Data Protection
secuvera easy Datenschutz
Provenance unknown Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 1 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by secuvera GmbH · secuvera.de
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
secuvera easy Datenschutz, the data-protection offering of secuvera GmbH (Siedlerstraße 22-24, 71126 Gäufelden/Stuttgart), is judged from a single captured vendor page presenting the firm's security consultancy — BSI-Grundschutz, ISO 27001 and VDA ISA/TISAX consulting, penetration testing since 2000 — rather than product documentation. Scoring sits at or near the floor throughout: privacy management, rights and incidents, integrations and automation, and pricing transparency each span 0 to 0, and the judges' weighted totals run from 0.1 to 0.5. Framework coverage and audit readiness span 0 to 1, the drafted generalist's 1s crediting the product's German data-protection name and the vendor's audit-world credentials while the other scores sit at 0. Sovereignty is the only criterion above the floor at 1 to 2 — four judges at 2, two at 1 — resting on the confirmed German GmbH; the rationales add that hosting location, a published data processing agreement and a subprocessor list are not publicly documented. The flagged splits report none, and no prices are published, which is normal in this market and excluded from the verdicts.
Speaks for it
- Vendor is a confirmed German GmbH seated at Siedlerstraße 22-24, 71126 Gäufelden/Stuttgart, the basis of every sovereignty rationale
- BSI certification on record for IS-Revision/Grundschutz and penetration tests
- Penetration-testing project experience since 2000, per the captured page
- Free initial consultation offered on the captured page
- Claims status as the longest-serving BSI testing lab for Common Criteria and ITSEC
Held against it
- No public information on records of processing, DPIAs, processor management or TOMs in the product
- No public information on data subject request workflows, statutory deadline tracking or a breach register
- No public information on an API, directory import, SSO or any workflow automation
- No public information on hosting location, a published data processing agreement or a subprocessor list
- The captured page presents the vendor's security-consulting services rather than the product's own capabilities
Best for
- You want a compliance product from a vendor that is verifiably a German GmbH seated in Gäufelden — the one criterion where scores rise above the floor
- You are also shopping for BSI-Grundschutz, ISO 27001 or VDA ISA/TISAX security consulting, which the captured page documents as the vendor's practice
- You are prepared to assess every product capability in a free initial consultation rather than from public documentation
Avoid if
- You must see records of processing, DPIA and TOM handling documented publicly before shortlisting any tool
- You rely on statutory deadline tracking, a breach register and authority notification output to run your compliance program
- Your record must stay current through directory import, SSO or an API, and you need that verified before purchase
- Procurement requires public documentation of hosting location, a data processing agreement and a subprocessor list
The scores
Records & DPIA depth
Show reasoningHide reasoning
How this is scored
The DSMS core: records of processing (RoPA/VVT), data protection impact assessments, processor/DPA management and TOMs — how deeply the legal artifacts are modeled and connected.
0 — Document templates in a folder tree; the "register" is a Word file with version numbers in the filename.
3 — A structured RoPA with basic fields and a DPIA questionnaire, but processors, TOMs and legal bases live outside the system.
5 — RoPA and DPIA as linked modules with templates; processor management and TOM assignment exist but are shallow, and group reuse is copy-paste.
8 — A connected data model — processing activities linked to systems, processors, TOMs and legal bases — with DPIA triggers derived from the record, reusable group templates, and outputs a supervisory authority accepts.
10 — Privacy records as a system of record: the RoPA drives DPIAs, processor management and TOM coverage from one data model, multi-client/mandate capability included, and the documentation is audit-ready without manual assembly.
The External DPO
The single captured page is about penetration testing, ISMS consulting and BSI approval support, and we found no public information on records of processing, DPIA handling, processor management or TOM modeling in the product. Nothing captured would replace a client's Word register, let alone drive one data model across thirty mandates. 1
The In-House Counsel
The captured vendor pages describe a security consultancy — penetration testing since 2000, BSI-Grundschutz, ISO 27001, TISAX — and I found no public information on records of processing, DPIA modeling, or processor and TOM management in the software itself. I cannot defend a DSMS purchase on a record showing none of the core legal artifacts. 1
The Drafted Generalist
The captured page talks exclusively about penetration testing and security consulting; we found no public information on records of processing, DPIA support, processor management or TOMs in the software. I cannot confirm the first brick of a privacy register from what is public, so this sits at the floor. 1
The Lead Auditor
The one captured page presents the vendor's security consulting practice, and we found no public information on records of processing, DPIA tooling, processor management or TOMs in a product. I cannot credit legal-artifact modeling that nothing public shows, so this sits at the bottom. 1
The IT Integrator
We found no public information on how easy Datenschutz models records of processing, DPIAs, processor management or TOMs. The captured vendor page presents secuvera's security-consulting practice — Grundschutz, ISO 27001, penetration testing — rather than a connected register data model, so the depth of the legal artifacts cannot be assessed from what is public. 1
The Skeptic
The only captured page presents a security consultancy — BSI-Grundschutz, ISO 27001 and TISAX consulting, penetration testing — and we found no public information on records of processing, DPIA handling, processor management or TOMs. What the page evidences is consulting services with a free initial consultation, not a privacy data model. 1
Data subject rights & incidents
Show reasoningHide reasoning
How this is scored
The operational half of the DSMS: data subject request handling with statutory clocks, breach register and authority notification, deletion concepts that actually delete.
0 — Requests arrive by email and live there; breaches are a phone call and a memo.
3 — A request log and a breach list exist, but deadlines are manual, intake is unstructured, and deletion rules are documentation rather than workflow.
5 — DSR workflows with the Art. 12 clock tracked, structured breach register with the 72-hour clock, deletion concepts assignable to records; automation is reminders.
8 — Intake channels for requests (portal/form), identity-check support, deadline automation with escalation, breach severity assessment and authority-report output, deletion rules tied to the RoPA with execution tracking.
10 — Rights and incidents as operations: end-to-end request handling an authority audit walks through, breach workflows that produce the Art. 33 notification, and deletion automation with evidence that the deletion happened.
The External DPO
We found no public information on data subject request intake, statutory clocks, a breach register or deletion execution. Without any evidence of the operational rights half, I cannot bill this as the layer that answers an authority for a client. 1
The In-House Counsel
I found no public information on data subject request handling, statutory clocks, a breach register, or authority notification output. A breach workflow that produces the Art. 33 notification is my minimum requirement, and nothing here evidences one exists. 1
The Drafted Generalist
Nothing on the captured page touches data subject requests, breach deadlines or deletion workflows, and we found no public information on any of it. Without statutory-clock handling I can see, the operational half of the job stays in my inbox. 1
The Lead Auditor
We found no public information on data subject request workflows, statutory deadline tracking, a breach register or authority notification output; the captured material is a services brochure for security testing. Requests and breaches are simply not visible in anything captured, which scores at the lowest mark. 1
The IT Integrator
We found no public information on data-subject request workflows, statutory deadline tracking, a breach register, authority-notification output or deletion execution for easy Datenschutz. The operational half of a DSMS is absent from the captured material, which the published level descriptions place at the floor. 1
The Skeptic
We found no public information on data subject request workflows, statutory deadline tracking, a breach register or deletion concepts. The closest the capture comes to incident topics is a penetration testing service offered as a project engagement, not a software capability. 1
Privacy regime coverage
Show reasoningHide reasoning
How this is scored
Which privacy regimes the product actually operationalizes — GDPR, BDSG, Swiss nDSG, UK GDPR, ePrivacy, EU AI Act privacy duties — and whether one record maps across them or each regime is a fresh island.
0 — One regime, hard-coded; anything else is "on the roadmap".
3 — GDPR plus one national law as separate checklists; the same processing activity is documented once per regime.
5 — The major regimes for its market with partial cross-mapping; newer duties (AI Act, ePrivacy changes) present as content packs of varying depth.
8 — Broad current coverage with one-record-many-regimes mapping and visible maintenance as regimes evolve.
10 — Regime coverage as a living product: multiple privacy regimes on one data basis, per-country variants, and documented update cadence when the law moves.
The External DPO
We found no public information on which privacy regimes the product operationalizes, whether one processing record serves several regimes, or any per-country variants and update cadence. The captured material describes German-market security services only, so cross-regime depth is unevidenced. 1
The In-House Counsel
The only frameworks named are the vendor's own certification and consulting schemes — BSI, ISO 27001, IEC 62443, TISAX — which describe security services, not privacy regimes the product operationalizes. I found no public information on GDPR, BDSG, Swiss nDSG or any cross-regime mapping. 1
The Drafted Generalist
The product's name points at German data protection, but the captured page names no privacy regime at all — its standards talk is BSI Grundschutz, ISO 27001 and TISAX, which is information security, not GDPR-family privacy. We found no public information on which regimes are operationalized or whether one record maps across them. 1
The Lead Auditor
The captured page names BSI Grundschutz, ISO 27001 and VDA ISA/TISAX as consulting subjects but we found no public information on which privacy regimes the product operationalizes — not even GDPR as a product feature. Regime coverage cannot rise above the bottom when public pages never show a single regime inside the tool. 1
The IT Integrator
We found no public information on which privacy regimes easy Datenschutz operationalizes. The frameworks named in the captured material — BSI Grundschutz, ISO 27001, VDA ISA/TISAX — belong to the vendor's consulting services, and I found no evidence of GDPR, BDSG or Swiss nDSG handling in the product itself. 1
The Skeptic
The schemes the captured page names — BSI-Grundschutz, ISO 27001, VDA ISA/TISAX, IEC 62443 — are security assessment services sold as consulting engagements, not privacy regimes a product maps records across. We found no public information on GDPR, BDSG, Swiss nDSG or any one-record-many-regimes capability. 1
Audit readiness & evidence
Show reasoningHide reasoning
How this is scored
Whether the system produces defensible proof: revision-safe history, evidence collection, reports for auditors, authorities and management.
0 — Exports are screenshots; history is overwritten in place.
3 — PDF reports exist but evidence is attached ad hoc and changes leave no reliable trail.
5 — Versioned records, standard report generators for the core registers, evidence attachments per activity; assembling a full audit file still takes days.
8 — Revision-safe change history, audit-scoped evidence packs on demand, management and authority reports current at a click, auditor access roles.
10 — Audit readiness as a standing state: continuous documentation status per regime and scope, exportable proof packs an auditor accepts as-is, and a defensible answer to "show me the state on date X".
The External DPO
The vendor is shown performing BSI Grundschutz and ISO 27001 audits for others, but we found no public information on revision-safe history, evidence packs or report generators in the product itself. An auditor's pedigree is not shown audit-ready software. 1
The In-House Counsel
The vendor's standing as a BSI-certified auditing body is credible for its services, but I found no public information on revision-safe change history, evidence collection, or authority-ready reports within the product. Credentials of the consulting firm are not proof that the software produces defensible evidence. 1
The Drafted Generalist
The vendor itself is a BSI-certified testing body, so it lives in the audit world, but that pedigree says nothing about what the software produces. We found no public information on revision-safe history, evidence packs or auditor-ready reports from the product. 1
The Lead Auditor
The vendor's own credentials are real — BSI certification for IS-Revision/Grundschutz and penetration tests, and the self-described longest-serving BSI testing lab for Common Criteria — but those speak to their audit services, not to any product capability. We found no public information on revision-safe change history, evidence packs, auditor access or report generators, and I will not let a consultancy's certifications stand in for an audit trail the product pages never show. 1
The IT Integrator
We found no public information on revision-safe change history, evidence collection or auditor-facing reports in easy Datenschutz. The vendor's BSI certification as a testing body describes its consultancy, not the proof packs the software would hand an auditor or supervisory authority. 1
The Skeptic
The certification claims on the page — BSI certification for IS-Revision/Grundschutz and penetration tests, and self-described status as the oldest BSI Common Criteria testing lab — describe the vendor's own service practice, not a product feature producing audit proof for a buyer. We found no public information on versioned records, change history, report generators or evidence packs. 1
Integrations & automation
Show reasoningHide reasoning
How this is scored
Whether the platform feeds from the real IT estate — directory import, ticketing, API — and automates the recurring privacy work instead of re-typing it.
0 — A closed island: manual entry in, PDF out, no API.
3 — CSV/Excel import and export; no live connections, no API worth the name.
5 — Directory import (AD/Entra), a documented REST API for core objects, a handful of native connectors (ticketing or SSO); automation is reminders and recurrence.
8 — Real connector set (ticketing, HR or asset sources), webhooks, SSO/SCIM, workflow automation with delegation and escalation, useful AI assistance with human review.
10 — The platform behaves like infrastructure: API parity for the data model, event streams, bidirectional sync with the estate, and automation that measurably removes the recurring toil (reviews, attestations, evidence pulls) rather than renaming it.
The External DPO
We found no public information on an API, directory import, ticketing or SSO connectors, or workflow automation of any kind. I cannot see how a record of processing would ever feed from a client's real IT estate rather than re-typing. 1
The In-House Counsel
The captured material contains nothing on an API, directory import, connectors, SSO or workflow automation, and I found no public information on any of it. The page presents a project consultancy, so automation of recurring privacy work is entirely unevidenced. 1
The Drafted Generalist
We found no public information on imports, connectors, single sign-on or an API of any kind. Everything visible points to human consultants and a free initial consultation, which is the opposite of the automated toil-removal my calendar needs. 1
The Lead Auditor
We found no public information on an API, directory import, ticketing connectors, SSO or workflow automation in any product. Nothing captured shows the platform feeding from a real IT estate, so this sits at the bottom. 1
The IT Integrator
This is what I look hardest at, and the captured material is silent on it: no public information on directory import from Entra ID or AD, a REST API, webhooks, SSO or SCIM for easy Datenschutz. A compliance record that stays current because it syncs with the estate is exactly what a buyer cannot verify from what is public here. 1
The Skeptic
We found no public information on an API, directory import, ticketing connectors or workflow automation; the captured page names none of these. The only interactive capability described is a contact path to a free initial consultation, which is a sales process rather than product integration. 1
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where the compliance record of the whole company actually lives and under whose law — entity, hosting, subprocessors, DPA. A platform that maps your processing is itself your most concentrated processing.
0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for the system holding your RoPA.
3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.
5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.
8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.
10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors, on-premises or sovereign-cloud options, and the whole chain documented publicly.
The External DPO
A German entity at an address in Gäufelden is confirmed, which places the vendor under European law; beyond that we found no public information on hosting location, a published DPA or a subprocessor list. That is exactly the chain I must clear before pointing any client's RoPA at the platform, so it sits just above the floor. 1
The In-House Counsel
A German GmbH in Gäufelden — an EU entity, with BSI certification as a German anchor — is the one confirmed fact on jurisdiction. But no sovereignty attributes are on record: I found no public information on hosting location, data centers, a published DPA or a subprocessor list, so the chain that would hold my RoPA is undocumented beyond the entity. 1
The Drafted Generalist
The vendor is a German limited company at a Stuttgart-area address, which is a genuine European anchor for the entity itself. But we found no public information on hosting location, a published data processing agreement or a subprocessor list, and for a system that would hold our entire compliance record that gap keeps the score low. 1
The Lead Auditor
The entity is verifiably German — secuvera GmbH at Siedlerstraße 22-24, Gäufelden, operating as a BSI-certified German service provider — which is the one solid signal. We found no public information on where the product is hosted, on a DPA, or on subprocessors, so the custody of the compliance record itself is undocumented; that lands between the extremes rather than at either end. 1
The IT Integrator
One solid fact: secuvera is a German GmbH seated in Gäufelden/Stuttgart, so the vendor behind the register product is an EU entity. We found no public information on hosting location, DPA terms or subprocessors, so the chain that would hold a company's most concentrated processing is only partly judgable. 1
The Skeptic
The one jurisdictional fact on record is a German entity — secuvera GmbH, Siedlerstraße 22-24, 71126 Gäufelden/Stuttgart — which is why this rises just above the floor. We found no public information on hosting location, a published DPA or a subprocessor list for the platform that would hold a buyer's compliance records, and the BSI certifications quoted cover the consulting business. 1
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real invoice — per module, per entity, per year, with consulting unbundled — from public pages alone. Unpublished pricing is the B2B norm in this market, so this criterion describes rather than condemns; the benches weight it accordingly.
0 — No public prices at all; every configuration is a sales conversation.
3 — An entry price exists, but module add-ons, entity counts or bundled consulting make the real total incomputable.
5 — Most editions carry real numbers with billing period stated and software separated from services; at least one commonly needed module or scale step is unpriced.
8 — Every edition and module priced publicly with entity/user boundaries and setup fees stated; only genuine corporate-group contracts are custom.
10 — Complete price computability: modules, scale steps, service packages and renewal rules public, so the invoice for a 100-employee company and a 10-client consultancy is a two-minute exercise.
The External DPO
No prices, editions or scale steps appear in the captured material; the only commercial signal is a free initial consultation. Every configuration therefore runs through a sales conversation, and a buyer cannot compute an invoice from public pages. 1
The In-House Counsel
The only pricing-adjacent statement is a 'kostenfreie Erstberatung' — a free initial consultation — and I found no public prices, editions, modules or billing terms anywhere. Every configuration begins as a sales conversation, which the market tolerates but this criterion records as it stands. 1
The Drafted Generalist
No price appears anywhere on the captured page; the only cost-related item is a free initial consultation, which means the sales conversation comes before any number. For an eighty-person firm I cannot compute even a rough invoice from what is public. 1
The Lead Auditor
The only pricing-adjacent statement anywhere is "eine kostenfreie Erstberatung" — every engagement opens with a consultation. We found no public information on prices, editions or modules, which is the bottom of this scale, though unpublished pricing is the norm in this market and I describe rather than condemn it. 1
The IT Integrator
The only price-adjacent statement in the captured material is a free initial consultation; we found no public information on editions, modules, licensing units or billing periods for easy Datenschutz. As is the market norm, every configuration reads as starting with a sales conversation. 1
The Skeptic
We found no public prices of any kind on the captured page — no edition, module, user or entity figures — and the only commercial signal is an offer of a free initial consultation, which points every configuration to a sales conversation. That matches the unpublished-pricing norm for this market, so the score describes the pattern rather than singling it out. 1
European sovereignty — proven facts
1 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Incorporated in DE ⚠ unverified | 3/3 pts | 2 Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | Not determined | — | uncited Report an error |
| Subprocessors | Not determined | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 29 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Legal entity. Country name is not spelled out on the page; the code is derived from the German commercial register court (Registergericht Stuttgart) and the HRB number.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- We found no public information on pricing on the pages we read (secuvera.de, secuvera.de/unternehmen/impressum, secuvera.de/unternehmen/datenschutzerklaerung). If the vendor publishes it somewhere else, send us the page. Know more? Tell us
- 2 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 product fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (3)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor page secuvera.de Checked 29 Sep 2026 Details →
- 2 Imprint — found from the homepage www.secuvera.de Checked 30 Sep 2026 Details →
- 3 Privacy policy — found from the homepage www.secuvera.de Checked 30 Sep 2026 Details →