Data Protection
DS|Datenschutz+KI
EU-Made Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 1 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by DATA Security GmbH · data-security.one
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
DS|Datenschutz+KI is the data protection module of DATA Security GmbH, a Kolbermoor-based German vendor holding ISO 27001, 37301 and 9001 certificates. Audit readiness is the bench's strength at 6-7: every change is recorded with timestamp and user, access requires two-factor authentication, and supervisory-authority-ready documentation is generated automatically. Privacy management sits at a uniform 4 — guided questionnaires and TOM checklists build the record of processing activities — but we found no public information on data protection impact assessment support, a processor register or legal-basis linkage. Rights and incidents is the weak end at 1-2: we found no public information on data subject request workflows, statutory deadlines or a breach register, and the structured intake shown serves whistleblowing law. Framework coverage splits 2-4: judges crediting GDPR depth plus the KI module scored 4, judges weighing the absence of Swiss, UK or per-country regimes scored 2. Pricing transparency reaches 5-6 on tiers of 79€, 115€ and 140€ per month up to 30 employees plus a 495€ one-time setup; sovereignty scores 2-3, with no public information on hosting, subprocessors or a data processing agreement.
Speaks for it
- Audit readiness scores 6-7, with every change logged by timestamp and user, mandatory two-factor access, and an automatic supervisory-authority-ready documentation export
- Pricing transparency scores 5-6, with three published employee tiers at 79€, 115€ and 140€ per month, each with a 495€ one-time setup fee, and consulting priced separately at 1250€, 1550€ or 1750€
- The vendor is a confirmed German GmbH — commercial register HRB26792, Amtsgericht Traunstein — holding ISO 27001, 37301 and 9001 certificates plus a downloadable DSGVO conformity statement
- A guided questionnaire builds the record of processing activities with automatically derived tasks and TOM checklists, and trainings are included for all employees
- Compliance seals are released only once documentation reaches a defined maturity level and can be shown with a verification link in audits
Held against it
- Rights and incidents scores 1-2: we found no public information on data subject request workflows, statutory deadline tracking, or a breach register with authority notification
- Framework coverage scores 2-4, with the privacy content on the captured pages DSGVO-framed and we found no public information on Swiss, UK or per-country privacy regimes
- Sovereignty scores 2-3: the captured pages describe a cloud offering without local installation, and we found no public information on hosting location, subprocessors, or a published data processing agreement
- Integrations and automation scores 3-4, with the only named data connection a DATEV import attested in a testimonial for the money-laundering product, and we found no public information on an API, directory sync or single sign-on
- Published prices stop at 30 employees, additional AI applications are billed at an individually agreed hourly rate, and we found no public prices for the other platform modules
Best for
- You run a German company or tax practice of up to 30 employees and want a guided questionnaire to build the record of processing activities, TOMs and trainings in one product
- You need audit-facing proof — timestamped change history, two-factor access, an automatic supervisory-authority-ready export and a seal with a verification link
- You want fixed, published pricing with consulting unbundled, including coverage for ChatGPT, DATEV Copilot and Microsoft Copilot in the consulting package
- You expect to add other German compliance duties — whistleblowing, GoBD procedure documentation, money-laundering prevention — on the same platform later
Avoid if
- You need to run data subject requests, statutory deadline clocks and breach notification as workflows — the captured pages show deletion concepts only as adaptable templates and a whistleblowing channel, and we found no public information on request or breach workflows
- You operate under Swiss, UK or multiple national privacy regimes — the captured privacy content is DSGVO-framed and the platform's other modules cover non-privacy German duties
- You need the record fed from your IT estate — the only named data connection is a DATEV import attested in a testimonial for the money-laundering product, and we found no public information on an API, directory sync or single sign-on
- You have more than 30 employees and need a computable public price — published tiers stop at 30 employees and further AI applications run at an individually agreed hourly rate
The scores
Records & DPIA depth
Show reasoningHide reasoning
How this is scored
The DSMS core: records of processing (RoPA/VVT), data protection impact assessments, processor/DPA management and TOMs — how deeply the legal artifacts are modeled and connected.
0 — Document templates in a folder tree; the "register" is a Word file with version numbers in the filename.
3 — A structured RoPA with basic fields and a DPIA questionnaire, but processors, TOMs and legal bases live outside the system.
5 — RoPA and DPIA as linked modules with templates; processor management and TOM assignment exist but are shallow, and group reuse is copy-paste.
8 — A connected data model — processing activities linked to systems, processors, TOMs and legal bases — with DPIA triggers derived from the record, reusable group templates, and outputs a supervisory authority accepts.
10 — Privacy records as a system of record: the RoPA drives DPIAs, processor management and TOM coverage from one data model, multi-client/mandate capability included, and the documentation is audit-ready without manual assembly.
The External DPO
The guided questionnaire builds a record of processing activities with automatically derived tasks, TOMs live in complete checklists in the same product, and the package ships adaptable templates for policies, deletion concepts and sample contracts. I found no public information on DPIA handling, processor or DPA management, legal-basis modeling, or any mandate-level reuse a multi-client consultancy could drive — so it sits between a basic register and a connected model. 4 2
The In-House Counsel
The guided questionnaire generates the register of processing activities, TOM checklists with automatically derived tasks, and risk assessment questionnaires with countermeasures — a structured register, not version-numbered files. I found no public information on a DPIA module, a processor register, or legal-basis modeling; sample contracts appear only as adaptable templates, so the connected data model an authority expects is not evidenced. 4 2
The Drafted Generalist
This is exactly the kind of plain-language workflow I need: a guided questionnaire builds the record of processing activities (purpose, use, access), TOMs sit in the same software as complete checklists, tasks derive automatically, and the seal only unlocks at a defined maturity level. But depth stops at the record itself — I found no public information on impact assessment support, a processor register, or legal-basis fields being modeled and linked. 2 4
The Lead Auditor
The record of processing activities is built through a guided questionnaire with automatically derived tasks, and TOMs are handled with complete in-system checklists, which is more than a bare structured register. The connected model stops there: we found no public information on DPIA support, processor or contract management, or legal bases linked to the record, and group reuse appears to be template adaptation rather than one data model. 4 2
The IT Integrator
The records side is a guided questionnaire producing a processing register, TOM checklists, automatically derived tasks and adaptable templates for policies, deletion concepts and sample contracts — a form-driven model rather than a connected register. We found no public information on DPIA handling, a processor register or legal-basis linkage, so the connected data model the strong profiles describe is not in evidence. 2 4
The Skeptic
The record of processing activities is built through a guided questionnaire and TOMs come as complete checklists, which is more than a folder of Word files — but the captured product pages never mention a data protection impact assessment, and processors appear only as adaptable sample contracts rather than a managed register. We found no public information on records linked to systems, legal bases and processors as one connected data model. 2 4
Data subject rights & incidents
Show reasoningHide reasoning
How this is scored
The operational half of the DSMS: data subject request handling with statutory clocks, breach register and authority notification, deletion concepts that actually delete.
0 — Requests arrive by email and live there; breaches are a phone call and a memo.
3 — A request log and a breach list exist, but deadlines are manual, intake is unstructured, and deletion rules are documentation rather than workflow.
5 — DSR workflows with the Art. 12 clock tracked, structured breach register with the 72-hour clock, deletion concepts assignable to records; automation is reminders.
8 — Intake channels for requests (portal/form), identity-check support, deadline automation with escalation, breach severity assessment and authority-report output, deletion rules tied to the RoPA with execution tracking.
10 — Rights and incidents as operations: end-to-end request handling an authority audit walks through, breach workflows that produce the Art. 33 notification, and deletion automation with evidence that the deletion happened.
The External DPO
I found no public information on data subject request workflows, statutory deadline clocks, a breach register or authority notification; the deletion concept appears only as an adaptable document template rather than a workflow. The structured intake and confidentiality protections evidenced serve the German whistleblower channel, which is a different regime from privacy rights operations. 4 2
The In-House Counsel
I found no public information on data subject request intake, deadline tracking on the Article 12 clock, or a breach register that produces a 72-hour Article 33 notification — for a GDPR product that silence is the decisive fact. Deletion concepts exist only as document templates, and the one structured intake workflow documented serves the German whistleblowing law, not data subject rights. 4 2 7
The Drafted Generalist
Deletion concepts come as adaptable document templates and there is a genuinely structured, confidential whistleblowing intake, but that serves the whistleblower law rather than privacy requests. I found no public information on data subject request workflows, statutory clocks, a breach register, or authority notification — the operational half of privacy is essentially templates on the captured pages. 2 4 7
The Lead Auditor
Deletion concepts exist as adaptable document templates rather than workflow, and the structured incident channel we can see serves the whistleblower statute, not data subject rights. We found no public information on data subject request workflows, statutory deadline tracking, a breach register, or authority notification output. 4 2
The IT Integrator
Deletion concepts appear only as adaptable document templates, which is documentation rather than execution workflow, and the one structured intake channel we can see is the whistleblower module with a documented processing flow. We found no public information on data subject request handling, statutory deadline tracking, a breach register or authority notification. 2 4
The Skeptic
Deletion concepts surface only as document templates, and we found no public information on data subject request workflows, statutory deadlines, identity checks, or a breach register with the 72-hour clock. The closest operational feature is the whistleblowing module, built around the HinSchG reporting channel — a different legal duty from GDPR rights handling. 2 1
Privacy regime coverage
Show reasoningHide reasoning
How this is scored
Which privacy regimes the product actually operationalizes — GDPR, BDSG, Swiss nDSG, UK GDPR, ePrivacy, EU AI Act privacy duties — and whether one record maps across them or each regime is a fresh island.
0 — One regime, hard-coded; anything else is "on the roadmap".
3 — GDPR plus one national law as separate checklists; the same processing activity is documented once per regime.
5 — The major regimes for its market with partial cross-mapping; newer duties (AI Act, ePrivacy changes) present as content packs of varying depth.
8 — Broad current coverage with one-record-many-regimes mapping and visible maintenance as regimes evolve.
10 — Regime coverage as a living product: multiple privacy regimes on one data basis, per-country variants, and documented update cadence when the law moves.
The External DPO
The privacy content is DSGVO — handbook, register of processing activities, TOMs — while the platform's breadth is in other German compliance domains like money-laundering prevention, GoBD, whistleblowing and Microsoft 365; I found no public information on BDSG specifics, Swiss or UK regimes, ePrivacy or AI Act privacy duties, or one record mapping across regimes. Central adoption of new requirements shows maintenance of the one privacy regime it serves. 4 1 2
The In-House Counsel
GDPR is operationalized in depth for the German market, and the central platform carries AI compliance, GoBD procedure documentation and whistleblowing duties alongside it, with changed requirements taken into the solution centrally. I found no public information on one record mapping across regimes, per-country variants, or coverage beyond German law such as Swiss or UK data protection. 4 1 2
The Drafted Generalist
GDPR is operationalized end to end — handbook, record of processing, TOMs, trainings — with a KI compliance module for AI duties and requirement updates pushed automatically to every user when the law moves, which is maintenance I can see. Beyond that, I found no public information on other privacy regimes such as Swiss or UK variants, or on one record mapping across several regimes. 4 2 1
The Lead Auditor
The operational privacy core is the GDPR for the German market, sitting on a central platform where money-laundering, GoBD, whistleblowing and AI compliance run as their own modules rather than as mappings across one record. New or changed requirements are stated to be adopted centrally and automatically, but we found no public information on further privacy regimes such as Swiss or UK law, per-country variants, or a documented update cadence. 4 1 2
The IT Integrator
GDPR is plainly the core regime — handbook, register of processing activities, TOMs — with a KI-compliance module as the only newer-duty content and centrally rolled-out updates when requirements change. We found no public information on national privacy-law variants, Swiss or UK regimes, or mapping one record across regimes. 4 2 1
The Skeptic
Everything privacy-related on the captured pages is DSGVO-framed — a data protection handbook, a DSGVO conformity seal, the record of processing activities and TOMs. The platform's other modules cover money laundering, GoBD and whistleblower law rather than further privacy regimes, and the KI content is consulting coverage for using ChatGPT, DATEV Copilot and Microsoft Copilot. We found no public information on national privacy law variants, Swiss or UK regimes, or AI Act duties being operationalized in the record itself. 4 1 2
Audit readiness & evidence
Show reasoningHide reasoning
How this is scored
Whether the system produces defensible proof: revision-safe history, evidence collection, reports for auditors, authorities and management.
0 — Exports are screenshots; history is overwritten in place.
3 — PDF reports exist but evidence is attached ad hoc and changes leave no reliable trail.
5 — Versioned records, standard report generators for the core registers, evidence attachments per activity; assembling a full audit file still takes days.
8 — Revision-safe change history, audit-scoped evidence packs on demand, management and authority reports current at a click, auditor access roles.
10 — Audit readiness as a standing state: continuous documentation status per regime and scope, exportable proof packs an auditor accepts as-is, and a defensible answer to "show me the state on date X".
The External DPO
Every change is captured with timestamp and user, access requires two-factor authentication, and the system generates supervisory-authority-ready documentation automatically, with a seal released at a defined documentation maturity level that can be shown as proof in audits. I found no public information on auditor access roles, scoped evidence packs on demand, or a defensible state-at-date view. 4 2
The In-House Counsel
Every change is captured with timestamp and user, access requires two-factor authentication, and the vendor states the system automatically produces documentation ready for submission to the supervisory authority — the artifacts a defense file needs. I found no public information on auditor access roles, on-demand evidence packs, or a demonstrated answer to "show me the state on date X", which keeps this below the top band. 4 1 2
The Drafted Generalist
Every change is stamped with timestamp and user, access requires two-factor authentication, and the system compiles supervisory-authority-ready documentation automatically with annual versioning — plus a seal with a verification link that works as proof in audits. I found no public information on auditor access roles or on-demand evidence packs, so the last mile of audit assembly is not evidenced. 2 4 1
The Lead Auditor
Every change to the system or documentation is recorded with timestamp and user, revision-safe operation is claimed with two-factor access, and a supervisory-authority-ready documentation export is produced automatically with annual versioning. We found no public information on audit-scoped evidence packs on demand, auditor access roles, or reconstructing the state of the records at a past date. 4 1 2
The IT Integrator
This is the stronger side: every change is captured with timestamp and user, the software claims to meet revision-safe-system requirements with mandatory two-factor access, authority-ready documentation is generated automatically, and the seal only releases at a defined documentation maturity level — effectively a standing status light. We found no public information on auditor access roles or reconstructing the state at a past date. 2 4
The Skeptic
Change history with timestamp and user, a revision-safe claim backed by mandatory two-factor login, and an automatic supervisory-authority-ready export are stated plainly, and the seal mechanism ties proof to a defined maturity level with a verification link. We found no public information on auditor access roles, evidence packs scoped on demand, or reconstructing the documentation state on a past date. 2 4
Integrations & automation
Show reasoningHide reasoning
How this is scored
Whether the platform feeds from the real IT estate — directory import, ticketing, API — and automates the recurring privacy work instead of re-typing it.
0 — A closed island: manual entry in, PDF out, no API.
3 — CSV/Excel import and export; no live connections, no API worth the name.
5 — Directory import (AD/Entra), a documented REST API for core objects, a handful of native connectors (ticketing or SSO); automation is reminders and recurrence.
8 — Real connector set (ticketing, HR or asset sources), webhooks, SSO/SCIM, workflow automation with delegation and escalation, useful AI assistance with human review.
10 — The platform behaves like infrastructure: API parity for the data model, event streams, bidirectional sync with the estate, and automation that measurably removes the recurring toil (reviews, attestations, evidence pulls) rather than renaming it.
The External DPO
The only integration evidence is a customer testimonial describing data import from DATEV-EO for the money-laundering product; for the privacy product I found no public information on an API, directory import, ticketing connectors, webhooks or SSO beyond mandatory two-factor login. Automation here means automatically derived tasks and centrally rolled-out requirement updates, not feeding from a real IT estate. 1 2
The In-House Counsel
The only documented feed from a real system is a DATEV import, and it appears in a customer testimonial for the money-laundering product rather than the privacy module; I found no public information on a documented API, directory import, or SSO and SCIM connections. The automation shown — derived tasks, central updates, the authority export — assists documentation but does not connect the IT estate. 2
The Drafted Generalist
The recurring work is genuinely automated — tasks derive from the questionnaire and requirement updates land in my account without me doing anything — and a DATEV import appears in a testimonial for their anti-money-laundering product. I found no public information on an API, directory sync, single sign-on or ticketing connections, so my actual IT estate stays outside the platform. 2 1
The Lead Auditor
The product is cloud-only with automatic updates and automatically derived tasks, and a DATEV-EO data import is attested by a customer testimonial — though that testimonial concerns the money-laundering sibling product. We found no public information on an API, directory import, ticketing or HR connectors, webhooks, or single sign-on beyond two-factor authentication. 1 2
The IT Integrator
The only estate feed in evidence is a testimonial describing data import from DATEV-EO, and that for the anti-money-laundering product's KYC checks, not the privacy register — alongside automatically derived tasks and two-factor access on a cloud platform. We found no public information on a REST API, webhooks, directory import from Entra ID or AD, SSO or SCIM, or ticketing connectors; on my bench that is a manual-entry compliance record. 2
The Skeptic
The only named data connection is a DATEV import, and it appears in a testimonial about the money-laundering product's KYC checks rather than the data protection product; the automation shown is automatically derived tasks and central updates. We found no public information on an API, directory sync, SSO, webhooks, or ticketing connections. 2 1
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where the compliance record of the whole company actually lives and under whose law — entity, hosting, subprocessors, DPA. A platform that maps your processing is itself your most concentrated processing.
0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for the system holding your RoPA.
3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.
5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.
8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.
10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors, on-premises or sovereign-cloud options, and the whole chain documented publicly.
The External DPO
A German GmbH with ISO 27001, 37301 and 9001 certificates and a downloadable GDPR conformity document, delivered as cloud software without local installation. I found no public information on hosting location, ownership, a subprocessor list or a public data processing agreement — exactly the chain I have to vet before pointing thirty client mandates at a system holding their records of processing. 3 5 1
The In-House Counsel
A German limited company with a Traunstein commercial register entry and its own ISO 27001, 37301 and 9001 certifications is the right jurisdiction for the system that would hold my register of processing activities. It is cloud-only with no local installation option, and I found no public information on hosting location, a published data processing agreement, or a subprocessor list — the chain behind the compliance record is undocumented. 3 5 1 2
The Drafted Generalist
The imprint pins a German GmbH with a commercial register number and the vendor itself carries ISO 27001, 37301 and 9001 plus a downloadable GDPR conformity statement. But for the cloud that would hold my compliance record — the most concentrated processing I have — I found no public information on hosting location, subprocessors, or a published data processing agreement. 5 3 1
The Lead Auditor
The vendor is an unambiguous German entity — a GmbH registered at Traunstein with a German VAT number — and holds ISO 27001 certification for its own management system. For the platform that would hold a customer's register of processing activities, we found no public information on hosting location, data residency, ownership, subprocessors, or a data processing agreement; only a cloud offering without local installation is described. 3 5 1
The IT Integrator
A German GmbH with a Traunstein registry entry and its own ISO 27001, 37301 and 9001 certifications is the plus side. The platform is cloud-only, and we found no public information on where it is hosted, a published data processing agreement, or the subprocessor chain — a gap that matters for the system that would hold a company's entire processing record. 5 2 3
The Skeptic
A German GmbH with its own ISO 27001, 37301 and 9001 certificates is confirmed, but that is where the trail ends: the product is cloud-only with no local installation, and we found no public information on hosting location, a published data processing agreement, or any subprocessor list — for the system meant to hold your register of processing activities. 5 2 3
Pricing transparency
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real invoice — per module, per entity, per year, with consulting unbundled — from public pages alone. Unpublished pricing is the B2B norm in this market, so this criterion describes rather than condemns; the benches weight it accordingly.
0 — No public prices at all; every configuration is a sales conversation.
3 — An entry price exists, but module add-ons, entity counts or bundled consulting make the real total incomputable.
5 — Most editions carry real numbers with billing period stated and software separated from services; at least one commonly needed module or scale step is unpriced.
8 — Every edition and module priced publicly with entity/user boundaries and setup fees stated; only genuine corporate-group contracts are custom.
10 — Complete price computability: modules, scale steps, service packages and renewal rules public, so the invoice for a 100-employee company and a 10-client consultancy is a two-minute exercise.
The External DPO
The product page prices three employee tiers at 79€, 115€ and 140€ per month, each with a one-time setup fee of 495€, and the all-round consulting package is priced separately at 1250€, 1550€ or 1750€ depending on tier, while further AI applications run only at an agreed hourly rate. Above thirty employees, for the other modules, and on the homepage itself — which offers only a free initial consultation — I found no public prices, so a real multi-client invoice stays incomputable. 1 2
The In-House Counsel
The product page prices three employee tiers exactly — "79€/Monat", "115€/Monat", "140€/Monat" — each with a stated "einmalige Einrichtungspauschale 495€", and the consulting package is unbundled at fixed add-on prices quoted per tier. Above 30 employees no figure appears and further AI applications are billed at an individually agreed hourly rate, so the real invoice for a larger company is not computable from public pages. 1 2
The Drafted Generalist
The product page states real numbers per employee band — 79€, 115€ and 140€ per month, each with a stated 495€ one-time setup — and the consulting package carries fixed prices from 1250€, so software and services are cleanly separated. But the bands stop at 30 employees, my 80-person company has no published price, and extra KI work runs on an agreed hourly rate — my real invoice still needs the sales call the homepage advertises. 2 1
The Lead Auditor
Three employee tiers carry public monthly prices (79€, 115€, 140€ by employee count) plus a stated one-time setup fee of 495€, and the consulting package is unbundled as a fixed-price add-on per tier with its included AI tools named. Beyond thirty employees, for the other platform modules, and for additional AI applications at an agreed hourly rate, we found no public information; the captured homepage shows only a free initial consultation while the product page carries the numbers. 1 2
The IT Integrator
The product page quotes real monthly figures per employee band — 79€/Monat, 115€/Monat and 140€/Monat, each with a einmalige Einrichtungspauschale of 495€ — and prices the consulting add-on separately at 1250€, 1550€ or 1750€, which cleanly separates software from services. The captured pages give different figures, though: the homepage capture shows no prices at all beyond a free initial consultation, and we found no public prices for the other modules, tiers above 30 employees, or the KI consulting billed at an agreed hourly rate. 2 1
The Skeptic
Three employee-count tiers carry real monthly numbers plus a stated one-time setup fee, and the consulting package is priced separately at fixed tiers, so software and services are distinguishable. But the tiers stop at thirty employees, the platform's other modules carry no public prices, and additional AI applications are billed at an individually agreed hourly rate — the real invoice is computable only within a narrow band. 2 1
European sovereignty — proven facts
1 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Incorporated in DE | 3/3 pts | 5 Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | Not determined | — | uncited Report an error |
| Subprocessors | Not determined | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 24 Aug 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 51 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 29 pricing facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 12 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 4 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 4 support facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 integrations facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (7)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage data-security.one Checked 5 Oct 2026 +2 earlier captures: 15 Sep 2026, 24 Aug 2026 Details →
- 2 Data protection product page data-security.one Checked 5 Oct 2026 +2 earlier captures: 15 Sep 2026, 24 Aug 2026 Details →
- 3 Company page data-security.one Checked 5 Oct 2026 Details →
- 4 Certification/seal page data-security.one Checked 5 Oct 2026 Details →
- 5 Imprint data-security.one Checked 5 Oct 2026 Details →
- 6 Data subject rights & incidents — found from sitemap data-security.one Checked 5 Oct 2026 Details →
- 7 Data subject rights & incidents — found from sitemap data-security.one Checked 5 Oct 2026 Details →