Records & DPIA depth
DataGuard
Everything on my checklist gets named — Daten-Mapping & VVT, DSFA & Risikobewertungen, Risikomanagement für Drittanbieter, plus a template library with acknowledgement tracking — but nothing shows the RoPA feeding the DPIA or TOMs hanging off processing activities, so I'd assume three modules I re-type between.
OneTrust
The GDPR materials describe a live processing register built from assessments, system integrations and imports, with automated DPIA and PIA workflows, vendor due diligence and a centralized record of data processing agreements — that is a genuinely connected picture, not form templates in folders. I stopped short of the top because nothing shows technical and organizational measures or legal bases linked to activities, and the developer documentation describes a stop-gap import workaround for the GDPR transfer impact assessment template.