What GDPR tooling actually costs across the stack.
“GDPR software” is not a single category. The stack is consent management, DPIA, records of processing, data subject access handling, and breach response. Each has its own vendor ecosystem, its own pricing logic, and its own twenty-times range from free to enterprise. Treating them as one purchase is the first procurement mistake.
Consent management platforms (CMP)
| Tier | Price band | Vendor examples | Best fit |
|---|---|---|---|
| Free / open source | £0 | Klaro, CookieConsent OSS, vendor free tiers | Single low-traffic UK site, internal capability to maintain |
| Entry SaaS | £5 - £30 / site / mo | Iubenda (from $5.99), CookieYes (from $10), OSANO entry | SME, single-language, low DSAR volume |
| Mid-market | £200 - £800 / mo | Cookiebot (post-2025 repricing), Usercentrics, Didomi | Multi-language, multi-domain, IAB TCF support |
| Enterprise | £10k - £100k+ ACV | OneTrust (2026 ACV floor £10k+), Securiti, BigID privacy | Multi-jurisdiction, IAB TCF + GPP, integration with consent ledger |
Vendor pricing collected from public pricing pages, April 2026. Cookiebot doubled base pricing in mid-2025; OneTrust set a 2026 ACV floor of approximately £10,000 that pushed mid-market customers off platform. Vendor pricing changes regularly; verify before procurement.
DPIA tools
DPIA tooling falls into three groups: spreadsheet templates (free, adequate for low-volume processing inventories), standalone DPIA modules (Konfirmity, Microsoft Priva, OSANO, ranging £200 - £1,500 per month), and platform-bundled (OneTrust, BigID, Securiti, where the DPIA module is part of an enterprise ACV). For most mid-market organisations, a standalone module beats both a spreadsheet (audit trail) and a full platform (cost) in years 1-3.
ROPA tools
Records of processing under Article 30 are within reach of a maintained spreadsheet for under-50-staff organisations with stable processing inventories. Once processor count exceeds 30, or once jurisdiction count exceeds three, a structured ROPA tool starts to earn its keep. Public pricing for standalone ROPA / privacy-mapping tools clusters £150 - £1,200 per month, scaling with processor count and user seats.
SAR / DSAR handling
The hidden cost of data subject access requests is volume scaling with marketing reach. A B2C product that grows from 50,000 to 500,000 users typically experiences a 5-15x increase in SAR volume over the same period, and the manual cost per SAR (commonly £200 - £900 fully loaded) is the dominant cost line. SAR automation tooling (OneTrust DSAR, Securiti DSR, Transcend, OSANO Data Subject Rights) starts paying back at roughly 30 SARs per month. Below that volume, a structured spreadsheet plus a documented playbook is more economical.
Breach response tooling
Pre-paid breach tooling (notification platforms, evidence preservation tools) rarely earns back its cost in years 1-3 for organisations that have not had a notifiable breach. Forensic retainer arrangements with an IR firm (Mandiant, NCC Group, Kroll, Bridewell) are the alternative, typically structured as a small annual retainer (£3,000 - £15,000) plus on-incident day rates (£1,200 - £2,500 / day). The retainer’s main value is guaranteed response SLA inside the 72-hour notification window.
What teams underestimate
Three patterns dominate: CMP renewal escalation (Cookiebot doubling and OneTrust’s 2026 ACV floor caught most mid-market customers unprepared), data-mapping discovery scope creep (the processor inventory grows once the platform is configured to look for unknowns), and SAR volume scaling with marketing reach (the fastest-growing operational cost line in B2C). Year 2 budgets that assume year 1 tooling spend rolls forward miss all three.
Sanity check scenarios
Iubenda or CookieYes ($60-£250 / yr), DPIA spreadsheet, structured ROPA spreadsheet, manual SAR playbook, IR retainer (£3k / yr).
Cookiebot or Usercentrics (£500-£800 / mo), Konfirmity DPIA (£300-£700 / mo), structured ROPA tool, manual SAR with template, IR retainer (£8k / yr).
OneTrust enterprise or Securiti (£25k+ ACV), DPIA module bundled, ROPA bundled, DSAR automation (the volume justifies it), IR retainer (£15k+ / yr).