The written short answer is being updated after a re-evaluation. The scores below are current.
Read this comparison as one judge. Each weighs the same scores by what they care about.
The Lead Auditor
Audits management systems for a living and has seen every folder of screenshots. Optimizes for revision-safe history, evidence packs on demand, and a defensible answer to "show me the state on date X". Rejects systems where the audit trail is assembled the week before the audit.
audatis MANAGER
preeco | datenschutz
This judge's pick
Criterion by criterion
Records & DPIA depth
audatis MANAGER
The VVT is a real register — 400+ prebuilt activities across sector packs, save-as and cross-org-unit group templates, and AVV management that automatically documents the Art. 30(2) processor register — plus native mandate capability. What's not evidenced is the connected model of the 8 anchor: no proof that activities link to TOMs, systems and legal bases in one data model, nor DPIA triggers derived from the record.
preeco | datenschutz
Processing activities carry every Art. 30 field and are linked graphically to systems, technical and organizational measures and Art. 28 contracts, with recipient-to-contract coverage created by automatic name matching and gaps surfacing as marked rows. Impact assessments, including transfer assessments for third-country cases, run off the same record with a necessity pre-check, measures are versioned and linked, and mandate capability with cross-client inheritance is built in rather than copy-paste. We found no public information on a coverage view showing measures complete across every record, which is what would close the loop.
Data subject rights & incidents
audatis MANAGER
DSR handling with templates and a Löschkonzept with fristen, storage locations and classes exist as features, but there is no intake portal, no Art. 12 clock, and no deletion execution tracking evidenced. Decisive gap: nowhere in the evidence is there a breach register or 72-hour/Art. 33 capability — the only incident-adjacent module is the whistleblower system, which is a different law — so the operational half sits at the log-and-templates anchor.
preeco | datenschutz
Requests come in through embeddable web forms, identity verification and rejection grounds are documented fields, replies go out as one-time encrypted links, and every request type under Art. 15–22 runs under automatic deadline monitoring with proactive warnings; breaches carry severity classification, a risk matrix, 72-hour monitoring and nine ready notification templates for Art. 33, Art. 34 and the German BSI with an unambiguous deadline status per report. Requests and incidents link to the affected processing activities, and deletion rules with deadlines, procedures and responsibilities derive from deletion classes tied to the register. We found no public information on escalation chains for missed deadlines or on evidence that a deletion was actually executed.
Privacy regime coverage
audatis MANAGER
Gesetzesbasis DSGVO/BDSG/DSG plus church statutes EKD and KDG, current law texts, a curated Infodienst update stream and regular updates cover the major regimes for this vendor's German Mittelstand/church/authority market, with ISO 27001, NIS-2 and TISAX breadth on top. But nothing evidences one-record-many-regimes mapping, and no non-German regimes (UK GDPR, AI Act, ePrivacy) appear at all — market-major-set coverage without cross-mapping.
preeco | datenschutz
The GDPR stack is deep and German in flavor — the register, breaches under Art. 33/34 alongside German BSI reporting duties, Art. 35 assessments including Schrems II transfer analysis, and the Bavarian supervisory authority's questionnaire at the push of a button — with EU AI Act risk classification running in the same system and roughly monthly updates as the visible maintenance cadence. One record therefore serves two regimes for the home market. We found no public information on Swiss, UK or ePrivacy regime support.
Audit readiness & evidence
audatis MANAGER
The VVT carries an edit history explicitly framed for Eingabekontrolle and exports as an official-register ('behördliches Verzeichnis') document, attestations are confirmed 'revisionssicher' online, and report management pulls KPIs automatically — better than ad-hoc PDF assembly. But revision safety is claimed per feature, not system-wide: no audit-scoped evidence packs, no auditor access role, and no defensible 'state on date X' reconstruction is evidenced, which caps it below 8.
preeco | datenschutz
Every approval freezes an immutable revision with SHA-256 checksums and color-coded comparison, described as a fixed documentation state at any point in time, and an automatic log records document changes and account administration with timestamp, user and action. Authority and management output is push-button — status reports, procedure files per activity, the Bavarian questionnaire, scheduled cross-tenant DPO reports — and the audits module separates answering from managing. We found no public information on evidence attachments collected per activity or exportable proof bundles, so assembling a full file still looks partly manual.
Integrations & automation
audatis MANAGER
The only estate-facing interface evidenced is CSV/Word export; no import, no documented API, no directory sync, no connectors or webhooks anywhere in the evidence — automation is task/workflow delegation and reminders. The whitelabel 'own ticket system integrable' is support plumbing for the host, not estate integration. That is the closed-ish island with export anchor.
preeco | datenschutz
The vendor's own pages describe a closed system with no public REST API — custom endpoints are developed only for Private Cloud and On-Premises — and standard-tier data exchange is DOCX/XLSX import against PDF/DOCX/XLSX export, with legacy migrations run as individual projects. Above a pure file island sit an MCP server letting external AI assistants query processing activities and export revisions under application access rights, embeddable intake forms, DeepL translation, and SAML2 single sign-on restricted to the upper hosting variants. We found no public information on directory import, ticketing or HR connectors, webhooks, or user provisioning sync.
European sovereignty
audatis MANAGER
German GmbH in the Herford registry with a Germany-datacenter default and an own-server option for the product is genuinely European — better than EU-on-request. But the SaaS chain itself is undocumented: no public product DPA, no product subprocessor list, no TOMs, and the vendor's own web chain runs US-anchored Elastic APM (San Francisco operator) — so it lands between the on-request and published-chain anchors.
preeco | datenschutz
A German company in Ulm hosts Cloud and Private Cloud exclusively in named Hetzner data centers in Nürnberg and Falkenstein, offers on-premises, publishes its Art. 28 contract with two-week subprocessor change notice and downloadable technical and organizational measures, and states no third-country transfer of product data; AI features are off by default and run on customer-held keys. The privacy notice additionally names UpCloud Oy of Finland as a hosting subprocessor, so the captured pages give different pictures of where hosting occurs, though both named providers sit inside the EU. Ownership structure is not publicly documented, which is what keeps this short of the cleanest band.
Pricing transparency
audatis MANAGER
Every single line — standard, group, whitelabel, storage per GB, users per 10, annual flatrate tiers, ISMS add-on — reads 'Auf Anfrage'; no euro figure is published, so the real invoice is a sales conversation by definition. The published edition structure (10 users included, 2 vs 46 tenants, 30-day trial, invoice billing) is the one point above bare zero.
preeco | datenschutz
Not one price figure appears on the captured pages: the license is described as scaling with employees, modules and hosting variant, with no setup fees and no cancellation periods, but the real invoice is not computable without a sales conversation. One page promises all GDPR obligations without add-on modules or hidden surcharges, while other captures list optional paid items such as audit catalogs, DeepL translation, premium support and migration projects. We found no public information on entry pricing, per-module figures or scale steps.
Sovereignty, side by side
Dimension
audatis MANAGER
preeco | datenschutz
Legal entity
Incorporated in DE
Incorporated in DE
Ownership
Not determined
Not determined
Data residency
Not determined
Not determined
Subprocessors
Not determined
Not determined
Facts, side by side
Only facts both products carry under the same definition — anything else would not be a fair row.