Data Protection
DataGuard
EU-Made Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 1 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by DataCo GmbH · www.dataguard.de
Compare with OneTrust → Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
No written verdict for this product
The panel scored DataGuard, but the summary our synthesizer wrote did not survive our own contradiction check — twice. Rather than print a paragraph we cannot stand behind, we print none. Every score, rationale and source below is unaffected; read them and draw the conclusion yourself.
The scores
Records & DPIA depth
Show reasoningHide reasoning
How this is scored
The DSMS core: records of processing (RoPA/VVT), data protection impact assessments, processor/DPA management and TOMs — how deeply the legal artifacts are modeled and connected.
0 — Document templates in a folder tree; the "register" is a Word file with version numbers in the filename.
3 — A structured RoPA with basic fields and a DPIA questionnaire, but processors, TOMs and legal bases live outside the system.
5 — RoPA and DPIA as linked modules with templates; processor management and TOM assignment exist but are shallow, and group reuse is copy-paste.
8 — A connected data model — processing activities linked to systems, processors, TOMs and legal bases — with DPIA triggers derived from the record, reusable group templates, and outputs a supervisory authority accepts.
10 — Privacy records as a system of record: the RoPA drives DPIAs, processor management and TOM coverage from one data model, multi-client/mandate capability included, and the documentation is audit-ready without manual assembly.
The External DPO
VVT, DSFA, third-party risk and Maßnahmen are all named features plus a ready-made policy template library, so the core artifacts live in the system — but the evidence shows not one fact about whether they form a connected data model, whether DPIAs trigger from the record, or whether anything is reusable across entities and mandates. For thirty clients I need a RoPA that drives the rest; here I have a feature list, not architecture. 3 7
The In-House Counsel
The GDPR page names Daten-Mapping & VVT, DSFA, third-party risk and Maßnahmen modules, so the DSMS inventory exists on paper, but nothing evidences processing activities linked to legal bases, processors and TOMs in one data model, DPIA triggers derived from the record, or group-reusable templates. Until I see that connected model, I treat this as modules and templates, not a system of record for our register. 3
The Drafted Generalist
Everything on my checklist gets named — Daten-Mapping & VVT, DSFA & Risikobewertungen, Risikomanagement für Drittanbieter, plus a template library with acknowledgement tracking — but nothing shows the RoPA feeding the DPIA or TOMs hanging off processing activities, so I'd assume three modules I re-type between. 3 7 2
The Lead Auditor
The GDPR page names the right modules — Daten-Mapping & VVT, DSFA & Risikobewertungen, Drittanbieter-Risikomanagement, Maßnahmen — but a feature list is not a data model: nothing shows activities linked to processors, TOMs and legal bases, and the 75%-automation claims are ISO-flavored marketing. Modules exist; connection is unevidenced. 3 4
The IT Integrator
The module names are all there — Daten-Mapping & VVT, DSFA & Risikobewertungen, Drittanbieter-Risikomanagement and Maßnahmen, plus policy templates with Bestätigungen & Nachverfolgung — but the evidence never shows they form a connected data model; DPIA triggers from records, legal bases and group reuse are unevidenced, so this is named modules, not linked ones. 3 7
The Skeptic
"Daten-Mapping & VVT" and "DSFA & Risikobewertungen" exist as feature names on the GDPR page, plus a template library with acknowledgements — but TOMs, legal bases, and any linkage between RoPA, DPIA and processors appear nowhere in seven captured pages. That is a feature glossary, not a data model; a structured register with a DPIA module and the rest outside the system is exactly the anchor at 3. 3 7
Data subject rights & incidents
Show reasoningHide reasoning
How this is scored
The operational half of the DSMS: data subject request handling with statutory clocks, breach register and authority notification, deletion concepts that actually delete.
0 — Requests arrive by email and live there; breaches are a phone call and a memo.
3 — A request log and a breach list exist, but deadlines are manual, intake is unstructured, and deletion rules are documentation rather than workflow.
5 — DSR workflows with the Art. 12 clock tracked, structured breach register with the 72-hour clock, deletion concepts assignable to records; automation is reminders.
8 — Intake channels for requests (portal/form), identity-check support, deadline automation with escalation, breach severity assessment and authority-report output, deletion rules tied to the RoPA with execution tracking.
10 — Rights and incidents as operations: end-to-end request handling an authority audit walks through, breach workflows that produce the Art. 33 notification, and deletion automation with evidence that the deletion happened.
The External DPO
'Betroffenenanfragen' and 'Sicherheitsvorfälle und Datenpannen' exist as named features, which puts a request register and breach register in the product. Nothing evidences the Art. 12 clock, the 72-hour clock, structured intake, or deletion concepts that execute — I would be betting statutory deadlines on unnamed functionality. 3
The In-House Counsel
Betroffenenanfragen and Sicherheitsvorfälle/Datenpannen appear as feature names with whistleblowing as an add-on, but the evidence is silent on the Art. 12 clock, the 72-hour clock, intake channels, severity assessment, any Art. 33 notification output — and deletion concepts are not mentioned at all. Names without workflows is a log, not the operational half of a DSMS. 3 7
The Drafted Generalist
'Betroffenenanfragen' and 'Sicherheitsvorfälle und Datenpannen' exist as feature names, but the evidence never mentions a deadline clock, an intake portal, or deletion concepts — deletion isn't even named — so the statutory machinery I'd be relying on is entirely unevidenced. 3 2
The Lead Auditor
Betroffenenanfragen and Sicherheitsvorfälle/Datenpannen exist as named modules, which clears a structured log — but no statutory clock, no intake channel, no authority-notification output, and deletion concepts are entirely absent from the evidence. 3
The IT Integrator
Betroffenenanfragen and Sicherheitsvorfälle/Datenpannen exist as product features and the whistleblowing add-on at least offers an anonymous intake channel, but nothing evidences Art. 12 or 72-hour clocks, deletion concepts tied to the RoPA, or authority-report output — a register with deadlines that live in someone's calendar. 3 7
The Skeptic
"Betroffenenanfragen" and "Sicherheitsvorfälle und Datenpannen" appear only as bullet names — no statutory clock, no 72-hour workflow, no intake portal, no identity check, and the word 'deletion' never occurs anywhere in the evidence. A request log and a breach list is precisely what the anchor at 3 describes. 3
Privacy regime coverage
Show reasoningHide reasoning
How this is scored
Which privacy regimes the product actually operationalizes — GDPR, BDSG, Swiss nDSG, UK GDPR, ePrivacy, EU AI Act privacy duties — and whether one record maps across them or each regime is a fresh island.
0 — One regime, hard-coded; anything else is "on the roadmap".
3 — GDPR plus one national law as separate checklists; the same processing activity is documented once per regime.
5 — The major regimes for its market with partial cross-mapping; newer duties (AI Act, ePrivacy changes) present as content packs of varying depth.
8 — Broad current coverage with one-record-many-regimes mapping and visible maintenance as regimes evolve.
10 — Regime coverage as a living product: multiple privacy regimes on one data basis, per-country variants, and documented update cadence when the law moves.
The External DPO
DSGVO and the EU AI Act are supported alongside ISO 27001, TISAX and NIS2, so GDPR is not a hard-coded island and the newest duty is at least on the list. But no BDSG specifics, no UK GDPR, no Swiss nDSG, no ePrivacy word beyond a cookie module, and nothing on whether one record maps across regimes or how updates are shipped — a gap for cross-border mandates. 2 5
The In-House Counsel
The supported list is DSGVO, ISO 27001, TISAX, NIS2 and the EU AI Act — workable for a purely German group, but no Swiss nDSG, UK GDPR, ePrivacy or BDSG variant appears, and there is no evidence one record maps across regimes rather than each framework being its own preparation track. The '50 countries served' claim makes that privacy-regime gap worse, not better. 2 5
The Drafted Generalist
DSGVO plus the EU AI Act are supported and the cookie/consent features nod at ePrivacy duties, but there's no BDSG, Swiss nDSG or UK GDPR anywhere, and no evidence one record maps across regimes — serving 50 countries is not the same as covering their laws. 2 3 5
The Lead Auditor
The supported list is DSGVO, ISO 27001, TISAX, NIS2, EU AI Act — the privacy half of that is GDPR alone: no BDSG, no nDSG, no UK GDPR, no ePrivacy, and '50 Länder' ships with zero per-country variants. GDPR plus AI Act duties is a content-pack story at best, with no cross-mapping evidence. 5 2 3
The IT Integrator
DSGVO and the EU AI Act sit alongside ISO 27001, TISAX and NIS2 on one platform, which is broader than a single-regime island, but no BDSG, Swiss nDSG, UK GDPR or ePrivacy variant appears, and nothing shows one record mapping across regimes rather than being re-documented per framework. 2 5
The Skeptic
The frameworks list is DSGVO plus four security regimes (ISO 27001, TISAX, NIS2) and an AI Act mention — exactly one actual privacy law, no BDSG, no Swiss nDSG, no UK GDPR, and no evidence a record maps across regimes. The TISAX badge comes with a disclaimer that DataGuard has no business relationship with ENX — the certification logo that links nowhere. 2 3 5
Audit readiness & evidence
Show reasoningHide reasoning
How this is scored
Whether the system produces defensible proof: revision-safe history, evidence collection, reports for auditors, authorities and management.
0 — Exports are screenshots; history is overwritten in place.
3 — PDF reports exist but evidence is attached ad hoc and changes leave no reliable trail.
5 — Versioned records, standard report generators for the core registers, evidence attachments per activity; assembling a full audit file still takes days.
8 — Revision-safe change history, audit-scoped evidence packs on demand, management and authority reports current at a click, auditor access roles.
10 — Audit readiness as a standing state: continuous documentation status per regime and scope, exportable proof packs an auditor accepts as-is, and a defensible answer to "show me the state on date X".
The External DPO
Reporting, 'fortlaufendes Monitoring' and 'strukturierte Nachweise' are claimed, the ISMS module tracks confirmations, and the vendor waves a 100% first-audit pass rate — a marketing number, not evidence. No revision-safe change history, no evidence packs, no auditor access roles, no answer to 'show me the state on date X'. 2 3 4 7
The In-House Counsel
What I can point to is a template collection with confirmations and tracking, a Reporting & Visualisierungen module, and vendor-reported claims of a 100% first-attempt audit pass rate — which is marketing, not proof. Nothing on revision-safe change history, audit-scoped evidence packs, or answering an authority's 'show me the state on date X'. 7 3 2 4
The Drafted Generalist
The 100%-first-attempt audit claim and 'strukturierte Nachweise' sound nice, and reporting plus acknowledgement tracking are named, but nothing shows revision-safe change history or on-demand evidence packs — a success rate is marketing, not a paper trail I can hand an auditor. 2 3 4 7
The Lead Auditor
'Reporting & Visualisierungen' and the 100% first-attempt audit claims describe outcomes, not trail: no revision-safe history, no evidence packs on demand, no auditor roles, and no answer to 'show me the state on date X' anywhere in the evidence. Policy 'Bestätigungen & Nachverfolgung' is the only trail-adjacent feature, and it lives in a template library. 3 4 7 2
The IT Integrator
What I have are marketing pass rates — 100% first-attempt ISO 27001/TISX audit success — plus a Reporting & Visualisierungen feature, which tells me nothing about revision-safe change history, evidence packs on demand, auditor roles or a date-X query; claims of audit outcomes are not audit capability. 1 4 3
The Skeptic
"Reporting & Visualisierungen" and templates with "Bestätigungen & Nachverfolgung" suggest report generators, but the entire audit story rests on unsubstantiated marketing numbers: 100% first-attempt success and "alle Kunden" passing ISO 27001 and TISAX audits first try. No revision-safe history, no evidence packs, no auditor access role anywhere in the evidence. 2 3 4 7
Integrations & automation
Show reasoningHide reasoning
How this is scored
Whether the platform feeds from the real IT estate — directory import, ticketing, API — and automates the recurring privacy work instead of re-typing it.
0 — A closed island: manual entry in, PDF out, no API.
3 — CSV/Excel import and export; no live connections, no API worth the name.
5 — Directory import (AD/Entra), a documented REST API for core objects, a handful of native connectors (ticketing or SSO); automation is reminders and recurrence.
8 — Real connector set (ticketing, HR or asset sources), webhooks, SSO/SCIM, workflow automation with delegation and escalation, useful AI assistance with human review.
10 — The platform behaves like infrastructure: API parity for the data model, event streams, bidirectional sync with the estate, and automation that measurably removes the recurring toil (reviews, attestations, evidence pulls) rather than renaming it.
The External DPO
'Integrationen & APIs' ship in the Base plan, with SSO and KI-gestützte Automatisierung named, which is more than a closed island. But not one connector, directory import, webhook, or API document is identified anywhere — with thirty client estates to feed, 'Integrationen' as a bare word is nothing I can bill against. 3 7
The In-House Counsel
'Integrationen & APIs' is a checkbox on the Base plan and SSO with granular roles is confirmed, but no directory import, named connectors, webhooks, SCIM or API documentation appear anywhere, and the 40%/75% automation figures are unanchored marketing numbers. A platform I cannot verify pulls from AD and our ticketing means my team re-types the IT estate into the RoPA. 7 1 4 3
The Drafted Generalist
'Integrationen & APIs' ship even on the Base plan with SSO and granular roles, and the AI-automation claims (up to 40% of tasks) beat plain reminders — but not a single connector is named, no directory, ticketing or HR source, and no API documentation, so I can't tell what I'd still be hand-entering. 7 3 1
The Lead Auditor
'Integrationen & APIs' ships in Base with SSO and granular roles, and AI automation is claimed at up to 40% of tasks — but not a single named connector, no directory import, no documented REST objects, no webhooks or SCIM. Claimed capability with nothing named. 7 3 1 2
The IT Integrator
"Integrationen & APIs" as a Base-plan bullet and SSO with granular roles are confirmed, but there is no evidence of directory import, SCIM, webhooks, a documented REST API for core objects, or a single named connector to ticketing, HR or asset sources — Datenmigration in the Pro plan is a service, not a sync, and that's a data island with a drawbridge I can't verify. 7 3
The Skeptic
"Integrationen & APIs" and "KI-gestützte Automatisierung" are listed as plan inclusions, yet not a single named connector, documented API, webhook, SCIM or directory import appears anywhere — 'AI-powered automation' with nothing behind the label. SSO and granular roles are real but modest; a closed island with an API claim not worth the name sits at 3. 7 3
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where the compliance record of the whole company actually lives and under whose law — entity, hosting, subprocessors, DPA. A platform that maps your processing is itself your most concentrated processing.
0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for the system holding your RoPA.
3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.
5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.
8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.
10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors, on-premises or sovereign-cloud options, and the whole chain documented publicly.
The External DPO
The imprint confirms a German GmbH in Munich with register court, HRB number and VAT ID, so the contracting entity is European — the one solid fact in the registry. Hosting location, subprocessor list, DPA and TOMs are entirely absent from the evidence, and US/UK VCs sit in the ownership unverified; for the platform that would hold my clients' RoPAs, that silence is disqualifying at this stage. 6
The In-House Counsel
The imprint gives me a German GmbH at Amtsgericht München — an EU entity — and that is the entire chain I can verify: no hosting location, no data residency, no subprocessor list, and no DPA anywhere in the evidence, with ownership marked unknown. For the system that would hold our most concentrated processing record, an EU letterhead with an undocumented processing chain is not something I can defend to a supervisor. 6 5
The Drafted Generalist
The imprint confirms a real German GmbH with a Munich register entry and VAT ID, but that's where the chain goes dark: no hosting location, no DPA, no subprocessor list anywhere in the evidence, and the provenance note flags US/UK investors pending verification — a thin answer for the system that would hold my entire RoPA. 6 5
The Lead Auditor
The imprint nails a German GmbH — HRB 235942 München, DE VAT — and beyond that the evidence is silent: no hosting location, no published DPA, no subprocessor list for the platform that would hold my RoPA. An EU entity with a fully undocumented chain beats rubric level 0 but is nowhere near rubric level 3's published DPA, and the US VC exposure flagged in provenance is unverified. 6 5
The IT Integrator
The imprint confirms a real German entity — DataCo GmbH, Amtsgericht München HRB 235942, DE VAT — which is more than nothing, but hosting location, DPA, subprocessor list and TOMs are entirely absent from the captured pages, and the ownership sits with UK/US VC backers; this is an EU letterhead with an undocumented processing chain. 6 5
The Skeptic
The imprint confirms a German GmbH (Munich, HRB 235942, Amtsgericht München) — and that is the entire sovereignty story: hosting location, subprocessor list and a DPA appear on none of the captured pages, with US/UK VC money in the background per the provenance note. For the system that would hold your RoPA, an entirely dark processing chain keeps this at the bottom of the scale, nudged off zero only by the confirmed EU entity. 6 1
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real invoice — per module, per entity, per year, with consulting unbundled — from public pages alone. Unpublished pricing is the B2B norm in this market, so this criterion describes rather than condemns; the benches weight it accordingly.
0 — No public prices at all; every configuration is a sales conversation.
3 — An entry price exists, but module add-ons, entity counts or bundled consulting make the real total incomputable.
5 — Most editions carry real numbers with billing period stated and software separated from services; at least one commonly needed module or scale step is unpriced.
8 — Every edition and module priced publicly with entity/user boundaries and setup fees stated; only genuine corporate-group contracts are custom.
10 — Complete price computability: modules, scale steps, service packages and renewal rules public, so the invoice for a 100-employee company and a 10-client consultancy is a two-minute exercise.
The External DPO
A public pricing page exists with a Base/Pro split and named add-ons (Whistleblowing, external ISB, external DSB), so the taxonomy is visible. But not one euro figure is evidenced anywhere, the Pro tier bundles expert services instead of unbundling them, and 'bis zu 50% günstiger als externe Berater' is a comparative slogan — the invoice for a 10-client consultancy is incomputable. 7 4
The In-House Counsel
The pricing page shows a Base/Pro tier structure and unbundled add-ons — whistleblowing, external DSB, external ISB — but the evidence contains not one euro figure; the only pricing-adjacent number is 'up to 50% cheaper than external consultants', which prices nothing. Plan names without figures plus expert-service add-ons mean the real invoice is incomputable from public pages alone. 7 4
The Drafted Generalist
The pricing page at least names the Base and Pro tiers with their contents and add-ons like the external DPO, so I know the shape of the quote — but not one euro figure exists anywhere, only a 'up to 50% cheaper than consultants' claim, so the real invoice is a sales conversation. 7 4
The Lead Auditor
The pricing page publishes the plan architecture — Base/Pro contents, Whistleblowing as an add-on, external DSB/ISB visibly unbundled as services — and not one number: no prices, no billing period, no user or entity boundaries. '50% günstiger als externe Berater' is a discount on an unpublished base, so the real invoice stays a sales conversation. 7 4
The IT Integrator
The pricing page publishes the plan shape — Base and Pro tiers with named add-ons like Whistleblowing, Externer DSB and Externer ISB — but not a single price, billing period or user/entity boundary; the only number anywhere is "up to 50% cheaper than external consultants," so the real invoice is computable only through a sales call. 7 4
The Skeptic
The pricing page names Base and Pro and what each contains but not one currency figure — the only price signal on the entire site is "bis zu 50 % günstiger als externe Berater", a slogan, not an invoice. Worse, Pro bundles experts, data migration and an external ISB: consulting sold as a software tier, so the real total is computable by nobody but sales. 7 4
European sovereignty — proven facts
1 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Incorporated in DE | 3/3 pts | 6 Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | Not determined | — | uncited Report an error |
| Subprocessors | Not determined | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 15 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- We could not confirm any pricing information on the vendor’s own pages as captured, so this page shows none rather than a statement we cannot stand behind. Know more? Tell us
- 21 subprocessors facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 4 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 integrations fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
- The panel’s written verdict is withheld: our own re-read found claims in it that the evidence does not carry, and a second synthesis did not fix them. The scores and the material below are unaffected. Know more? Tell us
Sources (18)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage (DE) www.dataguard.de Checked 15 Sep 2026 Details →
- 2 Platform/product page www.dataguard.de Checked 15 Sep 2026 Details →
- 3 GDPR framework page www.dataguard.de Checked 15 Sep 2026 Details →
- 4 ISO 27001 framework page www.dataguard.de Checked 15 Sep 2026 Details →
- 5 About page www.dataguard.de Checked 15 Sep 2026 Details →
- 6 Imprint www.dataguard.de Checked 15 Sep 2026 Details →
- 7 Vendor pricing page www.dataguard.de Checked 15 Sep 2026 Details →
- 8 Privacy policy www.dataguard.de Checked 30 Sep 2026 Details →
- 9 Records & DPIA depth — found from sitemap www.dataguard.de Checked 1 Oct 2026 Details →
- 10 Records & DPIA depth — found from sitemap www.dataguard.de Checked 1 Oct 2026 Details →
- 11 Data subject rights & incidents — found from sitemap www.dataguard.de Checked 1 Oct 2026 Details →
- 12 Data subject rights & incidents — found from sitemap www.dataguard.de Checked 1 Oct 2026 Details →
- 13 Privacy regime coverage — found from sitemap www.dataguard.de Checked 1 Oct 2026 Details →
- 14 Privacy regime coverage — found from sitemap www.dataguard.de Checked 1 Oct 2026 Details →
- 15 Audit readiness & evidence — found from sitemap www.dataguard.de Checked 1 Oct 2026 Details →
- 16 Audit readiness & evidence — found from sitemap www.dataguard.de Checked 1 Oct 2026 Details →
- 17 Integrations & automation — found from sitemap www.dataguard.de Checked 1 Oct 2026 Details →
- 18 Integrations & automation — found from sitemap www.dataguard.de Checked 1 Oct 2026 Details →