The written short answer is being updated after a re-evaluation. The scores below are current.
Read this comparison as one judge. Each weighs the same scores by what they care about.
The IT Integrator
Has to feed the compliance platform from the estate that already exists: Entra ID, Jira, the CMDB. Optimizes for directory import, a real API, webhooks and SSO — compliance data that stays current because it syncs, not because someone retypes it. Rejects data islands with a CSV drawbridge.
audatis MANAGER
preeco | datenschutz
This judge's pick
Criterion by criterion
Records & DPIA depth
audatis MANAGER
RoPA, DSFA with risk management, AVV and TOM modules all exist, and the RoPA layer is unusually deep — industry template packs of 65-77 activities, group templates, delegation to responsible users, and export as an official register — plus real multi-tenancy from 2 to 46 Mandanten. What's missing is evidence of the connected data model: no statement that activities drive DPIA triggers, TOM coverage or legal bases from one record, so it sits between rubric level 5 and 8.
preeco | datenschutz
The data model is genuinely connected: every processing activity carries its systems, TOMs and data processing agreements in a graphical relationship view, the record itself feeds the Art. 35 necessity assessment, and deletion classes derive rules from linked activities — with multi-mandate operation, strict tenant separation and cross-client inheritance documented in depth. It stays below the top for me because missing DPA-to-record connections are established by hand and by name matching rather than flowing from one model.
Data subject rights & incidents
audatis MANAGER
DSR management with central templates and a deletion-concept builder (deadlines, storage locations, deletion classes) are confirmed, which is more than a log. But the evidence is completely silent on a breach register, the 72-hour clock, authority notification output, and statutory deadline automation — missing evidence that a German DSMS should have surfaced loudly — so it can't clear rubric level 5.
preeco | datenschutz
Requests and incidents run as operations: embeddable web forms for intake, documented identity verification with rejection reasons, automatic deadline monitoring with proactive warnings, and nine ready report templates covering Art. 33 initial, follow-up and final notifications plus BSI reports with an unambiguous deadline status each. Deletion classes link to processing activities with deadlines, procedures and responsibilities; I found no public information on tracked evidence that a deletion actually executed.
Privacy regime coverage
audatis MANAGER
DSGVO/BDSG/DSG/EKD/KDG plus current legal texts and the curated Infodienst update feed is genuine coverage of its actual market, and regular updates are claimed. Nothing evidences one-record-many-regimes mapping, and UK GDPR, ePrivacy and AI Act duties are absent, which caps it at the anchor that describes market coverage with partial cross-mapping at best.
preeco | datenschutz
GDPR is the backbone with real German depth — the BayLDA questionnaire at a button push and BSIG reporting templates — and EU AI Act risk checks run in the same system as the GDPR record. Beyond that the picture thins: I found no public information on Swiss or UK regime mapping, so additions read as content packs rather than one record across regimes.
Audit readiness & evidence
audatis MANAGER
An edit history explicitly for Eingabekontrolle, revisionssicher-confirmed employee attestations, a report generator pulling KPIs from the DSMS, and CSV/Word export as an internal or authority-facing register clear rubric level 5's versioned-records-and-reports bar. No evidence of audit-scoped evidence packs, auditor access roles, or a point-in-time reconstruction, so the gap to 8 is unsubstantiated rather than just unclosed.
preeco | datenschutz
Every approval freezes an immutable revision with a SHA-256 checksum and colour-coded comparison — a defensible fixed state for any past date — and status reports, procedure files and the BayLDA questionnaire generate at a button push, backed by a dedicated audit module whose permissions separate answering from managing. Schedulable recurring reports and a permission-aware dashboard with compliance metrics round it out; I found no public information on auditor-scoped evidence packs bundled into a single export.
Integrations & automation
audatis MANAGER
This is the CSV-drawbridge island I reject: the only confirmed machine interface is CSV/Word export of the RoPA, employee management is manual records rather than directory sync, and the sole integration gesture is an 'own ticketsystem einbindbar' option in the whitelabel tier. There is not one mention of a REST API, webhooks, SSO/SCIM, AD/Entra import or any connector to the estate — the internal task workflow and delegation is the only automation on the evidence.
preeco | datenschutz
This is the make-or-break lens for me: the vendor's own pages describe the application as a closed system without a public REST API, with customer-specific endpoints developed only for Private Cloud and On-Premises, and data exchange via DOCX/XLSX import — a file drawbridge, not a sync. The token-authenticated MCP server genuinely lets external assistants query processing activities and export revisions under application access rights, and SAML2 single sign-on exists but is gated to the private hosting variants; I found no public information on directory import, webhooks or ticketing connectors.
European sovereignty
audatis MANAGER
A German GmbH at a German court, product hosting in a German datacenter with an own-server option, and a DPA with IONOS (Montabaur) are solid European facts. But the disclosure is website-shaped, not platform-shaped: no published DPA or TOMs for audatis MANAGER itself, no product subprocessor list, ownership unknown, and Elastic APM with a San Francisco address sits in the disclosed chain.
preeco | datenschutz
A German entity in Ulm hosts exclusively in named Hetzner datacenters in Nürnberg and Falkenstein with no third-country transfers stated, publishes its order-processing contract with downloadable TOMs and two weeks' notice on subprocessor changes, and the named hosting subprocessors (Hetzner, and UpCloud in Finland) all sit inside the EU. On-premises exists but is positioned for public sector and enterprise, and I found no public information on the ownership structure, so the cleanest end of the scale stays out of reach.
Pricing transparency
audatis MANAGER
Every edition and every add-on — Standard, Group, Whitelabel, extra users, storage, ISMS, the employee-tier flatrates — reads 'Auf Anfrage', with only billing-by-invoice and a 30-day trial public. That is rubric level 0 verbatim: not a single number from which any invoice could be computed.
preeco | datenschutz
No price figures appear anywhere on the captured pages — the licence basis is described as employees, modules and hosting variant (explicitly not the number of organisations) and the no-setup-fees, no-cancellation-terms posture is stated, but the actual invoice is only a sales conversation. Optional paid items such as the ISMS audit catalogs, DeepL translation, premium support and migration are named without figures.
Sovereignty, side by side
Dimension
audatis MANAGER
preeco | datenschutz
Legal entity
Incorporated in DE
Incorporated in DE
Ownership
Not determined
Not determined
Data residency
Not determined
Not determined
Subprocessors
Not determined
Not determined
Facts, side by side
Only facts both products carry under the same definition — anything else would not be a fair row.