77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
All comparisons
Provider comparison

CIVAC and DataGuard compared

Both offerings address the same problem: a company has duties that attach to an appointed person, and needs structure and evidence for them. They approach it from different directions. DataGuard publicly describes itself as security and compliance software with experts in the loop, and offers the external data protection officer and external information security officer as services. CIVAC is a workspace for the officers themselves — across every mandatory officer role, at a publicly stated price per role. This page sets out the differences so you can see which category fits your situation.

Criteria at a glance

CriterionCIVACDataGuard
CategoryA software workspace for appointed officers. The substantive work stays with your people; having us supply an officer is a separately engaged service.The provider publicly describes its offering as security and compliance software with experts in the loop — platform and personal support are marketed together.
Officer roles covered77 officer roles in the data model — from data protection and information security through occupational safety, fire safety and hazardous substances to immission control, dangerous goods and radiation protection. Version 1 is instantiated for the data protection officer.The public solution overview lists data protection, information security, whistleblower protection and adjacent frameworks such as ISO/IEC 27001, NIS2, TISAX and the EU AI Act. Roles from occupational, fire or environmental safety are not listed there (as of August 2026).
Pricing modelEUR 49 per officer role per month, publicly stated. Each further role is added individually; officers we supply are priced individually.Tiered subscription levels from a self-service package to an enterprise package. The pricing page states no figures; the provider points to an individual quote depending on company size, industry and scope, and additionally names a one-off audit fee.
Operating modelDefault is self-operation: your own appointed officers work in the workspace. Optionally we supply certified officers from our team and partner network who run the same platform for you.The provider lists the external data protection officer and the external information security officer as distinct services and describes dedicated contacts for higher tiers.
Getting startedCreate an account, pick a role, start working. No sales call in front of it.The route stated on the pricing page is a quote request; for the self-service tier a product entry point is described in addition.
Data residencyProcessing and storage exclusively in the EU (Google Cloud Frankfurt region). Sub-processors, encryption and the deletion concept are disclosed in our trust centre.Storage location, sub-processors and the provider's own certifications should — as with any vendor — be checked in the Art. 28 GDPR data processing agreement. We make no statements about third parties here.
Use of AIFive checks covering website, applicable duties and audit readiness run on hosted models in our own infrastructure, not through a public chat account. Every answer carries a source reference and a stated confidence; customer data is not used to train models.The provider publicly describes its product as AI-supported automation with experts in the loop. Details on models and processing should be requested from the provider.
Evidence trailTasks, trainings, audits and documentation share one data model. A monthly routine consolidates completed items into an export-ready compliance report; 905 templates are included.The provider describes modules for, among others, records of processing, data subject requests, breaches, risks and controls, third-party risk and training.
Stated target groupCompanies that fill more than one officer role in-house and want a shared workplace rather than a separate silo per role.The offering is publicly segmented into small and medium-sized enterprises and corporates.

About these statements: All statements about third parties rest on publicly available information published by the respective provider at the time this page was written (August 2026) and may have changed since. We compare only characteristics that can be verified from such sources; where we lacked evidence, we describe the category rather than the individual company. We deliberately do not quote third-party prices — the provider's current price list always governs. Trade and company names mentioned belong to their respective owners; they are named for identification only.

Two categories, not two variants of the same product

The most important point in this comparison is not a row in the table but the category. An offering that markets software and personal support together is fundamentally selling relief: you hand a task over and someone else carries it. A workspace sells structure: the task stays with you, but it is ordered, scheduled and evidenced. Both are legitimate, and which is better cannot be answered in the abstract — only against your situation.

In practice it usually turns on whether the role is already filled internally. If there is an appointed person in the house, an advisory component pays for capability you already hold. If there is none and none should be built, a provider with a service component is the shorter route. CIVAC covers both cases but keeps them apart: the licence for your team at the stated monthly price, and the supply of an officer as a separate engagement.

Why role coverage is the hardest difference

Data protection is rarely a company's only appointment duty. Above certain thresholds the occupational safety specialist and the occupational physician follow from the Occupational Safety Act, safety representatives from sec. 22 SGB VII, and — depending on installations and activities — fire safety, hazardous substances, dangerous goods, immission control, waste, water protection or radiation protection, plus anti-money-laundering under sec. 7 GwG and the internal reporting channel under the Whistleblower Protection Act. All of these produce the same kind of work: recurring deadlines, instruction sessions, inspections, documentation.

Providers whose publicly described portfolio sits in data protection, information security and whistleblower protection do not cover that work for the remaining roles — not out of a shortcoming, but because they serve a different domain. A company with several roles filled then ends up with one specialist tool per role and its evidence scattered across separate repositories again. That is exactly where CIVAC starts: one data model with 77 roles, shared task, training and audit logic, one evidence trail.

What this comparison does not answer

We only compare what can be verified from publicly available sources. On storage location, sub-processors, the other provider's own certifications, contract terms and actual prices we deliberately make no statement — partly because such details go stale quickly, partly because they were not publicly retrievable at the time of writing. Ask these points directly during your selection process and have them written into the contract.

Nor do we assess the substantive quality of another provider's advice. That could not be verified objectively and therefore does not belong on a comparison page. What you can compare instead: which roles are covered, how transparent the price is, whether you can start without a sales call, and whether the result is evidence an inspector will accept.

When each model fits

CIVAC fits when …

  • you have — or will soon have — more than one officer role in-house and do not want a silo per role.
  • the roles are filled internally and you need structure, deadline monitoring and evidence rather than the role itself.
  • you prefer a stated price per role with monthly cancellation over an individually negotiated package.
  • you want to start without a sales call and test the software against your own tasks.
  • evidence across tasks, trainings, audits and documentation should come from a single source.

An offering with an advisory component fits when …

  • your need is clearly confined to data protection and information security and should go deep there.
  • you want to place the role outside the company rather than build it internally — including responsibility for the ongoing work.
  • you expect substantive support with certification projects such as ISO/IEC 27001 or TISAX.
  • your company prefers an individually scoped package with a dedicated contact over a list price.
  • there is no internal person who could or should take on the duties.

Frequently asked

Is CIVAC an alternative to DataGuard?
Only partly, and that is the honest answer. If you are looking for software your appointed officers work in, the two are comparable. If instead you want to place the role of data protection or information security officer entirely outside the company, you are comparing a service with a product. CIVAC does supply officers as well, but as a separate engagement alongside the licence. The real difference is breadth: CIVAC is built for every mandatory officer role, not for data protection and information security alone.
Why do you not quote the other provider's prices?
For two reasons. First, third-party prices change; a figure that is correct today becomes an untrue statement in six months, and comparative advertising with untrue statements is unlawful. Second, this provider's prices are not publicly stated as figures but determined in a quote — any number from us would be a guess. So we describe only the shape of the model: tiered subscription levels, a quote based on company size and scope. Our own price we do state concretely: EUR 49 per officer role per month.
Does DataGuard cover occupational safety or fire safety?
In the provider's publicly visible solution overview at the time this page was written, data protection, information security, whistleblower protection and adjacent frameworks were listed; roles from occupational, fire or environmental safety were not named there. That is an observation on a given date, not proof of the opposite — portfolios change. Check the current position with the provider directly. For CIVAC: the data model covers 77 officer roles, version 1 is instantiated for the data protection officer, and further roles follow the same pattern.
What exactly does 'EUR 49 per role per month' mean?
The price applies per active officer role in your workspace, not per user and not per company. An organisation with one data protection officer pays for one role; if information security is added later, that role is booked individually. All 905 templates plus tasks, trainings, audits, documentation and the checks are included. Officers we supply are priced individually, because effort and responsibility differ by role and by company.
Where is my data stored with CIVAC?
Exclusively in the EU. Production systems run in the Google Cloud Frankfurt region; sub-processors, encryption, retention and the deletion concept are disclosed in our trust centre. Data leaves the European Economic Area only under a permitted transfer mechanism per Art. 46 GDPR. Customer data is not used to train AI models, and prompts, documents and answers are never shared between tenants. We make no statement about other providers' arrangements — have them put in writing in the Art. 28 GDPR data processing agreement.
Can I use both in parallel?
Yes, and it happens in practice. Companies keep a specialised data protection service and use CIVAC for the remaining officer roles — occupational safety, fire safety, hazardous substances, anti-money-laundering, the internal reporting channel — because no specialist tool exists there or because several silos should be consolidated. Evidence for those roles then lives in CIVAC while the data protection role stays external. Conversely, an existing data protection role can be moved into CIVAC at any time once you fill it internally.