Tested. Ranked. Trustworthy.

Software Evaluation Guide

How to Evaluate GDPR Compliance Software: The Buyer's Scorecard That Survives Legal Review

Evaluate GDPR compliance software without vendor spin: the weighted scorecard, the true 3-year cost, the Article 28 processor gate. Free scorecard included.

Topickz Editorial Team Last updated July 25, 2026 16 min read

Reviewed & fact-checked by Vignesh Sampath Kumar, Editor-in-Chief · How we test & score

A US company usually discovers its GDPR obligation one of two ways. A prospect’s security questionnaire asks for a data processing agreement, or an email lands from someone in Berlin asking for a copy of everything you hold on them. Either way, someone gets thirty days and no tooling.

That is when most GDPR software gets bought, and it is the worst moment to buy it. You are shopping under a deadline, three product categories rank for the same search term, and every vendor on the call will imply their platform is the compliance rather than the paperwork around it.

This guide is for the person holding that deadline. The privacy lead, the general counsel doing double duty, the security engineer who inherited it because nobody else raised a hand. You get the scorecard, the real three-year cost, the processor gate legal will run anyway, and the questions that make a sales engineer stop reading slides. Fill the downloadable scorecard as you read.

EUR 7.1bn
Cumulative GDPR fines issued between 25 May 2018 and 10 January 2026, with roughly EUR 1.2 billion of that in 2025 alone.
DLA Piper GDPR Fines and Data Breach Survey, January 2026

Three product shapes hiding behind one search term

Search “GDPR compliance software” and the results mix a $10 cookie plugin, a six-figure enterprise suite, and a developer library that ships as open source. They are not competitors. They solve different articles of the same regulation, on completely different meters.

Consent management platforms handle the banner. They record a visitor’s choice, block non-essential trackers until consent arrives, and produce the proof record. The legal hook is not GDPR itself, it is Article 5(3) of the ePrivacy Directive, which requires prior consent before storing or accessing anything on a user’s device. The EDPB’s Guidelines 2/2023 , adopted 16 October 2024, extended that reach past cookies to tracking pixels, tracking links, fingerprinting, certain IP-only tracking and IoT reporting. These tools are metered by web traffic.

Data mapping and DSAR automation solve a different problem. Where does personal data live across your systems, and can you find all of it when someone asks. That is Article 30 records and Article 12 request fulfilment, metered by data subjects or connected systems.

Full privacy suites bundle both, add assessments and vendor risk, and sell on a quote. Compliance automation platforms take a fourth angle, treating GDPR as one framework inside a SOC 2 and ISO 27001 evidence engine, which helps with the questionnaire problem and does nothing for the cookie banner.

Buying the wrong shape is the most expensive error here, and it is common. A marketing team evaluating an enterprise suite over a non-compliant banner will burn six months and a contract. A company fielding thirty requests a month on a $10 policy generator is running a manual process with a logo on it. Our full breakdown of the 20 tools splits them by shape for that reason.

The obligation inventory you build before the demos

Write the list before you take a call. Not “we need to be GDPR compliant.” The specific obligations that apply to you, in the order they will bite.

Start with territorial scope. A US controller with no EU establishment is still caught by Article 3(2) when it offers goods or services to people in the EU or monitors their behaviour. That also triggers Article 27 , a written designation of a representative in the Union, unless the processing is occasional, low risk and free of special category data. No software satisfies Article 27 for you, and vendors rarely mention it.

Then write the lawful basis for each processing activity. Consent is one of six bases in Article 6, not the default, and picking it where legitimate interest fits saddles you with a withdrawal obligation you did not need. Article 7(1) puts the burden of proof on you to demonstrate consent was given, and Article 7(3) requires withdrawal to be as easy as giving it. Those two sentences decide half your consent tooling requirements.

Next, records. Article 30 lists what a record of processing must contain: controller and DPO contacts, purposes, categories of data subjects and data, recipient categories, third-country transfers and safeguards, erasure periods, security measures. Article 30(5) exempts organisations under 250 people, but only where processing is occasional, low risk, and free of special category or criminal offence data. Most SaaS companies fail on the second condition alone, because customer data processing is never occasional.

Then risk. Article 35 requires a DPIA before high-risk processing and names three mandatory cases: systematic and extensive automated evaluation with legal effects, large-scale processing of special category or criminal offence data, and large-scale systematic monitoring of a publicly accessible area. If you run AI scoring on customer data, read the first case twice.

Finally, your processor chain. Article 28 requires a written contract with every processor covering eight specific duties, and Article 28(2) blocks a processor from adding a subprocessor without your authorisation and a right to object. Count the SaaS tools your company runs. That number is your Article 28 backlog.

The weighted scorecard, locked before the demos

Set the weights before you watch a demo. A weight assigned afterwards is not a weight, it is a rationalisation of whatever impressed you. Get the criteria signed off by the DPO, security, and finance, then let vendors present against them.

Score each tool 1 to 5 per criterion, and force a written comment on any 1 or any 5 so nobody’s gut feel hides inside a number. Multiply by weight and total it.

The weights below sit where these purchases actually fail. Product-shape fit and data discovery carry the most, because a platform pointed at the wrong obligation returns nothing, and one that cannot find your data cannot answer a request about it. Cookie banners no longer separate a $10 tool from a $50,000 one.

CriterionWeightWhat to score, and the evidence to demand
Obligation fit (product shape)16Does the tool’s shape match your top obligation? Score 5 only on a direct match. Note which article each capability serves.
Data discovery and mapping coverage16Hand over your real system list, count natively discovered systems versus manual entry. Score verified connectors, never the headline integration count.
Request fulfilment against the Article 12 clock15Submit a live test request through the portal and time it end to end. Ask their median fulfilment time across customers.
Consent capture and proof of consent13Demand an exportable per-visitor record: timestamp, banner version, text shown, categories accepted, withdrawals. No exportable record scores 2 at most.
Three-year TCO and metering exposure13Year 1 against year 3 on real volumes. Metering unit, overage rate, capped uplift, in writing. No stated overage rate is a hard score-down.
Records, DPIA and assessment workflow10Export a filled Article 30 record and a completed DPIA from the demo tenant. Check all four Article 35(7) elements, not just a risk matrix.
Processor chain and transfer controls9Can it tell you which of your vendors lack a signed DPA, which transfer mechanism each uses, and when each contract renews?
The vendor’s own security posture8They become your processor. SOC 2 Type II with scope, ISO 27001, subprocessor list, residency in writing, SSO in your tier.

The downloadable version totals this across your shortlist and flags the winner.

🧮

Get the GDPR Compliance Evaluation Toolkit

The weighted vendor scorecard (Excel, auto-scores your shortlist and ranks the winner) plus the 1-page checklist of questions to ask every vendor and the red flags to walk away from. Free.

Free. No spam. Unsubscribe in one click.

The true three-year cost, and the metering trap

Per-seat pricing barely exists here, which breaks the mental model buyers bring from every other software purchase. GDPR tools meter on monthly visitors, sessions, unique users, data subjects, pageviews, or connected systems. That choice of unit decides your cost curve, and it is usually missing from the proposal.

The consequence catches people out. A traffic-metered consent platform means a successful marketing quarter raises your compliance bill. Nobody models that. Then the invoice arrives.

Published self-serve pricing exists at the small end. Osano Plus is $199 a month for 3 domains and 30,000 monthly visitors. Ketch Starter is $150 a month for 30,000 unique users, with DSR automation and data mapping gated to the custom-priced Pro tier. iubenda Essentials is $6.99 per site per month for 25,000 pageviews. All verified on the vendors’ pricing pages, 25 July 2026.

Above that band, pricing goes quote-only, and the useful benchmark is transaction data rather than a rate card. Vendr puts OneTrust at an $11,835 average contract across 306 purchases, ranging from $1,620 to $47,622, and TrustArc at $15,120 across 47. Those averages include small deals, so treat them as a negotiating floor, not a forecast.

Cost lineWhat to budget, and what to ask for
Platform subscriptionPriced on a metering unit, not seats. Get the unit, the allowance, and the overage rate in the quote itself.
Implementation and configurationA banner ships in a day; a suite does not. Demand a line-item SOW for tenant setup, connectors, templates, workflow build.
Connectors beyond the allowanceGet the per-connector price plus annual maintenance. Your one non-standard internal system holds the data that matters.
Data-mapping labourDiscovery finds systems and columns. Assigning purpose, lawful basis, retention and recipients is human work, and the biggest hidden line in year one.
Internal ownershipArticle 37(6) lets a DPO be an employee or a service contract, so price your route inside this decision.
Legal reviewDPA redlines, transfer impact assessments, notice drafting, DPIA sign-off. Counsel hours belong in the business case, not a month-four invoice.
Metering overage and renewal escalationModel years two and three on projected traffic. Negotiate an uplift cap before signature; you have none after it.

One line nobody quotes: the request you cannot answer. Gartner’s 2020 legal and compliance research put the average cost of a manually handled subject access request at $1,406, driven mostly by routing them through internal counsel. At forty a year that is a headcount’s worth of legal time, and a better business case for automation than any feature grid.

The Article 12 clock, and what automation buys

Article 12(3) is the sentence to read before you score anything. You respond to a data subject request without undue delay and in any event within one month of receipt. You can extend by two further months where the request is complex or numerous, but only if you tell the requester the reason inside that first month. Miss the notification and you have no extension, just a late response.

That deadline is why discovery matters more than case management. The clock does not care that your ticketing system tracked the request neatly. It cares whether you found that person’s data in a support attachment, a warehouse table, and a marketing tool someone connected in 2023.

Manual fulfilment scales badly. Under about five requests a month a spreadsheet and a shared inbox genuinely work, and paying for automation is premature. Past twenty a month the labour cost overtakes the software cost, and the business case writes itself.

The 60-second GDPR tooling decision
1
Cookie banner, or subject request?
Banner means a consent platform. Requests mean data mapping and DSAR automation.
2
Did it clear the Article 28 gate (DPA, subprocessors, residency, transfer mechanism)?
If not, it is out. Legal will kill it later anyway.
3
Did a live test request on your own systems finish inside the one-month clock?
If not, you bought a dashboard, not fulfilment.
4
Does the three-year cost survive projected traffic with overage applied?
If yes, that is your recommendation.

Regulators have been explicit about the mechanics. Reject has to be as easy as accept, and legitimate interest is not available as a basis for storing or accessing information on a device. France’s CNIL priced that position in September 2025, fining Google EUR 325 million and SHEIN EUR 150 million in the same week. The SHEIN decision turned on tracking cookies still being read after users clicked reject all.

So score the proof, not the appearance. Ask for one visitor’s consent record exported as a file: timestamp, banner version, the exact text shown at that version, categories accepted, and any later withdrawal. That artefact discharges the Article 7(1) burden of proof. A banner that cannot produce it has moved your risk, not reduced it.

Track the proposed rule changes without pricing them in. The EU’s Digital Omnibus would move parts of the cookie regime into GDPR and adjust breach timing. Its AI half was adopted in mid-2026; the data protection half was still in negotiation, with authorities pushing back on the consent provisions. Buy for the law as it stands.

The security and processor gate

This part is pass or fail, not a score you can lose a point on. The tool will read personal data across your systems, which makes it your Article 28 processor and enlarges the surface your security team is paid to shrink.

Demand documents, not assurances. A current SOC 2 Type II report with its scope and trust services criteria stated, or an ISO 27001 certificate with the statement of applicability. A signed DPA before signature, containing the eight duties in Article 28(3) rather than a paraphrase. A subprocessor list with the notice-and-objection right Article 28(2) requires.

Then the details that only matter after something goes wrong. Data residency named in writing for storage and processing, including whether support staff outside that region can reach your tenant. Deletion or return of all personal data at termination under Article 28(3)(g).

Breach timing needs its own clause. Article 33 requires you to notify the supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of a breach. You cannot meet that if your processor takes five days to tell you, so their window has to be materially tighter than yours. Europe now averages 443 breach notifications a day, up 22% year on year per DLA Piper’s February 2026 analysis.

Check the SSO gating too. Single sign-on parked behind an enterprise tier means the configuration IT requires costs more than the plan you budgeted, a pattern we documented in The SSO Tax Report 2026 .

Transfers, residency, and the DPF question

Any US-headquartered vendor processing EU personal data needs a transfer mechanism, and “we’re SOC 2” is not one. Two live routes exist: the European Commission’s 2021 standard contractual clauses plus a transfer impact assessment, or an active EU-US Data Privacy Framework certification under the 2023 adequacy decision.

That decision survived its first challenge. The EU General Court dismissed the Latombe action on 3 September 2025. An appeal to the Court of Justice was lodged on 31 October 2025 and is still pending, and the Court of Justice is the body that struck down both Safe Harbour and Privacy Shield.

So ask for SCCs alongside any DPF reliance, not instead of it. A vendor who papers both has thought about the appeal succeeding. One who refuses because the framework covers it has handed you a future migration project.

The buying committee, mapped

A GDPR tool needs more signatures than its price suggests, and the evaluations that stall are the ones where the buyer mapped the software and not the room. Name everyone who can say no, and the artefact that answers them.

The CFO cares that a compliance cost now tracks marketing traffic instead of headcount; bring the three-year model with the overage rate applied. The DPO cares whether the output holds up in front of a supervisory authority; bring the exported Article 30 record and a completed DPIA from the trial tenant. Security cares that you are handing a third party discovery access to production; bring the SOC 2 scope, the subprocessor list, and a tested answer on whether the platform copies discovered data or orchestrates in place.

Legal cares about DPA redlines, the transfer mechanism, and the liability cap, so send them the standard agreement early. Engineering cares how much of this becomes connector work. Marketing cares that a stricter banner reads as a traffic drop, so measure the consent-rate delta on one real page first.

Write each person’s top objection and the evidence that answers it. That page is in the downloadable checklist.

Running the trial against your own systems

A vendor demo is the product on its best day, driven by the person who built the demo. Your trial has to be the opposite, and here that means three specific tests rather than a general poke around.

Scan your own production domain, not theirs, and compare the tracker list against what marketing believes is running. Submit one real subject request through the consumer-facing portal and time every stage: identity verification, discovery, redaction, packaging, delivery, audit record. Then wire one connector to a real system yourself and check whether it does discovery, deletion, or only discovery with deletion still on a roadmap. Price your actual volume while you are in there, not the entry tier.

Our testing methodology covers how we run the same sequence on every tool we review.

Red flags that should end an evaluation

Some findings are exits, not deductions. A vendor who says the software makes you GDPR compliant, which no software does. A refusal to state the metering unit and overage rate in writing. A DSAR demo that never touches one of your systems. Consent records that cannot be exported per visitor. No published subprocessor list, or a DPA with no right to object when they add one. A salesperson who cannot map an automated compliance claim to a specific article. Implementation quoted as “included, we’ll figure it out together” with no statement of work.

Each of those is the vendor showing you how the relationship works once your money has cleared. Believe the preview.

Questions buyers ask before they sign

Does GDPR compliance software actually make us compliant?

No, and any vendor implying otherwise has disqualified themselves. These tools reduce the manual labour of a privacy program: proving consent, finding personal data, answering requests inside the deadline, keeping records. Compliance depends on your processing activities, lawful bases, processor contracts, and legal review. Software makes a good program cheaper to run. It does not create one.

How long do we have to answer a data subject request?

One month from receipt under Article 12(3), and “without undue delay” if you can do better. You may extend by two further months where the request is genuinely complex or numerous, but you must tell the requester about the extension and its reason inside the first month. Skip that notice and the extension does not exist. Build that step into whatever tool you buy.

What can a GDPR fine actually reach?

Article 83 sets two tiers, each “whichever is higher”. The lower one is up to EUR 10 million or 2% of total worldwide annual turnover, covering most controller and processor duties. The upper one is up to EUR 20 million or 4%, covering the processing principles, lawful basis and consent, data subject rights, and international transfers. Cumulative fines reached EUR 7.1 billion by 10 January 2026 per DLA Piper.

Follow the pain. A tracking script firing before consent means a consent management platform, and the cost is small. A request nobody can answer because the data is unmapped means data mapping and DSAR automation, which is where the real spend sits. A full suite makes sense when you have both problems, a named privacy owner, and vendor management across a large SaaS estate. Buying a suite for a banner problem is the most common expensive mistake here.

As a US company with no EU office, are we in scope?

Probably, if you offer goods or services to people in the EU or monitor their behaviour, which Article 3(2) covers regardless of where you are incorporated. That also triggers Article 27, a written designation of a representative in the Union, with a narrow exemption for occasional low-risk processing involving no special category data. No software discharges Article 27 for you.

What should we budget for GDPR tooling in year one?

At the small end, a compliant banner and policy set runs from free to a few hundred dollars a month on published pricing (Osano Plus $199/mo, Ketch Starter $150/mo, iubenda Essentials $6.99/site/mo, verified 25 July 2026). Once data mapping and request automation enter the picture you are in quote-only territory: Vendr shows an $11,835 average OneTrust contract and $15,120 for TrustArc. Add implementation, connector work, legal review, and internal ownership, and the software line is usually the smaller half of year one.

How do we keep the renewal from doubling?

Get three things into the first contract, while you still have something to trade. The metering unit and its allowance stated explicitly. The overage rate per unit. A capped percentage uplift at renewal, with the cap applying to total contract value rather than list price. Then ask the rep in writing what a company your size pays at first renewal. A vendor who will not answer in writing has answered.

Ready to shortlist?

Best GDPR Compliance Software in 2026: 20 Tools Compared for US Privacy Teams

Read the full ranking →

Written by