The written short answer is being updated after a re-evaluation. The scores below are current.
Read this comparison as one judge. Each weighs the same scores by what they care about.
The Skeptic
Hunts certification logos that link nowhere, "AI-powered" features with no substance behind them, consulting bundled as software, legal-update promises with no named lawyer, and customer counts that disagree between pages. Exists to keep the rest of the bench honest.
caralegal
preeco | datenschutz
This judge's pick
Criterion by criterion
Records & DPIA depth
caralegal
The record side is genuinely connected: processing activities run in a workflow with approval steps, the DPIA is triggered by automated threshold analysis linked to risky activities, and vendors and TOMs synchronize automatically with the register, with legally reviewed, editable templates throughout. We found no public information on multi-client or mandate capability, which is what separates the top anchors. Note also that the captured pages give different figures for the total function count (26 and 27).
preeco | datenschutz
The record model is genuinely connected: every Art. 30 mandatory field, graphical links from processing activities to systems, TOMs and contracts, and a contract view flagging which data recipients are covered by a DPA — with missing links still set by hand rather than derived. Reusable text modules, cross-client inheritance for mandates and one-click BayLDA procedure files match the connected-model anchor; we found no evidence that DPIA necessity or processor coverage is derived rather than AI-proposed and hand-confirmed, which keeps it below system-of-record territory.
Data subject rights & incidents
caralegal
Requests arrive in the system with automatic data-location lookup, automatic deadlines and a secure data room for the response, and the deletion concept is generated from the record itself. The breach module is described only as central documentation with a guided decision process — we found no public information on a 72-hour clock, severity assessment, authority notification output or identity verification, which is why this sits below the stronger anchors.
preeco | datenschutz
Requests and breaches are run as real operations: embeddable intake forms, documented identity verification with timestamp, recorded rejection reasons, automatic deadline monitoring with per-report states, replies by one-time encrypted link, a 72-hour breach clock with severity classification, and nine ready report templates covering Art. 33/34 and BSI. Deletion classes are linked to processing activities and derive rules with deadlines and responsibilities, but we found no public information on deadline escalation or on evidence that a deletion was actually executed.
Privacy regime coverage
caralegal
Beyond GDPR the product carries the German Standard-Datenschutzmodell 3.1 with always-updated building blocks, audit templates for the AI Act, and a website cookie check, and the vendor states privacy and AI documentation build on the same basis. We found no public information on Swiss or UK coverage or per-country variants, so the breadth of a top score is not evidenced.
preeco | datenschutz
GDPR is deep and the German specifics are real — the BayLDA questionnaire generates at a button press, BSI reporting templates ship with the breach module, and EU AI Act risk classification runs in the same system as the GDPR record. We found no public information on UK GDPR, Swiss FADP or ePrivacy, and no evidence that one processing activity maps across regimes rather than living in a GDPR-centric world with content packs of varying depth.
Audit readiness & evidence
caralegal
An Audit & Vendor Flow, audit templates for ISO, GDPR and AI Act, gap-analysis questionnaires, PDF/Excel register export and submission to authorities with a single click are all evidenced. But we found no public information on revision-safe change history, auditor access roles or reconstructing the state on a given date, so the audit file may still take manual assembly even if the outputs are fast.
preeco | datenschutz
Every approval freezes an immutable revision sealed with a SHA-256 checksum and exported as PDF — the captured pages explicitly promise a fixed documentation state at any point in time — backed by an automatic log of every change and admin action with user and timestamp. Status reports, procedure files and the BayLDA questionnaire generate at a push of a button and a full audit module with gap-derived tasks exists; we found no public information on dedicated auditor access roles or pre-assembled evidence packs, which is what separates this from a standing audit state.
Integrations & automation
caralegal
The only connections to the outside estate evidenced are a one-time automatic transfer of existing documentation and PDF/Excel export; we found no public information on an API, directory import, ticketing or HR connectors, or SSO. The AI assistant and agents appear once in a webinar description with no detail on what they actually do, and I do not credit that as automation.
preeco | datenschutz
The vendor states plainly that the application is designed as a closed system without a public REST API, with custom endpoints developed per customer only on Private Cloud and On-Premises. The live touches that do exist — an MCP server for AI assistants under token control, SAML2 single sign-on on two hosting variants, embeddable web forms and optional DeepL — sit above pure import-and-export, but we found no public information on directory import, ticketing or HR connectors, webhooks or SCIM.
European sovereignty
caralegal
A German entity with a Berlin seat and VAT number is confirmed in the imprint, and the privacy policy discloses the website's processors — including US-based ones such as Supademo on AWS and Google and Microsoft under the Data Privacy Framework. For the platform holding the customer's register itself, we found no public information on hosting location, product subprocessors or a product data processing agreement, and the captured security page confirmed nothing on certifications either.
preeco | datenschutz
A German company hosts exclusively in named Hetzner data centers in Nürnberg and Falkenstein, publishes its DPA and downloadable TOMs, and names its subprocessors — Hetzner in Germany, UpCloud in Finland, both EU — with AI switched off by default and no third-country transfer claimed for platform data. We found no public information on ownership, and the on-premises route is described as typically reserved for the public sector and enterprise, which leaves the top anchor out of reach.
Pricing transparency
caralegal
Essential carries a published starting price of "ab 79€ pro Monat" with entity counts per tier, unlimited users and documents, a stated trial condition and a 50% nonprofit discount. Enterprise is "auf Anfrage" and we found no public prices for the Professional and Corporate tiers, so the real invoice for anything above one entity is not computable from the captured pages.
preeco | datenschutz
We found no public price figures of any kind; the license is described only as scaling with employees, modules and hosting variant, so the invoice remains a sales conversation. The no-setup-fee and no-cancellation terms are published, and audit catalogs (BSI IT-Grundschutz, CISIS12, VdA ISA) as well as DeepL, premium support and migration are listed as optional paid additions; without a single number published, no configuration is computable.
Sovereignty, side by side
Dimension
caralegal
preeco | datenschutz
Legal entity
Not determined
Incorporated in DE
Ownership
Not determined
Not determined
Data residency
Not determined
Not determined
Subprocessors
Not determined
Not determined
Facts, side by side
Only facts both products carry under the same definition — anything else would not be a fair row.
Data · Retention contact form
contact form data · deleted automatically after request fully processed1