Compliance › Software

Do I need GDPR compliance software? An honest decision guide

GDPR compliance software is not a legal requirement, and templates or a GDPR consultant may be enough. See the decision matrix by size, processors, entities and NIS2, with prices and a worked example.

Four steps from a single document to a spreadsheet, legal advice and a compliance platform

Table of Contents

    The question usually surfaces at a predictable moment. The spreadsheet holding your record of processing has sprouted a fourth tab, a customer has asked for evidence that you audit your processors, or NIS2 has just landed on the board agenda. Do we buy GDPR compliance software, or can we get by with templates, a GDPR consultant and the tools we already have?

    Most articles on the subject are written by software vendors and conclude that the answer is yes. We are a software vendor too, and the answer is not always yes. This article sets out what GDPR actually requires, which alternatives exist, when each of them is enough, and when they stop holding together. It ends with a worked example and an honest list of what software does not solve.

    If you are looking for a definition of a GDPR system, start with our article on what GDPR compliance software is. This one is about the decision.

    The short answer: do I need GDPR compliance software?

    GDPR does not require software. It requires you to be able to demonstrate compliance (Article 5(2) and Article 24) and to keep your record of processing in writing, including in electronic form (Article 30(3)). How you do that is up to you. An organisation with one legal entity, a handful of processing activities, fewer than ten processors and no large-scale special category data can manage perfectly well with the free templates from supervisory authorities and a fixed review schedule.

    The maths changes when several people have to contribute to the same documentation, when your processors run into the dozens, when you have more than one company, or when NIS2 requires the same suppliers and assets to be assessed for cyber security as well. At that point the problem is no longer writing the documents but keeping them current and consistent. That is where GDPR compliance software pays for itself. Whatever you choose, software does not replace legal judgement, and many organisations end up with a tool and an adviser working together.

    What GDPR actually requires, and what it does not

    The GDPR is technology neutral. No article says documentation must sit in a particular system. It does impose a set of obligations that create recurring work, and it is the volume and frequency of that work that decides whether a template is enough. The table shows the obligations that usually drive the decision.

    Obligation Legal basis What it means in practice What makes it heavy
    Accountability Art. 5(2) and Art. 24 You must be able to show compliance, not just comply Evidence scattered across folders, inboxes and people
    Record of processing Art. 30(1)-(5) Written record of processing activities with purposes, categories, recipients, transfers and retention periods Many activities, many contributors, frequent change
    Data processing agreements Art. 28(3) A written contract with every processor, not with every supplier Sub-processors, amendments and versions
    Processor oversight Art. 28(1) and 28(3)(h) Ongoing, risk-based follow-up on whether each processor honours the contract The number of processors and the need to show when oversight happened
    Personal data breaches Art. 33(1), 33(5) and Art. 34 Notification to the supervisory authority within 72 hours, an internal log of every breach, and communication to individuals without undue delay when the risk is high Finding the right facts quickly
    Data subject rights Art. 12(3) and Art. 15-22 A response within one month, extendable by two further months Volume and knowing where the data sits
    Data protection impact assessment Art. 35 Required where processing is likely to result in a high risk Reusing facts from the record and the risk assessment
    Data protection officer (DPO) Art. 37-39 Mandatory for public authorities and for certain core activities The DPO has to monitor compliance, which requires access to the documentation

    Two points in the table are easy to miss. First, Article 33(5) requires you to document every breach, including those you do not notify. Across Europe, supervisory authorities received an average of 443 breach notifications a day between 28 January 2025 and 27 January 2026, a 22% rise on the previous year, according to the DLA Piper GDPR Fines and Data Breach Survey (January 2026). Behind every notification sits an internal record. Second, keeping the record of processing is the controller's duty, not the DPO's.

    Infringements of Articles 25 to 39, which cover the record, processor contracts and the DPO rules, carry fines of up to EUR 10 million or 2% of worldwide annual turnover (Article 83(4)). The same DLA Piper survey puts total fines issued by European authorities in 2025 at roughly EUR 1.2 billion. The Court of Justice also held in Case C-60/22 (4 May 2023) that a missing record does not by itself make processing unlawful. The gap is an infringement in its own right, but it does not destroy your lawful basis.

    The record of processing is not required of everyone, but of nearly everyone

    The previous version of this article said the record of processing activities is mandatory for all companies. That is not correct. Article 30(5) exempts enterprises and organisations employing fewer than 250 persons. The exemption falls away if the processing is likely to result in a risk to individuals' rights, if it is not occasional, or if it includes special category data under Article 9(1) or criminal offence data under Article 10.

    In practice the exemption rarely helps. Payroll is not occasional, and HR files often contain health data. The Article 29 Working Party made this point in its position paper on Article 30(5), now published on the EDPB website. It uses employee data as the example of processing that "cannot be considered occasional". The same paper adds a useful nuance: an organisation under 250 employees only needs to record the processing activities that trigger one of the three conditions, not everything it does.

    Article 30(5) flow: fewer than 250 employees, then risk, occasional and Art. 9/10 checks per activity, ending in record or exempt

    Omnibus IV may move the threshold

    The rule is on its way to changing. On 9 June 2026 the European Parliament and the Council reached a provisional agreement on the Omnibus IV package. It extends the exemption to organisations with fewer than 1,000 employees and narrows the carve-out, so the record keeping duty only returns for processing likely to result in a high risk. The Commission's May 2025 proposal had set the threshold at 750. According to the European Parliament's Legislative Train, the file is "close to adoption": Coreper endorsed the text on 26 June 2026 and the lead Parliament committee approved it on 2 July 2026. At the time of writing (24 September 2026) it has not been formally adopted or published, so the 250 threshold still applies. Omnibus IV is EU legislation and does not change UK GDPR.

    If it is adopted, more mid-sized organisations will be able to limit their record to high-risk processing. It will not remove the accountability duty in Article 5(2), processor contracts under Article 28, the breach log under Article 33(5) or impact assessments under Article 35. And to know which processing is high risk, you still need an overview of all of it. Omnibus IV reduces paperwork. It does not make the tooling decision go away.

    For what the record must contain, see our guide to the record of processing activities.

    The alternatives, and what each one really solves

    There are five ways to carry your GDPR documentation. They are not mutually exclusive, and the most common mistake is to treat them as either-or. An adviser supplies judgement. A tool keeps the documentation in order. Templates supply structure. Those are three different things.

    Alternative What you get What you do not get Price (source)
    GDPR templates Structure and a sound starting point Follow-up, reminders, links between documents Free from the EDPB and national authorities
    Spreadsheet Flexibility and no procurement Change history, access control, links between activities, systems and suppliers Licences you already own plus internal hours
    GDPR consultant or outsourced DPO Expert judgement, independence, capacity at peak times A place where documentation lives once the engagement ends DKK 5,000-30,000 (about EUR 670-4,000) a month excl. VAT at one Danish provider (Compliance Team, checked September 2026)
    Law firm Professional liability for the advice, disputes, complex transfers and regulator cases Day-to-day upkeep of the documentation Usually hourly or fixed fee per matter
    GDPR compliance software One register, assigned owners, reminders, history, reports Legal decisions and ownership inside the organisation From EUR 0. At .legal the Data Protection module is EUR 200 a month excl. VAT (list price, September 2026)

    GDPR templates: better than their reputation

    Official templates have improved. The EDPB's data protection guide for small business walks through the record, security and data subject rights. Under its Helsinki Statement on making compliance easier, the EDPB adopted a DPIA template in April 2026 and a common breach notification template in June 2026, both put out for consultation. Many national authorities publish their own processor contract and record templates. We have gathered the most useful ones in our GDPR template guide.

    A template solves the blank page. It does not solve upkeep. It does not know that marketing has started using a new newsletter tool, and it will not remind anyone that the payroll provider's audit is overdue.

    Spreadsheets: fine for a few, fragile for many

    A spreadsheet is a real option as long as one person owns it and the number of rows stays manageable. Trouble starts when several people edit at once, when the same supplier has to appear in the record, the processor register and the NIS2 risk assessment, and when someone asks who changed what and when. We have a full article on that choice: GDPR in Excel or software.

    GDPR consultant or outsourced DPO: judgement, not operations

    A GDPR consultant can run a gap analysis, draft your policies and quality-check an impact assessment. If you are required to appoint a DPO under Article 37, the role may be filled under a service contract (Article 37(6)), and an external DPO often meets the independence requirement in Article 38 more easily than an internal one. In Case C-453/21 (X-FAB, 9 February 2023) the Court of Justice confirmed that a DPO must not hold other tasks that create a conflict of interest.

    The consultant is not the controller, though. Responsibility for the record, processor contracts and oversight stays with you. When the engagement ends, the documentation has to remain in a form your own people can keep working in. Read more about the role in our article on what a data protection officer is.

    Law firm: when it is legally hard

    A law firm is the right call for high-risk international transfers, joint controllership in complex partnerships, regulator investigations and damages claims. It is rarely the right call for maintaining the record, because hourly billing makes routine updates expensive.

    Grid rating templates, spreadsheet, consultant, law firm and software on judgement, upkeep, collaboration and history

    Decision matrix: when is each option enough?

    The matrix below is our rule of thumb, not a legal test. The figures are the points at which we typically see manual set-ups start to slip. Find the row that fits you best and read the column "Signs you have outgrown it".

    Profile Usually enough Signs you have outgrown it
    One entity, under 50 staff, under 15 processing activities, under 10 processors, no large-scale special category data Authority templates, an annual review in the calendar, perhaps a few hours of advice More than one person edits, customers ask for evidence of processor audits
    One entity, 50-250 staff, 15-40 processing activities, 10-30 processors A spreadsheet with one owner and a fixed update plan, or free software Departments must update their own entries, processor audits fall behind, the same supplier appears in three places
    One entity, 250+ staff or 40+ processing activities or 30+ processors GDPR compliance software with ownership and an annual compliance calendar The question is no longer whether, but which
    Group with several companies or countries Software that reuses documentation at group level and shows it per company Every subsidiary keeps its own copy of the spreadsheet
    Public authority A DPO is mandatory (Art. 37(1)(a)). Software plus DPO, because the DPO has to monitor The DPO spends time finding documents instead of assessing them
    Large-scale special category data (for example health) or systematic monitoring DPO (Art. 37(1)(b) and (c)), impact assessments and software DPIAs live as loose Word files with no link to the record
    In scope of NIS2 One platform for GDPR and cyber security, so suppliers and assets are assessed in one place IT and legal each maintain their own supplier list

    Note that headcount is only one of five factors. A company with 60 staff, 45 processors and three subsidiaries needs a tool more than one with 400 staff that only processes HR data and customer contacts in a single system.

    Radar with five factors (activities, processors, entities, special categories, NIS2) and zones from template to software plus DPO

    How to assess your own need in six steps

    Spend an hour on these six steps before you speak to a vendor or a GDPR consultant. The answers are also what a good vendor will ask you.

    1. Count your processing activities. Not systems but purposes: recruitment, payroll, customer service, newsletters and so on. Under 15 is manageable. Over 40 is a register, not a document.
    2. Count your processors. Go through the supplier list and separate those processing personal data on your behalf from those that do not. Only the former need a processing agreement and oversight.
    3. Map your legal entities. Each company in a group is a separate controller and needs its own record.
    4. Check the DPO duty and special categories. If you are a public authority, or your core activities involve large-scale processing of sensitive data, a DPO is mandatory.
    5. Check NIS2. If you are an essential or important entity, your suppliers also have to be assessed for cyber security.
    6. Count the contributors. Is it one person or ten? The number of contributors is the most underrated factor, because they are the ones who make a spreadsheet go stale.

    If you are under the line on four or more points, templates and a fixed plan are probably enough. If you are over it on three or more, or you are in scope of NIS2, it is time to look at a tool. For what to look for, see our separate article on features in GDPR compliance software.

    NIS2 changes the calculation

    The NIS2 Directive (EU) 2022/2555 sets requirements for cyber security risk management (Article 21), management body accountability (Article 20) and incident reporting with an early warning within 24 hours, a notification within 72 hours and a final report within one month (Article 23). It applies through national law, and transposition has moved at different speeds across member states. Denmark's NIS2 Act, for example, has been in force since 1 July 2025.

    For the GDPR decision, Article 21(2)(d) matters most. It requires supply chain security, which means assessing your suppliers. Many of them are the same processors you already oversee under GDPR. A personal data breach may also be a significant incident under NIS2, in which case it has to be reported under both regimes, each with its own deadline. Suppliers do not fall within NIS2 simply because they supply you, but they feel it through your requirements.

    If legal and IT each maintain their own supplier list in their own spreadsheet, you do the same work twice and risk the lists telling different stories. That is the strongest single argument for software we know of, and it has nothing to do with GDPR alone. Under Article 34, member states must set maximum NIS2 fines of at least EUR 10 million or 2% of worldwide turnover for essential entities and EUR 7 million or 1.4% for important entities. See our introduction to NIS2 for who is in scope.

    Worked example: Harbourline Parcels

    Harbourline Parcels A/S and Freya Lund are fictional. We invented them for this article, and they are neither a customer nor a case study.

    Harbourline Parcels is a Danish parcel and courier company with 180 employees in a single legal entity. As a medium-sized business in postal and courier services it falls under NIS2 as an important entity. It has 38 processing activities and 64 suppliers, 29 of which are processors. Three of those transfer data outside the EEA. Freya Lund is in-house counsel and spends about half her time on compliance. The IT manager owns NIS2.

    Today the record sits in a spreadsheet last reviewed 14 months ago. Processing agreements live in a shared folder. IT keeps its own supplier list for the NIS2 risk assessment, and 22 of the 29 processors appear on both lists. Freya sets out three models for the coming year. The adviser retainers are assumptions within the range one Danish provider publishes, and the software prices are .legal list prices as of September 2026.

    Model Contents External cost per year excl. VAT Freya's concern
    A. Spreadsheet and adviser Current spreadsheet, adviser retainer of EUR 1,000 a month EUR 12,000 Two supplier lists, no history, the adviser spends hours locating facts
    B. Software only Three modules: Data Protection, Vendor Management, Information and Cyber Security (3 x EUR 200 a month) EUR 7,200 No external quality check on the three international transfers
    C. Software and a smaller retainer As B plus an adviser retainer of EUR 700 a month EUR 15,600 The highest external cost

    Freya chooses model C, even though it costs the most on paper. Her reason is not that software saves a particular number of hours. It is that the 22 suppliers on both lists only need assessing once, that she and the IT manager can work in the same register, and that the adviser can be given access to the platform and spend the retainer on the three international transfers rather than on gathering facts. She also expects the smaller retainer to be workable precisely because the documentation is in order.

    Had Harbourline employed 40 people, run 12 processing activities with six processors and sat outside NIS2, Freya would have picked the authority templates, an annual review and a few hours of advice a year. The point of the example is that size does not decide it. The number of places the same fact has to be kept current does.

    Venn diagram for fictional Harbourline Parcels: 7 processors only on the GDPR list, 22 suppliers on both GDPR and NIS2 lists

    What GDPR compliance software does not solve

    This is where most vendor articles go quiet. Here are the limitations worth knowing before you buy.

    • Software does not make legal decisions. A tool can suggest a lawful basis from a template, but you are the one standing behind it.
    • Software does not replace a DPO. If a DPO is mandatory, it still is. A tool can make monitoring easier, not unnecessary.
    • Output depends on input. A record in a system is no more accurate than what departments have entered. Without an owner and a review rhythm, software becomes an expensive spreadsheet.
    • Implementation takes time. Expect the first pass through the record and your processors to take weeks rather than days, even with templates.
    • The vendor is your processor. The software holds personal data about your staff and supplier contacts, so you need an Article 28 agreement with the vendor and should know where the data is hosted.
    • Check the exit. Ask whether you can export the full documentation in a usable format if you switch.

    If you have reached the stage of comparing specific products, our guide to buying GDPR compliance software covers the procurement process in depth.

    How .legal supports the decision

    We would rather you chose well than quickly. That is why the .legal platform is free to use on the Free plan with unlimited users, so you can load your own processing activities and processors and see whether a tool actually adds anything before you pay. Modules cost EUR 200 a month each with no lock-in, priced per organisation rather than per user. See current pricing.

    The Data Protection module covers the record with templates for areas such as HR, marketing and finance, a register of processors and sub-processors, processing agreements, risk assessments, a DPIA template and a breach log. With Vendor Management you audit processors and assess the same suppliers for NIS2 in a single register. Partner access lets your GDPR consultant, law firm or outsourced DPO work directly in your documentation, so advice and tooling stop being a choice between two things.

    If you want to see how your own row in the matrix looks in the platform, book a demo.

    Frequently Asked Questions About GDPR Software

    Is GDPR compliance software a legal requirement?

    No. GDPR is technology neutral and never mentions software. It requires you to demonstrate compliance under Article 5(2) and to keep your record of processing in writing, which may be electronic. Whether that lives in a spreadsheet, a document or a dedicated system is your choice. A supervisory authority looks at whether the content is complete and current, not at the tool behind it.

    How much does a GDPR consultant or outsourced DPO cost?

    Prices vary widely with scope and hours. As one reference point, the Danish provider Compliance Team publishes a range of DKK 5,000 to 30,000 a month excluding VAT, roughly EUR 670 to 4,000, for DPO as a service on one-year contracts (checked September 2026). One-off work such as a gap analysis or a DPIA review is usually priced per task or per hour, so ask for a written quote with hours.

    Can a GDPR template be enough on its own?

    Yes, for a small organisation with one entity and only a few processors. The EDPB and national authorities publish free templates, and in 2026 the EDPB adopted templates for impact assessments and breach notifications. A template gives you a correct starting point, but it will not prompt anyone to update it, so pair it with a fixed review date and a named owner.

    What is the best GDPR compliance software?

    There is no single best product, only the one that fits your profile. A group needs documentation across companies, a public authority needs traceability and access control, and an organisation in scope of NIS2 needs a shared supplier register. Test with your own data on a free plan or trial, and check export options, the vendor's processing agreement and where data is hosted.

    Do organisations with fewer than 250 employees need a record of processing?

    Usually yes, at least for part of their processing. The Article 30(5) exemption falls away when processing is not occasional, is likely to result in a risk or includes special category or criminal offence data. Payroll and HR almost always meet one of those conditions. The Article 29 Working Party confirmed that the record then only has to cover the activities concerned.

    How will Omnibus IV change the record of processing duty?

    The provisional agreement of 9 June 2026 extends the exemption to organisations with fewer than 1,000 employees and limits their record keeping duty to processing likely to result in a high risk. As of 24 September 2026 it had not been formally adopted, so the 250 threshold still applies. Accountability, processor contracts, the breach log and impact assessments are unaffected, and UK GDPR is not changed.

    Can an outsourced DPO replace GDPR software?

    They do different jobs. An outsourced DPO advises, monitors compliance and acts as contact point for the authority and individuals under Article 39. Software is where the documentation lives and gets followed up. The record and processor contracts remain the controller's responsibility, not the DPO's. Many organisations use both and give the DPO access to the platform, so paid hours go on assessment.

    When is a spreadsheet no longer enough for GDPR?

    Typical signs are several departments editing the same sheet, the same supplier appearing on multiple tabs, nobody being able to see who changed what, and processor audits slipping behind schedule. When you cannot answer a customer's question about processor oversight without searching folders and inboxes, the spreadsheet has become a risk rather than a tool.

    Do we need a data processing agreement with our GDPR software vendor?

    In most cases, yes. The system will hold personal data about your staff, supplier contacts and often breaches and data subject requests. The vendor processes that data on your behalf and is therefore a processor under Article 28. Also ask where data is hosted, which sub-processors are used and whether any data is transferred outside the EEA.

    Can the same software cover both GDPR and NIS2?

    Yes, and that is often the biggest gain. NIS2 Article 21(2)(d) requires supply chain security, and many of the suppliers you must assess are the same processors you already oversee under GDPR. A platform that holds suppliers, assets and risk assessments together lets legal and IT work in one register instead of maintaining two lists that drift apart.

    Still unsure?

    Ask Johannes directly, he runs most demos personally

    Book him here
    Processing activities

    .legal compliance platform

    See Why Organizations Choose .legal for GDPR Compliance

    • Replace spreadsheets with automated compliance workflows
    • Save hundreds of hours annually on compliance tasks
    • Always audit-ready with comprehensive documentation
    • Affordable plans for organizations of all sizes
    • Free trial to experience the value firsthand
    +400 companies use .legal
    Region Sjælland
    Aarhus Universitet
    aj_vaccines_logo
    Realdania
    Right People
    IO Gates
    PLO
    Finans Danmark
    geia-food
    Evida
    Klasselotteriet
    NRGI1
    BLUE WATER SHIPPING
    Karnov
    Ingvard Christensen
    VP Securities
    AH Industries
    Lægeforeningen
    InMobile
    AK Nygart
    DEIF
    DMJX
    Axel logo
    qUINT Logo
    KAUFMANN (1)
    SMILfonden-logo
    kurhotel_skodsborg
    nemlig.com
    Molecule Consultancy
    Novicell