Data Protection
DATA FIRST Datenschutz-Software
Provenance unknown Report an error0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by DATA FIRST · datafirst.de
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
DATA FIRST Datenschutz-Software sits at the floor of this bench: five of the seven criteria — privacy management, rights and incidents, framework coverage, audit readiness, and integrations and automation — show a minimum and maximum of 0. The rationales give the same cause: the only captured page, https://datafirst.de, is a domain-marketplace listing for transfer, escrow and commission operated by Nameshift.com, not product documentation, and we found no public information on records of processing, DPIAs, data subject request handling, breach registers, regime coverage, revision-safe history, APIs or connectors. The strongest result is marginal: sovereignty spans 0 to 1, three judges partially crediting the footer's Dutch registration — Nameshift.com, KvK 88910652, Rijswijk — as at least a European legal identity while noting it is a domain brokerage, with no public information on hosting, a DPA or subprocessors; the remaining sovereignty scores sit at 0 over that same gap. Pricing transparency spans 0 to 1, with no public software prices, and is not counted in any judge's verdict. Nothing captured lets a buyer assess the software; every capability question is one for the vendor.
Speaks for it
- Page footer names a Dutch-registered entity — Nameshift.com, KvK 88910652, Steenplaatsstraat 6, 2288AA Rijswijk — the only jurisdictional fact published.
- An escrow service for the domain purchase is described, with no additional cost to the buyer stated.
- A stated average transfer time of 24 hours is published for domain purchases.
Held against it
- Five criteria — privacy management, rights and incidents, framework coverage, audit readiness, integrations and automation — each show a minimum and maximum of 0.
- The only captured page documents a domain-marketplace transfer and escrow service, not the data protection software.
- We found no public information on records of processing, DPIAs, TOMs, data subject request workflows, breach registers or regime coverage.
- We found no public information on the software vendor's own entity, hosting, DPA or subprocessors; the Dutch registration belongs to the domain brokerage.
Best for
- You are acquiring a web address through the captured marketplace and want escrow-protected transfer with a stated 24-hour average turnaround.
- You value a European legal identity in the page footer — Nameshift.com, KvK 88910652, Rijswijk — and will put every software question to the vendor directly.
- Your team wants a documented baseline of what is publicly evidenced before a first vendor conversation.
Avoid if
- You need records of processing, DPIA and TOM management in production now — privacy management sits at a minimum and maximum of 0.
- You must run data subject requests and 72-hour breach notifications on statutory clocks — ask the vendor: the public pages we read do not show it
- Your auditors or a supervisory authority will ask for revision-safe history and reports — audit readiness sits at 0.
- You require documented hosting, a DPA and subprocessor terms before adoption — sovereignty spans 0 to 1 and the only named entity is the domain brokerage.
The scores
Records & DPIA depth
Show reasoningHide reasoning
How this is scored
The DSMS core: records of processing (RoPA/VVT), data protection impact assessments, processor/DPA management and TOMs — how deeply the legal artifacts are modeled and connected.
0 — Document templates in a folder tree; the "register" is a Word file with version numbers in the filename.
3 — A structured RoPA with basic fields and a DPIA questionnaire, but processors, TOMs and legal bases live outside the system.
5 — RoPA and DPIA as linked modules with templates; processor management and TOM assignment exist but are shallow, and group reuse is copy-paste.
8 — A connected data model — processing activities linked to systems, processors, TOMs and legal bases — with DPIA triggers derived from the record, reusable group templates, and outputs a supervisory authority accepts.
10 — Privacy records as a system of record: the RoPA drives DPIAs, processor management and TOM coverage from one data model, multi-client/mandate capability included, and the documentation is audit-ready without manual assembly.
The External DPO
I found no public information on a records of processing structure, DPIA modules, processor management, or TOMs — the captured page's content is domain-transfer and escrow services. For a consultancy running thirty mandates there is nothing visible evidencing a RoPA or any linked legal-artifact data model, so this sits at the floor. 1
The In-House Counsel
The captured page shows only a domain-marketplace notice — imprint of Nameshift.com, commission and escrow terms, an average turnover time of 24 hours — and we found no public information on records of processing, DPIAs, processor management or TOMs. With nothing evidencing even a structured register, the legal artifacts cannot be scored above the floor. 1
The Drafted Generalist
The captured page never mentions a records of processing register, impact assessments, or processor and TOM management — it describes an escrow service with an average turnover time of 24 hours. We found no public information on the legal record-keeping side of the product, and for the heart of a data protection management system that absence decides the score. 1
The Lead Auditor
The captured vendor page is a domain-transfer and escrow offer; we found no public information on records of processing, DPIAs, processor management or TOMs. Nothing published evidences a structured register of any depth, so there is no legal artifact here to audit. 1
The IT Integrator
The only captured page is a domain-marketplace notice about transfer, escrow and commission; we found no public information on records of processing, DPIA tooling, processor management or TOMs. The register core is entirely unevidenced, which on this criterion is the minimum. 1
The Skeptic
The lone capture is a domain-transfer listing operated by a brokerage, not product documentation, and we found no public information on records of processing, DPIAs, processor management or TOMs. Nothing in the evidence shows a register of any kind, let alone a connected data model, so the score sits at the bottom of this criterion. 1
Data subject rights & incidents
Show reasoningHide reasoning
How this is scored
The operational half of the DSMS: data subject request handling with statutory clocks, breach register and authority notification, deletion concepts that actually delete.
0 — Requests arrive by email and live there; breaches are a phone call and a memo.
3 — A request log and a breach list exist, but deadlines are manual, intake is unstructured, and deletion rules are documentation rather than workflow.
5 — DSR workflows with the Art. 12 clock tracked, structured breach register with the 72-hour clock, deletion concepts assignable to records; automation is reminders.
8 — Intake channels for requests (portal/form), identity-check support, deadline automation with escalation, breach severity assessment and authority-report output, deletion rules tied to the RoPA with execution tracking.
10 — Rights and incidents as operations: end-to-end request handling an authority audit walks through, breach workflows that produce the Art. 33 notification, and deletion automation with evidence that the deletion happened.
The External DPO
I found no public information on data subject request workflows, statutory clocks, a breach register, or deletion execution. With not even a request log or intake channel visible, the bottom score is the honest one. 1
The In-House Counsel
We found no public information on data subject request workflows, deadline tracking, breach registers or authority notification. My core question — whether a breach workflow produces the Art. 33 notification — has no evidenced answer at all. 1
The Drafted Generalist
We found no public information on data subject request handling, breach registers, statutory clocks, or deletion workflows. As the person who would have to run those deadlines, I cannot see even a request log in what was captured. 1
The Lead Auditor
We found no public information on data subject request handling, statutory deadline tracking, a breach register, authority notification or deletion workflows. The only operational figure published, an average turnover time of 24 hours, describes domain transfers rather than any statutory clock. 1
The IT Integrator
We found no public information on data subject request workflows, statutory deadline tracking, a breach register with 72-hour handling, or deletion execution — the captured content is a broker's 24-hour domain-transfer promise. The operational half of a data protection program is simply not in evidence. 1
The Skeptic
We found no public information on data subject request handling, deadline tracking, a breach register or deletion workflows. The only time-based operational claim anywhere is the brokerage's 'average turnover time is only 24 hours', which concerns transferring a web address, not statutory clocks. 1
Privacy regime coverage
Show reasoningHide reasoning
How this is scored
Which privacy regimes the product actually operationalizes — GDPR, BDSG, Swiss nDSG, UK GDPR, ePrivacy, EU AI Act privacy duties — and whether one record maps across them or each regime is a fresh island.
0 — One regime, hard-coded; anything else is "on the roadmap".
3 — GDPR plus one national law as separate checklists; the same processing activity is documented once per regime.
5 — The major regimes for its market with partial cross-mapping; newer duties (AI Act, ePrivacy changes) present as content packs of varying depth.
8 — Broad current coverage with one-record-many-regimes mapping and visible maintenance as regimes evolve.
10 — Regime coverage as a living product: multiple privacy regimes on one data basis, per-country variants, and documented update cadence when the law moves.
The External DPO
I found no public information on which privacy regimes the product operationalizes; not even GDPR coverage appears in the captured page's content. Absent any regime evidence, there is nothing to assess for one-record-many-regimes mapping or update cadence. 1
The In-House Counsel
The page's only content is the marketplace's transfer and escrow terms; we found no public information on which privacy regimes the software operationalizes, whether GDPR, German BDSG, Swiss nDSG or AI Act duties. Regime coverage cannot be assessed above the floor. 1
The Drafted Generalist
We found no public information on which privacy regimes the product covers — GDPR included, let alone Swiss, UK, or AI Act duties. I cannot confirm a single regime from the captured material, so there is nothing to score above the floor. 1
The Lead Auditor
We found no public information on which privacy regimes the product operationalizes — GDPR, national laws, ePrivacy and AI Act duties are all unaddressed in what is published. I cannot establish even a single-regime baseline, let alone one-record-many-regimes mapping. 1
The IT Integrator
No captured page says which privacy regimes the product operationalizes; we found no public information on GDPR coverage, national variants such as the Swiss or UK laws, or AI Act duties. Regime coverage is unevidenced end to end, so I score the bottom case. 1
The Skeptic
We found no public information on which privacy regimes — GDPR, BDSG, Swiss nDSG or otherwise — the product operationalizes; the capture names no law at all. A listing for the web address itself leaves regime coverage entirely unevidenced. 1
Audit readiness & evidence
Show reasoningHide reasoning
How this is scored
Whether the system produces defensible proof: revision-safe history, evidence collection, reports for auditors, authorities and management.
0 — Exports are screenshots; history is overwritten in place.
3 — PDF reports exist but evidence is attached ad hoc and changes leave no reliable trail.
5 — Versioned records, standard report generators for the core registers, evidence attachments per activity; assembling a full audit file still takes days.
8 — Revision-safe change history, audit-scoped evidence packs on demand, management and authority reports current at a click, auditor access roles.
10 — Audit readiness as a standing state: continuous documentation status per regime and scope, exportable proof packs an auditor accepts as-is, and a defensible answer to "show me the state on date X".
The External DPO
I found no public information on revision-safe history, report generators, evidence packs, or auditor access roles. A privacy tool from which I cannot see defensible proof being produced is worthless to my clients' audits, so the floor stands. 1
The In-House Counsel
We found no public information on revision-safe history, versioning, or auditor- and authority-facing reports. There is no evidenced artifact here that a supervisory authority could be handed. 1
The Drafted Generalist
We found no public information on reports, versioned history, or evidence collection. Nothing captured shows the kind of proof an auditor or supervisory authority would ask me to produce. 1
The Lead Auditor
We found no public information on versioned records, revision-safe change history, evidence attachments, or auditor, authority and management reports. As someone who builds evidence packs, I see nothing published that would let a client answer 'show me the state on date X'. 1
The IT Integrator
We found no public information on revision-safe change history, report generators, evidence collection or auditor access; the only captured artifacts are escrow and commission terms. I cannot credit any audit-proof output on this basis. 1
The Skeptic
We found no public information on versioning, revision-safe history, evidence collection, or reports for auditors, authorities and management. The only assurance mechanism described is the broker's escrow service, which guards a domain purchase rather than producing audit proof. 1
Integrations & automation
Show reasoningHide reasoning
How this is scored
Whether the platform feeds from the real IT estate — directory import, ticketing, API — and automates the recurring privacy work instead of re-typing it.
0 — A closed island: manual entry in, PDF out, no API.
3 — CSV/Excel import and export; no live connections, no API worth the name.
5 — Directory import (AD/Entra), a documented REST API for core objects, a handful of native connectors (ticketing or SSO); automation is reminders and recurrence.
8 — Real connector set (ticketing, HR or asset sources), webhooks, SSO/SCIM, workflow automation with delegation and escalation, useful AI assistance with human review.
10 — The platform behaves like infrastructure: API parity for the data model, event streams, bidirectional sync with the estate, and automation that measurably removes the recurring toil (reviews, attestations, evidence pulls) rather than renaming it.
The External DPO
I found no public information on an API, directory import, ticketing or HR connectors, SSO, or workflow automation. The only service described on the page is a 24-hour domain transfer with escrow, which tells me nothing about feeding the platform from a real IT estate. 1
The In-House Counsel
We found no public information on an API, directory import, ticketing connectors or workflow automation. The only speed statement on the page — an average turnover time of 24 hours — concerns domain transfers by the marketplace, not privacy work. 1
The Drafted Generalist
We found no public information on imports, connectors, single sign-on, or an API. The captured page describes a transfer and escrow process, not software that feeds from a real IT estate. 1
The Lead Auditor
We found no public information on directory import, ticketing or HR connectors, a documented API, webhooks, SSO or workflow automation. The capture shows no software interfaces of any kind, only the escrow and transfer service. 1
The IT Integrator
My home ground, and it's empty: we found no public information on a REST API, directory import from Entra ID or Active Directory, ticketing connectors, SSO, SCIM or webhooks. The one automation claim captured — "Our average turnover time is only 24 hours" — is a domain broker's transfer speed, with nothing connecting this to an IT estate. 1
The Skeptic
We found no public information on an API, directory import, connectors, SSO or workflow automation. The capture describes exactly one 'service' — escrow — and it belongs to the marketplace intermediary, not to privacy tooling. 1
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where the compliance record of the whole company actually lives and under whose law — entity, hosting, subprocessors, DPA. A platform that maps your processing is itself your most concentrated processing.
0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for the system holding your RoPA.
3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.
5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.
8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.
10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors, on-premises or sovereign-cloud options, and the whole chain documented publicly.
The External DPO
No sovereignty attributes are on record, and I found no public information on the software vendor's legal entity, hosting region, DPA, or subprocessor list — the page's Dutch address and escrow offer belong to domain-marketplace services rather than an evidenced compliance platform. For the system that would hold my clients' most concentrated records, that silence is disqualifying at this level. 1
The In-House Counsel
The captured imprint names a Dutch company, Nameshift.com in Rijswijk, with KvK and VAT numbers, which is at least a European legal identity, though of a domain marketplace rather than a data protection software house. We found no public information on hosting locations, a data processing agreement, or any subprocessor list, so who would hold our records of processing and under whose law remains undocumented. 1
The Drafted Generalist
The captured footer names Nameshift.com at a Dutch address, which is at least an entity inside the EU, but the same page describes a transfer and escrow arrangement rather than where compliance records would be hosted. We found no public information on hosting, a data processing agreement, or subprocessors, so I cannot tell where a register of my processing would legally live. 1
The Lead Auditor
The page footer carries a Dutch registration — Nameshift.com, KvK 88910652, Steenplaetsstraat 6, Rijswijk — which is an EU entity, and that is the only jurisdictional fact published. We found no public information on hosting locations, a data protection agreement, or subprocessors for the platform that would hold a client's processing record, and the published entity is presented as a domain marketplace, so I credit the EU registration only partially. 1
The IT Integrator
The only legal entity in evidence is Nameshift.com, a Dutch brokerage at Steenplaetsstraat 6, Rijswijk with KvK 88910652 — that is the domain intermediary, not the software publisher; we found no public information on the vendor's own entity, hosting locations, DPA or subprocessors. For the system that would hold a company's records of processing, an unanswerable jurisdiction question is the lowest case. 1
The Skeptic
The only company identified anywhere on the page is Nameshift.com, KvK 88910652, Rijswijk — the Dutch brokerage operating the listing — and we found no public information on the software vendor's own legal entity, hosting region, DPA or subprocessor list. For the system that would hold a buyer's records of processing, that is exactly the situation the lowest description on this scale captures. 1
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real invoice — per module, per entity, per year, with consulting unbundled — from public pages alone. Unpublished pricing is the B2B norm in this market, so this criterion describes rather than condemns; the benches weight it accordingly.
0 — No public prices at all; every configuration is a sales conversation.
3 — An entry price exists, but module add-ons, entity counts or bundled consulting make the real total incomputable.
5 — Most editions carry real numbers with billing period stated and software separated from services; at least one commonly needed module or scale step is unpriced.
8 — Every edition and module priced publicly with entity/user boundaries and setup fees stated; only genuine corporate-group contracts are custom.
10 — Complete price computability: modules, scale steps, service packages and renewal rules public, so the invoice for a 100-employee company and a 10-client consultancy is a two-minute exercise.
The External DPO
The only pricing-adjacent statement on the page is "Our services are completely free for buyers" plus a seller-paid commission, which concerns domain brokerage rather than the software; I found no public information on editions, modules, per-entity costs, or billing period. A buyer cannot compute any invoice for this product from public pages. 1
The In-House Counsel
The only price statement captured — 'Our services are completely free for buyers. The seller pays for our commission.' — prices the marketplace's escrow service, not the data protection software. We found no public figures for editions, modules, entity counts or consulting, so a buyer cannot compute a real invoice. 1
The Drafted Generalist
We found no public prices for the software — no editions, modules, or user tiers of any kind. The only pricing statement captured is that services are "completely free for buyers" with "the seller pays for our commission," which describes the middleman's fees, not a product invoice I could ever compute. 1
The Lead Auditor
The only pricing statements published — "Our services are completely free for buyers. The seller pays for our commission." — apply to the marketplace's escrow service. We found no public information on licence prices, edition or module costs, billing periods or setup fees for the data protection software, so a real invoice cannot be computed from what is public. 1
The IT Integrator
The pricing statements captured are marketplace terms — "Our services are completely free for buyers. The seller pays for our commission." — describing domain purchase fees, not software editions, modules, entity counts or billing periods. We found no public prices for the product itself, so the real software invoice remains a sales conversation. 1
The Skeptic
We found no public prices for software of any kind — no editions, modules, user counts or setup fees. The only commercial terms published are the broker's: 'Our services are completely free for buyers. The seller pays for our commission.' — a commission model for buying a domain, from which no software invoice can be computed. 1
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 29 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- We found no public information on compliance on the pages we read (datafirst.de). If the vendor publishes it somewhere else, send us the page. Know more? Tell us
- 1 pricing fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
Sources (1)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor page datafirst.de Checked 29 Sep 2026 Details →