Data Governance Plane · Privacy & Compliance

OneTrust

Privacy, consent and data governance platform for regulatory compliance programmes.

Overview

OneTrust now describes itself as an AI-ready governance platform, connecting privacy, data, AI and technology risk in one system, across six solution families.

Its centre of gravity is consent, privacy programme management and assessment workflow. Discovery is present but was bought in rather than built, through an acquisition in 2020.

The consent stack is its deepest asset, and the numbers explain why: a database of more than 45 million pre-categorised cookies, banners in over 250 languages, and geolocation-aware templates you can A/B test.

Enforcement of consent is practical rather than advisory, with no-code blocking, tag manager integration or script rewriting, plus scanning behind logins and synchronisation across websites, apps and connected TV.

What sets it apart from the other privacy platforms is breadth beyond data. It is the only one here selling third-party and vendor risk, ethics and compliance, and IT risk as first-class products.

It also owns a regulatory research business and an industry questionnaire standard, so its assessment machinery rests on assets its rivals licence or lack.

The newest direction is enforcement rather than documentation. Data Use Governance turns written policy into executable control code, masking columns and filtering rows in real time inside Snowflake and Databricks.

AI governance has followed the same path, with policy management, guardrail enforcement, an SDK for detecting sensitive data in workflows, agent permission governance and policy enforcement for agent protocols.

One published gap worth knowing when comparing: it does not publish an identity graph linking data back to individual people, which both of its main rivals do and which affects how subject requests are fulfilled.

Two facts date older copy badly. Its chief executive changed in early 2026, its founder moving to the board, and its 2023 round was at a lower valuation than 2021.

Key features and capabilities

The same headings are used for every privacy & compliance entry, so two tools can be read side by side.

Finding personal data
  • Continuous detection of data assets across cloud providers, identity services and configuration databases
  • Automated data mapping with generated records of processing and data-flow visualisation
  • Classification technology acquired with Integris in 2020, covering structured and unstructured data
  • AI-driven classification with multi-contextual labelling across business, regulatory and consent context
  • An identity graph linking data to individual people is not published, unlike its two main rivals
Consent and subject rights
  • Two consent products, universal consent and preference management, and a cookie consent platform
  • A database of more than 45 million pre-categorised cookies keeps an evergreen tracker inventory
  • Geolocation-aware, multilingual banners in over 250 languages, with A/B testing of templates
  • Enforcement by no-code blocking, tag manager integration or script rewriting, including behind logins
  • Subject request automation covers intake, identity verification, discovery, deletion, legal hold and redaction
Regulations covered
  • GDPR, CCPA and CPRA named explicitly, plus hundreds of privacy laws and security frameworks
  • AI governance maps to the EU AI Act, the NIST AI risk framework and ISO 42001
  • A regulatory research business supplies same-day updates from in-house experts
  • Security frameworks including ISO 27001, and dozens more through its assurance acquisition
  • Health data compliance appears as a hosting option rather than a named regulatory module
Risk assessment and reporting
  • Privacy, data protection and transfer impact assessments with real-time risk scoring
  • Third-party risk management across the vendor lifecycle, plus automated due diligence screening
  • A risk exchange supplies pre-built analytics on thousands of vendors without sending a questionnaire
  • IT risk management and compliance automation across frameworks and business scopes
  • AI governance generates audit-ready evidence from assessment through to enforcement
Controls and remediation
  • Real-time column masking and row filtering executed through Snowflake and Databricks native controls
  • Purpose-based access control ties access to a stated justification for use
  • Policies become executable control code and machine-readable labels applied at machine speed
  • Guardrail enforcement, an SDK for detecting sensitive data, and agent permission governance
  • Automated redaction in documents and email using language and vision models, and deletion within subject requests
Integrations
  • 112 integrations published across fifteen categories
  • The largest categories are databases and warehouses, collaboration, big data and AI, and analytics
  • Named AI integrations include Amazon Bedrock, Azure AI Foundry, Google Vertex and Databricks Unity Catalog
  • Ticketing through Jira and security through Palo Alto Networks
  • A developer portal with API and SDK references, recipes, a changelog and hands-on labs
Where it runs and what it costs
  • Software as a service only; self-hosted or on-premises deployment is not published
  • A choice of European or United States hosted environments, with cloud hosting across several regions
  • European data residency is a separately purchasable feature, restricted to accounts already hosted there
  • A separate hosting option exists for health data
  • Certifications include ISO 27001, 27017 and 27701, SOC 2 Type II, PCI DSS, HITRUST and TISAX

Pricing

Price on requestQuote only; metering units published

Quote-only, with the metering basis published but no amounts. AI governance, technology risk and third-party management price on administrator users and inventory size; the consent platform prices on average daily visitors across all channels; universal consent prices on total data subject profiles captured. Tiers carry overage handling, with an account manager moving you up a tier if usage persistently exceeds it. Free tools were announced in 2020 but no free edition or trial appears on any current page, and the old cookie scanner URL is now a sales form.

Vendor pricing page →

Demos and videos

About OneTrust

OneTrust was founded in 2016 by Kabir Barday and is based in Atlanta with ten offices and around 2,000 staff. John Heyman became chief executive in early 2026, with Barday remaining on the board as founder, so any copy naming Barday as chief executive is out of date. It is private, having raised over $1bn across five rounds, peaking at a $5.3bn valuation in April 2021 before a $150m round in July 2023 at $4.5bn, a genuine down round. It reports more than half the Fortune 500 as customers, and has made eight acquisitions including Integris, Convercent and Tugboat Logic.

Founded 2016 · Atlanta, Georgia · onetrust.com

Other privacy & compliance tools

BigID

Data Governance Plane · Privacy & Compliance

Data discovery and classification for privacy, security and governance.

  • Commercial

Securiti

Data Governance Plane · Privacy & Compliance

Platform for data security, privacy and governance across clouds and SaaS applications. Veeam acquired Securiti in December 2025, and its releases now read Veeam's Securiti AI.

  • Commercial

Drafted with AI assistance and checked against the vendor’s own documentation.