The written short answer is being updated after a re-evaluation. The scores below are current.
Read this comparison as one judge. Each weighs the same scores by what they care about.
The Drafted Generalist
Office manager at an 80-employee firm who got compliance added to her job title, not her calendar. Optimizes for guided workflows in plain language and software that knows the law so she does not have to. Rejects consultant-shaped platforms that assume a compliance department.
audatis MANAGER
preeco | datenschutz
This judge's pick
Criterion by criterion
Records & DPIA depth
audatis MANAGER
The RoPA module is the real deal for someone like me — industry packs with 65–77 pre-built activities, save-as-template, group linking, delegation to the people who actually know the process, and export as the official register the authority expects. AVV management even auto-generates the processor's own register. But nothing shows DPIAs triggered from the record or TOMs and legal bases wired into one connected data model, so it's a strong set of modules, not one system of record.
preeco | datenschutz
The record of processing is a guided form through every mandatory field — purpose, data categories, legal bases, recipients, third-country transfers, retention — and the links run on to systems, TOMs and contracts in a graphical relationship view, which is exactly the software-knows-the-law experience I need. DPIA handling sits on the same record with Art. 35 necessity checks and a Schrems II assessment, and multi-client handling with cross-client inheritance is built in rather than copy-paste. Missing contract links are flagged automatically but you wire some of them by hand, which is what keeps this a rung below a fully self-driving register.
Data subject rights & incidents
audatis MANAGER
Betroffenenanfragen get managed centrally with answer templates and the Löschkonzept has genuine structure — deadlines, storage locations, deletion classes — which is more than a log. But there is no breach register anywhere in this sheet: no 72-hour clock, no authority notification, no statutory deadline automation, and for the operational half of the DSMS silence is the finding.
preeco | datenschutz
Requests arrive through embeddable web forms, every Art. 15–22 type is covered, deadlines are monitored automatically with clear status states and documented justifications, identity checks and rejection reasons are recorded, and replies go out as one-time encrypted links — close to end-to-end. Breach handling produces the actual authority notifications from nine ready templates (Art. 33/34 plus BSI reports) with the 72-hour clock tracked. I found no public information on escalation chains or on tracked evidence that a deletion actually executed, which is what held me back from the top of this band.
Privacy regime coverage
audatis MANAGER
DSGVO, BDSG, Swiss DSG and both church laws (EKD/KDG) genuinely match its market — Behörden und kirchliche Einrichtungen are named target customers — and the Infodienst pipes reviewed legal updates plus current law texts into the product. But this is German-market coverage: no UK GDPR, no AI Act privacy duties, and nothing showing one record mapping across regimes rather than being re-documented per law.
preeco | datenschutz
For a German buyer this goes deep: GDPR plus the BayLDA questionnaire at the push of a button, BSIG notification duties in the breach templates, an HinSchG whistleblower module, and EU AI Act conformity checks in the same system as the GDPR record, with roughly monthly updates as visible maintenance. Beyond that home market, I found no public information on Swiss nDSG, UK GDPR or ePrivacy operationalization, and the one-record-many-regimes mapping is really GDPR-plus-AI-Act rather than broad coverage.
Audit readiness & evidence
audatis MANAGER
Edit history per activity for Eingabekontrolle, revision-safe online confirmation of employee attestations, and reports that pull KPIs straight from the DSMS put this above PDF screenshots. What I don't see is an audit-scoped evidence pack on demand, auditor access roles, or any defensible answer to 'show me the state on date X' — so assembling the full file for an authority would still be my weekend.
preeco | datenschutz
Status reports, procedure files and the BayLDA questionnaire are push-button, reports can run on a schedule with email notification, and a full audits module with an included data protection catalog even separates who answers from who manages. I found no public information on a point-in-time view across the whole register or continuous status broken down per legal regime.
Integrations & automation
audatis MANAGER
No API, no directory import, no live connectors anywhere in the evidence — the best I get is CSV/Word export of the register and task workflows I can assign to colleagues. The only 'integration' is bolting my own ticket system onto the whitelabel tier, which tells me the automation lives in reminders and assignments, not in my actual IT estate.
preeco | datenschutz
The honest headline for my IT colleagues: the vendor's own pages describe the application as a closed system without a public REST API, with customer-specific endpoints only on Private Cloud or On-Premises — and single sign-on via SAML2 likewise only on those variants. What it automates, it automates well: deadline clocks, recurring reports, automatic revisioning, name-matching that links contracts to data recipients, and an MCP server that lets an AI assistant query records under the application's own permissions. I found no public information on directory import from AD or Entra, ticketing connectors or webhooks.
European sovereignty
audatis MANAGER
German GmbH in Herford, product datacenter 'Standort Deutschland' as the default, and even an own-server option at the top tier — my RoPA would live in Germany. But there's no published DPA or TOMs for the platform itself, the subprocessor list I can see is website-scoped and includes Elastic APM at a San Francisco address, and the evidence itself flags the vendor entity as unconfirmed, so the chain is plausibly clean but not proven clean.
preeco | datenschutz
A German entity, hosting exclusively in named ISO-27001 data centers at Hetzner in Nuremberg and Falkenstein, a published DPA with downloadable TOMs, deletion certified on contract end, and AI off unless I bring my own key — that is a chain I can explain to our managing director in one breath. I found no public information on the vendor's ownership, and the privacy policy names UpCloud in Finland as a host of the software alongside Hetzner, so the captured pages give different pictures of the hosting chain; a standalone public subprocessor list was also not evident to me.
Pricing transparency
audatis MANAGER
Every single price line — Standard, Group, Whitelabel, every add-on, even extra gigabytes of storage — reads 'Auf Anfrage'. I can see the tier shape (10 users included, 2 or 46 tenants) but not one number, so my two-minute invoice exercise starts with a sales call and a 30-day trial.
preeco | datenschutz
The model is at least published in words — license by employees, modules and hosting variant, not per organization, with no setup fees and no cancellation periods, and every GDPR obligation claimed included without add-on modules. But I found no public prices at all, not even an entry figure, so I cannot budget even a rough annual number for an 80-person company without booking the 30-minute demo and having the sales conversation.
Sovereignty, side by side
Dimension
audatis MANAGER
preeco | datenschutz
Legal entity
Incorporated in DE
Incorporated in DE
Ownership
Not determined
Not determined
Data residency
Not determined
Not determined
Subprocessors
Not determined
Not determined
Facts, side by side
Only facts both products carry under the same definition — anything else would not be a fair row.