Data Protection
PrivacyPerfect
Provenance unknown Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 1 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Privacy Perfect B.V. · privacyperfect.com
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
PrivacyPerfect, from Privacy Perfect B.V., is an EU-based legal-tech SaaS selling GRC for AI, privacy and security across four named modules: Privacy Management, Information Security Management, Third Party Risk and an AI Assessment Manager. The strongest scoring is sovereignty, 2-4 and clustering at 4: the vendor states it is "fully EU-based", processes all client data in the Netherlands and lists a Rotterdam address, and the spread reflects differing weight on the DPA, subprocessor and ownership details that remain unevidenced. Framework coverage scores 2-3 on stated GDPR positioning plus the dedicated AI module. The weakest areas are rights and incidents at 0-1 and integrations and automation at 0-1: we found no public information on data subject request workflows, statutory clocks, breach registers, an API, directory import, SSO or ticketing connectors. Audit readiness scores a flat 1 — the ISO 27001 certification speaks to the vendor's own management, not the product's audit outputs. Privacy management scores 1-2, a module name with no register structure shown. No prices are published; a free trial is offered.
Speaks for it
- The vendor states it is fully EU-based, processing all client data in the Netherlands, with a Rotterdam address (sovereignty 2-4, clustering at 4)
- A dedicated AI Assessment Manager module treats newer AI duties as product, alongside stated GDPR positioning
- ISO 27001 certification is stated on the vendor's page, evidencing its own security management
- A free trial is offered publicly
Held against it
- Rights and incidents scored 0-1; we found no public information on data subject request workflows, statutory deadline tracking or breach registers
- Integrations and automation scored 0-1; we found no public information on an API, directory import, SSO or ticketing connectors
- Audit readiness scored a flat 1; the ISO 27001 claim evidences the vendor's own security management, not evidence packs or auditor access in the product
- Privacy management scored 1-2; module names appear with no shown register structure for records of processing, DPIAs or TOMs
- We found no public information on a published DPA, a subprocessor list or ownership behind the EU hosting statements
Best for
- You need a compliance platform whose stated default is EU hosting, with all client data processed in the Netherlands
- Your work centres on GDPR plus AI governance, and you want AI assessment treated as a shipped module rather than roadmap
- You want to test the platform yourself before any commercial conversation, starting from the publicly offered free trial
Avoid if
- You must run data subject requests on statutory clocks and keep a breach register; rights and incidents scored 0-1 with nothing shown
- Your team expects the platform to feed from your real IT estate through an API, directory import or SSO rather than re-typed entries; integrations and automation scored 0-1
- You need to hand an auditor or authority revision-safe history and evidence packs; audit readiness scored a flat 1
- You require a published DPA, subprocessor list and ownership chain before contracting; we found no public information on any of these behind the EU statements
The scores
Records & DPIA depth
Show reasoningHide reasoning
How this is scored
The DSMS core: records of processing (RoPA/VVT), data protection impact assessments, processor/DPA management and TOMs — how deeply the legal artifacts are modeled and connected.
0 — Document templates in a folder tree; the "register" is a Word file with version numbers in the filename.
3 — A structured RoPA with basic fields and a DPIA questionnaire, but processors, TOMs and legal bases live outside the system.
5 — RoPA and DPIA as linked modules with templates; processor management and TOM assignment exist but are shallow, and group reuse is copy-paste.
8 — A connected data model — processing activities linked to systems, processors, TOMs and legal bases — with DPIA triggers derived from the record, reusable group templates, and outputs a supervisory authority accepts.
10 — Privacy records as a system of record: the RoPA drives DPIAs, processor management and TOM coverage from one data model, multi-client/mandate capability included, and the documentation is audit-ready without manual assembly.
The External DPO
A Privacy Management module and ten years of GRC positioning are named, but we found no public information on how records of processing, DPIAs, processors, TOMs or legal bases are modeled or linked. For a thirty-mandate practice the make-or-break is group templates and multi-client structure, and the captured page is silent on both. 1
The In-House Counsel
A dedicated Privacy Management module exists in a four-module suite, but the captured page stops at the name: we found no public information on records of processing, DPIA workflow, processor and DPA management, or TOM handling, so I cannot defend artifacts I have not seen. 1
The Drafted Generalist
The captured page names a Privacy Management module and ten-plus years of experience, but shows no register structure of any kind. I found no public information on records of processing, DPIA workflows, processor management or technical and organisational measures — I cannot build a register from a module name. 1
The Lead Auditor
Only module names are public — Privacy Management, Third Party Risk, an AI Assessment Manager — with no view into how records of processing, DPIAs, TOMs, legal bases or processors are modelled or linked. We found no public information on register structure, templates or reusable group content, so the depth of the legal artifacts cannot be verified beyond the marketing names. 1
The IT Integrator
The captured page names Privacy Management and Third Party Risk modules on a platform sold as GRC for privacy and security, so the register exists somewhere, but we found no public information on how records of processing, DPIAs, TOMs or legal bases are modeled or linked. A module list is not a data model, and I cannot score depth the page never shows. 1
The Skeptic
The captured page lists Privacy Management among four modules and pitches GRC for privacy, security and AI, but we found no public information on records of processing, impact assessments, processor management or security measures modeling — a module label with nothing shown behind it. "10+ years of expertise" and "thousands of professionals" are testimonials, not a data model. 1
Data subject rights & incidents
Show reasoningHide reasoning
How this is scored
The operational half of the DSMS: data subject request handling with statutory clocks, breach register and authority notification, deletion concepts that actually delete.
0 — Requests arrive by email and live there; breaches are a phone call and a memo.
3 — A request log and a breach list exist, but deadlines are manual, intake is unstructured, and deletion rules are documentation rather than workflow.
5 — DSR workflows with the Art. 12 clock tracked, structured breach register with the 72-hour clock, deletion concepts assignable to records; automation is reminders.
8 — Intake channels for requests (portal/form), identity-check support, deadline automation with escalation, breach severity assessment and authority-report output, deletion rules tied to the RoPA with execution tracking.
10 — Rights and incidents as operations: end-to-end request handling an authority audit walks through, breach workflows that produce the Art. 33 notification, and deletion automation with evidence that the deletion happened.
The External DPO
We found no public information on data subject request intake, statutory clocks, a breach register with the 72-hour duty, authority-report output or deletion execution. Nothing on the captured page speaks to the operational half of a DSMS, so I can credit only that a privacy module exists at all. 1
The In-House Counsel
For the operational half of my obligations this page is silent: we found no public information on data subject request workflows, statutory deadline tracking, a breach register, or authority notification output, and my standing rule is that an unproven clock is a slipping clock. 1
The Drafted Generalist
Nothing in the captured material addresses data subject requests, breach handling or deletion. I found no public information on request intake, statutory clocks or 72-hour breach workflows, which are exactly the things I would need spelled out in plain language before trusting a tool with them. 1
The Lead Auditor
We found no public information on data subject request workflows, statutory deadline tracking, breach registers, authority-notification output or deletion execution. Nothing in the captured material shows intake channels or operational handling, so this sits at the bottom of the scale. 1
The IT Integrator
We found no public information on data subject request workflows, statutory deadline tracking, a breach register or deletion execution — not even a module name touches the rights-and-incidents half of a DSMS. From the evidence I hold, this operational side is unverifiable. 1
The Skeptic
We found no public information on data subject request workflows, statutory clocks, breach registers, authority notifications or deletion tracking. Nothing on the captured pages so much as gestures at the operational half of a privacy programme. 1
Privacy regime coverage
Show reasoningHide reasoning
How this is scored
Which privacy regimes the product actually operationalizes — GDPR, BDSG, Swiss nDSG, UK GDPR, ePrivacy, EU AI Act privacy duties — and whether one record maps across them or each regime is a fresh island.
0 — One regime, hard-coded; anything else is "on the roadmap".
3 — GDPR plus one national law as separate checklists; the same processing activity is documented once per regime.
5 — The major regimes for its market with partial cross-mapping; newer duties (AI Act, ePrivacy changes) present as content packs of varying depth.
8 — Broad current coverage with one-record-many-regimes mapping and visible maintenance as regimes evolve.
10 — Regime coverage as a living product: multiple privacy regimes on one data basis, per-country variants, and documented update cadence when the law moves.
The External DPO
Privacy, information security, vendor risk and AI are named as product areas, and a dedicated AI Assessment Manager module at least treats the newer AI duties as product rather than roadmap. We found no public information on which privacy regimes are operationalized, on country variants, or on whether one processing record maps across regimes. 1
The In-House Counsel
The vendor says it helps clients navigate data protection and AI regulations and ships a dedicated AI Assessment Manager, but no specific regime is operationalized on the page — GDPR appears only in the statement about the vendor's own client-data processing — and we found no public information on cross-regime mapping or a maintenance cadence for the legal content. 1
The Drafted Generalist
The vendor markets privacy and AI regulation coverage, with a dedicated AI Assessment Manager module alongside the privacy one, and positions everything as GDPR-compliant. I found no public information on which regimes are actually operationalized — Swiss or UK variants, ePrivacy duties — or whether one processing record maps across them. 1
The Lead Auditor
The captured page anchors everything in GDPR compliance from a Netherlands base and mentions AI regulations in passing, with the AI module as the only visible nod beyond privacy. We found no public information on national law variants, UK or Swiss coverage, or one-record-many-regimes mapping; the weekly regulatory newsletter is a service, not evidenced regime coverage in the product. 1
The IT Integrator
GDPR compliance is stated plainly and a dedicated AI Assessment Manager module signals the newer AI duties are treated as product rather than roadmap. But we found no public information on national variants such as BDSG or the Swiss nDSG, or whether one processing record maps across regimes instead of being documented per regime. 1
The Skeptic
GDPR is the only regime the page actually invokes ("strict GDPR compliance"), with an AI Assessment Manager module hinting at AI-regulation work; we found no public information on other regimes, cross-mapping between them, per-country variants or update cadence. One regime named, everything else unevidenced. 1
Audit readiness & evidence
Show reasoningHide reasoning
How this is scored
Whether the system produces defensible proof: revision-safe history, evidence collection, reports for auditors, authorities and management.
0 — Exports are screenshots; history is overwritten in place.
3 — PDF reports exist but evidence is attached ad hoc and changes leave no reliable trail.
5 — Versioned records, standard report generators for the core registers, evidence attachments per activity; assembling a full audit file still takes days.
8 — Revision-safe change history, audit-scoped evidence packs on demand, management and authority reports current at a click, auditor access roles.
10 — Audit readiness as a standing state: continuous documentation status per regime and scope, exportable proof packs an auditor accepts as-is, and a defensible answer to "show me the state on date X".
The External DPO
The vendor's own ISO 27001 certification speaks to their security posture, not to the product's audit outputs. We found no public information on revision-safe history, report generators, evidence packs or auditor access, so there is nothing to hand a client before an authority visit on this capture. 1
The In-House Counsel
The ISO 27001 certification is real and I credit it, but it evidences the vendor's own security management, not my audit file: we found no public information on revision-safe change history, report generators, evidence collection, or auditor access in the product itself. 1
The Drafted Generalist
The ISO 27001 certification speaks to the vendor's own security management rather than anything I could hand an auditor or a supervisory authority. I found no public information on revision-safe history, report generators, evidence packs or auditor access in the product. 1
The Lead Auditor
The only evidence is the vendor's own ISO 27001 certification, which speaks to their information security management, not to revision-safe change history or evidence packs in the product. We found no public information on versioned records, auditor reports, auditor access roles or exportable proof — a defensible answer to "show me the state on date X" is entirely unevidenced. 1
The IT Integrator
The vendor's own ISO 27001 certification speaks to their internal ISMS, not to what the product produces for an auditor; we found no public information on revision-safe change history, evidence packs, auditor roles or authority-facing reports. Nothing captured shows me proof I could hand to a supervisor. 1
The Skeptic
The page asserts "ISO 27001 certification" in passing, and we found no public information identifying a certifying body, scope or certificate link behind the badge — exactly the kind of logo I hunt. Beyond that claim, we found no public information on revision-safe history, evidence packs, auditor access or report generation. 1
Integrations & automation
Show reasoningHide reasoning
How this is scored
Whether the platform feeds from the real IT estate — directory import, ticketing, API — and automates the recurring privacy work instead of re-typing it.
0 — A closed island: manual entry in, PDF out, no API.
3 — CSV/Excel import and export; no live connections, no API worth the name.
5 — Directory import (AD/Entra), a documented REST API for core objects, a handful of native connectors (ticketing or SSO); automation is reminders and recurrence.
8 — Real connector set (ticketing, HR or asset sources), webhooks, SSO/SCIM, workflow automation with delegation and escalation, useful AI assistance with human review.
10 — The platform behaves like infrastructure: API parity for the data model, event streams, bidirectional sync with the estate, and automation that measurably removes the recurring toil (reviews, attestations, evidence pulls) rather than renaming it.
The External DPO
A free trial and dedicated support offerings are described, but we found no public information on an API, directory import, ticketing connectors, SSO or workflow automation. Nothing here shows the platform feeding from a client's real IT estate instead of re-typed entries. 1
The In-House Counsel
We found no public information on an API, directory import, ticketing or HR connectors, SSO, or automation of recurring privacy work; nothing captured here shows the platform feeding from a real IT estate rather than re-typing. 1
The Drafted Generalist
The only operational detail visible on the page is a Start Free Trial button. I found no public information on an API, directory import, ticketing connectors or single sign-on, and re-typing our IT estate by hand is a deal-breaker for an 80-person firm with no compliance department. 1
The Lead Auditor
We found no public information on an API, directory import, ticketing connectors, SSO or any workflow automation. The support offerings on the captured page — newsletter, training programmes, dedicated teams — are services around the product, not automation within it. 1
The IT Integrator
This is where I look first, and the page shows me nothing to connect to: we found no public information on an API, directory import from Entra ID or AD, webhooks, SSO or SCIM, or ticketing and asset connectors. For a platform that would hold our records of processing, an undocumented integration story is a data island until proven otherwise, and I score the evidence, not the likely reality. 1
The Skeptic
We found no public information on an API, directory or ticketing connectors, SSO, webhooks or workflow automation. The only operational artifact on the captured pages is a free-trial button. 1
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where the compliance record of the whole company actually lives and under whose law — entity, hosting, subprocessors, DPA. A platform that maps your processing is itself your most concentrated processing.
0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for the system holding your RoPA.
3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.
5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.
8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.
10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors, on-premises or sovereign-cloud options, and the whole chain documented publicly.
The External DPO
The captured page states plainly that all client data is processed in the Netherlands, fully EU-based, with a Rotterdam address — a reasonable home for a client's most concentrated processing record. But we found no public information on the DPA, the subprocessor list, named data centers or ownership, so the chain is only half-documented. 1
The In-House Counsel
The page states the vendor is fully EU-based and processes all client data in the Netherlands, backed by a Rotterdam address and ISO 27001 — the right default for the system that would hold my records of processing — but we found no public information on a published DPA, a subprocessor list, named data centers, or the ownership chain, so the end-to-end jurisdictional picture stays unverified. 1
The Drafted Generalist
The page states that all client data is processed in the Netherlands, and the Rotterdam address and fully-EU-based positioning fit that. But I found no public information on a published data processing agreement, a subprocessor list, or ownership — and this platform would be holding my entire compliance record, so the chain matters. 1
The Lead Auditor
The captured page states the vendor processes all client data in the Netherlands under GDPR, lists a Rotterdam address and claims ISO 27001 certification — a European posture for the system that would hold a client's registers. We found no public information on a published DPA, a subprocessor list, ownership or named data centres, so the chain is asserted in marketing rather than documented. 1
The IT Integrator
The vendor's own words — fully EU-based, with all client data processed in the Netherlands under GDPR — alongside a Rotterdam address put EU hosting as the default rather than an option, with a Dutch entity behind the product. We found no public information on a published DPA, a subprocessor list or named data centers, which is what stands between EU-by-default and a jurisdictionally documented chain. 1
The Skeptic
The vendor states it is "fully EU-based", processes all client data in the Netherlands, and publishes a Rotterdam street address, which puts EU hosting on the right side of default. But we found no public information on a published DPA, a subprocessor list, or ownership, so everything above the hosting claim remains unevidenced. 1
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real invoice — per module, per entity, per year, with consulting unbundled — from public pages alone. Unpublished pricing is the B2B norm in this market, so this criterion describes rather than condemns; the benches weight it accordingly.
0 — No public prices at all; every configuration is a sales conversation.
3 — An entry price exists, but module add-ons, entity counts or bundled consulting make the real total incomputable.
5 — Most editions carry real numbers with billing period stated and software separated from services; at least one commonly needed module or scale step is unpriced.
8 — Every edition and module priced publicly with entity/user boundaries and setup fees stated; only genuine corporate-group contracts are custom.
10 — Complete price computability: modules, scale steps, service packages and renewal rules public, so the invoice for a 100-employee company and a 10-client consultancy is a two-minute exercise.
The External DPO
A free trial is offered publicly, but we found no public information on edition, module, per-entity or service pricing, and nothing separates software from consulting. The real invoice for a ten-client consultancy is uncomputable from the captured pages, which is the market norm but still my starting question on a first call. 1
The In-House Counsel
The only pricing-adjacent fact anywhere is a free trial offer; no editions, module prices, billing periods or setup fees appear, so every configuration is a sales conversation and the real invoice cannot be computed from public pages. 1
The Drafted Generalist
The captured page shows a Start Free Trial button and no price figures of any kind. I found no public information on editions, per-module prices or billing terms — unpublished pricing is the norm in this market, but there is nothing here to compute an invoice from. 1
The Lead Auditor
The only pricing-related item anywhere in the capture is a free-trial offer. We found no public information on edition prices, module costs, billing periods, user or entity boundaries, or how consulting is bundled, so a buyer cannot compute any part of the invoice from these pages. 1
The IT Integrator
The only commercial signal on the captured page is a free trial; we found no public information on edition prices, module add-ons, user or entity boundaries, or software separated from services. Unpublished pricing is the norm in this market, but from the page alone I cannot begin to compute an invoice. 1
The Skeptic
The only pricing-adjacent signals are a "Start Free Trial" button and a claim to serve "SMEs to multinationals"; we found no public information on edition or module prices, billing periods, entity boundaries, setup fees or how consulting is separated from software. A trial is not a price. 1
European sovereignty — proven facts
1 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined ⚠ unverified | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | EU only ⚠ unverified | 3/3 pts | 1 Report an error |
| Subprocessors | Not determined | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 22 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Legal entity. Not confirmed on the vendor’s own pages as captured.
- Weak sourcing — Data residency. This is homepage marketing copy; the privacy policy or DPA contractually confirming the hosting location is not among the excerpts.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 5 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 sovereignty dimension could not be confirmed on the vendor’s own pages and is shown as unknown. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (6)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor page privacyperfect.com Checked 22 Sep 2026 Details →
- 2 Terms of service — found from the homepage privacyperfect.com Checked 30 Sep 2026 Details →
- 3 Records & DPIA depth — found from sitemap privacyperfect.com Checked 1 Oct 2026 Details →
- 4 Data subject rights & incidents — found from sitemap privacyperfect.com Checked 1 Oct 2026 Details →
- 5 Data subject rights & incidents — found from sitemap privacyperfect.com Checked 1 Oct 2026 Details →
- 6 Privacy regime coverage — found from sitemap privacyperfect.com Checked 1 Oct 2026 Details →