Records & DPIA depth
Akarion GRC Cloud
The Datenschutz module is a real connected model: VVT as a dynamic system where changes to processes and assets update automatically, DSFA with in-system data flow visualization, processor management with contracts and audits, central TOMs with authority reports, plus TIAs — and multi-tenancy with inheritance and template tenants, handles group reuse. It stops short of the top anchor: legal bases are never mentioned, and nothing shows DPIA triggers being derived from the record or audit-ready output without manual assembly.
caralegal
The record of processing sits in a guided workflow with an approval step, and the things that usually live in separate files hang off it: the DPIA decision is derived automatically from risky activities, vendors link to the record with a compliance check, TOMs can be process-specific, and the deletion concept is generated from the record itself. Legal-entity counts per plan point to group use, and the package to the supervisory authority goes out with one click, "von AVV bis VVT". I found no public information on multi-client mandate work, so I stop just short of the top.