Compliance software, consulting or do-it-yourself
The duties are the same however you organise them: deadlines run, instruction sessions fall due, evidence gets requested. What differs is only where the work happens. In practice there are three routes — software, a consulting engagement, or a home-built arrangement of spreadsheets, folders and calendar entries. All three work under certain conditions and all three have clear limits. This page names both sides, including the points where software such as CIVAC is not enough.
Three models compared
| Criterion | Compliance software | Consulting engagement | Do-it-yourself in Excel |
|---|---|---|---|
| What you acquire | A tool with built-in routines, templates and deadline logic. The expertise comes from your officers. | Time and expertise from people who assess the situation and make recommendations. | Nothing you do not already have. The effort sits in building and maintaining it. |
| Who does the work | Your people — but guided: tasks are assigned, dated and set up to recur. | Mostly the consultant, within the agreed scope. Implementation on the ground usually stays with you. | Your people, unguided. The structure is only as good as whoever last maintained the file. |
| Multiple officer roles | One data model for all roles; tasks, trainings, audits and documents follow the same logic. Further roles are added individually. | Engagements are awarded per subject area. Several roles usually mean several contacts and separate reports. | One file per role, with its own conventions and its own storage. Reconciling them is manual work. |
| Deadlines | Recurring cycles with an owner, escalation and history; deadlines such as the 72 hours under Art. 33 GDPR run as a monitored item. | Monitored within the engagement as agreed. Internal deadlines remain your responsibility. | Calendar entries and reminders. Works as long as the person who set them is still there. |
| Evidence in an audit | Generated from day-to-day operation: completed tasks, attendance, audit findings and documents feed an export-ready report. | Reports and opinions from the engagement; evidence of implementation on the ground comes from your side. | Assembled before the inspection. A patchy history becomes visible at exactly that moment. |
| Assessment of an individual case | Limited. Templates and checks structure the question and supply sources; the assessment is made by your designated person. | Core service. That is what an engagement is for, especially where matters are unsettled or contested. | Absent. A spreadsheet knows no law. |
| Cost structure | A running price per role per month — with CIVAC, EUR 49 and publicly stated. Predictable and independent of workload. | A fee by time spent or a flat rate with a defined scope; additional work is usually agreed separately. | Apparently free. The cost sits in working time and in whatever has to be reconstructed when an inspection comes. |
| Retaining knowledge | In the system: history, templates and ownership survive a change of staff. | With the provider. When the engagement ends, what matters is what the contract requires to be handed over. | In people's heads and in the file share. A departure regularly costs most of it. |
| Time to start | Short: create an account, pick a role, start from templates. | Medium: selection, contract, familiarisation with your processes. | Long and never finished — the structure keeps growing with every edge case. |
About these statements: This page is for orientation and is not legal advice. It compares organisational models in general rather than the offerings of particular providers; statements about consulting engagements describe the category, not any individual company. The legal position is as at the time of writing (August 2026) and may have changed. Which combination suits your organisation depends on your duties, your size and your people.
What software actually delivers
The value of compliance software lies not in knowing something but in not forgetting it. Recurring duties are set up as cycles and come back by themselves. Tasks have an owner and a date, not just a recipient in an email. Trainings run with attendance tracking instead of somebody chasing inboxes. Audit findings stay attached to their photo, criterion and corrective action. And documentation emerges as a by-product of the work rather than as a scramble before an inspection.
The second effect is comparability across roles. When data protection, occupational safety, fire safety and anti-money-laundering all use the same task, training and audit logic, management sees a single status for the first time instead of four reporting formats. That is what CIVAC is designed for: 77 officer roles in one data model, 905 templates, one monthly report.
Where software is not enough
There are limits, and knowing them is part of an honest decision. First: software does not assess a contested individual case. Whether a legitimate-interests balancing under Art. 6(1)(f) GDPR holds, whether a processing operation triggers an impact assessment under Art. 35 GDPR, how to respond to a fine notice — those are judgements made by qualified people. Second: software does not represent you. Before a supervisory authority, an accident insurance institution or a court you need people, and legal advice may in any case only be given by those authorised to give it.
Third: software does not substitute for an appointment. Where the law requires a named person — Art. 37 GDPR, the Occupational Safety Act, sec. 7 GwG and many more — no tool gets you past the duty. Fourth, and practically the most important: software structures a process, it does not invent one. Where it is entirely unclear who owns which processing, which installations are affected and which duties apply at all, a consulting engagement is the faster route to that clarity — and the software is then the place where the result stays alive.
Why the do-it-yourself route survives so long
Spreadsheets are the most honest competitor, because at the start they genuinely work. They cost nothing, they are there immediately and they bend to every edge case. Things get difficult at three points: at the second role, because every file develops its own logic; at a change of staff, because the structure lives in the head of whoever built it; and at an inspection, because a spreadsheet shows today's state but does not evidence who did what and when.
That history is exactly what inspectors ask for. Accountability under Art. 5(2) GDPR requires not just a tidy state but evidence that it came about properly. Moving off the do-it-yourself route therefore rarely pays off for convenience; it pays off for traceability — and the best moment is before the first inspection, not after it.
When each model fits
Software fits when …
- the roles are filled internally and the duties are settled in principle.
- several officer roles exist in-house or will be added soon.
- recurring deadlines, instruction sessions and evidence make up most of the work.
- an inspection is coming and the history has to hold up.
- knowledge should survive a change of staff.
Consulting fits when …
- it is unclear which duties apply at all and who owns them.
- a contested or unsettled individual case has to be assessed.
- a project such as a certification or an impact assessment needs expert support.
- an authority, a customer or a court expects a professional opinion.
- nobody internally has the expertise and building it would be disproportionate.
Do-it-yourself is enough when …
- exactly one role is involved and the scope stays manageable.
- there is no appointment duty and no external inspection ahead.
- one person holds the structure and a named deputy exists.
- the file storage is versioned in an audit-proof way anyway.
- the effort for upkeep and rework is knowingly budgeted for.
Frequently asked
- Does compliance software replace a consultant?
- No, it shifts the division of labour. Software takes over the recurring part: deadlines, ownership, training evidence, audit findings, documentation. What it does not take over is assessing a contested individual case, representing you before authorities or courts, and legal advice, which in any case only authorised persons may give. In practice the need for advice on routine questions drops considerably while it remains for the hard cases — and there it is well spent. CIVAC reflects that: delicate cases can be escalated from the workspace to an external law firm.
- Is a spreadsheet enough for a record of processing activities?
- Formally yes: Art. 30 GDPR requires the record in writing, which includes electronic form, and prescribes no tool. In practice a spreadsheet hits limits in three places. It shows today's state but not the history — who changed what and when, which is precisely what accountability under Art. 5(2) GDPR is meant to make visible. It does not link the record to tasks, retention periods and processors, so reconciliation stays manual. And it scales badly as soon as further officer roles arrive with files of their own.
- When should you move off the do-it-yourself route?
- Three triggers are typical. First, the second officer role: from then on competing conventions appear and reconciliation eats more time than the work itself. Second, a change of staff: when the person who built the structure leaves, the structure leaves with them. Third, the first announced inspection — supervisory authority, accident insurance institution, certification audit or customer audit. Moving is cheapest before the third trigger, because a history cannot be created retrospectively; back-filled evidence is exactly what stands out in an inspection.
- What does the do-it-yourself route really cost?
- It costs no licence, but working time in an expensive place. The effort sits in building the structure, chasing deadlines by calendar and email, assembling evidence before every inspection, rebuilding after a change of staff, and reworking whatever an inspection shows to be missing. None of those appear in a budget, but all of them are real. An honest comparison sets them against a running price per role — with CIVAC, EUR 49 per officer role per month.
- Can software and consulting run alongside each other?
- That is in fact the normal case. The consulting clarifies which duties apply, how a situation should be assessed and how a project should be set up; the software then keeps the result alive — with deadlines, ownership and evidence. It makes sense to give the consultant access to the workspace so findings become tasks directly instead of ending in a report. In that case, settle roles, access rights and the data processing agreement before the access is granted.
- Where does CIVAC expressly not help?
- With anything that requires an appointed person or a legal assessment. CIVAC does not decide a legitimate-interests balancing, does not produce a binding statement to a supervisory authority, does not represent you in any proceeding, and does not substitute for a legally required appointment under Art. 37 GDPR, the Occupational Safety Act or sec. 7 GwG. Where responsibilities inside the company are still entirely unsettled, expert clarification comes first — software structures a process, it does not invent one.