Overview
Responsum BV builds software for privacy, security and compliance management from Excelsiorlaan 43 in Zaventem. The modular platform covers records of processing activities, data protection impact assessments, legitimate interest assessments, transfer impact assessments, data subject requests, incident and breach management, cookie management, vendor assessments, risk management, an information security management system, e-learning and phishing simulations. Supported frameworks include GDPR, UK GDPR, ISO 27001, NIST, NIS2, DORA, PDPA and PDPL, with separate tooling for the EU AI Act. Customers named by the company include Grant Thornton, Swedbank, Colruyt Group, Brussels Airport Company, DocMorris, Kinepolis, BP, Doccle and Radisson Blu. In September 2021 Volta Ventures put in 1 million euros in a round that could be extended to 2.5 million euros, after a 486,000 euro Vlaio grant and a 350,000 euro PMV loan; more than 70 companies were using the platform at that point. Effective 1 March 2024 Responsum took over the GDPR services division of RealCGR. Responsum BV was one of the 50 nominees in Deloitte Belgium's 2025 Technology Fast 50.
Funding history
- Pre-2021 public funding: 486,000 EUR Vlaio grant and a 350,000 EUR PMV loan
- 2021 growth round: 1M EUR from Volta Ventures, announced 30 September 2021, with the round extendable to 2.5M EUR; Koen De Waele of Volta Ventures and business angel Catalina Daniels joined the board
Stated facts & numbers
- Founded: 2020
- Headquarters: Excelsiorlaan 43, 1930 Zaventem
- Legal name: RESPONSUM BV
- Employees: 11-50
- CEO: Alex Van Cauwenbergh, co-founder, CEO since November 2021
- Co-founder: Bavo Van den Heuvel, Chief Knowledge Officer
- Origin: Spin-off of privacy consultancy CRANIUM
- Product: Modular SaaS platform for privacy, security, risk and AI governance
- Frameworks: GDPR, UK GDPR, ISO 27001, NIST, NIS2, DORA, PDPA, PDPL, EU AI Act
- Customers: Grant Thornton, Swedbank, Colruyt Group, Brussels Airport Company, DocMorris, Kinepolis, BP, Novotel, Paramount
- Acquisition: GDPR services division of RealCGR, effective 1 March 2024
- Investor: Volta Ventures
- Certification: ISO 27001
- Recognition: Nominee, Deloitte Belgium Technology Fast 50 2025
Key people
In the news
- Privacy work piles up fast: RoPAs, DPIAs, vendor reviews... all in different files. It doesn't have to feel like that. Responsum brings it into one place, so your team spends less time hunting for information and more time actually protecting it. Learn more at www.responsum.eu.
- Nordic Privacy Arena 2026 is just around the corner: https://lnkd.in/eUk3Jgmn This year's theme "Innovation and Compliance in the Era of Cloud, AI and Geopolitical Uncertainty" is exactly where privacy teams are focused right now. We're looking forward to hearing from speakers including Max Schrems, Trevor Hughes, and DPA leaders from Sweden, Estonia, and Lithuania. If you're heading to Stockholm on 28–29 September, let's connect there.
- Our September newsletter is live! 🤗 This issue covers a new eBook on being a DPO in a complex organization, how Responsum fits the way the automotive industry actually works, a customer spotlight on Fintraffic, and a video look at what really makes a privacy management tool the right one. And... we're also heading to Nordic Privacy Arena 2026 in Stockholm from 28 to 29 September!
- In case you hadn't heard: we're sponsoring and exhibiting Nordic Privacy Arena 2026 in Stockholm, taking place 28–29 September! 👉https://lnkd.in/eUk3Jgmn This year's theme "Innovation and Compliance in the Era of Cloud, AI and Geopolitical Uncertainty" couldn't be more timely, with speakers including Max Schrems, Trevor Hughes, and DPA leaders from Sweden, Estonia, and Lithuania. In case you're attending as well, make sure to swing by the Responsum booth! We'd love to connect and talk about where privacy is headed.
- Not every data subject request needs to land on the DPO's desk. In hospitals for example, when a patient requests access to their medical file, that request doesn't necessarily need to travel to the DPO. Doctors and nursing staff are trained to handle it. They know the process, they know what to share, and they can act on it directly. That's not a workaround, that's simply good governance. So, if you're a DPO in a complex organization, one of the most effective things you can do is deliberately build yourself out of certain
- In a complex organization, you can't be everywhere all at once. So instead, build a network that is. One practical approach shared in this webinar: start with the informal connections that already exist, such as people you know, teams you already collaborate with, and deliberately turn those into a structure that keeps everyone oriented. Not ad hoc conversations when something goes wrong, but rather: monthly touchpoints with key contacts across departments, regular alignment with data stewards, consistent communication with legal
- In a complex organization, everything is a priority. Which in practice means nothing really is... For DPOs navigating that reality, a yearly report is one of the most underrated tools available. A genuine instrument serving two things at once: 1. Accountability: what has the privacy function actually done this year? Where was time spent? What was delivered? In an environment where the DPO's work can be invisible until something goes wrong, having that on paper matters. 2. Direction: what are the priorities for next year?
- Unlike many compliance activities that can be scheduled, prioritized, or pushed to next quarter, DSARs come with a hard legal deadline: one month. While there is a limited right to extend by a further two months, that extension requires a legitimate reason... And no, having a full inbox won't suffice... In complex organizations where requests can get lost between departments, this is where governance really earns its keep. The process needs to work regardless of how the rest of the organization is running at that moment. Watch the
Alumni 2 went on to found or lead
- PDavid Du PreNon-Executive Advisor→Co-Founder & CCO at Warren
Marte GreefsIntern→Co-founder & Sea-EO (Sea Executive Officer) at Go Ocean
Jord GoossensTester→Mede-oprichter at Finit Solutions
Backers
Volta Ventures
Early-stage Belgian VC firm based in Ghent, investing in digital and SaaS companies.
Related profiles
Something wrong or missing? Send an update. Fixed within 24 hours.







