Records & DPIA depth
DataGuard
The module names are all there — Daten-Mapping & VVT, DSFA & Risikobewertungen, Drittanbieter-Risikomanagement and Maßnahmen, plus policy templates with Bestätigungen & Nachverfolgung — but the evidence never shows they form a connected data model; DPIA triggers from records, legal bases and group reuse are unevidenced, so this is named modules, not linked ones.
OneTrust
The record of processing is generated live from a central processing inventory fed by assessments, system integrations, questionnaire responses and bulk imports — records that stay current because they sync, exactly the model I run. DPIA and PIA workflows are automated, vendor records centrally hold DPAs, transfer mechanisms and security obligations, and there is a published, versioned GDPR transfer impact assessment template; I stop short of the top because the captured pages show no DPIA triggers derived from the record, no reusable group templates and no multi-client/mandate capability.