Data Privacy Software: Automate GDPR and Stay Audit-Ready (2026)

Key Takeaways

  • Data privacy software covers eight concrete GDPR obligations, including the record of processing activities under Art. 30, data subject requests under Art. 12 to 23, and breach notification within 72 hours under Art. 33.
  • The exemption from the RoPA obligation for companies under 250 employees in Art. 30(5) GDPR almost never applies in practice, because it falls away as soon as processing is more than occasional.
  • Software alone does not satisfy the accountability principle. The data protection officer role attaches to a person with expertise, not to a tool.
  • Kertos combines the platform with certified experts and an external DPO mandate, hosts in the EU, and covers ISO 27001, ISO 27701, ISO 42001, NIS2, the EU AI Act, SOC 2, TISAX, and C5 alongside the GDPR.

Most companies do not start looking for data privacy software because of the GDPR. They start because of a specific trigger. An enterprise prospect asks for a record of processing activities in a security questionnaire. A deletion request has been sitting in an inbox for four weeks. The RoPA in Excel has been wrong since the last tool migration. At that point the problem is no longer knowledge, it is having a system that holds the state.

What does privacy management software actually do?

Privacy management software turns the GDPR's documentation and evidence obligations into guided processes with deadlines, owners, and version history. The mapping below shows which obligation requires which function.

GDPR obligation Legal basis Function in the software
Record of processing activities (RoPA) Art. 30 GDPR Structured entry per processing activity, version history, updates when new tools appear
Technical and organizational measures (TOMs) Art. 32 GDPR Measure catalog with evidence, reused in data processing agreement annexes
Data subject rights, such as access and erasure Art. 12 to 23 GDPR Request intake, deadline tracking (one month, extendable by two), data retrieval from connected systems
Personal data breach notification Art. 33 and 34 GDPR Incident intake, risk assessment, 72-hour clock, notification drafts
Data protection impact assessment (DPIA) Art. 35 GDPR Threshold analysis, guided assessment, tracking of mitigations
Processor management Art. 28 GDPR Vendor register, data processing agreement management, sub-processor review
International transfers Chapter V GDPR Transfer impact assessment, standard contractual clauses, evidence of safeguards
Accountability Art. 5(2) and Art. 24 GDPR Complete audit trail across every change and decision

Kertos covers these obligations in its automated privacy management system. Documentation is produced in the RoPA, DPIA, and TOM module, and requests run through automated DSAR handling. More than 500,000 data subject requests have been resolved this way.

Why do GDPR tools fail in practice?

The difference between a maintained privacy management system and a worthless one is rarely feature coverage. Three patterns repeat:

  • The tool is a filing cabinet, not a system. A GDPR tool that only supplies templates moves the work from Word into a web interface. Without deadlines, named owners, and reminders, the documentation goes stale within a few months.
  • The documentation does not know the real IT estate. A RoPA is only as current as your knowledge of which systems process personal data. When a team adopts a new analytics tool and nobody records it, you get a gap that surfaces in an audit. Automated discovery of connected systems therefore matters more than another template. Kertos uses over 100 integrations for this.
  • The exemption is misread. Smaller companies often rely on Art. 30(5) GDPR and skip the RoPA. The exemption already falls away if processing is more than occasional, if there is a risk to the rights of data subjects, or if special categories of data are involved. For any company with an HR function and customer data, that is effectively always the case.
  • Ownership sits with nobody. Privacy work is usually split across legal, IT, and operations. If the software does not assign each obligation to a named person, the deadlines are the first thing to slip.

The penalty range in Art. 83 GDPR reaches up to 20 million euros or 4 percent of total worldwide annual turnover. In practice the more common damage is different: a lost enterprise deal, because the security questionnaire could not be answered credibly.

What can GDPR software not take over?

The data protection officer role attaches to a person with demonstrated expertise and cannot be delegated to software. Assessments, case-by-case balancing, and communication with the supervisory authority remain a professional responsibility. Software can prepare that work, evidence it, and make it traceable; a person still has to decide. Kertos handles this through an external DPO mandate that works inside the same system where the documentation is produced, which removes the handover effort between tool and consultant.

How does Kertos differ from other data privacy software vendors?

Vendors in this market are aimed at different buyers. The overview below places the established German-speaking providers according to their own public positioning.

Vendor Stated target audience Scope of offering Frameworks covered
Kertos Tech companies, startups, scaleups, and mid-sized SaaS and fintech companies Platform with the KAIA AI agent plus certified experts, including external DPO and CISO mandates GDPR, ISO 27001, ISO 27701, ISO 42001, NIS2, EU AI Act, SOC 2, TISAX, C5
caralegal Enterprise and mid-market, plus startups and scaleups Software with built-in legal assistance GDPR, EU AI Act, Swiss FADP
Keyed Large companies with multiple legal entities Software plus separately commissioned services, including external data protection officer and external AI officer GDPR, EU AI Act
otris privacy Corporate groups and multi-entity organizations Multi-tenant software, as German cloud or on-premises GDPR, with a focus on group-wide privacy governance

As of August 2026, based on public vendor information. This overview describes each vendor's stated focus and is not a substitute for evaluating specific functionality.

For corporate groups with many legal entities, multi-tenant systems are often the better fit. Kertos is built for a different profile: growing tech companies that run privacy with a small team and have to prove it to customers and auditors at short notice. The record there is a 100 percent audit pass rate, roughly 80 percent less manual compliance effort, 98 percent customer satisfaction, and cost savings of up to 60 percent compared with traditional consulting.

How does a privacy management system scale to ISO 27001, NIS2, and the EU AI Act?

The GDPR is the first requirement for most companies, and rarely the last. The decisive question when choosing a system is therefore whether the groundwork you capture once stays reusable. Concretely, the following carries over from GDPR documentation:

  • The record of processing activities and the system inventory become the asset and information inventory for ISO 27001.
  • The technical and organizational measures under Art. 32 GDPR overlap substantially with the Annex A controls of ISO 27001 and with the risk management measures required under NIS2.
  • The vendor register with its data processing agreements is the basis for the NIS2 supply chain requirements.
  • The DPIA methodology under Art. 35 GDPR is the template for risk assessment of AI systems under the EU AI Act.
  • ISO 27701 extends an existing ISO 27001 ISMS into a certifiable privacy information management system, drawing on the same processing records and evidence.

When that groundwork sits in separate tools, every additional certification becomes a new project. With Kertos the underlying data set stays the same and is mapped onto additional frameworks. AskUI reached ISO 27001 in 8 to 10 weeks on that basis, without external consultants.

How do you implement a privacy management system, and how long does it take?

Implementation runs in three phases. The timings are typical ranges for companies between 20 and 200 employees and depend on the system landscape and the quality of existing documentation.

Phase Content Typical duration
Discovery Connecting systems, automated detection of data-processing tools, import of existing documentation Weeks 1 to 2
Build RoPA, TOMs, vendor and DPA register, retention and deletion concept, processes for data subject requests and incidents Weeks 3 to 6
Operation Deadlines and reviews, onboarding of new tools, evidence for customers and audits Ongoing from week 6

One point that is often overlooked during selection: existing documentation should be importable. If you have maintained a RoPA in Excel, you otherwise lose weeks retyping it.

What should you check on EU hosting and processor terms?

Your data privacy software vendor is itself your processor under Art. 28 GDPR. It processes details of your systems, your vendors, and, when handling requests, personal data belonging to your customers and employees. Four questions belong in every evaluation:

  • Is there a data processing agreement meeting Art. 28(3) GDPR, and does it cover the AI features in use?
  • Which sub-processors are involved, and in which countries do they process?
  • Where does the data physically sit, and who has administrative access to it?
  • Is your content used to train models?

The last question matters most for AI-assisted features. If a vendor passes your content to a model outside the EU, that creates an international transfer under Chapter V GDPR, which you have to record in your own register and assess with a transfer impact assessment. Your privacy software then becomes an object of review in its own right.

Kertos is developed in Germany, runs on European infrastructure, and is co-financed with EU funds. For companies that would rather not assess the international transfers of their own compliance system, that is the practical difference between data residency in the EU and a supply chain with no third-country exposure.

Kertos holds 4.8 stars on G2 and OMR Reviews, is listed as a Leader in GRC Tools by OMR, and was named a startup leader by WirtschaftsWoche from 2023 to 2025. The fastest way to see what this looks like for your system landscape is a conversation: book a demo, or see how Kertos automates GDPR compliance.

📅 Schedule Your 5min Compliance Check

Please enter your business email to continue. We require a company email address to ensure we can best serve your organization.

📞 5min Compliance Check