buy. The recognised certification routes are ISO 27701 (a privacy extension of ISO 27001) and Europrivacy (an EU data protection certification scheme). A certification audit through an accredited body typically costs £12,000 to £80,000+ for initial certification, plus surveillance audits at 70 to 80 percent of that cost each year and recertification at three years.
What drives the cost of a GDPR audit?
The strongest drivers are data volume (number of data subjects, processing activities, and special-category records), sub-processor inventory length (50+ processors pushes audit days into the mid-market range), jurisdiction count (UK plus each additional EU country adds two to three audit days beyond the second), and prior maturity (a maintained ROPA, signed-off DPIAs, and a current policy bundle is audited in roughly half the days). Scope creep during the engagement is the single biggest in-engagement cost inflator.
Does existing ISO 27001 certification reduce GDPR audit cost?
Yes. Organisations with existing ISO 27001 certification typically reduce GDPR external audit days by 25 to 35 percent on the technical-and-organisational layer, because the auditor can rely on the ISMS evidence. The privacy-specific layer (lawful basis, DSAR, transfer mechanisms, DPIA framework) is unaffected and remains the bulk of the audit effort.