GDPR software for your
data protection management
Complaica is data protection management software for companies and data protection officers. Manage processing activities, data protection impact assessments, data subject requests and data privacy incidents centrally — with clear responsibilities, deadlines and traceable evidence.
Connect your data protection management system (DPMS) with your ISMS and use shared assets, risks and measures.
- 01Ten typical data protection activities as tasks — from the processing activity to the confidentiality commitment
- 02Record of processing activities (Art. 30) and DPIA report (Art. 35) from your data
- 03Deadlines on the task: answering data subject requests within one month, notifying data privacy incidents where feasible within 72 hours
- 04Take over existing records from Excel — as SaaS or on-premises
- 05Optionally in addition: data protection consulting and an external data protection officer
Data protection management software for ROPA, DPIA and data subject rights
What the Complaica data protection software covers day to day — from the record of processing activities to the evidence for the supervisory authority.
- 01Record of processing activities under Art. 30 — purposes, data categories, data subjects, recipients, retention periods and TOM, linked to processes, systems and service providers
- 02Deletion concept per processing activity — deletion rules with starting point and period, deletion units per system, from the standard catalogue or created yourself
- 03DPIA threshold assessment and data protection impact assessment under Art. 35 with risk matrix, measures and report
- 04Data subject requests, complaints and data privacy incidents as tasks with workflow, owners and statutory deadline
- 05Consent records, legitimate interest assessments, transfer impact assessments and confidentiality commitments documented in a traceable way
- 06Assess the requirements of the GDPR, the BDSG and your own policies per object — with implementation status and criticality
- 07A log of every change: who changed what and when, with documents and decisions on the object
- 08Reports and dashboards for data protection officers and management — open tasks, deadlines due, level of fulfilment per norm
- 09Collaboration with business departments and external parties — access per object and by link
Ten data protection activities with workflow, deadline and evidence
Data protection management consists of recurring tasks. Complaica runs each of them as a task type of its own — with the workflow, the deadline and the evidence the GDPR provides for it.
Every task hangs on the object it concerns — the processing activity, the system, the service provider, the person —, carries owners, documents and action items and logs every status change with author and date. The status chain below is the workflow as it is stored in the software. Further task types — processor review, security incident, lesson learned — are included as well; the data model can be adapted to your processes.
- PA
Processing activity
Every processing of personal data as a task with purpose, data categories, data subjects, recipients, legal basis, retention periods and TOM — linked to the processes, systems and service providers that carry it. The record of processing activities arises from the approved tasks.
Workflow- Draft
- In review
- Approved
- Review due
- Discontinued
- DSR
Data subject request
Access, rectification, erasure, restriction, data portability, objection: every request is run with date of receipt, identity check, owner and deadline; the answer, any extension of the deadline with its reasons and the evidence sit on the task.
Workflow- Received
- Identity check
- In progress
- Answered
- Refused
- Closed
- CMP
Complaint
Complaints by data subjects — directly or through the supervisory authority — with opinion, correspondence and outcome. While an appeal is pending, the task stays open until it is decided.
Workflow- Received
- Under examination
- Opinion drafted
- With the supervisory authority
- Closed
- Appeal pending
- DPI
Data privacy incident
From detection through the risk assessment to the decision whether the supervisory authority must be notified — unless the breach is unlikely to result in a risk to the data subjects — and whether, where the risk is high, the data subjects must be informed without undue delay. Every step is documented with its date, including the incident that need not be notified (Art. 33(5)).
Workflow- Detected
- In assessment
- Risk classified
- No notification duty
- Reported to authority (Art. 33)
- Authority notified
- Data-subject check (Art. 34)
- Art. 34(3) exemption
- Data subjects informed (Art. 34)
- Remediation in progress
- Closed
- TA
DPIA threshold assessment
The preliminary check per processing activity: is it likely to result in a high risk to the data subjects — by the cases listed in Art. 35(3) and the lists of the supervisory authorities? The result decides, and justifies, whether a DPIA follows.
Workflow- Draft
- In review
- Approved
- Superseded
- DPIA
Data protection impact assessment
Description of the processing, necessity and proportionality, risks to the data subjects and measures to address them — with risk matrix, linked TOM and the report for the file or for the prior consultation of the supervisory authority.
Workflow- Threshold analysis
- DPIA required
- Not required
- In progress
- Completed
- TIA
Transfer Impact Assessment
For every transfer to a third country: recipient, transfer instrument — adequacy decision, standard contractual clauses, binding corporate rules —, legal situation in the destination country and supplementary measures. The result carries a review date, because the legal situation changes.
Workflow- Draft
- In review
- Approved — permissible
- Approved — with conditions
- Not permissible
- Review due
- Superseded
- CR
Consent record
Consents with purpose, wording, date, data subject and channel — so that you can demonstrate them, as Art. 7(1) requires. A withdrawal changes the status, and the processing that rests on it sees it.
Workflow- Active
- Withdrawn
- Expired
- LIA
Legitimate interest assessment
The three-step test for legitimate interest: interest, necessity, balancing against the interests and fundamental rights of the data subjects — documented and linked to the processing activity that relies on it.
Workflow- Draft
- In review
- Completed
- CC
Confidentiality commitment
The written commitment to confidentiality and to processing only on instructions — the usual evidence for Art. 29 and Art. 32(4); for processors, Art. 28(3)(b) requires that the persons authorised to process the data have committed themselves to confidentiality. Per person with status, date and document.
Workflow- Open
- Sent
- Signed
- Refused
- Expired
- Void
Deletion concept: deletion rules and deletion units per processing activity
Personal data may be kept only for as long as is necessary for the purposes for which it is processed (Art. 5(1)(e) GDPR), and the record states, where possible, the envisaged time limits for erasure (Art. 30(1)(f)). The deletion concept turns this into rules that can be implemented and demonstrated.
How a deletion concept is built is described in DIN EN ISO/IEC 27555 — the successor of DIN 66398, whose method it takes over. In Complaica every processing activity has a tab of its own, “Deletion concept”.
- 01One data category and one group of data subjects per row — for example “business log data” and “employees of business partners” — with the deletion rule and the deletion unit that apply to them
- 02Deletion rules (LR) with starting point, triggering event and period — for example six months after the applicant has received the rejection
- 03Deletion units (LE) describe where and how data is deleted: system, reference object, granularity and whether it can be deleted selectively
- 04Take over deletion rules and deletion units from the standard catalogue or create your own, and arrange them by drag and drop
Six modules, one data set
Organisation, assets, requirements, risks, reports and tasks work on the same objects — a change is visible wherever the object appears.
01 / 06 · Organisation management
Controllers, processors and locations
Map your organisation as a tree — entities, locations, departments, roles — and define who is controller, joint controller or processor. Rights are granted per unit and per object.
02 / 06 · Asset structure analysis
Processes, systems, data categories and recipients
Business processes, applications, systems, categories of personal data, groups of data subjects, processors and recipients are assets with attributes, linked to the processing activities that run on them.
Dependency graphs and matrices show which processing uses which system and which service provider sees which data — and so whom an incident affects.
03 / 06 · Compliance management
GDPR, BDSG and your own policies per object
Assess the requirements of the GDPR (Art. 5–49), the BDSG and your own policies per processing activity, system or unit — with degree of implementation, criticality, owners and evidence. The assessment cumulates over the tree to the level of fulfilment per norm.
04 / 06 · Risk management
Risks to the data subjects
The GDPR assesses risks from the data subjects' point of view. Identify threats per processing activity, assess likelihood and severity in a configurable risk matrix and track measures and residual risk over time. Threshold assessment and DPIA draw on the same risks.
05 / 06 · Reporting & data analysis
ROPA, DPIA report and dashboards
The record of processing activities, DPIA reports, the documentation of data privacy incidents and overviews of open tasks arise from your own data — as a report template or a custom report. Distribution is handled by the Teams integration and the mail bot.
06 / 06 · Task management & collaboration
Tasks, owners and deadlines
Tasks and action items carry owners, deadlines and status; every change is recorded with author and date. Business departments, the data protection officer and external parties work in the same system.
DPMS and ISMS on one platform
Data protection and information security draw on the same systems, service providers and risks. In Complaica your data protection management system (DPMS) and your ISMS share assets, risks, measures and evidence: the technical and organisational measures under Art. 32 can — where they fit in substance — be taken over from the ISMS according to ISO 27001 or from IT-Grundschutz, a security incident can become a data privacy incident, and NIS2 or the data protection chapter of TISAX are assessed on the same data set.
Templates, catalogues and a prepared organisational model for the start come with the Data Protection Kit. Every standard ships with its requirement catalogue; your own catalogues can be added.
Take over your existing data protection documentation
You do not start from zero: your existing record, system lists and service provider overviews can be taken over.
- 01Import and export from and to Excel — for example your existing record of processing activities
- 02Connection of CMDB and asset management systems such as Microsoft Azure, i-doit, GLPI or FNT Command over the REST API
- 03Jira, Microsoft Planner and others as task system
- 04Data marts, REST API and MCP for external analysis and reporting systems
- 05Migrating your data is free and accompanied by our specialists
SaaS or on-premises: run Complaica your way
Complaica comes in two operating modes. The licence costs the same in both.
- SaaS
Complaica is operated for you; the SaaS variant is hosted in Germany.
- On-premises
You run Complaica in your own infrastructure.
- AI integration of your choice
The AI integration is optional and connects over MCP to ChatGPT, Claude or a locally hosted AI service.
What the GDPR requires — and which task maps it
The General Data Protection Regulation (Regulation (EU) 2016/679) has applied directly in all Member States since 25 May 2018. It covers processing in the context of the activities of an establishment in the Union and — under the conditions of Art. 3(2) — also controllers not established in the Union that offer goods or services to data subjects in the Union or monitor their behaviour there. In Germany the BDSG supplements it, for instance on designating the data protection officer.
At its core is accountability under Art. 5(2): the controller is responsible for compliance with the principles and must be able to demonstrate it. Complaica maps the duties as tasks with workflow and evidence — the legal assessment stays with you and your data protection officer.
Six groups of duties and their task types
Record and accountability
Art. 5(2), Art. 24, Art. 30
Controllers and processors maintain a record of processing activities and make it available to the supervisory authority on request. The exemption for fewer than 250 employees does not apply where the processing is likely to result in a risk, is not occasional, or includes special categories (Art. 9) or personal data relating to criminal convictions and offences (Art. 10).
In Complaica: PA · report under Art. 30
Legal basis per processing
Art. 6, Art. 7, Art. 9
No processing without a legal basis: consent, contract, legal obligation, vital interests, public task or legitimate interest — the last after a documented balancing test. Special categories additionally need an exemption under Art. 9(2).
In Complaica: CR · LIA
Data subject rights
Art. 12–22, Art. 77
Access, rectification, erasure, restriction, data portability and objection — to be answered without undue delay, at the latest within one month; extendable by two further months where necessary, taking into account the complexity and number of the requests. Every data subject may also lodge a complaint with the supervisory authority.
In Complaica: DSR · CMP
Security and incidents
Art. 28, Art. 29, Art. 32–34
Technical and organisational measures appropriate to the risk; persons with access to data process it only on instructions; processors are bound by contract. A personal data breach is notified without undue delay and, where feasible, within 72 hours, unless it is unlikely to result in a risk — and documented in every case.
In Complaica: DPI · CC · TOM · processor review
Risk and impact assessment
Art. 35, Art. 36
Where a processing is likely to result in a high risk to the rights and freedoms of the data subjects, a data protection impact assessment is carried out beforehand. Where it indicates a high risk in the absence of measures to mitigate it, the supervisory authority is consulted prior to the processing.
In Complaica: TA · DPIA
Transfers to third countries
Art. 44–49
Personal data leaves the EU only on a basis in Chapter V: an adequacy decision, appropriate safeguards such as the Commission's standard contractual clauses, or binding corporate rules — since the Schrems II judgment (C-311/18) with an assessment of the legal situation in the destination country.
In Complaica: TIA
Five steps to a running DPMS
How the introduction with Complaica runs — from taking over what you already have to the evidence.
- 01
Take overInventory and structure
Take over the existing record, system lists and service providers from Excel or connected systems; the Data Protection Kit supplies the starting structure.
- 02
LinkProcessing and assets
Connect every processing activity with processes, systems, data categories and recipients — the basis for the record and the risk analysis.
- 03
AssessThreshold assessment and DPIA
Clarify per processing whether a DPIA is needed and record risks with measures; the TOM come from the ISMS where they fit.
- 04
OperateRequests, incidents, consents
Run ongoing tasks with workflow, deadline and owner; the dashboard shows what is due.
- 05
DemonstrateReports and review
Generate the record, DPIA reports and incident documentation from the data and review them regularly.
Why Complaica as data protection software?
Six reasons controllers and data protection officers run their DPMS with Complaica.
Workflows instead of e-mail and Excel
Every data protection activity runs as a task with status, deadline and owner — instead of in mailboxes and spreadsheets that can hardly be kept current at the same time.
Traceable down to the detail
Every change is logged with author and date; documents, assessments and decisions sit on the object they refer to.
Ready to start with the Data Protection Kit
The Data Protection Kit brings a typical organisational structure, the record template under Art. 30, DPIA assessment and report, and threat and measure catalogues.
Adaptable to your organisation
The data model is tailored to your processes; further norms and internal requirement catalogues can be added.
Collaboration with external parties
Business departments, processors, lawyers or auditors work in the same system — access is granted per object and by link.
Criticality and implementation status at a glance
Implemented requirements are marked and show owners, documents, tasks and notes. Requirements are fulfilled through tasks, action items or individual controls — or assessed by self-assessment.
Streamline data protection tasks with AI assistance
With the optional AI integration (MCP), Complaica answers questions on the GDPR, explains requirements and task types, helps with creating processing activities and tasks and finds answers in your own policies and contracts. It supports the work on the DPMS — assessment and decision stay with you and your data protection officer.
- 01Answer questions on the GDPR, the BDSG and deadlines
- 02Explain requirements and task types — what is required and what counts as evidence
- 03Suggest, formulate and assign processing activities, tasks and measures
- 04Analyse your policies, data processing agreements and documents and answer questions about them
- 05Explain how to use Complaica — which function for what
What customers say about Complaica
“We can do everything we need in one tool”
Complaica is extremely user-friendly and customising it is child’s play. We can take care of ISO compliance and data protection with it — we can do everything we need in one tool. For us, Complaica is better than the alternatives on the market and cheaper at the same time.
More …Less
Complaica is extremely user-friendly and customising it is child’s play. We can take care of ISO compliance and data protection with it — we can do everything we need in one tool.
For us, Complaica is better than the alternatives on the market and cheaper at the same time.
“The optimised compliance process”
One of the features we like best about Complaica is the optimised compliance process. The user interface has a clear, structured design that offers more usability and encourages a higher working speed. This not only gives new users a steep learning curve, it also lets experienced users minimise their effort. In every phase of the security management lifecycle, recurring tasks such as scoping, structure analysis, modelling and even the tracking of risks and measures are supported by a wealth of functionality. On top of that the platform’s performance is great — it is stable and excellent in terms of speed.
More …Less
One of the features we like best about Complaica is the optimised compliance process. The user interface has a clear, structured design that offers more usability and encourages a higher working speed. This not only gives new users a steep learning curve, it also lets experienced users minimise their effort.
In every phase of the security management lifecycle, recurring tasks such as scoping, structure analysis, modelling and even the tracking of risks and measures are supported by a wealth of functionality.
On top of that the platform’s performance is great — it is stable and excellent in terms of speed.
“The guided approach played a decisive role for us”
We were new to compliance and to implementing ISO 27001, and had to go through the complicated certification process. Given the regulatory complexity, we wanted to find the best way for us to get started. Our project manager (aka security officer) had never worked with such compliance standards and rules before. So we decided on support from a third party — Complaica, to be precise. The guided approach played a decisive role for us. Complaica had all the detailed explanations for the compliance check and the risk analysis, including practical suggestions.
More …Less
We were new to compliance and to implementing ISO 27001, and had to go through the complicated certification process.
Given the regulatory complexity, we wanted to find the best way for us to get started. Our project manager (aka security officer) had never worked with such compliance standards and rules before.
So we decided on support from a third party — Complaica, to be precise. The guided approach played a decisive role for us. Complaica had all the detailed explanations for the compliance check and the risk analysis, including practical suggestions.
In addition: data protection consulting and an external data protection officer
The software stands on its own. If you would like support, our data protection experts accompany you in addition — from the gap analysis to the role of the external data protection officer.
- Gap analysis and data protection audit
Comparison of your current state with the requirements of the GDPR and the BDSG. Result: level of fulfilment per article, a prioritised list of gaps and an implementation plan.
- Setup of the DPMS and the record
Organisation, roles, processes, systems and processing activities are set up in Complaica. You get a working DPMS with a record under Art. 30.
- Threshold assessment and DPIA
Support with the preliminary check of your processing and with the data protection impact assessment for the high-risk ones — naming risks, assigning measures, producing the report.
- Processing on behalf and third-country transfers
Review data processing agreements under Art. 28, put standard contractual clauses in place, carry out transfer impact assessments.
- Training and commitment of employees
Training on data protection and data security, confidentiality commitments and instructions for the business departments — so that requests and incidents are recognised and passed on.
- External data protection officer
Our data protection experts take on the role under Art. 37 GDPR and Section 38 BDSG — as the contact for the supervisory authority, data subjects and management, for a time or permanently.
Frequently asked questions about GDPR software
What is the GDPR?
The General Data Protection Regulation (Regulation (EU) 2016/679, in German DSGVO) is the data protection law of the European Union. It has applied directly in all Member States since 25 May 2018 and governs the conditions under which personal data may be processed, which rights data subjects have and which duties fall on controllers and processors. In Germany the Federal Data Protection Act (BDSG) supplements it.
What is a data protection management system (DPMS)?
A data protection management system (DPMS) is the whole of the rules, processes, roles and evidence with which an organisation complies with the GDPR and can prove it. It covers the record of processing activities, the legal bases, the technical and organisational measures, the handling of requests and incidents and the regular review.
What is GDPR software?
GDPR software maps the requirements of the regulation as a catalogue and links them to what they refer to — processing activities, systems, data categories, service providers, persons. The recurring activities run as tasks with workflow and deadline, and the record, the DPIA report and the incident documentation arise from the data rather than in spreadsheets.
How does this differ from the Data Protection Kit?
The Data Protection Kit is the prepared starting set of the Complaica DPMS software: a typical organisational structure, a record template under Art. 30, DPIA assessment and report, and threat and measure catalogues. This page describes the functions and workflows of the GDPR software; the page on the DPMS software presents the contents of the Kit.
Which data protection activities does Complaica support?
Ten task types with a workflow of their own: processing activity (PA), data subject request (DSR), complaint (CMP), data privacy incident (DPI), DPIA threshold assessment (TA), data protection impact assessment (DPIA), transfer impact assessment (TIA), consent record (CR), legitimate interest assessment (LIA) and confidentiality commitment (CC). Plus processor review, security incident and lesson learned.
How long may the answer to a data subject request take?
Under Art. 12(3) GDPR without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests; the data subject must be informed of any such extension within one month of receipt, together with the reasons for it. In Complaica every request carries its deadline, and the dashboard shows what is due.
When must a data privacy incident be notified?
Under Art. 33(1) GDPR the controller notifies a personal data breach to the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it — unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification is not made within 72 hours, it is accompanied by reasons for the delay. A processor notifies the controller without undue delay. Where the breach is likely to result in a high risk, it must also be communicated to the data subjects without undue delay under Art. 34. Under Art. 33(5) every breach is documented.
When is a data protection impact assessment required?
Under Art. 35 GDPR, where a processing — in particular using new technologies — is likely to result in a high risk to the rights and freedoms of natural persons. Art. 35(3) names in particular a systematic and extensive evaluation of personal aspects, including profiling, on which decisions producing legal effects are based; processing on a large scale of special categories of data or of personal data relating to criminal convictions and offences; and a systematic monitoring of a publicly accessible area on a large scale. The supervisory authorities publish lists under Art. 35(4). Whether a DPIA is required is settled in Complaica by the threshold assessment per processing activity.
What is a transfer impact assessment (TIA)?
The assessment of whether a transfer of personal data to a third country is permissible: which instrument of Chapter V applies — adequacy decision, standard contractual clauses, binding corporate rules —, whether the law of the destination country impairs the protection and which supplementary measures are needed. The Court of Justice of the European Union required this assessment in its Schrems II judgment (C-311/18). In Complaica the TIA is a task type with a review date.
How do I demonstrate consent?
Under Art. 7(1) GDPR the controller must be able to demonstrate that the data subject has consented. Under Art. 7(3) consent can be withdrawn at any time, and withdrawing must be as easy as giving it. Complaica runs consents as tasks with the statuses Active, Withdrawn and Expired, linked to the processing activity that relies on them.
What is a legitimate interest assessment?
The test of whether a processing can rest on legitimate interest under Art. 6(1)(f) GDPR: is there a legitimate interest, is the processing necessary for it, and are the interests or fundamental rights of the data subject not overriding? The result is documented — in Complaica as a task that hangs on the processing activity.
What is the confidentiality commitment for?
Persons acting under the authority of the controller or of the processor who have access to personal data may process them only on instructions (Art. 29, Art. 32(4)); under Art. 28(3)(b) the persons authorised by a processor to process the data must have committed themselves to confidentiality. The written confidentiality commitment is the usual evidence of this. Complaica runs it per person: sent, signed, expired or refused, with document and date.
What belongs in a deletion concept?
A deletion concept sets out when which personal data is deleted, and how. Data categories are assigned to deletion rules — with a starting point and a period, derived from the purpose and from statutory retention obligations —, and deletion units describe in which system and at which granularity the data is deleted. The method is described in DIN EN ISO/IEC 27555:2025-09, which replaced DIN 66398 in September 2025. In the GDPR it rests on storage limitation (Art. 5(1)(e)), the right to erasure (Art. 17) and the time limits for erasure in the record (Art. 30(1)(f)).
Who must keep a record of processing activities?
Under Art. 30 GDPR every controller and every processor. Art. 30(5) exempts enterprises and organisations employing fewer than 250 persons — but not where the processing they carry out is likely to result in a risk to the rights and freedoms of data subjects, is not occasional, or includes special categories of data as referred to in Art. 9(1) or personal data relating to criminal convictions and offences referred to in Art. 10. In Complaica the record arises from the approved processing activities as a report.
What does the BDSG add?
The German Federal Data Protection Act uses the opening clauses of the GDPR. Among other things, Section 38 BDSG requires a data protection officer to be designated where, as a rule, at least twenty persons are permanently engaged in the automated processing of personal data, or where processing is carried out that is subject to a data protection impact assessment. In Complaica the BDSG is assessed as a requirement catalogue of its own beside the GDPR.
Do you offer an external data protection officer?
Yes, as an additional service. Our data protection experts take on the role under Art. 37 GDPR and Section 38 BDSG — as the contact for the supervisory authority, data subjects and management, with Complaica as the working tool. Beyond that we advise on gap analysis, the record, DPIA, processing on behalf and training.
Sources References and legal sources
6 sources · GDPR, BDSG, DIN EN ISO/IEC 27555, WP 248, … Show Hide
Legislation
Norms & standards
Guidelines & official publications
Only the version published in the respective official journal is legally binding. Standards are available from the publishers named.
Start GDPR compliance with Complaica
Request a trial account and test Complaica yourself, get the price list or talk about taking over your existing record — write to us.
Thank you.
We will get back to you within one business day.
Not sent.
That did not work. Please check the fields or email us directly.