Records & DPIA depth
DataGuard
"Daten-Mapping & VVT" and "DSFA & Risikobewertungen" exist as feature names on the GDPR page, plus a template library with acknowledgements — but TOMs, legal bases, and any linkage between RoPA, DPIA and processors appear nowhere in seven captured pages. That is a feature glossary, not a data model; a structured register with a DPIA module and the rest outside the system is exactly the anchor at 3.
OneTrust
The GDPR pages describe a live record of processing assembled from assessments, system integrations and imports, automated DPIA and PIA workflows, and vendor files holding DPAs, transfer mechanisms and security obligations — a connected model corroborated by assessment launch, approval, archive and template APIs in the developer portal. The same developer documentation, though, describes the published GDPR Transfer Impact Assessment template as not directly addable, requiring a stop-gap import through an API. We found no public information on TOM management, legal bases driving DPIA triggers, or reusable group templates.