Records & DPIA depth
DataGuard
The GDPR page names the right modules — Daten-Mapping & VVT, DSFA & Risikobewertungen, Drittanbieter-Risikomanagement, Maßnahmen — but a feature list is not a data model: nothing shows activities linked to processors, TOMs and legal bases, and the 75%-automation claims are ISO-flavored marketing. Modules exist; connection is unevidenced.
OneTrust
A live RoPA built from assessments, system integrations and questionnaire responses into one central processing inventory, with automated DPIA/PIA workflows and vendor records holding DPAs, transfer mechanisms and security obligations, reads as a genuinely connected data model rather than a register in isolation. Two things hold it back: we found no public information on reusable group templates or multi-client mandates, and the one legal artifact I can inspect — the GDPR Transfer Impact Assessment template — reaches the application only through a template-import workaround rather than native support.