Data Protection
DocSetMinder ONE
EU-Made Report an error0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Allgeier CyRis GmbH · www.allgeier-cyris.de
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
DocSetMinder ONE is an integrated management system from Allgeier CyRis GmbH, a German GmbH registered at Amtsgericht Bremen (HRB 37552 HB) and formed in 2023 from Allgeier group units. The bench scores it highest on framework coverage and sovereignty: the product bundles BSI IT-Grundschutz, ISO 27001, BCM per BSI 200-4 and EU-DSGVO in one system, and the imprint puts a German entity and German VAT ID on the record — though judges found no public information on hosting, a data processing agreement or a subprocessor list. The lowest scores go to integrations and automation, where judges found no public information on an API, directory import or SSO, and to rights and incidents, which sits at 1 because the only incident offering captured is a managed security service, not a product workflow. EU-DSGVO is the only privacy regime the captured pages name. Privacy management and audit readiness spread by one point; the bench computed no disagreements. No prices appear on any captured page.
Speaks for it
- Bundles BSI IT-Grundschutz, ISO 27001, BCM per BSI 200-4 and EU-DSGVO in one integrated management system
- Imprint documents a German GmbH at Amtsgericht Bremen (HRB 37552 HB) with German VAT ID DE351887674
- Group-wide license terms run under German Allgeier SE framework conditions, a defensible starting point for the in-house counsel
- The integrated framing suggests a shared documentation basis across security, continuity and privacy standards
Held against it
- The captured GDPR evidence is one bundled-standards sentence, with no public information found on records of processing, DPIAs, processors or TOMs
- EU-DSGVO is the only privacy regime the captured pages name, the bundle-mates being security and continuity frameworks
- Incident response is captured only as a managed security service, with no public information found on data subject request intake, statutory clocks or a breach register
- No public information was found on an API, directory import, ticketing connectors, SSO or workflow automation, the only captured delivery modes concerning the awareness program
- No public information was found on hosting location, a data processing agreement or a subprocessor list for the system that would hold the register
Best for
- You want one system documenting BSI IT-Grundschutz, ISO 27001, BCM and EU-DSGVO together rather than separate standards folders
- Your procurement requires a documented German legal entity with a German commercial register entry and group-wide German license terms
- You would take incident response, awareness training with phishing simulations and audit support as managed services from the same vendor
Avoid if
- You need the product itself to run data subject request intake and breach notification — the only incident capability captured is a human managed service
- You operate under more than one privacy regime — the captured pages name EU-DSGVO alone
- You expect the platform to sync with your directory, ticketing or SSO — the captured delivery modes concern only the awareness program
The scores
Records & DPIA depth
Show reasoningHide reasoning
How this is scored
The DSMS core: records of processing (RoPA/VVT), data protection impact assessments, processor/DPA management and TOMs — how deeply the legal artifacts are modeled and connected.
0 — Document templates in a folder tree; the "register" is a Word file with version numbers in the filename.
3 — A structured RoPA with basic fields and a DPIA questionnaire, but processors, TOMs and legal bases live outside the system.
5 — RoPA and DPIA as linked modules with templates; processor management and TOM assignment exist but are shallow, and group reuse is copy-paste.
8 — A connected data model — processing activities linked to systems, processors, TOMs and legal bases — with DPIA triggers derived from the record, reusable group templates, and outputs a supervisory authority accepts.
10 — Privacy records as a system of record: the RoPA drives DPIAs, processor management and TOM coverage from one data model, multi-client/mandate capability included, and the documentation is audit-ready without manual assembly.
The External DPO
The only product evidence is a single line that the GDPR sits in an integrated management system alongside BSI IT-Grundschutz, ISO 27001 and BCM; we found no public information on a structured records of processing register, DPIA workflow, processor register or TOM linkage. Across thirty mandates that surface is what I bill hours against, and nothing captured here evidences it. 2 3
The In-House Counsel
The captured product page names EU-DSGVO as one of four standards bundled into an integrated management system, with data protection otherwise appearing as consulting services; we found no public information on records of processing, DPIA tooling, processor management or TOMs being modeled in the product. Without a modeled register I cannot keep the record of processing defensible in one place, so this sits at the document-folder end of the scale. 2 3
The Drafted Generalist
The product page describes an integrated management system that bundles EU-DSGVO alongside BSI IT-Grundschutz, ISO 27001 and BCM as standards, and that is all I can see of the privacy core — I found no public information on a structured record of processing, DPIA workflows, processor management or TOMs. Nothing on these pages evidences guided register-keeping; GDPR appears as a bundled standard, not as modeled legal artifacts. 2
The Lead Auditor
The captured product description bundles EU-DSGVO alongside BSI IT-Grundschutz, ISO 27001 and BCM in one integrated management system, which is the extent of the privacy-record evidence. We found no public information on records of processing, DPIA support, processor or TOM management, so the legal artifacts' modeling depth cannot be assessed beyond the single sentence. 2
The IT Integrator
The product page carries exactly one sentence of positioning — GDPR as one of four standards inside an integrated management system — and nothing more, so I found no public information on how records of processing, DPIAs, processors or TOMs are modeled. It is a software system rather than a folder of documents, which puts it above the floor, but the depth of the privacy core is entirely unevidenced. 2
The Skeptic
The entire GDPR evidence is one sentence bundling EU-DSGVO with BSI IT-Grundschutz, ISO 27001 and BCM into an integrated management system, with nothing further captured. We found no public information on records of processing, DPIA workflows, processor management or TOMs, and the data protection page that was captured sits under a consulting heading — advisory material where software evidence should be. 2 3
Data subject rights & incidents
Show reasoningHide reasoning
How this is scored
The operational half of the DSMS: data subject request handling with statutory clocks, breach register and authority notification, deletion concepts that actually delete.
0 — Requests arrive by email and live there; breaches are a phone call and a memo.
3 — A request log and a breach list exist, but deadlines are manual, intake is unstructured, and deletion rules are documentation rather than workflow.
5 — DSR workflows with the Art. 12 clock tracked, structured breach register with the 72-hour clock, deletion concepts assignable to records; automation is reminders.
8 — Intake channels for requests (portal/form), identity-check support, deadline automation with escalation, breach severity assessment and authority-report output, deletion rules tied to the RoPA with execution tracking.
10 — Rights and incidents as operations: end-to-end request handling an authority audit walks through, breach workflows that produce the Art. 33 notification, and deletion automation with evidence that the deletion happened.
The External DPO
The incident-response page describes a managed security service where consultants deliver preparation, retainer and response — a human offering, and cyber-focused at that. We found no public information on data subject request intake, statutory clocks, a 72-hour breach register or deletion execution inside the product. 8
The In-House Counsel
The only incident capability evidenced is Incident Response sold as a managed security service — retainer, preparation, response — a human cyber service rather than a statutory breach workflow; we found no public information on data subject request handling, statutory clocks, a breach register or authority notification output. I judge this on whether the workflow produces the Art. 33 notification, and nothing captured speaks to that. 2 8
The Drafted Generalist
The only incident-related offering I can find is Incident Response sold as a managed security service with retainer — consultants, not software — and I found no public information on data subject request handling, statutory deadline clocks, a breach register or deletion tracking. The operational half of GDPR, the part that arrives with a clock attached, is invisible on the captured pages. 8
The Lead Auditor
The only incident-related evidence is incident response delivered as a managed service by the vendor's security practice, which is a human retainer offering rather than a product workflow for statutory clocks or authority notification. We found no public information on data subject request handling, breach registers, or deletion concepts tied to privacy records. 2 8
The IT Integrator
The only incident-related offering captured is incident response and readiness delivered as a managed security service — a human retainer, not a product workflow for data subject requests or breach notification. I found no public information on request intake, statutory deadline tracking, a breach register, or deletion execution. 8
The Skeptic
The only incident-related capture sells "Incident Response & Readiness" as a managed service by an MSSP with preparation, retainer and response — a human service contract, not a product workflow with a 72-hour clock or authority-report output. We found no public information on data subject request intake, deadline tracking, a breach register, or deletion rules and their execution. 8
Privacy regime coverage
Show reasoningHide reasoning
How this is scored
Which privacy regimes the product actually operationalizes — GDPR, BDSG, Swiss nDSG, UK GDPR, ePrivacy, EU AI Act privacy duties — and whether one record maps across them or each regime is a fresh island.
0 — One regime, hard-coded; anything else is "on the roadmap".
3 — GDPR plus one national law as separate checklists; the same processing activity is documented once per regime.
5 — The major regimes for its market with partial cross-mapping; newer duties (AI Act, ePrivacy changes) present as content packs of varying depth.
8 — Broad current coverage with one-record-many-regimes mapping and visible maintenance as regimes evolve.
10 — Regime coverage as a living product: multiple privacy regimes on one data basis, per-country variants, and documented update cadence when the law moves.
The External DPO
EU-GDVO is the only privacy regime named anywhere in the captured pages; the genuinely interesting claim of four standards in one system covers IT-Grundschutz, ISO 27001 and BCM rather than privacy-law variants. We found no public information on BDSG specifics, Swiss nDSG, UK GDPR, or one-record-many-regimes mapping. 2
The In-House Counsel
Exactly one privacy regime, EU-DSGVO, is named, bundled alongside BSI IT-Grundschutz, ISO 27001 and BCM; we found no public information on BDSG, Swiss or UK variants, ePrivacy or AI Act privacy duties, nor on whether one processing record maps across regimes. Legal content nobody visibly maintains is a liability for any company operating in more than one jurisdiction. 2 3
The Drafted Generalist
EU-DSGVO appears as one of four standards bundled in the management system, and the other three are security and continuity frameworks rather than privacy regimes; no BDSG, Swiss, UK or AI Act duties appear anywhere I can see. The integrated framing suggests standards share one home, but nothing shows one record mapping across privacy regimes or being maintained as regimes evolve. 2
The Lead Auditor
One privacy regime, EU-DSGVO, is named, integrated with security and continuity standards in a single system, which suggests a shared documentation basis across framework families. We found no public information on other privacy regimes such as Swiss or UK law, ePrivacy duties, or how one processing record maps across regimes, so coverage beyond GDPR is not evidenced. 2
The IT Integrator
EU-DSGVO is named alongside BSI IT-Grundschutz, ISO 27001 and BCM in one integrated management system, but the other three are security and continuity frameworks, not privacy regimes — GDPR is the only one evidenced. I found no public information on BDSG, Swiss nDSG, UK GDPR, ePrivacy or AI Act duties, nor on whether a single processing record maps across regimes. 2
The Skeptic
EU-DSGVO is the only privacy regime the product description names; its bundle-mates are BSI IT-Grundschutz, ISO 27001 and BCM, which are security and continuity frameworks rather than privacy regimes. The integrated management system claim is a single sentence with no detail captured, and we found no public information on national law variants, one-record-many-regimes mapping, or AI Act duties. 2
Audit readiness & evidence
Show reasoningHide reasoning
How this is scored
Whether the system produces defensible proof: revision-safe history, evidence collection, reports for auditors, authorities and management.
0 — Exports are screenshots; history is overwritten in place.
3 — PDF reports exist but evidence is attached ad hoc and changes leave no reliable trail.
5 — Versioned records, standard report generators for the core registers, evidence attachments per activity; assembling a full audit file still takes days.
8 — Revision-safe change history, audit-scoped evidence packs on demand, management and authority reports current at a click, auditor access roles.
10 — Audit readiness as a standing state: continuous documentation status per regime and scope, exportable proof packs an auditor accepts as-is, and a defensible answer to "show me the state on date X".
The External DPO
The audit-related pages are consultancy offers — cyber security audits and certification support performed by Allgeier people — rather than evidence that the product itself generates revision-safe history, evidence packs or authority-ready reports. We found no public information on change tracking, audit-scoped exports or auditor access; as a consultancy I need client-ready output at a click, and I cannot see any here. 9 10 2
The In-House Counsel
Audits and certifications appear as services the vendor delivers rather than evidence features of the product; we found no public information on revision-safe change history, evidence packs, auditor access roles, or report generation for authorities and management. "Show me the state on date X" needs a product answer, and I found none. 2 9 10
The Drafted Generalist
The vendor sells cyber security audits and certification services, and the product exists to run management systems for certifiable standards, but I found no public information on revision-safe history, report generators, evidence packs or auditor outputs from the software itself. What an auditor would actually receive from this system is not shown on any captured page. 2 9 10
The Lead Auditor
The audit pages captured are consulting services — cyber security audits and certification support — and the product pitch is an IMS for auditable standards, but no page shows the product producing the proof itself. We found no public information on revision-safe change history, evidence collection, report generators, or auditor access, so I cannot credit audit readiness beyond an orientation toward audit-driven standards. 2 9 10
The IT Integrator
An integrated management system spanning multiple standards implies standardized documentation, but that is positioning, not proof of defensible output. I found no public information on revision-safe change history, on-demand evidence packs, auditor access roles, or report generation for the product. 2
The Skeptic
The audit-oriented pages captured are service pages — a cyber security audit and a certifications-and-audits offering — with no product facts underneath them. We found no public information on revision-safe change history, report generators, evidence packs or auditor access; the integrated management system sentence gives no audit-output detail to evaluate. 9 10 2
Integrations & automation
Show reasoningHide reasoning
How this is scored
Whether the platform feeds from the real IT estate — directory import, ticketing, API — and automates the recurring privacy work instead of re-typing it.
0 — A closed island: manual entry in, PDF out, no API.
3 — CSV/Excel import and export; no live connections, no API worth the name.
5 — Directory import (AD/Entra), a documented REST API for core objects, a handful of native connectors (ticketing or SSO); automation is reminders and recurrence.
8 — Real connector set (ticketing, HR or asset sources), webhooks, SSO/SCIM, workflow automation with delegation and escalation, useful AI assistance with human review.
10 — The platform behaves like infrastructure: API parity for the data model, event streams, bidirectional sync with the estate, and automation that measurably removes the recurring toil (reviews, attestations, evidence pulls) rather than renaming it.
The External DPO
We found no public information on an API, directory import, ticketing connectors, SSO or any workflow automation for the product; the self-service versus managed-service modes captured on the pages concern the awareness offering, not DocSetMinder ONE. Manual re-entry across thirty clients is exactly the cost I exist to eliminate, and nothing captured evidences tooling against it. 2 7
The In-House Counsel
We found no public information on an API, directory import, ticketing connectors or SSO for the product; the captured pages describe delivery self-service or as a managed service, which puts the automation in the vendor's service organization rather than in the software. For my side that means re-typing the processing estate by hand. 2 7
The Drafted Generalist
I found no public information on an API, directory import, ticketing connections or workflow automation anywhere in the captured pages — the only modes described are taking the awareness program as self-service or as a managed service, which is a service choice, not a connection to our IT estate. Nothing here suggests the platform feeds from anything but manual entry. 2 7
The Lead Auditor
The only delivery-model evidence concerns the awareness program, offered as self-service or as a managed service — meaning the vendor's staff, not system integrations, carries the recurring work. We found no public information on APIs, directory import, ticketing or SSO connectors, or workflow automation in the product. 2 7
The IT Integrator
I found no public information on an API, directory import, ticketing or HR connectors, SSO, SCIM or webhooks for DocSetMinder ONE — nothing that would let the compliance record stay current by syncing with the directory, ticketing or CMDB that already exists. The only deployment statement captured describes the security-awareness program in self-service or managed-service mode, which concerns service delivery, not data integration. 2 7
The Skeptic
No capture mentions an API, directory import, SSO, webhooks or connectors of any kind; the only delivery choice evidenced is self-service or managed service for an awareness program with phishing simulations and KPI reporting. We found no public information on any automation beyond that managed-service wrapper. 7
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where the compliance record of the whole company actually lives and under whose law — entity, hosting, subprocessors, DPA. A platform that maps your processing is itself your most concentrated processing.
0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for the system holding your RoPA.
3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.
5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.
8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.
10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors, on-premises or sovereign-cloud options, and the whole chain documented publicly.
The External DPO
The imprint confirms a German GmbH registered at the Bremen court and part of a German group, which is the right starting point. But we found no public information on hosting location, named data centers, a DPA or a subprocessor list — and for the system that would hold my clients' entire records of processing, that silence decides it. 6 4
The In-House Counsel
The imprint confirms a German GmbH in Bremen with a commercial-register entry and German VAT ID, part of the Allgeier group with license terms running through Allgeier SE's German framework — a defensible starting point. But we found no public information on hosting location, data residency, a data processing agreement or a subprocessor list, and a platform that would hold my register is my most concentrated processing; an undocumented chain I will not sign. 4 5 6
The Drafted Generalist
The imprint documents a German GmbH in Bremen with a Bremen commercial register entry and German VAT ID, formed in a 2023 merger of German Allgeier group units — the European entity itself is solid. But I found no public information on hosting location, data centers, subprocessors, or a published data processing agreement, so the chain that would hold my compliance record is only half documented. 4 6
The Lead Auditor
A German GmbH with a Bremen commercial register entry, German VAT identification, and group linkage to Allgeier SE is well evidenced, and the license terms run under German group-wide conditions. But we found no public information on hosting locations, data centers, a data processing agreement, or a subprocessor list — for a system that would hold the privacy record, that chain is undocumented in the captures. 4 5 6
The IT Integrator
The imprint settles entity jurisdiction — a German GmbH registered at Amtsgericht Bremen, formed in 2023 from units of the German Allgeier group — but I found no public information on hosting locations, a DPA, TOMs, or a subprocessor list. For a platform meant to hold the register of processing, that undocumented chain is material even with a clean German entity. 4 6
The Skeptic
The imprint does give a German entity — Allgeier CyRis GmbH, Amtsgericht Bremen HRB 37552 HB, VAT DE351887674 — formed in 2023 from units of the Allgeier group, so the entity side is European and on the record. But we found no public information on hosting location, a data processing agreement, or any subprocessor list, and the license terms describe only their scope over Allgeier-affiliated contracts rather than the processing chain for the system that would hold your records. 6 4 5
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real invoice — per module, per entity, per year, with consulting unbundled — from public pages alone. Unpublished pricing is the B2B norm in this market, so this criterion describes rather than condemns; the benches weight it accordingly.
0 — No public prices at all; every configuration is a sales conversation.
3 — An entry price exists, but module add-ons, entity counts or bundled consulting make the real total incomputable.
5 — Most editions carry real numbers with billing period stated and software separated from services; at least one commonly needed module or scale step is unpriced.
8 — Every edition and module priced publicly with entity/user boundaries and setup fees stated; only genuine corporate-group contracts are custom.
10 — Complete price computability: modules, scale steps, service packages and renewal rules public, so the invoice for a 100-employee company and a 10-client consultancy is a two-minute exercise.
The External DPO
We found no public information on pricing — no edition, module, licensing or scale figures on either the product page or the license-terms page. Every configuration is therefore a sales conversation, which is the bottom of the scale by its own definition; budgeting thirty client mandates from these pages is impossible. 2 5
The In-House Counsel
No price appears on any captured page; the product is offered self-service or as a managed service including planning, roll-out and reporting, which mixes software with services, and we found no public information on licence, module or service pricing. Every configuration is a sales conversation. 2 7
The Drafted Generalist
No price, edition or scale figure appears anywhere in the captured pages, and the only pricing-adjacent document — the license terms — states that exceptions are individually agreed, which makes every real configuration a sales conversation. As a buyer I cannot compute even a starting invoice from public information. 5 7
The Lead Auditor
No price figure of any kind appears on the captured product page or in the license terms, which state only that group-wide terms apply with individually agreed exceptions. A buyer can compute nothing from public pages; every configuration is a conversation. 2 5
The IT Integrator
No price figures appear on any captured page; the license terms define contractual scope for Allgeier-affiliated companies without any numbers attached. I found no public pricing at all, so the real invoice cannot be computed from public sources — an entry price would at least anchor the conversation. 2 5
The Skeptic
We found no public prices in any capture — no edition, module, per-user or service figures of any kind — and the captured license terms state only their scope over Allgeier-affiliated contracts without naming a price. Unpublished pricing is the norm in this market, but a buyer reading these pages has nothing to compute an invoice from. 5
European sovereignty — proven facts
0 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined ⚠ unverified | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined ⚠ unverified | — | uncited Report an error |
| Data residency | Not determined ⚠ unverified | — | uncited Report an error |
| Subprocessors | Not determined | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 15 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Ownership, Data residency, Legal entity. Not confirmed on the vendor’s own pages as captured.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- We could not confirm any pricing information on the vendor’s own pages as captured, so this page shows none rather than a statement we cannot stand behind. Know more? Tell us
- We could not confirm any compliance information on the vendor’s own pages as captured, so this page shows none rather than a statement we cannot stand behind. Know more? Tell us
- 80 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 8 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 6 support facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 4 data facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 hosting facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 integrations fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 3 sovereignty dimensions could not be confirmed on the vendor’s own pages and are shown as unknown. Know more? Tell us
Sources (10)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage www.allgeier-cyris.de Checked 15 Sep 2026 Details →
- 2 Product page www.allgeier-cyris.de Checked 15 Sep 2026 Details →
- 3 Data protection services page www.allgeier-cyris.de Checked 15 Sep 2026 Details →
- 4 About page www.allgeier-cyris.de Checked 15 Sep 2026 Details →
- 5 License terms www.allgeier-cyris.de Checked 15 Sep 2026 Details →
- 6 Imprint www.allgeier-cyris.de Checked 15 Sep 2026 Details →
- 7 Security / trust page www.allgeier-cyris.de Checked 30 Sep 2026 Details →
- 8 Data subject rights & incidents — found from sitemap www.allgeier-cyris.de Checked 1 Oct 2026 Details →
- 9 Audit readiness & evidence — found from sitemap www.allgeier-cyris.de Checked 1 Oct 2026 Details →
- 10 Audit readiness & evidence — found from sitemap www.allgeier-cyris.de Checked 1 Oct 2026 Details →