The written short answer is being updated after a re-evaluation. The scores below are current.
Read this comparison as one judge. Each weighs the same scores by what they care about.
The Drafted Generalist
Office manager at an 80-employee firm who got compliance added to her job title, not her calendar. Optimizes for guided workflows in plain language and software that knows the law so she does not have to. Rejects consultant-shaped platforms that assume a compliance department.
caralegal
preeco | datenschutz
This judge's pick
Criterion by criterion
Records & DPIA depth
caralegal
The record of processing sits in a guided workflow with an approval step, and the things that usually live in separate files hang off it: the DPIA decision is derived automatically from risky activities, vendors link to the record with a compliance check, TOMs can be process-specific, and the deletion concept is generated from the record itself. Legal-entity counts per plan point to group use, and the package to the supervisory authority goes out with one click, "von AVV bis VVT". I found no public information on multi-client mandate work, so I stop just short of the top.
preeco | datenschutz
The record of processing is a guided form through every mandatory field — purpose, data categories, legal bases, recipients, third-country transfers, retention — and the links run on to systems, TOMs and contracts in a graphical relationship view, which is exactly the software-knows-the-law experience I need. DPIA handling sits on the same record with Art. 35 necessity checks and a Schrems II assessment, and multi-client handling with cross-client inheritance is built in rather than copy-paste. Missing contract links are flagged automatically but you wire some of them by hand, which is what keeps this a rung below a fully self-driving register.
Data subject rights & incidents
caralegal
Requests arrive in the tool with an automatic lookup of where the relevant data sits, the reply deadline shown, and answers sent through a protected data room, and incidents get central documentation with a guided decision process — exactly the plain-language hand-holding someone like me needs. I found no public information on escalation when a clock runs out, identity checks, the 72-hour breach clock, or evidence that a deletion was actually executed.
preeco | datenschutz
Requests arrive through embeddable web forms, every Art. 15–22 type is covered, deadlines are monitored automatically with clear status states and documented justifications, identity checks and rejection reasons are recorded, and replies go out as one-time encrypted links — close to end-to-end. Breach handling produces the actual authority notifications from nine ready templates (Art. 33/34 plus BSI reports) with the 72-hour clock tracked. I found no public information on escalation chains or on tracked evidence that a deletion actually executed, which is what held me back from the top of this band.
Privacy regime coverage
caralegal
GDPR is the backbone and the German depth is real — the Standard-Datenschutzmodell 3.1 with its seven guarantee goals and building blocks sits inside the same records, and the AI Flow builds on the same documentation with AI Act audit templates and a cookie check on top. I found no public information on Swiss nDSG, UK GDPR or other per-country variants, so this reads as its home market rather than broad coverage.
preeco | datenschutz
For a German buyer this goes deep: GDPR plus the BayLDA questionnaire at the push of a button, BSIG notification duties in the breach templates, an HinSchG whistleblower module, and EU AI Act conformity checks in the same system as the GDPR record, with roughly monthly updates as visible maintenance. Beyond that home market, I found no public information on Swiss nDSG, UK GDPR or ePrivacy operationalization, and the one-record-many-regimes mapping is really GDPR-plus-AI-Act rather than broad coverage.
Audit readiness & evidence
caralegal
Everything can go to the authority with a single click "from DPAs to RoPAs", the register exports as PDF or Excel, and there are audit templates for ISO, GDPR and AI Act checks. I found no public information on revision-safe change history, auditor access roles, or reconstructing the state on a given date, so I cannot tell how a full audit file would stand up.
preeco | datenschutz
Status reports, procedure files and the BayLDA questionnaire are push-button, reports can run on a schedule with email notification, and a full audits module with an included data protection catalog even separates who answers from who manages. I found no public information on a point-in-time view across the whole register or continuous status broken down per legal regime.
Integrations & automation
caralegal
Existing documentation is transferred automatically rather than re-typed, requests become cases with owner, status and ID, and an AI assistant and agents take over recurring steps. I found no public information on a documented API, directory import, ticketing connectors or single sign-on, so the platform may still be an island in our IT estate.
preeco | datenschutz
The honest headline for my IT colleagues: the vendor's own pages describe the application as a closed system without a public REST API, with customer-specific endpoints only on Private Cloud or On-Premises — and single sign-on via SAML2 likewise only on those variants. What it automates, it automates well: deadline clocks, recurring reports, automatic revisioning, name-matching that links contracts to data recipients, and an MCP server that lets an AI assistant query records under the application's own permissions. I found no public information on directory import from AD or Entra, ticketing connectors or webhooks.
European sovereignty
caralegal
The vendor is a Berlin GmbH with a German VAT number, and the privacy policy openly lists its website processors — including Supademo Inc. in Delaware, Google and Microsoft under the EU-US Data Privacy Framework, and AWS behind the demo tool. I found no public information on where the compliance platform itself is hosted, its product subprocessors, named data centers or a public product DPA, which for the system holding our register is the part I most need.
preeco | datenschutz
A German entity, hosting exclusively in named ISO-27001 data centers at Hetzner in Nuremberg and Falkenstein, a published DPA with downloadable TOMs, deletion certified on contract end, and AI off unless I bring my own key — that is a chain I can explain to our managing director in one breath. I found no public information on the vendor's ownership, and the privacy policy names UpCloud in Finland as a host of the software alongside Hetzner, so the captured pages give different pictures of the hosting chain; a standalone public subprocessor list was also not evident to me.
Pricing transparency
caralegal
The Essential plan is published at "ab 79€ pro Monat" with legal-entity counts per tier and unlimited users and documents, plus a free trial and a 50% nonprofit discount. The middle tiers carry no prices in the captured pages and Enterprise is "auf Anfrage", and nothing says what pushes the starting price upward, so our real invoice still needs a sales call.
preeco | datenschutz
The model is at least published in words — license by employees, modules and hosting variant, not per organization, with no setup fees and no cancellation periods, and every GDPR obligation claimed included without add-on modules. But I found no public prices at all, not even an entry figure, so I cannot budget even a rough annual number for an 80-person company without booking the 30-minute demo and having the sales conversation.
Sovereignty, side by side
Dimension
caralegal
preeco | datenschutz
Legal entity
Not determined
Incorporated in DE
Ownership
Not determined
Not determined
Data residency
Not determined
Not determined
Subprocessors
Not determined
Not determined
Facts, side by side
Only facts both products carry under the same definition — anything else would not be a fair row.
Data · Retention contact form
contact form data · deleted automatically after request fully processed1