Data Protection
Privacysoft
EU-Made Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 2 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Projekt 29 GmbH & Co. KG · privacysoft.de
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
No written verdict for this product
The panel scored Privacysoft, but the summary our synthesizer wrote did not survive our own contradiction check — twice. Rather than print a paragraph we cannot stand behind, we print none. Every score, rationale and source below is unaffected; read them and draw the conclusion yourself.
The scores
Records & DPIA depth
Show reasoningHide reasoning
How this is scored
The DSMS core: records of processing (RoPA/VVT), data protection impact assessments, processor/DPA management and TOMs — how deeply the legal artifacts are modeled and connected.
0 — Document templates in a folder tree; the "register" is a Word file with version numbers in the filename.
3 — A structured RoPA with basic fields and a DPIA questionnaire, but processors, TOMs and legal bases live outside the system.
5 — RoPA and DPIA as linked modules with templates; processor management and TOM assignment exist but are shallow, and group reuse is copy-paste.
8 — A connected data model — processing activities linked to systems, processors, TOMs and legal bases — with DPIA triggers derived from the record, reusable group templates, and outputs a supervisory authority accepts.
10 — Privacy records as a system of record: the RoPA drives DPIAs, processor management and TOM coverage from one data model, multi-client/mandate capability included, and the documentation is audit-ready without manual assembly.
The External DPO
The RoPA is real — Art. 30 register with sample templates in DE/EN/FR, DSB-gated evaluation statuses, and a DPIA trigger derived from risk point 13 or the authority blacklist — but the DSFA module 'is currently a listing of executed assessments', group reuse is a copy function, and processors, TOMs and legal bases appear nowhere as evidenced modules. For my mandates that means half the legal artifacts live outside the tool, and cross-client reuse is manual. 3 4
The In-House Counsel
The VV module is a real Art. 30 register — sample templates in DE/EN/FR, status evaluation restricted to the DSB role, and DPIA triggers derived from the record itself (risk point 13 red or supervisory authority blacklist). But the DSFA module is described as 'currently a listing' of conducted assessments, and nowhere in the registry is there processor/DPA management, TOM assignment or legal bases as structured data — they live outside the system. 3 4
The Drafted Generalist
The RoPA module is genuinely structured — Art. 30 fields, sample templates in three languages, copy function, tags and attachments — with DPIA triggers derived from the risk assessment. But the DPIA module is explicitly 'a listing of conducted DPIAs', and nothing shows processor management, TOMs or legal bases living in the system, so that paperwork stays in my spreadsheets. 3 4
The Lead Auditor
A genuinely structured RoPA with three-language sample templates, tags/attachments and DSB-role-gated evaluation, plus a DPIA trigger derived from the record's risk assessment; but the DPIA module is explicitly 'currently a listing' of conducted assessments, and processor, TOM and legal-basis management appear nowhere in the evidence. That sits between a structured register with shallow sides and linked modules — 4. 3 4
The IT Integrator
The RoPA module is real — Art. 30 register with sample templates in three languages, tags/links/comments, and a copy function for reuse — and DPIA triggers derive from the record's risk assessment or the authority blacklist. But the DPIA module is explicitly 'a listing of conducted DPIAs', and processors, TOMs and legal bases appear nowhere in the documentation; group reuse is literally copy-paste, so this sits between rubric level 3 and 5. 3 4
The Skeptic
The RoPA module is real enough — Art. 30 register, trilingual templates, sample Vorlagen, copy function, DSB-gated evaluation statuses — but the DPIA module's own documentation admits it 'is currently a listing of conducted data protection impact assessments', which is a filing cabinet, not an assessment tool. No processor, TOM or legal-basis module appears anywhere in the captured pages, so they live outside the system by silence. Structured register, shallow everything else. 3 4
Data subject rights & incidents
Show reasoningHide reasoning
How this is scored
The operational half of the DSMS: data subject request handling with statutory clocks, breach register and authority notification, deletion concepts that actually delete.
0 — Requests arrive by email and live there; breaches are a phone call and a memo.
3 — A request log and a breach list exist, but deadlines are manual, intake is unstructured, and deletion rules are documentation rather than workflow.
5 — DSR workflows with the Art. 12 clock tracked, structured breach register with the 72-hour clock, deletion concepts assignable to records; automation is reminders.
8 — Intake channels for requests (portal/form), identity-check support, deadline automation with escalation, breach severity assessment and authority-report output, deletion rules tied to the RoPA with execution tracking.
10 — Rights and incidents as operations: end-to-end request handling an authority audit walks through, breach workflows that produce the Art. 33 notification, and deletion automation with evidence that the deletion happened.
The External DPO
Nothing on DSR intake, Art. 12 clocks, a breach register or 72-hour workflows appears anywhere in the captured documentation; the only deletion primitive is that uploaded attachments can be permanently deleted while register entries cannot be deleted at all. That is data hygiene, not rights operations — I would be running client requests by email beside the tool. 3
The In-House Counsel
Nothing in the registry evidences a data subject request workflow, a breach register or any authority notification path — no Art. 12 clock, no 72-hour clock, nothing I could show a supervisory authority. The only deletion facts concern RoPA records (archived, never deleted) and attachments, which is register hygiene, not deletion-as-workflow. Missing evidence is information: this half of the DSMS does not exist on this sheet, and I cannot defend a notification timeline with it. 2 3
The Drafted Generalist
Nothing in the captured documentation shows a request inbox, a breach register, statutory clocks or deletion workflows — the only deletion fact is that processing activities cannot be deleted at all, only archived. For my 80-person firm, data subject requests and breach cases would still live in an email folder. 3
The Lead Auditor
Nothing evidences DSR intake, statutory clocks, a breach register or authority-report output, and the only deletion facts run the other way: processing activities cannot be deleted, only archived. By the anchors, absence of any request or incident capability is a 0. 3
The IT Integrator
Total silence on DSR intake, statutory clocks, breach register or authority notification — nothing in the captured docs evidences any of it. The only deletion-adjacent fact is that attachments can be permanently deleted while processing activities cannot be deleted at all, only archived; that's document hygiene, not rights operations. 3
The Skeptic
Total silence on data subject requests and breach handling — no request log, no statutory clock, no authority-notification output anywhere in the evidence. The only deletion facts are that processing activities cannot be deleted at all (archive only) and attached files can be, which is file hygiene, not rights operations. 3
Privacy regime coverage
Show reasoningHide reasoning
How this is scored
Which privacy regimes the product actually operationalizes — GDPR, BDSG, Swiss nDSG, UK GDPR, ePrivacy, EU AI Act privacy duties — and whether one record maps across them or each regime is a fresh island.
0 — One regime, hard-coded; anything else is "on the roadmap".
3 — GDPR plus one national law as separate checklists; the same processing activity is documented once per regime.
5 — The major regimes for its market with partial cross-mapping; newer duties (AI Act, ePrivacy changes) present as content packs of varying depth.
8 — Broad current coverage with one-record-many-regimes mapping and visible maintenance as regimes evolve.
10 — Regime coverage as a living product: multiple privacy regimes on one data basis, per-country variants, and documented update cadence when the law moves.
The External DPO
Everything anchors to DSGVO — Art. 30, the supervisory-authority blacklist, German-language documentation — and the German/English/French template versions are language variants of one GDPR standard, not regimes. No BDSG, Swiss nDSG, UK GDPR or AI Act duties and no one-record-many-regimes mapping are evidenced, so each non-GDPR mandate would be a fresh island. 3 4
The In-House Counsel
Everything captured is GDPR in German practice — Art. 30 DSGVO, the Aufsichtsbehörden blacklist trigger — and the German/English/French options are language versions of the same GDPR template, not different regimes. No BDSG, nDSG, UK GDPR, ePrivacy or AI Act content appears anywhere, and no cross-regime mapping is evidenced. One regime, hard-coded; if my company operates outside Germany, this register has nothing to say about it. 3 4
The Drafted Generalist
Everything documented is GDPR: the Art. 30 register, the supervisory-authority blacklist check, with templates in German, English and French. No BDSG, nDSG, UK GDPR or AI Act content appears anywhere in the captured pages, so it reads as one regime, well done, full stop. 3
The Lead Auditor
The entire captured surface is GDPR (Art. 30 DSGVO, DSFA); the English and French templates are translations of the same DSGVO standard, not separate regimes, and no BDSG, nDSG, UK GDPR, ePrivacy or AI Act content is evidenced. One hard-coded regime with multilingual window dressing. 3 4
The IT Integrator
Every regime reference is GDPR: Art. 30 DSGVO register, DSGVO templates in DE/EN/FR — and language variants are not regimes. No BDSG, nDSG, UK GDPR, ePrivacy or AI Act duty appears anywhere in the captured evidence; one regime, one record base, no cross-mapping story. 3
The Skeptic
Everything routes to DSGVO: an Art. 30 register, a GDPR risk assessment where point 13 triggers a DPIA, supervisory-authority blacklist references. The German/English/French 'versions' are translations of one GDPR standard template (#13v10), not different regimes — no BDSG specifics, no nDSG, no UK GDPR, no AI Act appears anywhere. 3
Audit readiness & evidence
Show reasoningHide reasoning
How this is scored
Whether the system produces defensible proof: revision-safe history, evidence collection, reports for auditors, authorities and management.
0 — Exports are screenshots; history is overwritten in place.
3 — PDF reports exist but evidence is attached ad hoc and changes leave no reliable trail.
5 — Versioned records, standard report generators for the core registers, evidence attachments per activity; assembling a full audit file still takes days.
8 — Revision-safe change history, audit-scoped evidence packs on demand, management and authority reports current at a click, auditor access roles.
10 — Audit readiness as a standing state: continuous documentation status per regime and scope, exportable proof packs an auditor accepts as-is, and a defensible answer to "show me the state on date X".
The External DPO
The report wizard outputs RoPA and DPIA reports, activities carry attachments, and records can only be archived, never deleted, which gives weak immutability. But no revision-safe change history, auditor access roles or evidence packs are evidenced — assembling a client's audit file would still cost me days of billable hours per mandate. 3 4
The In-House Counsel
The report wizard outputs reports over VVs and DSFAs, and the non-deletability of processing records ('cannot be deleted, only archived') is a genuine integrity gesture. But there is no revision-safe change history, no evidence packs, no auditor access role and no defensible answer to 'show me the state on date X' — I would still assemble the audit file by hand. Reports exist; the trail behind them does not. 3 4
The Drafted Generalist
There's a report wizard for VVs and DPIAs and document evaluation is locked to the DSB role, which is decent governance for a two-person function. But there's no evidence of revision-safe change history, evidence packs or auditor access, so an audit file would still be days of assembly and hoping. 3 4
The Lead Auditor
Report wizards for RoPA and DPIA, a four-state documentation status per record, and a register that structurally cannot be silently deleted (archival only) give a partial trail — better than ad-hoc PDFs. But no revision-safe change history, no audit-scoped evidence packs and no auditor access roles are evidenced, so the audit file is still assembled by hand. 3 4
The IT Integrator
There is a report wizard for RoPA and DPIA outputs, per-document evaluation statuses gated to the DSB role, and archive-not-delete prevents silent overwrites. But no versioned change history, evidence packs, auditor roles or point-in-time answer are evidenced — assembling a full audit file still looks like days of manual work, which anchors between 3 and 5. 3 4
The Skeptic
There is a report wizard over one or more VVs and DSFAs, attachments per activity, and archive-not-delete gives records some permanence. But no versioned change history, no evidence packs, no auditor access roles are evidenced anywhere — assembling a defensible audit file would still be days of manual work. 3 4
Integrations & automation
Show reasoningHide reasoning
How this is scored
Whether the platform feeds from the real IT estate — directory import, ticketing, API — and automates the recurring privacy work instead of re-typing it.
0 — A closed island: manual entry in, PDF out, no API.
3 — CSV/Excel import and export; no live connections, no API worth the name.
5 — Directory import (AD/Entra), a documented REST API for core objects, a handful of native connectors (ticketing or SSO); automation is reminders and recurrence.
8 — Real connector set (ticketing, HR or asset sources), webhooks, SSO/SCIM, workflow automation with delegation and escalation, useful AI assistance with human review.
10 — The platform behaves like infrastructure: API parity for the data model, event streams, bidirectional sync with the estate, and automation that measurably removes the recurring toil (reviews, attestations, evidence pulls) rather than renaming it.
The External DPO
The vendor hosts everything and bundles IT administration, maintenance and updates into the license fee, but no API, directory import, ticketing connector or SSO appears anywhere in the captured pages; the report export is the only outbound path. Across thirty clients that means re-typing each estate by hand — a closed island with PDF out. 1 3
The In-House Counsel
The registry shows no API, no directory import, no ticketing or SSO connectors, no webhooks — not even CSV import is evidenced. The only 'included' services are the vendor's own IT administration, maintenance and updates under the license fee, which is a managed-hosting promise, not estate integration. Manual entry in, report out: a closed island. 1 2
The Drafted Generalist
The captured pages show no API, no directory import, no connectors and no automated workflows — data goes in by hand and comes out as reports. The closest thing to automation is that the license fee bundles the vendor's IT administration, maintenance and updates, which is a service, not an integration. 1 3
The Lead Auditor
No API, directory import, connector or SSO appears anywhere in the evidence; the only automation-adjacent feature is a manual copy function for processing activities, and the license bundling 'complete IT administration' confirms a managed closed island. Manual entry in, report out — rubric level 0. 1 3
The IT Integrator
My home turf, and it's empty: the product documentation portal and module pages mention no API, no webhooks, no SSO, no directory import, not even CSV. Data goes in through manual forms and sample templates and out through the report wizard — a closed island where the RoPA is stale the day after someone types it; the only bundled service is that the vendor runs the hosting, which is operations, not integration. 1 2 3
The Skeptic
Not one word on API, CSV import, directory sync, SSO, ticketing or webhooks in the entire captured set — the only I/O evidence is manual entry and report output, a closed island by the anchor's own definition. The vendor taking over your IT administration as part of the license is a hosting promise, not an integration. 1 3
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where the compliance record of the whole company actually lives and under whose law — entity, hosting, subprocessors, DPA. A platform that maps your processing is itself your most concentrated processing.
0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for the system holding your RoPA.
3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.
5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.
8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.
10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors, on-premises or sovereign-cloud options, and the whole chain documented publicly.
The External DPO
German KG with a named Verwaltungs-GmbH, Regensburg seat and infrastructure in a German ISO 27001 data center — the right jurisdiction for the system holding my clients' RoPA. But ownership of the Verwaltungs-GmbH is undisclosed and no public DPA, TOMs or subprocessor list is evidenced, so the chain is German at both ends yet undocumented in the middle. 1 2 5
The In-House Counsel
The entity is verifiably German — Projekt 29 GmbH & Co. KG, Regensburg, HRA 8442, VAT DE278338298 — and hosting sits in a German ISO 27001 data center, which is what I want under the system holding my RoPA. But no DPA, TOMs or subprocessor list are published in the evidence, and the ownership chain stops at an undisclosed Verwaltungs-GmbH, so I cannot verify the chain is free of non-European jurisdictional reach. Solid facts, unreadable chain: middle of the field. 1 5
The Drafted Generalist
A German entity in Regensburg with hosting in a German ISO-27001 data center is a solid base for the system holding my RoPA. But vendor ownership is undisclosed and no DPA or subprocessor list appears in the captured pages, so the chain under my compliance record isn't documented end to end. 1 5
The Lead Auditor
German entity is fully evidenced down to the register court and VAT ID and hosting is outsourced to a German ISO 27001 data center — but the center hides behind the product's own name, with no published DPA, no subprocessor list and undisclosed ownership of the Verwaltungs-GmbH. For the system holding your RoPA, that is not yet a defensible chain. 1 5
The IT Integrator
German KG with clean register entries and ISO-27001 German data-center hosting — the bones are right, and this clears rubric level 3. But the general partner's ownership is undisclosed, and no DPA, subprocessor list or TOMs appear in the evidence at all; for the system that holds the RoPA, an undocumented chain of processors keeps it below rubric level 5. 1 5
The Skeptic
German entity with full register transparency and German hosting claimed — but 'PRIVACYSOFT-Rechenzentrum (nach ISO 27001 zertifiziert)' is a self-branded data center with no named operator and no certificate detail, no public DPA, no subprocessor list, and the ownership behind the Verwaltungs-GmbH is undisclosed. Your entire compliance record lives in a facility the vendor describes only by its own brand name. 1 2 5
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real invoice — per module, per entity, per year, with consulting unbundled — from public pages alone. Unpublished pricing is the B2B norm in this market, so this criterion describes rather than condemns; the benches weight it accordingly.
0 — No public prices at all; every configuration is a sales conversation.
3 — An entry price exists, but module add-ons, entity counts or bundled consulting make the real total incomputable.
5 — Most editions carry real numbers with billing period stated and software separated from services; at least one commonly needed module or scale step is unpriced.
8 — Every edition and module priced publicly with entity/user boundaries and setup fees stated; only genuine corporate-group contracts are custom.
10 — Complete price computability: modules, scale steps, service packages and renewal rules public, so the invoice for a 100-employee company and a 10-client consultancy is a two-minute exercise.
The External DPO
The only pricing fact is scope, not numbers: the license fee includes IT administration, maintenance and updates. No edition prices, module prices or per-client scale steps are public, so I cannot compute the invoice for a ten-mandate deployment without a sales conversation. 1
The In-House Counsel
The only pricing fact captured is what the license fee includes — IT administration, maintenance, updates — with no figure, edition, module price or billing period anywhere in the registry. The real invoice is a sales conversation by definition; rubric level 0 describes the market norm rather than condemning it, but it is 0 all the same. 1
The Drafted Generalist
The only pricing fact is what the license fee includes — IT administration, maintenance, updates — with no figures, editions, module prices or scale steps anywhere. I cannot even ballpark what an 80-employee firm pays without calling sales. 1
The Lead Auditor
The only pricing fact is what the license fee bundles (IT administration, maintenance, updates) — no number for any edition, module or scale step exists in the evidence. Every configuration is a sales conversation, which is rubric level 0. 1
The IT Integrator
One fee statement — the license includes IT administration, maintenance and updates — and not a single number anywhere in the captured pages, so bundled services actually make the invoice less computable. Every configuration is a sales conversation, which is exactly rubric level 0 with a sliver of scope disclosure. 1
The Skeptic
No price figure appears anywhere on the captured pages; the single pricing fact says the license fee bundles IT administration, maintenance and updates — services welded to software with no module boundaries and no numbers. Every invoice is a sales conversation, and the bundling means you cannot even decompose what you would be paying for. 1
European sovereignty — proven facts
2 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Incorporated in DE ⚠ unverified | 3/3 pts | 5 Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | EU only ⚠ unverified | 3/3 pts | 1 Report an error |
| Subprocessors | Not determined ⚠ unverified | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 15 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Legal entity. Es werden weder Landesname noch Registerauflösungsbeteiligungen zu Nicht-EU-Investoren angegeben; die Einordnung folgt dem deutschen Register und der deutschen USt-ID.
- Weak sourcing — Data residency. Die Aussage steht nur im Marketing- bzw. Lizenzabschnitt der Homepage; ein Betreiber oder eine konkrete Serverstandortangabe in rechtlichen Dokumenten fehlt.
- Weak sourcing — Subprocessors. Not confirmed on the vendor’s own pages as captured.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- We found no public information on compliance on the pages we read (privacysoft.de, help.privacysoft.online, help.privacysoft.online/pso/mod_vv, help.privacysoft.online/pso/mod_dsfa, privacysoft.de/impressum). If the vendor publishes it somewhere else, send us the page. Know more? Tell us
- 1 legal fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 product fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 sovereignty dimension could not be confirmed on the vendor’s own pages and is shown as unknown. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
- The panel’s written verdict is withheld: our own re-read found claims in it that the evidence does not carry, and a second synthesis did not fix them. The scores and the material below are unaffected. Know more? Tell us
Sources (5)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage privacysoft.de Checked 15 Sep 2026 Details →
- 2 Product documentation portal help.privacysoft.online Checked 15 Sep 2026 Details →
- 3 RoPA module documentation help.privacysoft.online Checked 15 Sep 2026 Details →
- 4 DPIA module documentation help.privacysoft.online Checked 15 Sep 2026 Details →
- 5 Imprint privacysoft.de Checked 15 Sep 2026 Details →