Records & DPIA depth
DataGuard
VVT, DSFA, third-party risk and Maßnahmen are all named features plus a ready-made policy template library, so the core artifacts live in the system — but the evidence shows not one fact about whether they form a connected data model, whether DPIAs trigger from the record, or whether anything is reusable across entities and mandates. For thirty clients I need a RoPA that drives the rest; here I have a feature list, not architecture.
OneTrust
The live record of processing fed from assessments, system integrations and bulk imports into a central inventory, alongside DPIA/PIA workflows and centralized vendor records carrying DPAs, transfer mechanisms and security obligations, is the connected model I need to run across mandates. We found no public information on reusable group templates or multi-client mandate structures, and the GDPR transfer impact assessment template needs a documented import-API stop-gap rather than native support, so this stops just short of the top.