The written short answer is being updated after a re-evaluation. The scores below are current.
Read this comparison as one judge. Each weighs the same scores by what they care about.
The Skeptic
Hunts certification logos that link nowhere, "AI-powered" features with no substance behind them, consulting bundled as software, legal-update promises with no named lawyer, and customer counts that disagree between pages. Exists to keep the rest of the bench honest.
audatis MANAGER
preeco | datenschutz
This judge's pick
Criterion by criterion
Records & DPIA depth
audatis MANAGER
The RoPA module is real — sector template packs of 65–77 activities, delegation to responsible users, edit history, group templates and an official-register export — with DSFA-with-risk-management, AVV and TOM modules listed. But nothing captured shows processing activities linked to legal bases, systems or TOMs in one data model, or DPIAs triggered from the record; 67 pre-filled activities is content depth, not connection.
preeco | datenschutz
The record model is genuinely connected: every Art. 30 mandatory field, graphical links from processing activities to systems, TOMs and contracts, and a contract view flagging which data recipients are covered by a DPA — with missing links still set by hand rather than derived. Reusable text modules, cross-client inheritance for mandates and one-click BayLDA procedure files match the connected-model anchor; we found no evidence that DPIA necessity or processor coverage is derived rather than AI-proposed and hand-confirmed, which keeps it below system-of-record territory.
Data subject rights & incidents
audatis MANAGER
DSR handling exists as centralized request management with answer templates, and a deletion concept with retention periods, storage locations and deletion classes is offered — but no statutory clock, no intake channel, and no evidence deletion is executed rather than documented. A breach register and 72-hour/authority-notification workflow appear nowhere in the captured pages; the only incident-adjacent module is the optional whistleblower system, which is not Art. 33.
preeco | datenschutz
Requests and breaches are run as real operations: embeddable intake forms, documented identity verification with timestamp, recorded rejection reasons, automatic deadline monitoring with per-report states, replies by one-time encrypted link, a 72-hour breach clock with severity classification, and nine ready report templates covering Art. 33/34 and BSI. Deletion classes are linked to processing activities and derive rules with deadlines and responsibilities, but we found no public information on deadline escalation or on evidence that a deletion was actually executed.
Privacy regime coverage
audatis MANAGER
The regime list fits its German market exactly — DSGVO, BDSG, Swiss DSG, EKD and KDG as current statutory texts — with regular updates and an in-product Infodienst. But one-record-many-regimes mapping is nowhere evidenced, AI Act, ePrivacy and UK GDPR are absent, and the 'fachlich geprüfte Datenschutz-Updates' name no lawyer or accountable editor — a legal-update promise with no human behind it.
preeco | datenschutz
GDPR is deep and the German specifics are real — the BayLDA questionnaire generates at a button press, BSI reporting templates ship with the breach module, and EU AI Act risk classification runs in the same system as the GDPR record. We found no public information on UK GDPR, Swiss FADP or ePrivacy, and no evidence that one processing activity maps across regimes rather than living in a GDPR-centric world with content packs of varying depth.
Audit readiness & evidence
audatis MANAGER
Revision-safe employee attestations, a per-record edit history for Eingabekontrolle, and report generation pulling KPIs from the DSMS, plus export as an internal or official register, are genuine anchors. But no audit-scoped evidence packs, no auditor access roles, and no demonstrated answer to 'show me the state on date X'; the outputs are CSV and Word files, not proof packs an authority accepts as-is.
preeco | datenschutz
Every approval freezes an immutable revision sealed with a SHA-256 checksum and exported as PDF — the captured pages explicitly promise a fixed documentation state at any point in time — backed by an automatic log of every change and admin action with user and timestamp. Status reports, procedure files and the BayLDA questionnaire generate at a push of a button and a full audit module with gap-derived tasks exists; we found no public information on dedicated auditor access roles or pre-assembled evidence packs, which is what separates this from a standing audit state.
Integrations & automation
audatis MANAGER
Not one captured page mentions an API, SSO, directory import or webhook — the estate-facing surface is CSV/Word export, and the only ticket-system integration is the whitelabel variant's own support channel. Automation means internal tasks, workflows and delegation, i.e., the recurring work is organized, not removed; this is a closed island with an export button.
preeco | datenschutz
The vendor states plainly that the application is designed as a closed system without a public REST API, with custom endpoints developed per customer only on Private Cloud and On-Premises. The live touches that do exist — an MCP server for AI assistants under token control, SAML2 single sign-on on two hosting variants, embeddable web forms and optional DeepL — sit above pure import-and-export, but we found no public information on directory import, ticketing or HR connectors, webhooks or SCIM.
European sovereignty
audatis MANAGER
A German GmbH under Amtsgericht Bad Oeynhausen, Germany as the default datacenter and an own-server option are solid and confirmed. But no product DPA or subprocessor list is published anywhere captured, ownership is undocumented, the header says 'audatis Group GmbH' while the imprint and copyright say 'audatis Services GmbH', and the vendor's own site leans on US-addressed Elastic APM — a compliance vendor that doesn't publish its own chain.
preeco | datenschutz
A German company hosts exclusively in named Hetzner data centers in Nürnberg and Falkenstein, publishes its DPA and downloadable TOMs, and names its subprocessors — Hetzner in Germany, UpCloud in Finland, both EU — with AI switched off by default and no third-country transfer claimed for platform data. We found no public information on ownership, and the on-premises route is described as typically reserved for the public sector and enterprise, which leaves the top anchor out of reach.
Pricing transparency
audatis MANAGER
Every single price line — standard, group, whitelabel, extra users, storage, ISMS module, unlimited flatrate — reads 'Auf Anfrage'; the only computable fact is a 30-day free trial. Published edition boundaries (10 users included, 2 vs 46 tenants, employee-tier flatrates) are the sole reason this isn't the floor.
preeco | datenschutz
We found no public price figures of any kind; the license is described only as scaling with employees, modules and hosting variant, so the invoice remains a sales conversation. The no-setup-fee and no-cancellation terms are published, and audit catalogs (BSI IT-Grundschutz, CISIS12, VdA ISA) as well as DeepL, premium support and migration are listed as optional paid additions; without a single number published, no configuration is computable.
Sovereignty, side by side
Dimension
audatis MANAGER
preeco | datenschutz
Legal entity
Incorporated in DE
Incorporated in DE
Ownership
Not determined
Not determined
Data residency
Not determined
Not determined
Subprocessors
Not determined
Not determined
Facts, side by side
Only facts both products carry under the same definition — anything else would not be a fair row.