whats-best.ai
Search Sign in

Data Protection

i-doit GRC Suite (INPRIVE / INDITOR)

EU-Made Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: not determined

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by i-doit GmbH · www.i-doit.com

Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The panel's verdict

The i-doit GRC Suite (INPRIVE for GDPR, INDITOR for ISMS) scores highest on integrations and automation and audit readiness: a JSON-RPC API that reads and writes all data with permissions respected, named connectors for ticketing, monitoring and discovery, and revision-safe documents feeding automatic audit reports. Its weakness is framework coverage, the widest split at 1-4: the pages name GDPR as the only privacy regime, with no public information on Swiss nDSG, UK GDPR, ePrivacy or AI Act duties, and the judges disagree over how much the shared-basis breadth through ISO 27001, BSI IT-Grundschutz, NIS-2, KRITIS and TISAX should count. Rights and incidents holds at 4 with no spread — incident workflows are documented, while data subject rights appear only as a named capability. Pricing transparency is a flat 3: one public figure, INPRIVE 'ab 599€/ Jahr', and a 30-day trial with no payment details, but no public prices beyond it. Sovereignty rests on a German imprint and on-premises option; we found no public information on a data processing agreement, subprocessors or cloud hosting.

Report an error

Speaks for it

  • A documented JSON-RPC API reads and writes all data including custom categories with permissions respected, earning integrations and automation scores of 7-8
  • Revision-safe versioned documents, guided audit programs and automatic standardized audit reports hold audit readiness at 6-7
  • Data protection incidents are documented GDPR-compliantly with affected processing operations assigned, risk assessment, deadline monitoring and automatic notifications
  • The record of processing activities, impact assessments, industry processing templates and multi-tenant capability sit on a data basis shared with the CMDB and ISMS
  • An on-premises deployment option sits alongside the cloud under a German GmbH whose imprint lists the Düsseldorf register court, register number 33104 and a German VAT ID

Report an error

Held against it

  • Framework coverage splits 1-4, the widest spread of any criterion, because GDPR is the only privacy regime the pages name, with no public information on Swiss nDSG, UK GDPR, ePrivacy or AI Act duties
  • Data subject rights appear only as a named capability, with no public information on request intake channels, identity checks, statutory clocks, deletion concepts or authority notification output
  • Only one price is public — INPRIVE 'ab 599€/ Jahr' — so the real invoice for Suite+ modules, add-ons beyond the '4 add-ons for the price of 2' bundle, support tiers or setup fees is not computable from public pages
  • Privacy management stops short of a connected model, with no public information on legal-basis modelling, TOMs, DPIA triggers derived from the record, or processor/DPA management
  • Sovereignty rests on the imprint and the on-premises option alone, with no public information on a published data processing agreement, subprocessor list or cloud hosting locations

Report an error

Best for

  • You want your privacy records to live next to the real IT estate, fed by Active Directory/LDAP import and the JSON-RPC API on a shared data basis
  • You need audit evidence on demand — revision-safe versioned documents, guided audit programs and automatic standardized audit reports aimed at auditors and management
  • You operate in the German market, where GDPR alongside ISO 27001, BSI IT-Grundschutz, NIS-2, KRITIS and TISAX matches your regime mix
  • You must keep the register of processing activities on infrastructure you control, using the on-premises deployment option

Report an error

Avoid if

  • You operate under privacy regimes beyond GDPR — the captured pages show no Swiss nDSG, UK GDPR, ePrivacy or AI Act privacy duties, and framework coverage splits 1-4 on exactly this point
  • You need data subject request handling end to end — intake, identity checks, statutory clocks and authority notification output — while the pages show only a named capability beside substantiated incident workflows
  • You must compute your real invoice from public pages — ask the vendor: the public pages we read do not show it
  • You are buying it for the AI assistance — the 'AI-supported platform' and 'AI Add-ons' claims appear without models, examples or a human-review story in the captures

Report an error

The scores

Records & DPIA depth

Show reasoning
How this is scored

The DSMS core: records of processing (RoPA/VVT), data protection impact assessments, processor/DPA management and TOMs — how deeply the legal artifacts are modeled and connected.

0 — Document templates in a folder tree; the "register" is a Word file with version numbers in the filename.

3 — A structured RoPA with basic fields and a DPIA questionnaire, but processors, TOMs and legal bases live outside the system.

5 — RoPA and DPIA as linked modules with templates; processor management and TOM assignment exist but are shallow, and group reuse is copy-paste.

8 — A connected data model — processing activities linked to systems, processors, TOMs and legal bases — with DPIA triggers derived from the record, reusable group templates, and outputs a supervisory authority accepts.

10 — Privacy records as a system of record: the RoPA drives DPIAs, processor management and TOM coverage from one data model, multi-client/mandate capability included, and the documentation is audit-ready without manual assembly.

Report an error

The External DPO

The record of processing activities, impact assessments, measures, roles and industry-specific processing templates sit on one shared data basis, multi-tenant capability is stated outright, and register reports are generated automatically — the bones of a thirty-mandate practice are genuinely there. The captured pages do not show legal bases modeled on the record or assessments triggered from it, so I stop short of the fully connected-model tier. 2 3 2 7

Report an error

The In-House Counsel

INPRIVE names a record of processing activities, a data protection impact assessment and GDPR evidence tracking, and the shared data basis with ISMS and the CMDB is real — incidents get assigned to affected processing operations, measures link to target objects, and industry templates plus multi-client capability are stated. But we found no public information on legal-basis or TOM modeling or on DPIA triggers derived from the record, and without those connections I cannot treat the artifacts as one connected register at audit weight. 2 2 6 7

Report an error

The Drafted Generalist

The register of processing activities, the impact assessment function, industry-specific processing templates, and measures with owners, deadlines and automatic email notification are all documented, and the GDPR page describes mapping processing directories, data flows, roles, risks, measures and checks in one structured system on a shared data basis with the IT inventory. As a non-lawyer I like that the records live next to the real systems list. We found no public information on how legal bases are modeled or whether impact assessments are triggered from the register itself, so I stop short of the fully connected data model. 2 3 7

Report an error

The Lead Auditor

The register of processing activities, the data protection impact assessment, industry templates and multi-client capability are all named, and the GDPR documentation claim spans processing directories, data flows, roles, risks, measures and checks on a shared data basis with the ISMS. What holds it down: we found no public information on processor and DPA management, legal bases, or impact-assessment triggers derived from the record, so the connected data model is asserted more than shown. 2 2 7

Report an error

The IT Integrator

The record of processing activities and the impact assessment run on a shared data basis with the CMDB, ISMS and emergency planning, with measures linked to target objects, supplier and contract management, industry processing templates and multi-tenant capability — that is a connected model I can feed from the estate instead of retyping it. The captured pages stop at capability names though: we found no public information on legal basis modelling, processor/DPA management as a privacy artifact, or DPIA triggers derived from a record. 2 3 7 3

Report an error

The Skeptic

Record of processing activities, data protection impact assessments, industry processing templates and multi-client capability are named and repeated, and the shared data basis with ISMS plus incidents assigned to affected processing operations corroborates a connected model. I found no public information on processor and DPA management, technical and organizational measures, legal bases, or DPIA triggers derived from the record, so the depth stops short of the full picture. 2 3 2 6

Report an error

Data subject rights & incidents

Show reasoning
How this is scored

The operational half of the DSMS: data subject request handling with statutory clocks, breach register and authority notification, deletion concepts that actually delete.

0 — Requests arrive by email and live there; breaches are a phone call and a memo.

3 — A request log and a breach list exist, but deadlines are manual, intake is unstructured, and deletion rules are documentation rather than workflow.

5 — DSR workflows with the Art. 12 clock tracked, structured breach register with the 72-hour clock, deletion concepts assignable to records; automation is reminders.

8 — Intake channels for requests (portal/form), identity-check support, deadline automation with escalation, breach severity assessment and authority-report output, deletion rules tied to the RoPA with execution tracking.

10 — Rights and incidents as operations: end-to-end request handling an authority audit walks through, breach workflows that produce the Art. 33 notification, and deletion automation with evidence that the deletion happened.

Report an error

The External DPO

Incident handling is structured: incidents documented GDPR-compliant, assigned to affected processing operations, risks assessed, measures derived with deadline monitoring and automatic notifications. Data subject rights appear only as a named capability with a promise of professional handling, and we found no public information on statutory clocks, structured intake, authority notification output or deletion concepts. 2 3 6 8

Report an error

The In-House Counsel

Data protection incidents are documented GDPR-compliantly with risk assessment, assignment to processing operations and centrally derived measures, and data subject rights management is named as a capability alongside generic deadline monitoring and automatic notifications. We found no public information on a 72-hour clock, an authority notification output under Art. 33, structured request intake with identity checks, or deletion concepts with execution tracking — the clock and the notification are what I must produce in a breach, so this sits below my defensibility bar. 2 3 6 8

Report an error

The Drafted Generalist

The incident half is concrete: data protection incidents are documented centrally, assigned to the affected processing operations, risk-assessed, and deadlines are monitored with automatic notifications. Data subject rights appear only as a feature name on the product page, and we found no public information on request intake channels, statutory clocks, deletion concepts or authority-notification output. 2 3 6

Report an error

The Lead Auditor

The incident half is properly described — GDPR-conform incident documentation, assignment of affected processing operations, risk assessment, measure tracking, deadline monitoring and automatic notifications. The rights half appears only as a one-line capability name, and we found no public information on statutory clocks, request intake channels, identity checks or deletion concepts. 2 3 6 8

Report an error

The IT Integrator

Incident handling is real: incidents documented GDPR-compliant, affected processing operations assigned, risks assessed, with deadline monitoring and automatic notifications. Data subject rights management appears as a single named capability, and we found no public information on request intake channels, identity checks, the statutory clock for requests, or deletion concepts with execution tracking. 2 3 6 8

Report an error

The Skeptic

Rights handling appears as a single feature line, while the incident use case is better substantiated: GDPR-conform documentation with affected processing operations assigned, risks assessed, plus deadline monitoring and automatic notifications. I found no public information on request intake channels, identity verification, the 72-hour clock, authority notification output, or deletion concepts and their execution. 2 6 8

Report an error

Privacy regime coverage

panel disagrees Show reasoning
How this is scored

Which privacy regimes the product actually operationalizes — GDPR, BDSG, Swiss nDSG, UK GDPR, ePrivacy, EU AI Act privacy duties — and whether one record maps across them or each regime is a fresh island.

0 — One regime, hard-coded; anything else is "on the roadmap".

3 — GDPR plus one national law as separate checklists; the same processing activity is documented once per regime.

5 — The major regimes for its market with partial cross-mapping; newer duties (AI Act, ePrivacy changes) present as content packs of varying depth.

8 — Broad current coverage with one-record-many-regimes mapping and visible maintenance as regimes evolve.

10 — Regime coverage as a living product: multiple privacy regimes on one data basis, per-country variants, and documented update cadence when the law moves.

Report an error

The External DPO

GDPR is the native privacy regime, with dedicated product depth and a claim of EU-wide legally compliant documentation on a data basis shared with the ISMS side, so an activity is not re-documented per domain. The captured standards lists are otherwise security regimes — ISO 27001, BSI IT-Grundschutz, NIS-2, TISAX — and we found no public information on Swiss nDSG, UK GDPR, ePrivacy or AI Act privacy duties. 2 1 3

Report an error

The In-House Counsel

Coverage is shaped to the German market — GDPR alongside BSI IT-Grundschutz, B3S, KRITIS, NIS-2 and TISAX — on one shared data basis, with a claim of EU-wide legally compliant documentation. We found no public information on Swiss nDSG, UK GDPR, ePrivacy or AI Act privacy duties, and no documented update cadence when the law moves, so for operations beyond the DACH footprint I would want confirmation before relying on the content. 2 1 3

Report an error

The Drafted Generalist

GDPR is clearly the privacy module's core, with industry templates and a claim of EU-wide legally compliant documentation, and the wider suite names ISO 27001, NIS-2, B3S, KRITIS and TISAX — but those are certification and security regimes rather than additional privacy regimes. We found no public information on Swiss, UK, ePrivacy or AI Act privacy duties, so I cannot confirm a second privacy regime on the same record. 2 7 10

Report an error

The Lead Auditor

GDPR is the privacy regime, operationalized as a dedicated module with an EU-wide legally compliant documentation claim and a certification use case, riding the same machinery that runs ISO 27001, NIS-2, TISAX and BSI IT-Grundschutz. We found no public information on any other privacy regime — Swiss, UK, ePrivacy or AI Act duties — or on one record mapping across several privacy regimes. 2 1 7 8

Report an error

The IT Integrator

GDPR is the one privacy regime the captured pages operationalize; the breadth sits on the ISMS and security side (ISO 27001, BSI IT-Grundschutz, NIS-2, KRITIS, TISAX, DORA). We found no public information on Swiss nDSG, UK GDPR, ePrivacy or AI Act privacy duties, or on one record mapping across multiple privacy regimes — the EU-wide legally compliant documentation claim reads as GDPR for the EU market, not multi-regime coverage. 2 1 10 3

Report an error

The Skeptic

GDPR is the only privacy regime the captured pages actually name; "EU-wide legally compliant documentation" is a slogan with no second named privacy law behind it. The platform demonstrably runs many regimes such as ISO 27001, NIS-2 and TISAX on one shared data basis, but for BDSG specifics, Swiss nDSG, UK GDPR, ePrivacy or AI Act privacy duties I found no public information. 2 3 2 1

Report an error

Audit readiness & evidence

Show reasoning
How this is scored

Whether the system produces defensible proof: revision-safe history, evidence collection, reports for auditors, authorities and management.

0 — Exports are screenshots; history is overwritten in place.

3 — PDF reports exist but evidence is attached ad hoc and changes leave no reliable trail.

5 — Versioned records, standard report generators for the core registers, evidence attachments per activity; assembling a full audit file still takes days.

8 — Revision-safe change history, audit-scoped evidence packs on demand, management and authority reports current at a click, auditor access roles.

10 — Audit readiness as a standing state: continuous documentation status per regime and scope, exportable proof packs an auditor accepts as-is, and a defensible answer to "show me the state on date X".

Report an error

The External DPO

Revision-safe versioned documents, guided audits from document review through implementation check, automatic standardized audit reports, and exports aimed at auditors, management and specialist departments — this is client-file assembly at a click, which is precisely what I bill hours against. We found no public information on point-in-time reconstruction of the state on a given date or dedicated auditor access roles. 2 8 9 10

Report an error

The In-House Counsel

Revision-safe document management with versioning, changes documented in an audit-capable manner, guided audit programs with document assignment, task and role assignment, and standardized automatic audit reports — including automatic register reports such as the VVT — give me an auditor file without weeks of assembly. We found no public information on auditor access roles or a point-in-time reconstruction of the state on a given date, which is the answer I need standing ready in an inspection. 2 7 8 9 10

Report an error

The Drafted Generalist

Documents are managed revision-safe with versioning, changes and statuses are traceable and usable as audit evidence, standardized and automatic audit reports are generated, and the tool guides you from document review through audit planning to implementation checks — exactly the guided hand I need. We found no public information on dedicated auditor access roles or on reproducing the exact state of the records at a past date, which is what separates good from defensible. 2 9 10

Report an error

The Lead Auditor

This is the best-populated story in the captures: revision-safe versioned documents, changes documented in an audit-capable way, automatic and standardized audit reports, guided audit execution from document review to implementation review, gap detection, and exports aimed at auditors and management. I stop short of higher because the evidence is report-shaped — we found no public information on audit-scoped evidence packs on demand or on reconstructing the state of a record on a past date. 2 8 9 10

Report an error

The IT Integrator

Revision-safe versioned document management, traceable change and status documentation usable as audit evidence, automatic audit report generation, compilable audit programs, audit task and role assignment, and exports aimed at auditors, management and departments — that is most of the way to evidence packs on demand. We found no public information on point-in-time state reconstruction or dedicated auditor access roles, so it sits just under the top band. 2 8 9 10

Report an error

The Skeptic

Revision-safe versioned documents, changes documented in an audit-capable way, traceable data and status documentation as audit evidence, guided audit programs with task and role assignment, and automatic standardized audit reports from current data are all substantiated on dedicated use-case pages. I found no public information on auditor access roles as such, authority-facing report output, or a defensible answer to showing the state on a given date. 2 8 9 10

Report an error

Integrations & automation

Show reasoning
How this is scored

Whether the platform feeds from the real IT estate — directory import, ticketing, API — and automates the recurring privacy work instead of re-typing it.

0 — A closed island: manual entry in, PDF out, no API.

3 — CSV/Excel import and export; no live connections, no API worth the name.

5 — Directory import (AD/Entra), a documented REST API for core objects, a handful of native connectors (ticketing or SSO); automation is reminders and recurrence.

8 — Real connector set (ticketing, HR or asset sources), webhooks, SSO/SCIM, workflow automation with delegation and escalation, useful AI assistance with human review.

10 — The platform behaves like infrastructure: API parity for the data model, event streams, bidirectional sync with the estate, and automation that measurably removes the recurring toil (reviews, attestations, evidence pulls) rather than renaming it.

Report an error

The External DPO

A documented JSON-RPC interface reads and writes all data including custom categories, external systems synchronize on event, schedule or manual trigger, and ticketing (Zammad, OTRS, KIX), discovery (JDisc, OCS), monitoring (Nagios, Checkmk) and LDAP/Active Directory feeds plus a no-code automation add-on make this behave like estate infrastructure rather than a data island. We found no public information on webhooks or single-sign-on user provisioning. 1 10 11 12

Report an error

The In-House Counsel

A documented JSON-RPC API through which external systems read, create and update data with permissions respected and access traceable, directory import from LDAP and Active Directory, named connectors for ticketing, monitoring and discovery (Zammad, Nagios, Checkmk, JDisc, OCS), and event-based triggers plus no-code Flows make the recurring work automatable rather than re-typed. We found no public information on SCIM or webhooks specifically, or on human review of the AI assistance, so it holds at this level rather than higher. 1 10 11 12

Report an error

The Drafted Generalist

This is where the platform earns its keep: Active Directory and LDAP import, an API that can read, write and update all data with permissions respected, named connectors for ticketing, monitoring and discovery tools, no-code Flows automations and event-triggered data transfer. We found no public information on single sign-on, SCIM or HR-system connections, so I hold just below the top marks. 1 11 12

Report an error

The Lead Auditor

The estate connections are real and named — ticketing (Zammad, OTRS, KIX), monitoring (Nagios, Checkmk), discovery (JDisc, OCS), directory (LDAP and Active Directory), ERP and ITSM imports — over a JSON-RPC API that reads and writes all data, respects permissions and synchronizes event-based, with no-code automations and event triggers on top. We found no public information on webhooks or SSO/SCIM specifically, and AI assistance is claimed as add-ons with no statement on human review. 1 10 11 12

Report an error

The IT Integrator

This is where the product earns its keep with me: Active Directory/LDAP person import feeding central user and rights management, a JSON-RPC API that reads and writes all data including custom categories, synchronization that is event-based, time-controlled or manual, ticketing connectors (Zammad, OTRS Community Edition, KIX), discovery via JDisc and OCS, monitoring via Nagios and Checkmk, importers from ServiceNow, Matrix42 and others, plus no-code Flows triggered by data changes. We found no public information on SSO/SCIM or webhooks as named capabilities, which is what keeps it from infrastructure grade. 2 1 11 12

Report an error

The Skeptic

The connector story is real: a JSON-RPC API with read, write and real-time access that respects permissions, ticketing, monitoring and discovery systems, AD/LDAP import, plus event-triggered and no-code automation add-ons. I found no public information on SSO/SCIM, and the "AI-supported platform" and "AI Add-ons" claims carry no substance in the captures — no model, no example, no human-review story. 1 1 11 12

Report an error

European sovereignty panel opinion

Show reasoning
How this is scored

Where the compliance record of the whole company actually lives and under whose law — entity, hosting, subprocessors, DPA. A platform that maps your processing is itself your most concentrated processing.

0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for the system holding your RoPA.

3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.

5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.

8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.

10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors, on-premises or sovereign-cloud options, and the whole chain documented publicly.

Report an error

The External DPO

The imprint shows a Düsseldorf address with a German register court and VAT number, and an on-premises deployment option exists alongside the cloud — a European-looking entity and deployment story. We found no public information on a data processing agreement, a subprocessor list, hosting locations or named data centers, which for a system holding thirty clients' registers is exactly the paper I need before signing. 5 1 11

Report an error

The In-House Counsel

The imprint shows i-doit GmbH with the Düsseldorf register court, register number 33104 and a German VAT identification, and the product runs on-premises or in cloud, so the register of processing can stay in-house. We found no public information on a published data processing agreement, a subprocessor list, or named data centers for the cloud variant — for the platform that maps my processing, I need that chain documented publicly before sign-off. 5 1 11

Report an error

The Drafted Generalist

The vendor is a German GmbH with a Düsseldorf register court and VAT ID, and on-premises deployment sits as an equal option next to the cloud, so I could keep our compliance record on our own servers. But we found no public information on where the cloud variant is hosted, or on a published data processing agreement, TOMs or a subprocessor list — and the platform mapping my processing is itself my most concentrated processing. 5 11

Report an error

The Lead Auditor

A German GmbH is fully confirmed by the imprint — Düsseldorf register court, register number 33104, VAT ID, managing directors — and on-premises deployment is offered alongside cloud. But for the system that would hold the register of processing, we found no public information on hosting locations, a published data processing agreement, or a subprocessor list. 5 11

Report an error

The IT Integrator

The imprint confirms a German legal entity — Düsseldorf address, Düsseldorf register court, German VAT ID — and an on-premises deployment option exists, so the compliance record can stay on infrastructure I control. Beyond that we found no public information on a published DPA, a subprocessor list, or where the cloud variant is hosted. 4 5 11

Report an error

The Skeptic

The imprint pins a German GmbH to a Düsseldorf register court with a German VAT ID, and on-premises is a first-class deployment option, so the foundation is solid. I found no public information on the data processing agreement, the subprocessor list, cloud hosting locations, or the ownership chain — exactly the documentation a buyer needs for the system holding their register of processing activities. 5 1 11

Report an error

Pricing transparency

Show reasoning
How this is scored

Whether a buyer can compute the real invoice — per module, per entity, per year, with consulting unbundled — from public pages alone. Unpublished pricing is the B2B norm in this market, so this criterion describes rather than condemns; the benches weight it accordingly.

0 — No public prices at all; every configuration is a sales conversation.

3 — An entry price exists, but module add-ons, entity counts or bundled consulting make the real total incomputable.

5 — Most editions carry real numbers with billing period stated and software separated from services; at least one commonly needed module or scale step is unpriced.

8 — Every edition and module priced publicly with entity/user boundaries and setup fees stated; only genuine corporate-group contracts are custom.

10 — Complete price computability: modules, scale steps, service packages and renewal rules public, so the invoice for a 100-employee company and a 10-client consultancy is a two-minute exercise.

Report an error

The External DPO

One real entry figure — INPRIVE at "ab 599€/ Jahr" — plus a free API and a 30-day trial with full functionality and no payment details. The other suite modules, the add-on bundle ("4 add-ons for the price of 2") and any per-tenant or user scaling carry no public numbers, so the invoice for a multi-mandate setup stays a sales conversation. 2 6 11

Report an error

The In-House Counsel

One real number is public — INPRIVE "ab 599€/ Jahr" — alongside a free API add-on, a 30-day trial with no payment details, and an add-on bundle quoted only as "4 powerful add-ons for the price of 2". We found no public prices for the ISMS, BCM or emergency editions, nor for user and entity boundaries or setup fees, so the invoice for anything beyond the entry product is not computable from public pages. 2 6 11

Report an error

The Drafted Generalist

One real number is public — the privacy module is quoted "ab 599€/ Jahr" — and the 30-day trial with full functionality and no payment details required is clearly stated. But the suite editions, add-ons, user or entity counts, and any setup or consulting costs carry no public prices, so I cannot compute the real invoice from public pages alone. 2 11

Report an error

The Lead Auditor

One real number is public — i-doit INPRIVE from 599€ per year — alongside a free 30-day trial without payment details, a free API add-on and a 4-for-2 add-on bundle. The other suite modules, scale steps and any setup or support fees carry no public figures, so the real total for a given company cannot be computed from the pages alone. 2 6 11

Report an error

The IT Integrator

One entry number is public — i-doit INPRIVE from 599€ per year, with a free 30-day trial — but we found no public information on prices for the Suite+ modules, the rental versus purchase licensing models, support tiers, or add-ons beyond a '4 add-ons for the price of 2' bundle claim, so the real invoice is not computable from the public pages alone. 2 5 6 11

Report an error

The Skeptic

One real number exists — "I-DOIT INPRIVE ab 599€/ Jahr" — with the API stated as free and a 30-day full-functionality trial requiring no payment details. For Suite+ module prices, individual add-on prices beyond a "4 for the price of 2" bundle, user or entity boundaries, setup fees and cloud pricing I found no public information; the FAQ asks about a cloud variant but the captured pages do not show the answer, let alone its price. 2 6 11

Report an error

European sovereignty — proven facts

0 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined — uncited Report an error
Data residency Not determined — uncited Report an error
Subprocessors Not determined — uncited Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (12)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor homepage www.i-doit.com Checked 5 Oct 2026 +2 earlier captures: 16 Sep 2026, 11 Sep 2026 Details →
  2. 2 INPRIVE data protection product page www.i-doit.com Checked 5 Oct 2026 +2 earlier captures: 15 Sep 2026, 31 Aug 2026 Details →
  3. 3 GRC suite overview www.i-doit.com Checked 5 Oct 2026 +3 earlier captures: 28 Sep 2026, 15 Sep 2026, 31 Aug 2026 Details →
  4. 4 Company page www.i-doit.com Checked 5 Oct 2026 +1 earlier capture: 31 Aug 2026 Details →
  5. 5 Imprint www.i-doit.com Checked 5 Oct 2026 +3 earlier captures: 28 Sep 2026, 16 Sep 2026, 31 Aug 2026 Details →
  6. 6 Data subject rights & incidents — found from sitemap www.i-doit.com Checked 5 Oct 2026 Details →
  7. 7 Privacy regime coverage — found from sitemap www.i-doit.com Checked 5 Oct 2026 Details →
  8. 8 Privacy regime coverage — found from sitemap www.i-doit.com Checked 5 Oct 2026 Details →
  9. 9 Audit readiness & evidence — found from sitemap www.i-doit.com Checked 5 Oct 2026 Details →
  10. 10 Audit readiness & evidence — found from sitemap www.i-doit.com Checked 5 Oct 2026 Details →
  11. 11 Integrations & automation — found from sitemap www.i-doit.com Checked 5 Oct 2026 Details →
  12. 12 Integrations & automation — found from sitemap www.i-doit.com Checked 5 Oct 2026 Details →