Independent reference.Not legal advice. Consult a qualified data protection lawyer for advice on your specific situation.Methodology and sources.
Tooling cost

What GDPR tooling actually costs across the stack.

“GDPR software” is not a single category. The stack is consent management, DPIA, records of processing, data subject access handling, and breach response. Each has its own vendor ecosystem, its own pricing logic, and its own twenty-times range from free to enterprise. Treating them as one purchase is the first procurement mistake.

Cookie consent

Consent management platforms (CMP)

TierPrice bandVendor examplesBest fit
Free / open source£0Klaro, CookieConsent OSS, vendor free tiersSingle low-traffic UK site, internal capability to maintain
Entry SaaS£5 - £30 / site / moIubenda (from $5.99), CookieYes (from $10), OSANO entrySME, single-language, low DSAR volume
Mid-market£200 - £800 / moCookiebot (post-2025 repricing), Usercentrics, DidomiMulti-language, multi-domain, IAB TCF support
Enterprise£10k - £100k+ ACVOneTrust (2026 ACV floor £10k+), Securiti, BigID privacyMulti-jurisdiction, IAB TCF + GPP, integration with consent ledger

Vendor pricing collected from public pricing pages, April 2026. Cookiebot doubled base pricing in mid-2025; OneTrust set a 2026 ACV floor of approximately £10,000 that pushed mid-market customers off platform. Vendor pricing changes regularly; verify before procurement.

Risk assessment

DPIA tools

DPIA tooling falls into three groups: spreadsheet templates (free, adequate for low-volume processing inventories), standalone DPIA modules (Konfirmity, Microsoft Priva, OSANO, ranging £200 - £1,500 per month), and platform-bundled (OneTrust, BigID, Securiti, where the DPIA module is part of an enterprise ACV). For most mid-market organisations, a standalone module beats both a spreadsheet (audit trail) and a full platform (cost) in years 1-3.

Records of processing

ROPA tools

Records of processing under Article 30 are within reach of a maintained spreadsheet for under-50-staff organisations with stable processing inventories. Once processor count exceeds 30, or once jurisdiction count exceeds three, a structured ROPA tool starts to earn its keep. Public pricing for standalone ROPA / privacy-mapping tools clusters £150 - £1,200 per month, scaling with processor count and user seats.

Data subject rights

SAR / DSAR handling

The hidden cost of data subject access requests is volume scaling with marketing reach. A B2C product that grows from 50,000 to 500,000 users typically experiences a 5-15x increase in SAR volume over the same period, and the manual cost per SAR (commonly £200 - £900 fully loaded) is the dominant cost line. SAR automation tooling (OneTrust DSAR, Securiti DSR, Transcend, OSANO Data Subject Rights) starts paying back at roughly 30 SARs per month. Below that volume, a structured spreadsheet plus a documented playbook is more economical.

Incident handling

Breach response tooling

Pre-paid breach tooling (notification platforms, evidence preservation tools) rarely earns back its cost in years 1-3 for organisations that have not had a notifiable breach. Forensic retainer arrangements with an IR firm (Mandiant, NCC Group, Kroll, Bridewell) are the alternative, typically structured as a small annual retainer (£3,000 - £15,000) plus on-incident day rates (£1,200 - £2,500 / day). The retainer’s main value is guaranteed response SLA inside the 72-hour notification window.

Where the budget fails

What teams underestimate

Three patterns dominate: CMP renewal escalation (Cookiebot doubling and OneTrust’s 2026 ACV floor caught most mid-market customers unprepared), data-mapping discovery scope creep (the processor inventory grows once the platform is configured to look for unknowns), and SAR volume scaling with marketing reach (the fastest-growing operational cost line in B2C). Year 2 budgets that assume year 1 tooling spend rolls forward miss all three.

What stack actually fits

Sanity check scenarios

25-person SaaS

Iubenda or CookieYes ($60-£250 / yr), DPIA spreadsheet, structured ROPA spreadsheet, manual SAR playbook, IR retainer (£3k / yr).

200-person retailer

Cookiebot or Usercentrics (£500-£800 / mo), Konfirmity DPIA (£300-£700 / mo), structured ROPA tool, manual SAR with template, IR retainer (£8k / yr).

1,000-person fintech

OneTrust enterprise or Securiti (£25k+ ACV), DPIA module bundled, ROPA bundled, DSAR automation (the volume justifies it), IR retainer (£15k+ / yr).

Vendor names appear in this reference because the SERP rewards specificity and buyers are evaluating these products by name. Mention is descriptive; this site is not a comparison grid and does not rank vendors. Verify pricing on the vendor’s own page before procurement.