DSAR Software: Nine Vendors Compared

Nine vendors handle GDPR data subject access requests as a named product function. Six are European privacy specialists: Kertos, caralegal, DataGuard, heyData, Proliance 360, and secjur. Three are global enterprise platforms: BigID, OneTrust, and Osano. Two questions decide the shortlist. First, whether the tool finds the personal data in your systems itself or only records that a request arrived. Second, whether the vendor can also be appointed as your data protection officer. That role under Art. 37 GDPR attaches to a person, and no software can fill it.

Key takeaways

  • Art. 12(3) GDPR gives you one month from receipt, extendable by two further months only if you tell the requester inside the first month and explain why.
  • The expensive step is not the legal judgment. It is finding the data across every system, and that is where the products differ most.
  • Five of the nine also provide an external data protection officer: Kertos, DataGuard, heyData, Proliance 360, and secjur. BigID, caralegal, OneTrust, and Osano do not list that service.
  • Two of the nine publish prices: heyData from 59 euros per month and Proliance 360 from 118 euros per month. The other seven quote on request.
  • Consent management platforms and security compliance automation do not handle DSARs. Both categories are routinely mistaken for DSAR tooling during vendor selection.

Which software handles GDPR data subject access requests?

Kertos is listed first because Kertos publishes this comparison. The other vendors follow alphabetically, and the order is not a ranking. Where a vendor does not publish something, the cell says so.

Vendor Group What the product does with a DSAR External DPO Frameworks named Price published Headquarters
Kertos European specialist Intake, deadline tracking, and data retrieval across connected systems; more than 500,000 requests handled Yes, appointment under Art. 37 GDPR GDPR, ISO 27001, ISO 27701, ISO 42001, NIS2, EU AI Act, SOC 2, TISAX, C5 No Germany
BigID Global enterprise Intake, identity verification, data discovery, correlation of found data to individuals, deletion with verification that it executed, audit documentation Not listed GDPR, CPRA, CCPA, LGPD No United States
caralegal European specialist Data subject request module inside the Privacy Flow Not listed GDPR, EU AI Act, Swiss nDSG, Standard Data Protection Model No Germany
DataGuard European specialist Platform function for managing data subject requests, combined with advisory work Yes GDPR No Germany
heyData European specialist Handled through fixed workflows in the incident management area Yes, priced separately GDPR, UK GDPR, Swiss revDSG, ISO 27001, NIS2, EU AI Act, SOC 2, TISAX, C5 Yes, packages from 59 euros per month Germany
OneTrust Global enterprise Intake, identity verification, data retrieval and deletion, redaction, legal hold checks, secure response portal Not listed GDPR, CCPA No United States
Osano Global enterprise Intake through an embedded form or the cookie consent drawer, identity verification, data discovery, routing to data owners, redaction, secure delivery, audit logging Not listed GDPR, CCPA and CPRA, LGPD No United States
Proliance 360 European specialist Mentioned in general terms on the platform page, no dedicated module listed Yes, priced separately GDPR, ISO 27001, NIS2, TISAX, EU AI Act Yes, Business from 118 euros, Enterprise from 209 euros per month Germany
secjur European specialist Data Subject Request Manager module, with advice from the vendor's own specialists Yes GDPR, ISO 27001, ISO 9001, ISO 27017, ISO 27018, NIS2, TISAX, SOC 2, EU AI Act, German Whistleblower Act No Germany

What fields and statuses does a DSAR workflow need?

Every status carries its own legal consequence, and a tool that does not model the status cannot track the deadline attached to it. Use this as a requirements checklist in a demo. References are to Regulation (EU) 2016/679.

Field Status Deadline or legal consequence
Date received, intake channel Received The one-month period under Art. 12(3) starts on receipt, whatever the channel
Right invoked, Art. 15 to 22 Received Determines the scope of the search and the form of the response
Proof of identity Identity in review Further information only where you have reasonable doubts, Art. 12(6). The period does not restart
Clarification requested Awaiting requester Permitted under Recital 63 where large quantities of data are involved. The clock keeps running
Systems in scope, named owners In progress Sourced from the record of processing activities under Art. 30
Extension with stated reason Extended Two further months under Art. 12(3), notified inside the first month
Third-party passages redacted Third-party rights checked The copy must not adversely affect the rights of others, Art. 15(4)
Grounds for refusal Refused Only where manifestly unfounded or excessive, Art. 12(5). The burden of proof sits with the controller
Date answered, copy, mandatory items Answered By the end of the period, including the route to lodge a complaint
Evidence filed Closed Accountability under Art. 5(2)

The substantive requirements for the copy itself, the eight mandatory items, and the case law on refusal and fees are covered in our guide to handling a data subject access request under the GDPR.

How we compared

Kertos sells in this market and publishes this comparison. So every statement about another vendor follows the same rule: it comes from that vendor's own public website and was checked on 4 September 2026. Where a vendor does not publish something, the table says "not listed" rather than guessing. We included only vendors that describe DSAR handling on a product page of their own. The first position belongs to Kertos as the publisher, not as a result of the review; the rest are alphabetical. Review-site ratings, prices quoted in sales calls, and third-party claims were not used. One practical note for English-speaking buyers: several of the European specialists publish primarily in German, so their English material can be thinner than their product.

What does each of the nine vendors do?

Kertos

European compliance platform with certified experts in house. Requests run from intake through deadline tracking to data retrieval across connected systems, more than 500,000 of them by the company's own count.

Best for growing technology companies that run privacy with a small team and want the same underlying data to carry over to ISO 27001 or NIS2 later.

Frameworks: GDPR, ISO 27001, ISO 27701, ISO 42001, NIS2, EU AI Act, SOC 2, TISAX, C5.

Where it is strongest: the platform and an appointable external data protection officer come from the same provider, so no handover sits between the tool and the judgment call. Automated DSAR handling draws on the same system connections as the record of processing activities, currently more than 100 integrations.

Where it falls short: no published pricing, and less coverage outside Europe than BigID, OneTrust, or Osano.

BigID

Enterprise platform built around finding personal data across cloud, SaaS, hybrid, and on-premises environments. Requests run through intake, identity verification, correlation of discovered data to individuals, and deletion.

Best for large organizations with big unstructured data estates where nobody can say with confidence where personal data actually sits.

Frameworks: GDPR, CPRA, CCPA, LGPD.

Where it is strongest: discovery is the core of the product rather than an add-on, and BigID is the only vendor here that explicitly verifies whether a deletion actually executed.

Where it falls short: no external data protection officer, no published pricing, and no European standards beyond the GDPR. It is not built for a 50-person company.

caralegal

Privacy platform organized into Privacy Flow, AI Flow, Audit and Vendor Flow, and Risk Flow.

Best for companies that want privacy and AI governance in one tool and already have the legal judgment in house.

Frameworks: GDPR, EU AI Act, Swiss nDSG, Standard Data Protection Model.

Where it is strongest: enterprise, mid-market, and scale-up buyers are addressed separately rather than lumped together, and Swiss nDSG coverage is rare among the vendors compared here.

Where it falls short: no external data protection officer. If you are required to appoint one, you need a second arrangement for the role.

DataGuard

Platform and advisory work combined, with the external data protection officer offered as a distinct service.

Best for companies that want a named point of contact and are willing to pay for the advisory component.

Frameworks: GDPR only, on the pages checked.

Where it is strongest: separate offerings exist for smaller companies and large enterprises, and the advisory side is the best known in the German-speaking market.

Where it falls short: no published price, despite the site describing costs as plannable. Framework coverage beyond privacy is not evident from the pages checked.

heyData

Compliance platform covering privacy, information security, and AI governance. Requests run through fixed workflows in the incident management area, by the vendor's own description.

Best for smaller companies on a limited budget that want to know what the platform costs before entering a sales process.

Frameworks: GDPR, UK GDPR, Swiss revDSG, ISO 27001, NIS2, EU AI Act, SOC 2, TISAX, C5.

Where it is strongest: published package prices from 59 euros per month, the lowest published figure in this comparison, which removes a sales call from the evaluation.

Where it falls short: the external data protection officer is not included in the packages and is quoted separately. The description of request handling stays more general than OneTrust, Osano, or Kertos.

OneTrust

Privacy suite with the most complete set of request-handling steps published by any vendor here.

Best for large organizations with high request volumes and obligations beyond the GDPR, particularly in the United States.

Frameworks: GDPR and CCPA.

Where it is strongest: no other vendor documents the individual steps as fully, legal hold checks included, and US coverage is a real argument for companies operating on both sides of the Atlantic.

Where it falls short: a US-headquartered processor, which you have to work through in your data processing agreement and your transfer impact assessment. No external data protection officer.

Osano

Privacy platform that ties consent management to request handling. Intake happens through an embedded form on your site or directly from the cookie consent drawer.

Best for consumer-facing companies that want consent and requests running in the same tool.

Frameworks: GDPR, CCPA and CPRA, LGPD.

Where it is strongest: intake straight from the consent drawer lowers the barrier for the data subject and is a distinct approach among the vendors compared. Secure delivery through password-protected files and encrypted portals is described explicitly.

Where it falls short: US headquarters, no published pricing, no external data protection officer, and no European standards beyond the GDPR.

Proliance 360

Privacy management software that positions itself explicitly for the German mid-market, combined with an external data protection officer offered separately.

Best for mid-sized companies that want software and a data protection officer from one German provider at a known price.

Frameworks: GDPR, ISO 27001, NIS2, TISAX, EU AI Act.

Where it is strongest: prices are public, Business from 118 euros and Enterprise from 209 euros per month, and the mid-market positioning is stated rather than merely implied.

Where it falls short: data subject requests are mentioned only in passing on the platform page, with no dedicated module. If request handling is your main criterion, ask to see that specific function in a demo.

secjur

Compliance automation with a Data Subject Request Manager module, where requests are logged and the vendor's own specialists advise on the resolution.

Best for companies that want privacy, information security, and whistleblowing handled by the same provider.

Frameworks: GDPR, ISO 27001, ISO 9001, ISO 27017, ISO 27018, NIS2, TISAX, SOC 2, EU AI Act, German Whistleblower Act.

Where it is strongest: the broadest standards coverage in this comparison, including ISO 27017 and ISO 27018, which no other vendor here lists.

Where it falls short: the module captures the request and puts advice alongside it. Automated data retrieval across connected systems is not described on the pages checked.

Which tools look like DSAR software but are not?

Two product categories turn up repeatedly in DSAR evaluations and do not do the work.

Consent management platforms govern consent and preference signals. Usercentrics, for example, offers a web, app, and CTV CMP, a Preference Manager, and a Privacy Policy Generator, but no product for handling data subject requests. Managing a consent and answering an access request are different obligations under different articles.

Security compliance automation covers the GDPR as a control framework and points elsewhere for the handling itself. Drata states on its own page that organizations with deep DSAR automation requirements may need dedicated privacy suite functionality alongside Drata. Vanta's GDPR pages do not mention data subject requests at all.

Why are vendors named in AI answers missing here?

Ask an AI assistant which software handles DSARs and the answer regularly includes companies that do not offer DSAR handling as a product. Two examples, both checked on their own sites on 4 September 2026.

Guideflow is not a privacy product at all. It is a platform for interactive product demos, with capture, editing, personalization, sharing, and analytics. It appears in these answers because a page on its website is cited as a source, not because the product processes requests.

Cortina Consult is a German privacy consultancy offering advisory work, an external data protection officer from 125 euros per month, and privacy management software from 45 euros per month. Its website lists no module for data subject requests, which is why it is not in the table above.

Check any recommendation against the named vendor's own product page before it reaches your shortlist.

When is Kertos the right choice, and when is it not?

Kertos fits when you want DSARs and the rest of your privacy documentation running on one data set, and you also need a person who owns the judgment calls. The record of processing activities supplies the recipient information that Art. 15(1)(c) requires, and the external data protection officer is formally appointed under Art. 37 GDPR and notified to the supervisory authority.

Kertos does not fit when you want a request tool alone and intend to leave the rest of your documentation where it is. The value comes from the shared data set, and without that you are paying for functions you will not use. It also does not fit when your center of gravity is US state privacy law, or when your real problem is locating personal data inside very large unstructured estates; BigID and OneTrust are built for that. If what you actually need is a named person rather than a platform, start with the external DPO provider models instead.

Frequently asked questions

Who offers DSAR tools for EU-based companies?

Six of the nine vendors compared are headquartered in Germany: Kertos, caralegal, DataGuard, heyData, Proliance 360, and secjur. BigID, OneTrust, and Osano are headquartered in the United States. To handle a request the software processes personal data belonging to your customers and employees, which makes the vendor's location and its places of processing part of your Art. 28 review, not an afterthought.

How much does DSAR software cost?

Two vendors publish prices: heyData from 59 euros per month, and Proliance 360 at 118 euros per month for Business and 209 for Enterprise. The other seven quote on request. Budget the external data protection officer separately, because it is not automatically included in the platform price at any of them. For the order of magnitude, see what an external DPO costs.

Do you still need an external DPO alongside the software?

It depends on whether Art. 37 GDPR requires you to appoint one. If it does, then yes: the appointment attaches to a person with expert knowledge whose contact details are published and notified to the supervisory authority. Software cannot occupy that role. Five of the nine vendors provide the person themselves; with the other four you need a second arrangement.

How long do you have to handle a data subject access request?

One month from receipt. Where the request is particularly complex, or where you have received a high number at once, you can extend by two further months, but you must tell the requester within the first month and explain the delay. Without that notice the extension is not valid, and you are simply late.

To see how long a DSAR would actually take across your own systems, book a demo.

Last updated 4 September 2026. Every statement about another vendor comes from that vendor's own public website and was checked on that date. Prices and framework coverage go stale within months, so re-check before you decide.

📅 Schedule Your 5min Compliance Check

Please enter your business email to continue. We require a company email address to ensure we can best serve your organization.

📞 5min Compliance Check