Complies

ARTICLE 30 RECORDS · ARTICLE 32 CONTROLS · DEADLINES

GDPR compliance software: GDPR management software for US companies of 5 to 200 selling into the EU

One record of what you process, the Article 32 controls that protect it, the processor contracts behind it, and every deadline the regulation puts on a clock, owned by a named person instead of a shared drive.

See pricing

From $79/mo · Prices published · No sales call · Monthly billing

SOC 2 · TRUST SERVICES CRITERIA

Audit readiness

0 %

Your auditor makes the final call

Built for teams of 5 to 200

AWS GitHub Google Workspace Slack Jira Azure Okta
GDPR

What GDPR compliance software actually does

GDPR compliance software keeps a US company's European privacy obligations in one system: a record of what personal data you process and why, the security controls that protect it, the processor contracts behind every vendor that touches it, and the deadlines the regulation attaches to breaches and data subject requests. The category splits three ways, and buyers lose weeks because the three are sold as if they were one product. Consent and cookie tools like Osano, iubenda, and Cookiebot handle the banner and the consent record on your website; they do not manage your controls or your audit evidence. Privacy management suites like OneTrust, TrustArc, and BigID handle data discovery, data mapping, DSAR workflow, and consent at enterprise scale, sold quote-only through procurement. Compliance platforms like Complies, Vanta, and Drata treat GDPR as one framework among several, mapping the Article 32 security controls to the SOC 2 and ISO 27001 work you are already doing and tracking the obligations with owners and due dates. Complies sits deliberately at the small end of that third group: prices published at $79 to $499 a month, monthly billing, self-serve signup, and GDPR cross-mapped against SOC 2, ISO 27001, HIPAA, and PCI DSS so a control you evidence once counts everywhere it applies. Be clear about the boundary, because it decides whether this is the right purchase. Complies does not ship a cookie banner, a consent management platform, automated data discovery, or DSAR request automation. If your GDPR problem is a consent banner or a queue of subject access requests, buy a privacy suite or a consent tool. If your GDPR problem is that you cannot show an auditor or an enterprise customer a current record of processing, a mapped set of Article 32 controls, and evidence that somebody reviews them, that is the problem this solves.

Complies assists with compliance workflows. It is not legal advice, and it does not certify you or guarantee audit outcomes. Your auditor decides; Complies gets you ready.

Last updated August 2026

THE THREE JOBS

The three jobs GDPR actually puts on a small company

1

Know what you process, and be able to show it

Article 30 wants a record of processing activities: the purposes, the categories of data and data subjects, the recipients, the transfers, the retention periods, and the security measures. Article 30(5) exempts organisations with fewer than 250 employees, but only if the processing is occasional, is unlikely to result in a risk to people, and involves no special category or criminal conviction data. A SaaS company processing customer data continuously fails the occasional test, so the exemption almost never applies to the companies that assume it does. The record lives in the platform with an owner and a review date rather than in a spreadsheet somebody built once.

obligation tracking software
2

Protect it, and prove the protection

Article 32 requires security appropriate to the risk and names pseudonymisation, encryption, confidentiality, integrity, availability, resilience, restoration after an incident, and a process for regularly testing the measures. It does not hand you a control list, which is why most teams reuse one they already have. Map the Article 32 obligations onto the SOC 2 or ISO 27001 controls you are already running, collect the evidence on a schedule from AWS, GitHub, and Okta, and the same access review satisfies three frameworks instead of one.

control mapping software
3

Meet the deadlines somebody is timing

GDPR runs on clocks. Article 33 gives you 72 hours from becoming aware of a personal data breach to notify the supervisory authority. Article 12 gives you one month to answer a data subject request, extendable by two more. Article 28 requires a written contract with every processor before they touch the data. Deadlines fail because nobody owns them, not because nobody knows them. Each obligation gets a named owner, a due date, and a reminder that fires before the date rather than after it.

compliance obligation management
COMPARE

Three kinds of GDPR software, and who each one is for

Search results for GDPR software mix three different products together. Comparing them on price alone produces the wrong purchase, because they answer different questions. Here is the honest split.

Dimension Consent and cookie tool Privacy management suite Complies
Example vendors Osano, iubenda, Cookiebot, Termly OneTrust, TrustArc, BigID, DataGrail Complies
Core question answered Is our website collecting consent lawfully and can we prove it Where does personal data live across the business and how do we run privacy at scale Can we show a current processing record and evidenced Article 32 controls
How it works A banner and a consent log on your site, plus generated privacy and cookie policies Data discovery and mapping, DSAR workflow, consent, assessments, vendor modules Obligations, controls, evidence, policies, and vendor documents in one register cross-mapped across frameworks
Who runs it Marketing or whoever owns the website A privacy team or a dedicated DPO with budget A founder, an engineer, or an ops lead doing compliance as a second job
Typical pricing model Self-serve monthly, published, low Quote-only annual contracts sold through procurement, modular Published monthly prices, self-serve signup, no sales call
Handles cookie consent Yes, this is the product Yes, usually as a paid module No. We do not ship a consent banner
Handles DSAR automation Sometimes, at a basic level Yes, with workflow and discovery behind it No. We track the deadline and the owner, not the request workflow
Handles Article 32 controls and evidence No Partly, usually as an assessment module Yes, and cross-mapped to SOC 2, ISO 27001, HIPAA, and PCI DSS
Best for A website that needs a lawful banner this week A large organization with a privacy function and multiple jurisdictions A US company of 5 to 200 that sells into the EU and gets asked for evidence

Read that honestly. If the thing keeping you awake is a cookie banner, the first column is a cheaper and better answer than we are, and you should buy it. Plenty of companies need two of these three, and the usual pairing for a US SaaS company is a consent tool on the website plus a compliance platform behind it. If you are weighing the compliance platforms that treat GDPR as one framework among several, compare them in detail on OneTrust alternatives, Vanta alternatives and Drata alternatives.

VENDOR BY VENDOR

GDPR compliance software compared, and what each vendor actually publishes

Pricing in this category is split between tools that publish a number and suites that will not quote without a call. Below is what each vendor published on its own site in August 2026. Where a vendor publishes nothing, this table says so instead of guessing, and no figure here is an estimate.

Platform What it is Published pricing (August 2026) Best for
Complies Compliance platform, GDPR as one of five mapped frameworks Published: $79, $199, $499 a month. Monthly billing available US teams of 5 to 200 that need evidenced controls and a current processing record
OneTrust Enterprise privacy management suite: discovery, mapping, DSAR, consent No figures published. Quote-only, priced per module Large organizations with a privacy team and multiple jurisdictions
TrustArc Privacy management, consent, and assessment platform No figures published, and no pricing page on the site. Demo-led Organizations that want privacy assessments and consent under one vendor
BigID Data discovery and classification for privacy and security No figures published. Quote-only Companies whose core problem is not knowing where personal data lives
Osano Consent management and privacy platform Publishes self-serve consent plans: Free at $0 a month for 1 user, 1 domain, 5,000 monthly visitors; Plus at $199 a month for 2 users, 3 domains, 30,000 monthly visitors. Broader privacy plans quote-only Websites that need a consent banner with a published price
iubenda Privacy and cookie policy generation with consent management Publishes USD pricing: Essentials $5.99, Advanced $24.99, Ultimate $99.99 a month billed yearly Small sites that need policies and a banner cheaply
Vanta Compliance automation platform with a GDPR framework No figures published. Quote-only. Vendr reports a $20,000 median across 372 purchases, re-verified August 2026 Funded startups running a sales-led compliance rollout
Drata Compliance automation platform with a GDPR framework No figures published. Quote-only. Vendr reports a $24,868 median, February 2026 Startups that want GDPR alongside SOC 2 in one audit platform

The Vendr medians are third party benchmark data from a company that brokers real software contracts, not vendor list prices, and they are included because they are the only figures in this category with a disclosed sample size. Treat them as a budgeting anchor, not a quote. Everything else in the pricing column was read off the vendor's own site in August 2026 and will drift, so check before you budget.

CAPABILITIES

What GDPR looks like when it shares a system with your other frameworks

One processing record that stays current

The Article 30 record carries the purpose, the categories of data and data subjects, the recipients, the transfers, the retention period, and the security measures for each activity, with an owner and a review date on every entry. It updates when you add a processor rather than the week before somebody asks for it, which is the difference between a record and an archaeology project.

Article 32 mapped to controls you already run

Encryption, access control, backup and restore, and regular testing are not GDPR-specific. Map each Article 32 obligation to the SOC 2 or ISO 27001 control that already satisfies it and the quarterly access review you already do becomes GDPR evidence at the same time. SOC 2 work pre-fills a large share of what GDPR asks for on the security side.

Processor contracts tracked, not assumed

Article 28 requires a written contract with every processor. The DPA, the sub-processor list, the transfer mechanism, and the renewal date sit against each vendor in the register with an owner, so the question of whether the analytics tool you added in March has a signed DPA has an answer rather than a search.

The 72 hour clock with a named owner

Article 33 starts counting from awareness, not from resolution, and the failure mode is always ownership rather than ignorance. The breach obligation carries a named owner, the notification content Article 33(3) requires, and a documented internal record for the breaches that never reach the regulator.

Policies that people actually acknowledge

A data protection policy nobody has read is worth nothing to a supervisory authority and nothing to an enterprise customer. Policies get versions, review dates, and staff acknowledgments, so when a customer asks who approved your retention policy and when, the answer is a record.

Answers for the security questionnaire

Most of the GDPR pressure on a US SaaS company arrives as a question in an enterprise procurement review, not as a letter from a regulator. Having the processing record, the DPA, the sub-processor list, and the control evidence in one place turns a two week scramble into an export.

SETUP

From a spreadsheet nobody trusts to a record you can hand over

01

Establish whether GDPR actually applies to you

Article 3(2) catches a US company with no European office if it offers goods or services to people in the EU or monitors their behaviour. Pricing in euros, shipping to EU addresses, or running analytics and retargeting pixels that observe EU visitors is enough. Settle this first, in writing, because the answer decides the size of everything that follows.

02

Build the processing record from what you already run

Connect the stack and start from the systems that actually hold personal data, then add the ones that never went through IT. For each activity, capture the purpose, the lawful basis, the categories of data and people, who receives it, where it goes, and how long you keep it. The first version is always longer than anybody expects.

03

Map Article 32 onto controls, not onto a new project

Take the security measures you already operate and map them to the Article 32 obligations. Where a control is missing, the gap is visible in the register with an owner and a date instead of a note in somebody's head. This is where the overlap with SOC 2 and ISO 27001 pays for itself.

04

Put every deadline on a clock somebody owns

The 72 hour breach notification, the one month data subject request response, the annual review of the processing record, the DPA renewals, and the sub-processor change notices all get an owner and a reminder. Then run it, and let the evidence accumulate rather than being assembled.

FIT

Who this is for, and who it is not

A GOOD FIT WHEN

  • You are a US company selling to customers in the EU or UK and procurement has started asking about GDPR.
  • You are chasing SOC 2 or ISO 27001 and want the GDPR security work to reuse the same controls and evidence.
  • Your record of processing is a spreadsheet that has not been opened since it was created.
  • You need to know which vendors have a signed DPA and which do not, without a search through email.
  • You want the price before a sales call, and you want to start the same day.
  • You have 5 to 200 employees and no dedicated privacy team.

LOOK ELSEWHERE WHEN

  • Your immediate problem is a cookie consent banner. Buy a consent tool, it is cheaper and better at that job.
  • You need automated data discovery and classification to find where personal data lives.
  • You need DSAR intake, identity verification, and fulfilment workflow automated end to end.
  • You employ a privacy function or a full time DPO running a multi-jurisdiction program.
  • You want legal advice on lawful basis, legitimate interest assessments, or transfer impact assessments.
  • You need a supervisory authority filing service or an Article 27 representative provided by the vendor.
QUESTIONS

Common questions about GDPR compliance software

GDPR compliance software is a system that holds the records, controls, contracts, and deadlines the General Data Protection Regulation requires, with an owner against each one. In practice that means a record of processing activities under Article 30, the security measures under Article 32 with evidence that they run, the processor contracts under Article 28, and the notification clocks under Articles 33 and 12. It replaces a spreadsheet and a shared drive with something you can hand to an auditor or an enterprise customer.

Yes, if Article 3(2) applies. A US company with no office or staff in Europe is still in scope when it offers goods or services to people in the EU, or monitors their behaviour. Accepting euros, shipping to EU addresses, running an EU language site aimed at that market, or running analytics and retargeting that observe EU visitors are each enough. Physical location does not decide it and intent does not excuse it.

Almost certainly yes. GDPR sets no minimum number of data subjects and no revenue threshold for the regulation to apply. A handful of EU customers puts you in scope. What volume changes is the depth of what is proportionate: a company with twelve EU users runs a much smaller program than one with twelve thousand, but the obligations exist either way and the Article 32 security duty does not scale away.

It depends which of the three problems you have. If you need a lawful cookie banner and a privacy policy, a consent tool like iubenda or Osano is the right purchase and both publish prices. If you need to show enterprise customers evidenced security controls and a current processing record, a compliance platform is the right purchase. If you need data discovery across a sprawling estate, you need a privacy suite and the budget that comes with it. Buying the wrong one of the three is the most common and most expensive mistake in this category.

It ranges from a few dollars a month to five and six figures a year, because the label covers three different products. Consent tools publish low self-serve prices: iubenda lists $5.99 to $99.99 a month billed yearly, and Osano lists a free consent tier and $199 a month for its Plus consent plan. Compliance platforms with GDPR as one framework run from $79 a month at the small end to quote-only annual contracts, where Vendr benchmark data puts Vanta around a $20,000 median and Drata around $24,868. Enterprise privacy suites like OneTrust and TrustArc publish no figures at all.

Usually yes, despite the exemption. Article 30(5) exempts organisations with fewer than 250 employees, but only when the processing is occasional, is unlikely to result in a risk to the rights and freedoms of data subjects, and involves no special category data under Article 9(1) or criminal conviction data under Article 10. A SaaS company processing customer data continuously is not doing it occasionally, so the exemption fails on the first condition. Most small companies that believe they are exempt are not.

Article 32 requires security appropriate to the risk and names specific measures to consider: pseudonymisation and encryption, ongoing confidentiality, integrity, availability and resilience of systems, the ability to restore access after an incident, and a process for regularly testing and evaluating the effectiveness of the measures. It deliberately does not publish a control list, so the practical approach is to map it onto a framework you already run, such as the SOC 2 common criteria or the ISO 27001 Annex A controls, and evidence those.

If you are a controller or processor not established in the EU but caught by Article 3(2), yes, unless an exception applies. Article 27(2) removes the requirement where the processing is occasional, does not include large scale special category or criminal conviction data, and is unlikely to result in a risk to people, or where you are a public authority. A representative is a designated contact in a member state where your data subjects are, named in your privacy notice. Complies tracks that you have appointed one; it does not act as one.

Yes, under a valid mechanism. The European Commission adopted an adequacy decision for the EU-US Data Privacy Framework in July 2023, and the EU General Court upheld it in September 2025 in the Latombe case. An appeal is pending, so treat the mechanism as something you review rather than settle once. Companies not certified under the framework generally rely on standard contractual clauses with a transfer impact assessment behind them. Record which mechanism each transfer uses in the processing record, because that is the question you will be asked.

There is no single official GDPR certificate the way people expect. Articles 42 and 43 provide for certification mechanisms approved by supervisory authorities or the European Data Protection Board, and a small number exist, but none is a general purpose GDPR stamp and none makes you compliant by itself. Article 42(4) says explicitly that certification does not reduce the responsibility of the controller or processor. In practice, US buyers ask for a SOC 2 report or an ISO 27001 certificate plus your DPA, not a GDPR certificate.

No, but it covers a large part of the security half. Article 32 is about security of processing, and the SOC 2 common criteria and the ISO 27001 Annex A controls satisfy most of what it asks for, which is why cross-mapping saves real work. What neither covers is the rest of GDPR: lawful basis, transparency and privacy notices, data subject rights, retention limits, international transfers, and the processing record itself. Treat SOC 2 or ISO 27001 as a running start on Article 32 and nothing more.

A consent management platform handles the banner on your website: it collects, stores, and proves consent for cookies and trackers, and it usually generates the cookie and privacy policies. GDPR compliance software handles everything behind the website: the processing record, the security controls and their evidence, the processor contracts, the retention rules, and the deadlines. They solve different halves of the regulation, and most US SaaS companies selling into the EU end up running one of each rather than choosing between them.

GO DEEPER

Frameworks and guides

GDPR in the same system as your controls, evidence, and policies

Prices published, $79 to $499 a month. Monthly billing. Start today, no sales call.