GDPR Compliance,
done right.
A complete, multi-tenant GDPR compliance platform. Manage data subjects, consent, subject access requests, breach reports, RoPA registers, DPIAs, vendor registers, and audit trails — all in one place, with mandatory 2FA and your data stored in the region you choose.
No credit card required · 14-day free trial · Cancel anytime
Everything you need for GDPR compliance
Built around the specific requirements of GDPR Articles 5–34 so you never have to guess what's needed.
Data Subject Management
Register and manage data subjects, handle deletion and anonymisation requests, and maintain a searchable subject registry.
Consent Management
Track granular consent per purpose (analytics, marketing, third-party). Grant, revoke, and view full consent history with IP and timestamp.
Subject Access Requests
Manage all Articles 15–22 rights requests with 30-day deadline tracking. Assign, complete, and close requests with a full audit trail.
Breach Management
Report and track data breaches with 72-hour ICO notification deadline monitoring. Severity levels, status tracking, and authority reporting.
Immutable Audit Logs
Every action is recorded in a tamper-evident log with user, timestamp, IP address, and entity details. Filter by date range and action type.
Data Catalogue
Define and manage personal data categories with sensitivity levels, legal basis, and retention periods. Covers special category data (Art. 9).
Records of Processing Activities
Maintain a complete Article 30 register of all processing activities, including controller details, data categories, international transfers, and legal basis. Export a full PDF report on demand.
Data Protection Impact Assessments
A guided 5-step DPIA workflow covering Article 35 screening criteria, risk identification and scoring (1–25 matrix), mitigation planning, and DPO consultation — with PDF export and approval workflow.
Vendor & Processor Register
Track all third-party data processors under Article 28. Monitor DPA status, expiry dates, risk levels, and processing countries. Automated alerts for expired or high-risk processors.
Your data stays in your region
Each tenant gets a fully isolated database. Choose the region that matches your regulatory obligations — we never move your data across borders.
EU West
Covers GDPR obligations for EU-based organisations
UK South
UK GDPR compliant, post-Brexit data residency
More Coming
US, APAC, and additional EU zones planned
Every API response includes an X-Data-Region header
so you can verify where your data is processed.
Simple, transparent pricing
GDPR compliance for every organisation size. No hidden fees. Cancel anytime.
Free Trial
Evaluate risk-free for 14 days
14-day free trial
- 25 data subjects
- 5 DSARs / month
- 1 admin user
- All compliance modules
- 30-day audit retention
- No exports or PDF reports
- No deadline alerts
Starter
Freelancers & micro-businesses
per month, billed annually
- 500 data subjects
- 25 DSARs / month
- 3 admin users
- 1 API key
- CSV export & ROPA PDF
- Email deadline alerts
- 90-day audit retention
- No DPIA module
Professional
SMBs & growing SaaS
per month, billed annually
- 5,000 data subjects
- 100 DSARs / month
- 10 admin users · 5 API keys
- CSV + Excel export
- ROPA + DPIA PDF reports
- Vendor Register (25 vendors)
- 1-year audit retention
Business
Mid-market & regulated industries
per month, billed annually
- 25,000 data subjects
- Unlimited DSARs
- 25 admin users · 20 API keys
- All exports & PDF reports
- Unlimited DPIAs & vendors
- Priority support
- 2-year audit retention
Enterprise
Large organisations & multi-entity DPOs
per month, billed annually
- Unlimited everything
- Dedicated database instance
- Custom data regions
- SSO / SAML (roadmap)
- 99.9% SLA guarantee
- Priority support with onboarding call
- White-label option (roadmap)
Ready to simplify your compliance?
Join hundreds of organisations already using DataShield HQ. Setup takes under 5 minutes.
Create Your Free AccountNo credit card required · 14-day free trial