How it works today in many small and mid-sized companies
In a company with 80 or 300 employees, data protection is rarely a department of its own. It is a task someone in HR, IT or the managing director's office takes on alongside their actual role – often together with an external data protection officer who visits twice a year and is reachable by email in between.
The documentation grows accordingly. The records of processing activities sit in "Records_2024_final.xlsx", the data protection impact assessment for the new applicant tracking system in a Word document in the folder "Data Protection/DPIA", the data processing agreements as PDFs in the purchasing team's mailbox. A data breach is reported by someone writing to "privacy@", and "I'll send you the latest version" is part of everyday work.
At some point the decision is made to buy software. Then the search begins: comparison sites, three demos in two weeks, a scoring sheet called "Selection_Privacy_Software.xlsx" in which features get ticked off. Almost every product has records of processing, a DPIA template and an incident module. The ticks barely differ.
The search usually starts with questions like "Which GDPR software suits a mid-sized company?" or "Is there a tool for data protection impact assessments?". The answers list vendors and features but say little about how well a product fits a company with two sites, a subsidiary and an external data protection officer. Selecting this way compares catalogs, not workflows – and the decision often comes down to the impression left by the last demo.
The moment it becomes obvious
The differences only show in daily operation. The external data protection officer needs their own access but sees either everything or nothing. The subsidiary is supposed to be documented separately, yet the tool knows only one organization. Or the first reportable data breach happens, and nobody can say at a glance when the 72-hour deadline under Art. 33 GDPR expires and which processing activities are affected.
This is when it becomes clear that the scoring sheet asked the wrong questions. It asked whether a feature exists – not whether it fits the organization that will use it, and whether the documents are connected to each other.
The analysis
Five questions a comparison list does not answer
Each of them decides whether the software is still in use after a year or whether the documentation drifts back into spreadsheets.
View processing activities in preecoDoes the structure fit your organization?
Sites, subsidiaries or the clients of an external data protection officer need separate areas. If the software knows only one organization, the separation gets rebuilt through file names and folders.
Are the documents connected?
An impact assessment refers to processing activities, a data breach affects systems. If these documents sit side by side without links, the very references people ask about are missing when it matters.
Are deadlines visible?
For a reportable data breach, 72 hours count. Software that keeps deadlines only as a date field does not show whether a report was made, whether the deadline is still running or whether it has passed.
Can access be controlled in detail?
Business units, internal owners and the external data protection officer do not see the same things. Without roles and confidentiality levels, the only choice left is between too much access and none at all.
Can a small team work with it?
Whoever handles data protection alongside another role has no time for long onboarding. An interface that only specialists can operate ends up back at the spreadsheet within a few months.
The target process in six steps
A sound selection does not start with demos but with your own starting point. The following steps have proven themselves in small and mid-sized companies.
1. Take stock. Collect what exists today: the records of processing, existing impact assessments, data processing agreements, the latest data breaches and data subject requests. Note where each document lives and who maintains it. This list shows which processes are missing today or exist only on paper. Also note which questions customers, the supervisory authority or the works council have asked in recent years – they show which evidence is actually requested.
2. Define the structure. Clarify how many organizations, sites or companies must be documented separately and which role the external data protection officer plays. In preeco | data protection, several organizations can be managed in one team; an organization selector switches between them, and external data protection officers look after several clients this way.
3. Test with your own scenario. Instead of a standard demo, walk through a real case: a processing activity from your records, an impact assessment for it and a fictitious data breach that affects this processing. This shows whether the documents are linked, how many clicks an entry takes and whether the person who handles data protection on the side manages without help. Let that person run the test, not IT. In preeco | data protection, the "Relationships" tab on every document shows graphically what it is connected to.
4. Carry over what exists. The existing work is the content foundation. Records as DOCX or XLSX can be uploaded to preeco | data protection; an optional AI feature detects the processing activities they contain, and you decide in a preview which ones to adopt as drafts.
5. Assign responsibilities and access. User groups are freely defined, confidentiality classes set per group. Business units contribute through data collection forms, including external people by email, without an account of their own.
6. Plan for operation. Follow-ups remind you of regular reviews, every approval automatically creates an immutable revision, and the activity log records who changed what and when.
What counts when it happens: the data breach
For a personal data breach, the supervisory authority must generally be notified within 72 hours under Art. 33 GDPR. In preeco | data protection, the incident is recorded with times, people involved and the assessment of the reporting obligation, and linked to the affected processing activities. Nine included report templates cover, among others, the notification to the supervisory authority and the communication to data subjects under Art. 34 GDPR. Each report shows whether the deadline is still running and whether it was met or missed. If a deadline is missed, the reason is documented on the incident. Custom report templates can be built from the included ones, and a preview shows the report before it is saved.
Before and after at a glance
| Criterion | Before | After |
|---|---|---|
| Structure | One folder per company, maintained by hand | Several organizations in one team |
| Context | Records, DPIAs and incidents unconnected | Linked documents with a relationships view |
| Deadlines | A date in an email | Reporting deadline status per report |
| Access | Sharing entire folders | User groups and confidentiality classes |
| Collaboration | Versions by email | Tasks, comments and forms for business units |
| Evidence | Last file version | Revision on every approval, activity log |
| Currency | Reviews from memory | Follow-ups with notifications |
| Single point of failure | Knowledge held by one person | Documentation visible to everyone authorized |
In practice
How this looks in preeco | data protection
The three building blocks that carry a data protection organization in an SME.
Records of processing activities
Processing activities under Art. 30 GDPR, optionally carried over by AI from existing records or derived from a task description, linked to systems and contracts.
Impact assessments
A structured form, details carried over from the linked processing activities, a graphical risk map and automatic revisions in the statuses acceptable, act/review and unacceptable.
Requests and incidents
Data subject requests and data breaches with deadlines, assessment of the reporting obligation, included report templates and a clear reporting deadline status.
What the switch means in practice
Moving to software is less a technical task than an organizational one. The content already exists; it gets a structure in which responsibility, references and status are recorded. What stands out along the way are gaps – a processing activity without a legal basis, a contract with no counterpart in the records. Those gaps are better found during the switch than during an inquiry from the supervisory authority.
The time frame is manageable. A cloud environment of preeco | data protection is ready within 48 hours on business days. Onboarding covers setting up the organizational structure, user groups and permissions, an optional import of master data and online training for administrators and users. Also plan time for clarifying content: who is responsible for which processing activity, and who approves documents?
Three mistakes that make the selection harder than it needs to be
Deciding by feature list. Almost every solution has the same modules. What matters is whether it reflects your organizational structure and whether the documents are connected. Only a test with your own data shows that.
Involving the external data protection officer too late. They work with the documentation every day and know the questions supervisory authorities ask. Asking them only after the purchase means learning too late that their way of working is not supported.
Trying to carry over everything at once. Start with the records of processing, because impact assessments and incidents build on them. The rest follows in the order in which it is needed.
How to tell it is time
Spreadsheets and folders are not a mistake at the start. They become a risk when at least one of these applies:
- Several companies or sites must be documented separately.
- An external data protection officer works with your files in their own system.
- You cannot say which processing activities a data breach would affect.
- Impact assessments refer to versions of the records that no longer exist.
- Only one person knows where each document is.
FAQ
Frequently asked questions about GDPR software for SMEs
Software that reflects your organizational structure, links records of processing, impact assessments and incidents, makes deadlines visible and can be operated by a small team without its own IT department. preeco | data protection is operated in ISO 27001-certified data centers in Germany and is available as cloud, private cloud or on-premises.
Yes. preeco | data protection supports multiple clients: several organizations are managed in one team, an organization selector switches between them, and permissions define who sees which organization. External data protection officers are explicitly among its users.
Yes. Existing records can be uploaded as a DOCX or XLSX file. An optional AI feature detects the processing activities they contain; you review the result in a preview and decide which entries to adopt as drafts.
The incident is recorded with times, people involved and the assessment of the reporting obligation, and linked to the affected processing activities. preeco | data protection includes report templates for the supervisory authority under Art. 33 GDPR and for communicating with data subjects under Art. 34 GDPR, and shows for each report whether the deadline is still running or was met.
That depends less on size than on the number of people and documents involved. As soon as several people work on the documentation, an external data protection officer is involved or deadlines must be met, a shared data basis saves coordination effort. A conversation about your current documentation is often enough for a first overview.
Go through your selection together
Bring your records of processing. In 30 minutes we use one of your cases to show how records, impact assessment and data breach connect in preeco | data protection.