whats-best.ai
Search Sign in

Data Protection

DATA FIRST Datenschutz-Software

Provenance unknown Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: not determined

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by DATA FIRST · datafirst.de

Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The panel's verdict

DATA FIRST Datenschutz-Software sits at the floor of this bench: five of the seven criteria — privacy management, rights and incidents, framework coverage, audit readiness, and integrations and automation — show a minimum and maximum of 0. The rationales give the same cause: the only captured page, https://datafirst.de, is a domain-marketplace listing for transfer, escrow and commission operated by Nameshift.com, not product documentation, and we found no public information on records of processing, DPIAs, data subject request handling, breach registers, regime coverage, revision-safe history, APIs or connectors. The strongest result is marginal: sovereignty spans 0 to 1, three judges partially crediting the footer's Dutch registration — Nameshift.com, KvK 88910652, Rijswijk — as at least a European legal identity while noting it is a domain brokerage, with no public information on hosting, a DPA or subprocessors; the remaining sovereignty scores sit at 0 over that same gap. Pricing transparency spans 0 to 1, with no public software prices, and is not counted in any judge's verdict. Nothing captured lets a buyer assess the software; every capability question is one for the vendor.

Report an error

Speaks for it

  • Page footer names a Dutch-registered entity — Nameshift.com, KvK 88910652, Steenplaatsstraat 6, 2288AA Rijswijk — the only jurisdictional fact published.
  • An escrow service for the domain purchase is described, with no additional cost to the buyer stated.
  • A stated average transfer time of 24 hours is published for domain purchases.

Report an error

Held against it

  • Five criteria — privacy management, rights and incidents, framework coverage, audit readiness, integrations and automation — each show a minimum and maximum of 0.
  • The only captured page documents a domain-marketplace transfer and escrow service, not the data protection software.
  • We found no public information on records of processing, DPIAs, TOMs, data subject request workflows, breach registers or regime coverage.
  • We found no public information on the software vendor's own entity, hosting, DPA or subprocessors; the Dutch registration belongs to the domain brokerage.

Report an error

Best for

  • You are acquiring a web address through the captured marketplace and want escrow-protected transfer with a stated 24-hour average turnaround.
  • You value a European legal identity in the page footer — Nameshift.com, KvK 88910652, Rijswijk — and will put every software question to the vendor directly.
  • Your team wants a documented baseline of what is publicly evidenced before a first vendor conversation.

Report an error

Avoid if

  • You need records of processing, DPIA and TOM management in production now — privacy management sits at a minimum and maximum of 0.
  • You must run data subject requests and 72-hour breach notifications on statutory clocks — ask the vendor: the public pages we read do not show it
  • Your auditors or a supervisory authority will ask for revision-safe history and reports — audit readiness sits at 0.
  • You require documented hosting, a DPA and subprocessor terms before adoption — sovereignty spans 0 to 1 and the only named entity is the domain brokerage.

Report an error

The scores

Records & DPIA depth

Show reasoning
How this is scored

The DSMS core: records of processing (RoPA/VVT), data protection impact assessments, processor/DPA management and TOMs — how deeply the legal artifacts are modeled and connected.

0 — Document templates in a folder tree; the "register" is a Word file with version numbers in the filename.

3 — A structured RoPA with basic fields and a DPIA questionnaire, but processors, TOMs and legal bases live outside the system.

5 — RoPA and DPIA as linked modules with templates; processor management and TOM assignment exist but are shallow, and group reuse is copy-paste.

8 — A connected data model — processing activities linked to systems, processors, TOMs and legal bases — with DPIA triggers derived from the record, reusable group templates, and outputs a supervisory authority accepts.

10 — Privacy records as a system of record: the RoPA drives DPIAs, processor management and TOM coverage from one data model, multi-client/mandate capability included, and the documentation is audit-ready without manual assembly.

Report an error

The External DPO

I found no public information on a records of processing structure, DPIA modules, processor management, or TOMs — the captured page's content is domain-transfer and escrow services. For a consultancy running thirty mandates there is nothing visible evidencing a RoPA or any linked legal-artifact data model, so this sits at the floor. 1

Report an error

The In-House Counsel

The captured page shows only a domain-marketplace notice — imprint of Nameshift.com, commission and escrow terms, an average turnover time of 24 hours — and we found no public information on records of processing, DPIAs, processor management or TOMs. With nothing evidencing even a structured register, the legal artifacts cannot be scored above the floor. 1

Report an error

The Drafted Generalist

The captured page never mentions a records of processing register, impact assessments, or processor and TOM management — it describes an escrow service with an average turnover time of 24 hours. We found no public information on the legal record-keeping side of the product, and for the heart of a data protection management system that absence decides the score. 1

Report an error

The Lead Auditor

The captured vendor page is a domain-transfer and escrow offer; we found no public information on records of processing, DPIAs, processor management or TOMs. Nothing published evidences a structured register of any depth, so there is no legal artifact here to audit. 1

Report an error

The IT Integrator

The only captured page is a domain-marketplace notice about transfer, escrow and commission; we found no public information on records of processing, DPIA tooling, processor management or TOMs. The register core is entirely unevidenced, which on this criterion is the minimum. 1

Report an error

The Skeptic

The lone capture is a domain-transfer listing operated by a brokerage, not product documentation, and we found no public information on records of processing, DPIAs, processor management or TOMs. Nothing in the evidence shows a register of any kind, let alone a connected data model, so the score sits at the bottom of this criterion. 1

Report an error

Data subject rights & incidents

Show reasoning
How this is scored

The operational half of the DSMS: data subject request handling with statutory clocks, breach register and authority notification, deletion concepts that actually delete.

0 — Requests arrive by email and live there; breaches are a phone call and a memo.

3 — A request log and a breach list exist, but deadlines are manual, intake is unstructured, and deletion rules are documentation rather than workflow.

5 — DSR workflows with the Art. 12 clock tracked, structured breach register with the 72-hour clock, deletion concepts assignable to records; automation is reminders.

8 — Intake channels for requests (portal/form), identity-check support, deadline automation with escalation, breach severity assessment and authority-report output, deletion rules tied to the RoPA with execution tracking.

10 — Rights and incidents as operations: end-to-end request handling an authority audit walks through, breach workflows that produce the Art. 33 notification, and deletion automation with evidence that the deletion happened.

Report an error

The External DPO

I found no public information on data subject request workflows, statutory clocks, a breach register, or deletion execution. With not even a request log or intake channel visible, the bottom score is the honest one. 1

Report an error

The In-House Counsel

We found no public information on data subject request workflows, deadline tracking, breach registers or authority notification. My core question — whether a breach workflow produces the Art. 33 notification — has no evidenced answer at all. 1

Report an error

The Drafted Generalist

We found no public information on data subject request handling, breach registers, statutory clocks, or deletion workflows. As the person who would have to run those deadlines, I cannot see even a request log in what was captured. 1

Report an error

The Lead Auditor

We found no public information on data subject request handling, statutory deadline tracking, a breach register, authority notification or deletion workflows. The only operational figure published, an average turnover time of 24 hours, describes domain transfers rather than any statutory clock. 1

Report an error

The IT Integrator

We found no public information on data subject request workflows, statutory deadline tracking, a breach register with 72-hour handling, or deletion execution — the captured content is a broker's 24-hour domain-transfer promise. The operational half of a data protection program is simply not in evidence. 1

Report an error

The Skeptic

We found no public information on data subject request handling, deadline tracking, a breach register or deletion workflows. The only time-based operational claim anywhere is the brokerage's 'average turnover time is only 24 hours', which concerns transferring a web address, not statutory clocks. 1

Report an error

Privacy regime coverage

Show reasoning
How this is scored

Which privacy regimes the product actually operationalizes — GDPR, BDSG, Swiss nDSG, UK GDPR, ePrivacy, EU AI Act privacy duties — and whether one record maps across them or each regime is a fresh island.

0 — One regime, hard-coded; anything else is "on the roadmap".

3 — GDPR plus one national law as separate checklists; the same processing activity is documented once per regime.

5 — The major regimes for its market with partial cross-mapping; newer duties (AI Act, ePrivacy changes) present as content packs of varying depth.

8 — Broad current coverage with one-record-many-regimes mapping and visible maintenance as regimes evolve.

10 — Regime coverage as a living product: multiple privacy regimes on one data basis, per-country variants, and documented update cadence when the law moves.

Report an error

The External DPO

I found no public information on which privacy regimes the product operationalizes; not even GDPR coverage appears in the captured page's content. Absent any regime evidence, there is nothing to assess for one-record-many-regimes mapping or update cadence. 1

Report an error

The In-House Counsel

The page's only content is the marketplace's transfer and escrow terms; we found no public information on which privacy regimes the software operationalizes, whether GDPR, German BDSG, Swiss nDSG or AI Act duties. Regime coverage cannot be assessed above the floor. 1

Report an error

The Drafted Generalist

We found no public information on which privacy regimes the product covers — GDPR included, let alone Swiss, UK, or AI Act duties. I cannot confirm a single regime from the captured material, so there is nothing to score above the floor. 1

Report an error

The Lead Auditor

We found no public information on which privacy regimes the product operationalizes — GDPR, national laws, ePrivacy and AI Act duties are all unaddressed in what is published. I cannot establish even a single-regime baseline, let alone one-record-many-regimes mapping. 1

Report an error

The IT Integrator

No captured page says which privacy regimes the product operationalizes; we found no public information on GDPR coverage, national variants such as the Swiss or UK laws, or AI Act duties. Regime coverage is unevidenced end to end, so I score the bottom case. 1

Report an error

The Skeptic

We found no public information on which privacy regimes — GDPR, BDSG, Swiss nDSG or otherwise — the product operationalizes; the capture names no law at all. A listing for the web address itself leaves regime coverage entirely unevidenced. 1

Report an error

Audit readiness & evidence

Show reasoning
How this is scored

Whether the system produces defensible proof: revision-safe history, evidence collection, reports for auditors, authorities and management.

0 — Exports are screenshots; history is overwritten in place.

3 — PDF reports exist but evidence is attached ad hoc and changes leave no reliable trail.

5 — Versioned records, standard report generators for the core registers, evidence attachments per activity; assembling a full audit file still takes days.

8 — Revision-safe change history, audit-scoped evidence packs on demand, management and authority reports current at a click, auditor access roles.

10 — Audit readiness as a standing state: continuous documentation status per regime and scope, exportable proof packs an auditor accepts as-is, and a defensible answer to "show me the state on date X".

Report an error

The External DPO

I found no public information on revision-safe history, report generators, evidence packs, or auditor access roles. A privacy tool from which I cannot see defensible proof being produced is worthless to my clients' audits, so the floor stands. 1

Report an error

The In-House Counsel

We found no public information on revision-safe history, versioning, or auditor- and authority-facing reports. There is no evidenced artifact here that a supervisory authority could be handed. 1

Report an error

The Drafted Generalist

We found no public information on reports, versioned history, or evidence collection. Nothing captured shows the kind of proof an auditor or supervisory authority would ask me to produce. 1

Report an error

The Lead Auditor

We found no public information on versioned records, revision-safe change history, evidence attachments, or auditor, authority and management reports. As someone who builds evidence packs, I see nothing published that would let a client answer 'show me the state on date X'. 1

Report an error

The IT Integrator

We found no public information on revision-safe change history, report generators, evidence collection or auditor access; the only captured artifacts are escrow and commission terms. I cannot credit any audit-proof output on this basis. 1

Report an error

The Skeptic

We found no public information on versioning, revision-safe history, evidence collection, or reports for auditors, authorities and management. The only assurance mechanism described is the broker's escrow service, which guards a domain purchase rather than producing audit proof. 1

Report an error

Integrations & automation

Show reasoning
How this is scored

Whether the platform feeds from the real IT estate — directory import, ticketing, API — and automates the recurring privacy work instead of re-typing it.

0 — A closed island: manual entry in, PDF out, no API.

3 — CSV/Excel import and export; no live connections, no API worth the name.

5 — Directory import (AD/Entra), a documented REST API for core objects, a handful of native connectors (ticketing or SSO); automation is reminders and recurrence.

8 — Real connector set (ticketing, HR or asset sources), webhooks, SSO/SCIM, workflow automation with delegation and escalation, useful AI assistance with human review.

10 — The platform behaves like infrastructure: API parity for the data model, event streams, bidirectional sync with the estate, and automation that measurably removes the recurring toil (reviews, attestations, evidence pulls) rather than renaming it.

Report an error

The External DPO

I found no public information on an API, directory import, ticketing or HR connectors, SSO, or workflow automation. The only service described on the page is a 24-hour domain transfer with escrow, which tells me nothing about feeding the platform from a real IT estate. 1

Report an error

The In-House Counsel

We found no public information on an API, directory import, ticketing connectors or workflow automation. The only speed statement on the page — an average turnover time of 24 hours — concerns domain transfers by the marketplace, not privacy work. 1

Report an error

The Drafted Generalist

We found no public information on imports, connectors, single sign-on, or an API. The captured page describes a transfer and escrow process, not software that feeds from a real IT estate. 1

Report an error

The Lead Auditor

We found no public information on directory import, ticketing or HR connectors, a documented API, webhooks, SSO or workflow automation. The capture shows no software interfaces of any kind, only the escrow and transfer service. 1

Report an error

The IT Integrator

My home ground, and it's empty: we found no public information on a REST API, directory import from Entra ID or Active Directory, ticketing connectors, SSO, SCIM or webhooks. The one automation claim captured — "Our average turnover time is only 24 hours" — is a domain broker's transfer speed, with nothing connecting this to an IT estate. 1

Report an error

The Skeptic

We found no public information on an API, directory import, connectors, SSO or workflow automation. The capture describes exactly one 'service' — escrow — and it belongs to the marketplace intermediary, not to privacy tooling. 1

Report an error

European sovereignty panel opinion

Show reasoning
How this is scored

Where the compliance record of the whole company actually lives and under whose law — entity, hosting, subprocessors, DPA. A platform that maps your processing is itself your most concentrated processing.

0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for the system holding your RoPA.

3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.

5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.

8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.

10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors, on-premises or sovereign-cloud options, and the whole chain documented publicly.

Report an error

The External DPO

No sovereignty attributes are on record, and I found no public information on the software vendor's legal entity, hosting region, DPA, or subprocessor list — the page's Dutch address and escrow offer belong to domain-marketplace services rather than an evidenced compliance platform. For the system that would hold my clients' most concentrated records, that silence is disqualifying at this level. 1

Report an error

The In-House Counsel

The captured imprint names a Dutch company, Nameshift.com in Rijswijk, with KvK and VAT numbers, which is at least a European legal identity, though of a domain marketplace rather than a data protection software house. We found no public information on hosting locations, a data processing agreement, or any subprocessor list, so who would hold our records of processing and under whose law remains undocumented. 1

Report an error

The Drafted Generalist

The captured footer names Nameshift.com at a Dutch address, which is at least an entity inside the EU, but the same page describes a transfer and escrow arrangement rather than where compliance records would be hosted. We found no public information on hosting, a data processing agreement, or subprocessors, so I cannot tell where a register of my processing would legally live. 1

Report an error

The Lead Auditor

The page footer carries a Dutch registration — Nameshift.com, KvK 88910652, Steenplaetsstraat 6, Rijswijk — which is an EU entity, and that is the only jurisdictional fact published. We found no public information on hosting locations, a data protection agreement, or subprocessors for the platform that would hold a client's processing record, and the published entity is presented as a domain marketplace, so I credit the EU registration only partially. 1

Report an error

The IT Integrator

The only legal entity in evidence is Nameshift.com, a Dutch brokerage at Steenplaetsstraat 6, Rijswijk with KvK 88910652 — that is the domain intermediary, not the software publisher; we found no public information on the vendor's own entity, hosting locations, DPA or subprocessors. For the system that would hold a company's records of processing, an unanswerable jurisdiction question is the lowest case. 1

Report an error

The Skeptic

The only company identified anywhere on the page is Nameshift.com, KvK 88910652, Rijswijk — the Dutch brokerage operating the listing — and we found no public information on the software vendor's own legal entity, hosting region, DPA or subprocessor list. For the system that would hold a buyer's records of processing, that is exactly the situation the lowest description on this scale captures. 1

Report an error

Pricing transparency not rated — the vendor publishes no price

Show reasoning
How this is scored

Whether a buyer can compute the real invoice — per module, per entity, per year, with consulting unbundled — from public pages alone. Unpublished pricing is the B2B norm in this market, so this criterion describes rather than condemns; the benches weight it accordingly.

0 — No public prices at all; every configuration is a sales conversation.

3 — An entry price exists, but module add-ons, entity counts or bundled consulting make the real total incomputable.

5 — Most editions carry real numbers with billing period stated and software separated from services; at least one commonly needed module or scale step is unpriced.

8 — Every edition and module priced publicly with entity/user boundaries and setup fees stated; only genuine corporate-group contracts are custom.

10 — Complete price computability: modules, scale steps, service packages and renewal rules public, so the invoice for a 100-employee company and a 10-client consultancy is a two-minute exercise.

Report an error

The External DPO

The only pricing-adjacent statement on the page is "Our services are completely free for buyers" plus a seller-paid commission, which concerns domain brokerage rather than the software; I found no public information on editions, modules, per-entity costs, or billing period. A buyer cannot compute any invoice for this product from public pages. 1

Report an error

The In-House Counsel

The only price statement captured — 'Our services are completely free for buyers. The seller pays for our commission.' — prices the marketplace's escrow service, not the data protection software. We found no public figures for editions, modules, entity counts or consulting, so a buyer cannot compute a real invoice. 1

Report an error

The Drafted Generalist

We found no public prices for the software — no editions, modules, or user tiers of any kind. The only pricing statement captured is that services are "completely free for buyers" with "the seller pays for our commission," which describes the middleman's fees, not a product invoice I could ever compute. 1

Report an error

The Lead Auditor

The only pricing statements published — "Our services are completely free for buyers. The seller pays for our commission." — apply to the marketplace's escrow service. We found no public information on licence prices, edition or module costs, billing periods or setup fees for the data protection software, so a real invoice cannot be computed from what is public. 1

Report an error

The IT Integrator

The pricing statements captured are marketplace terms — "Our services are completely free for buyers. The seller pays for our commission." — describing domain purchase fees, not software editions, modules, entity counts or billing periods. We found no public prices for the product itself, so the real software invoice remains a sales conversation. 1

Report an error

The Skeptic

We found no public prices for software of any kind — no editions, modules, user counts or setup fees. The only commercial terms published are the broker's: 'Our services are completely free for buyers. The seller pays for our commission.' — a commission model for buying a domain, from which no software invoice can be computed. 1

Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (1)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor page datafirst.de Checked 29 Sep 2026 Details →