Most SMEs start GDPR in spreadsheets and outgrow them fast - a ROPA in one file, DPAs in an inbox, TOM in a slide deck, nothing connected. GDPR compliance software exists to pull those into one workflow that stays current. This guide covers what to look for, the features that are noise rather than signal, and the questions that separate a genuine privacy management platform from a template library with a login. For the wider context, see the GDPR compliance checklist pillar.
- The point of the software is connection: ROPA, privacy notice, TOM, DPA and DPIA in one place that flags what's out of date.
- Watch for "template packs with a login" - static files behind a dashboard aren't a compliance system.
- For most SMEs, integrated GDPR + AI Act coverage and a review path matter more than feature count.
What Should GDPR Compliance Software Do?
Which features actually matter?
| Capability | Why it matters |
|---|---|
| ROPA builder | The master record everything connects to |
| Linked TOM and DPA tracking | Security and vendor evidence tied to each process |
| DPIA workflow | Triggered automatically for high-risk processing |
| Review reminders | Documentation decays without scheduled prompts |
| Privacy notice generation | Generated from the ROPA, not a blank page |
| Audit export | Produce the pack on a short deadline |
The single most useful behaviour is the system telling you what's stale - a ROPA entry that hasn't been reviewed, a missing DPA, a DPIA that's overdue. Static documentation can't do that.
What to Avoid
How do I spot a weak tool?
- Template packs with a login. If it's just downloadable files behind a dashboard, it's not a compliance system.
- No review triggers. A tool that lets documentation silently age out adds little over a spreadsheet.
- GDPR only, no AI Act. If your team uses AI tools, you have EU AI Act obligations too - separate tools produce records that don't reconcile.
- No expert review path. Software documents; it doesn't sign off. For YMYL legal exposure, a route to a certified DPO matters.
How a Connected Platform Works
What does "one workflow" look like in practice?
You create a processing entry once; the platform checks whether a DPA is missing and whether a DPIA is required, references the applicable TOM, and reflects it in the privacy notice. Change the entry and it raises a review task. This is what keeps documentation audit-ready without manual tracking.
See how ETHYX connects ROPA, TOM, DPA and DPIA
Where ETHYX Fits
What does ETHYX add beyond documentation?
ETHYX is a GDPR documentation platform built for SMEs, with EU AI Act deployer coverage in the same workflow and a certified external DPO (CIPP/E) who reviews and signs off where your plan calls for it. Pricing starts at €149/month for the self-serve platform; the Expert plan at €299/month adds the named DPO. It replaces the spreadsheet sprawl, not just the storage.