whats-best.ai
Search Sign in

Data Protection

OneTrust

Rest of world Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: not determined

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by OneTrust LLC · www.onetrust.com

Compare with DataGuard → Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The panel's verdict

OneTrust (OneTrust LLC, Atlanta, USA) is a data protection platform with more than 14,000 customers. Its strongest area is integrations and automation, scored 8 with no spread, resting on a documented developer portal with API families across the modules, more than 500 pre-built plug-ins, SCIM user provisioning and native Swift and Java SDKs. Privacy management follows at 7-8 on a live record of processing fed from assessments and system integrations; rights and incident handling scores 6-7, with requests strongly evidenced and incidents appearing only as record-keeping; audit readiness scores 6-7 on timestamped logs and export APIs. The weak ends are framework coverage at 4-5 — GDPR deep, CCPA named, and we found no public information on UK GDPR or Swiss operation — and sovereignty at 2-3, where judges genuinely split: those at 3 credit the published DPA, SCCs, subprocessor list and Schrems II response; those at 2 weigh the Atlanta entity, FTC enforcement for the Data Privacy Framework and the unanswered residency question. Pricing transparency scored 0; no figures appear on any captured page (not counted here).

Report an error

Speaks for it

  • Integrations and automation earns 8 with no spread, on a documented developer portal with API families across the modules, more than 500 pre-built plug-ins, SCIM user provisioning and native Swift and Java SDKs.
  • A live record of processing, fed from assessments, system integrations and imports and paired with automated DPIA and PIA workflows, underpins privacy management at 7-8.
  • Data subject request handling is evidenced end to end, from portal and API intake through automated identity verification, deletion with legal hold checks and timestamped logging.
  • Exportable evidence includes a deleted-assessment audit log, assessment exports carrying respondents, approvers and risks, and bulk exports of consent and cookie receipts for regulatory reporting.
  • A DPA, SCCs, a subprocessor list and a Schrems II response paper are published on the trust page.

Report an error

Held against it

  • Sovereignty scores 2-3, with the platform held by OneTrust LLC of Atlanta under FTC enforcement for the Data Privacy Framework and no public information on hosting residency or named data centers.
  • Framework coverage stops at 4-5; beyond GDPR and CCPA we found no public information on UK GDPR or Swiss operation.
  • Incident management appears only as streamlined record-keeping, and we found no public information on a 72-hour clock, severity assessment or authority-report output.
  • The published GDPR Transfer Impact Assessment template reaches the application through a documented import-API stop-gap rather than native support.

Report an error

Best for

  • You need to wire privacy operations into a large integration estate and want a documented API surface plus more than 500 pre-built plug-ins.
  • You run a GDPR-centric program with high data subject request volume and need automated intake, identity verification, deletion with legal hold checks and timestamped logs.
  • You want a record of processing that stays current by syncing from assessments and system integrations instead of being retyped.
  • You are preparing for Europrivacy certification and want built-in workflows, templates and documentation.

Report an error

Avoid if

  • Your rules bar a US-jurisdiction processor for the system holding your full processing record, given the Atlanta entity and FTC enforcement for the Data Privacy Framework.
  • Your program must run UK or Swiss regimes alongside GDPR in one record — framework coverage scores 4-5, with GDPR and CCPA evidenced by name.
  • Breach response is your first priority — the captured pages evidence incident record-keeping, and we found no public information on a 72-hour clock or authority-report output.

Report an error

The scores

Records & DPIA depth

Show reasoning
How this is scored

The DSMS core: records of processing (RoPA/VVT), data protection impact assessments, processor/DPA management and TOMs — how deeply the legal artifacts are modeled and connected.

0 — Document templates in a folder tree; the "register" is a Word file with version numbers in the filename.

3 — A structured RoPA with basic fields and a DPIA questionnaire, but processors, TOMs and legal bases live outside the system.

5 — RoPA and DPIA as linked modules with templates; processor management and TOM assignment exist but are shallow, and group reuse is copy-paste.

8 — A connected data model — processing activities linked to systems, processors, TOMs and legal bases — with DPIA triggers derived from the record, reusable group templates, and outputs a supervisory authority accepts.

10 — Privacy records as a system of record: the RoPA drives DPIAs, processor management and TOM coverage from one data model, multi-client/mandate capability included, and the documentation is audit-ready without manual assembly.

Report an error

The External DPO

The live record of processing fed from assessments, system integrations and bulk imports into a central inventory, alongside DPIA/PIA workflows and centralized vendor records carrying DPAs, transfer mechanisms and security obligations, is the connected model I need to run across mandates. We found no public information on reusable group templates or multi-client mandate structures, and the GDPR transfer impact assessment template needs a documented import-API stop-gap rather than native support, so this stops just short of the top. 2 3 10

Report an error

The In-House Counsel

The live record of processing drawing from assessments, system integrations and imports into a central processing inventory, automated DPIA and PIA workflows, and vendor due diligence with a centralized record of data processing agreements and security obligations give me a connected data model I could put in front of a supervisory authority. I found no public information on legal bases tied to activities, on DPIA triggers derived from the record, or on multi-client mandate capability, which is what separates this from a full system of record. 3 2 10

Report an error

The Drafted Generalist

The GDPR materials describe a live processing register built from assessments, system integrations and imports, with automated DPIA and PIA workflows, vendor due diligence and a centralized record of data processing agreements — that is a genuinely connected picture, not form templates in folders. I stopped short of the top because nothing shows technical and organizational measures or legal bases linked to activities, and the developer documentation describes a stop-gap import workaround for the GDPR transfer impact assessment template. 3 10 2

Report an error

The Lead Auditor

A live RoPA built from assessments, system integrations and questionnaire responses into one central processing inventory, with automated DPIA/PIA workflows and vendor records holding DPAs, transfer mechanisms and security obligations, reads as a genuinely connected data model rather than a register in isolation. Two things hold it back: we found no public information on reusable group templates or multi-client mandates, and the one legal artifact I can inspect — the GDPR Transfer Impact Assessment template — reaches the application only through a template-import workaround rather than native support. 3 10 2

Report an error

The IT Integrator

The record of processing is generated live from a central processing inventory fed by assessments, system integrations, questionnaire responses and bulk imports — records that stay current because they sync, exactly the model I run. DPIA and PIA workflows are automated, vendor records centrally hold DPAs, transfer mechanisms and security obligations, and there is a published, versioned GDPR transfer impact assessment template; I stop short of the top because the captured pages show no DPIA triggers derived from the record, no reusable group templates and no multi-client/mandate capability. 3 10

Report an error

The Skeptic

The GDPR pages describe a live record of processing assembled from assessments, system integrations and imports, automated DPIA and PIA workflows, and vendor files holding DPAs, transfer mechanisms and security obligations — a connected model corroborated by assessment launch, approval, archive and template APIs in the developer portal. The same developer documentation, though, describes the published GDPR Transfer Impact Assessment template as not directly addable, requiring a stop-gap import through an API. We found no public information on TOM management, legal bases driving DPIA triggers, or reusable group templates. 3 10

Report an error

Data subject rights & incidents

Show reasoning
How this is scored

The operational half of the DSMS: data subject request handling with statutory clocks, breach register and authority notification, deletion concepts that actually delete.

0 — Requests arrive by email and live there; breaches are a phone call and a memo.

3 — A request log and a breach list exist, but deadlines are manual, intake is unstructured, and deletion rules are documentation rather than workflow.

5 — DSR workflows with the Art. 12 clock tracked, structured breach register with the 72-hour clock, deletion concepts assignable to records; automation is reminders.

8 — Intake channels for requests (portal/form), identity-check support, deadline automation with escalation, breach severity assessment and authority-report output, deletion rules tied to the RoPA with execution tracking.

10 — Rights and incidents as operations: end-to-end request handling an authority audit walks through, breach workflows that produce the Art. 33 notification, and deletion automation with evidence that the deletion happened.

Report an error

The External DPO

Request handling is genuinely operational — portal and API intake, automated identity verification, data discovery, deletion, redaction and legal hold checks, six statutory rights supported, timestamped action logs, and the one-month clock with two-month extension described. Incident management appears only as streamlined record-keeping; we found no public information on a breach register with the 72-hour clock, severity assessment or authority notification output, which for my clients is the half that gets tested in a real breach. 3 7 8

Report an error

The In-House Counsel

The request half is genuinely operational — portal and API intake, automated identity verification, data discovery, deletion, legal-hold checks and redaction with timestamped logging, and the one-month response requirement with two-month extension is stated. But I found no public information on deadline automation with escalation, and nothing beyond the phrase 'streamline incident management' on breach severity assessment, a 72-hour clock, or authority-report output — the notification workflow I most need to see is not evidenced. 3 7 8 2

Report an error

The Drafted Generalist

The request side is strongly evidenced: intake through a secure customer portal, automated identity verification, deletion with legal hold checks and redaction, the one-month deadline with a two-month extension, and timestamped logging of every action — that is the end-to-end workflow I need. The incident half is thin by comparison: the pages say incident management is streamlined and records are kept, but I found no public information on a 72-hour clock, severity assessment, or authority notification output. 7 3 8 2

Report an error

The Lead Auditor

The request half is strongly evidenced: intake through a secure portal and a documented API, automated identity verification, automated discovery, redaction and deletion with legal-hold checks, timestamped logging of every action, and the one-month clock with two-month extension stated. The incident half offers only named incident records and a bullet to streamline incident management — we found no public information on a 72-hour breach clock, severity assessment or authority-report output. 7 3 8

Report an error

The IT Integrator

The rights side is genuinely operational: a public API to submit requests on a data subject's behalf, a secure customer portal for intake, automated identity verification, data discovery, deletion, legal hold checks and redaction, all logged with timestamps against the stated one-month clock with two-month extension. The incident side is thin by comparison — the pages speak of streamlined incident management and maintained records, and we found no public information on a 72-hour breach clock, severity assessment or authority notification output. 2 3 7 8

Report an error

The Skeptic

Rights operations are convincingly evidenced: intake through a secure portal and a documented API, automated identity verification, data retrieval and deletion, legal hold checks and redaction, timestamped logging of every action, and the one-month response window with a two-month extension named. On the incident side the pages offer only "streamline incident management" and an incident management API family — we found no public information on a 72-hour clock, severity assessment, or authority notification output, nor on deletion execution tracked against the processing record. 7 3 8

Report an error

Privacy regime coverage

Show reasoning
How this is scored

Which privacy regimes the product actually operationalizes — GDPR, BDSG, Swiss nDSG, UK GDPR, ePrivacy, EU AI Act privacy duties — and whether one record maps across them or each regime is a fresh island.

0 — One regime, hard-coded; anything else is "on the roadmap".

3 — GDPR plus one national law as separate checklists; the same processing activity is documented once per regime.

5 — The major regimes for its market with partial cross-mapping; newer duties (AI Act, ePrivacy changes) present as content packs of varying depth.

8 — Broad current coverage with one-record-many-regimes mapping and visible maintenance as regimes evolve.

10 — Regime coverage as a living product: multiple privacy regimes on one data basis, per-country variants, and documented update cadence when the law moves.

Report an error

The External DPO

GDPR is deeply operationalized with readiness assessments against the seven principles and a published transfer impact assessment template, CCPA is named throughout, and the Europrivacy partnership adds certification workflows. We found no public information on Swiss nDSG, UK GDPR or BDSG operation, and nothing shows one record mapping across regimes — for my Swiss and UK mandates each regime looks like a separate exercise. 3 7 10 14

Report an error

The In-House Counsel

GDPR is covered deeply — readiness assessments against the seven principles, a Transfer Impact Assessment template published at version nine, and Europrivacy certification preparation as a formal partner — with CCPA named in the request automation. I found no public information on Swiss nDSG, UK GDPR, per-country variants, or one-record-many-regimes mapping, and no documented update cadence beyond that template version number. 3 10 7

Report an error

The Drafted Generalist

GDPR is well served with readiness assessments, Europrivacy certification prep and a transfer impact assessment template, and CCPA appears alongside GDPR for the request portal. Beyond that I found no public information on Swiss or UK privacy law variants, ePrivacy or AI Act duties, and nothing evidences one record mapping across several regimes — so the multi-regime promise stays unproven to me. 3 10 7 2

Report an error

The Lead Auditor

GDPR is deep — readiness aligned to the seven principles, automated DPIA workflows, an official Europrivacy partnership — CCPA is named alongside it, and a separate AI governance line exists; that is the major regimes for the market delivered as content of varying depth. We found no public information on UK GDPR, Swiss nDSG or ePrivacy coverage, per-country variants, a documented update cadence, or one record mapping across regimes. 3 7 2

Report an error

The IT Integrator

The captured pages name GDPR and CCPA support, an official Europrivacy certification-prep partnership with built-in workflows and templates, and a published GDPR transfer impact assessment template with visible version maintenance. We found no public information on BDSG, Swiss nDSG, UK GDPR or AI Act privacy duties, and nothing showing one record mapping across regimes rather than separate content per regime. 3 7 10

Report an error

The Skeptic

GDPR is worked deeply — readiness assessments against the seven principles, a published and versioned transfer impact assessment template, Europrivacy certification preparation — and CCPA appears by name in the DSR portal and global opt-out API, with an AI Governance module in the API catalog. Beyond those, we found no public information on Swiss or German national law, UK GDPR, ePrivacy or AI Act privacy duties being operationalized, and nothing showing one processing record mapping across regimes. 3 10 7 2

Report an error

Audit readiness & evidence

Show reasoning
How this is scored

Whether the system produces defensible proof: revision-safe history, evidence collection, reports for auditors, authorities and management.

0 — Exports are screenshots; history is overwritten in place.

3 — PDF reports exist but evidence is attached ad hoc and changes leave no reliable trail.

5 — Versioned records, standard report generators for the core registers, evidence attachments per activity; assembling a full audit file still takes days.

8 — Revision-safe change history, audit-scoped evidence packs on demand, management and authority reports current at a click, auditor access roles.

10 — Audit readiness as a standing state: continuous documentation status per regime and scope, exportable proof packs an auditor accepts as-is, and a defensible answer to "show me the state on date X".

Report an error

The External DPO

Timestamped DSAR logs, per-individual consent history across any channel, change capture with decisions and approvals, assessment exports carrying respondents, approvers and risks, a deleted-assessment audit log, and bulk exports of data subjects and receipts framed for compliance reporting give me client-ready evidence without manual assembly. We found no public information on auditor access roles or a point-in-time state view, so I cannot yet promise an authority the state of the program on a given date. 3 11 12

Report an error

The In-House Counsel

Change monitoring captures decisions and approvals, deleted assessments keep an exportable audit log, bulk exports of consent and cookie receipts are framed for regulatory reporting, and the platform can produce consent history for any individual across any channel. I found no public information on revision-safe reconstruction of the state on a given date, auditor access roles, or ready-made management and authority reports, so a full audit file still looks like assembly work. 3 11 12

Report an error

The Drafted Generalist

There are real export paths: an assessment export API including respondents, approvers, questions and risks, an audit log endpoint for deleted assessments, and bulk exports of data subjects, consent receipts and cookie receipts positioned for compliance reporting. What I found no public information on is point-in-time reconstruction, auditor access roles, or ready-made authority reports, so audit day still looks like assembly work on my calendar. 11 12 3

Report an error

The Lead Auditor

Timestamped consent receipts, per-individual consent history across channels, captured decisions and approvals, a bulk-export recipe covering data subjects and consent and cookie receipts, and an API that exports the deleted-assessment audit log — this is more than PDFs assembled ad hoc. But we found no public information on revision-safe change history across the registers, audit-scoped evidence packs, auditor access roles, or any answer to showing the state on a given date. 11 12 3

Report an error

The IT Integrator

Every action carries a timestamp, changes in data flows and systems are flagged and routed with decisions and approvals captured, and there are export APIs for assessment detail including a deleted-assessment audit log, plus automated bulk export jobs for compliance reporting on data subjects and consent receipts. What I could not evidence is auditor access roles, audit-scoped evidence packs on demand, or an answer to the state of the record on a given date. 3 11 12

Report an error

The Skeptic

The developer portal carries the strongest proof: an endpoint exporting an audit log of deleted assessments, assessment exports including respondents, approvers and risks, and a bulk export recipe generating data subject, consent receipt and cookie receipt exports for regulatory reporting. The GDPR pages add timestamped request logging, per-individual consent history and auditable vendor outcomes. We found no public information on auditor access roles, audit-scoped evidence packs, or reports reconstructing the program state on a given date. 11 12 3

Report an error

Integrations & automation

Show reasoning
How this is scored

Whether the platform feeds from the real IT estate — directory import, ticketing, API — and automates the recurring privacy work instead of re-typing it.

0 — A closed island: manual entry in, PDF out, no API.

3 — CSV/Excel import and export; no live connections, no API worth the name.

5 — Directory import (AD/Entra), a documented REST API for core objects, a handful of native connectors (ticketing or SSO); automation is reminders and recurrence.

8 — Real connector set (ticketing, HR or asset sources), webhooks, SSO/SCIM, workflow automation with delegation and escalation, useful AI assistance with human review.

10 — The platform behaves like infrastructure: API parity for the data model, event streams, bidirectional sync with the estate, and automation that measurably removes the recurring toil (reviews, attestations, evidence pulls) rather than renaming it.

Report an error

The External DPO

Over five hundred pre-built plug-ins, a documented API surface spanning every module including SCIM user provisioning, a OneTrust-built MuleSoft connector for consent activation, native Swift and Java SDKs with bridging to cross-platform frameworks, and DSR automation of verification, retrieval, deletion, legal holds and redaction — with a Forrester study quote crediting a four-person team with the output of nine. We found no public information on webhooks or explicit single sign-on, which keeps this below the very top. 5 7 8 9 10 14

Report an error

The In-House Counsel

The developer portal documents API families across essentially the whole platform — assessments, data mapping, requests, incident management, SCIM provisioning, bulk export — alongside more than 500 pre-built plug-ins and native mobile SDKs with framework bridges. Request handling is automated end to end including identity verification and legal-hold checks, with a Forrester study cited for fulfillment-cost reduction; I found no public information on webhooks or event streams. 10 5 8 7

Report an error

The Drafted Generalist

This is the strongest area: the developer portal documents API families across the whole platform including user provisioning, bulk export and task management, with 500+ pre-built plug-ins, native Swift and Java SDKs, framework bridges for React Native and Flutter, and connectors such as MuleSoft, Apigee, Azure and Amazon API Gateway feeding the request workflows. The automation is evidenced in substance — automated identity verification, legal hold checks, vendor reassessments, and change monitoring that routes updates for review — though I found no public information on webhooks or AI assistance inside the workflows. 10 5 9 14 7

Report an error

The Lead Auditor

The developer portal documents API families across essentially every module — assessment automation, data mapping, DSR, incident management, inventory, task management, SCIM user provisioning — alongside more than 500 pre-built plug-ins, native mobile SDKs with bridging to React Native, Flutter and Cordova/Ionic, and named connectors such as MuleSoft and Apigee feeding DSR servicing. Webhooks and AI assistance with human review are the prongs we found no public information on, which is what keeps it off the top bench. 10 5 8 14

Report an error

The IT Integrator

This is a platform I could actually wire into the estate: a documented developer portal with API families spanning data mapping, assessments, DSR automation, incident management, inventory, task management and SCIM user provisioning, OAuth2 and rate limits, over 500 prebuilt plug-ins including MuleSoft, Azure and Apigee connectors, and a RoPA fed from system integrations rather than retyped, with consent preferences enforced downstream automatically. To score higher the pages would need to show webhooks, directory import from Entra ID or AD by name, and bidirectional sync with the estate — we found no public information on those. 3 5 10 12 14

Report an error

The Skeptic

The best-evidenced strength of the set: documented REST APIs spanning every module, SCIM user provisioning, a bulk export script with full job lifecycle control, native Swift and Java SDKs, and DSAR connectors for MuleSoft, Apigee, Amazon API Gateway and Azure App Gateway behind a 500-plus pre-built plug-ins claim. Even here, the framework bridging documentation concedes some native methods go unexposed unless requested through a representative. We found no public information on webhooks or SSO, and the AI-Ready Governance Platform name carries no evidenced in-workflow AI assistance — the privacy notice describes AI use only for user experience and internal operations. 8 10 12 9 14 5

Report an error

European sovereignty panel opinion

Show reasoning
How this is scored

Where the compliance record of the whole company actually lives and under whose law — entity, hosting, subprocessors, DPA. A platform that maps your processing is itself your most concentrated processing.

0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for the system holding your RoPA.

3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.

5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.

8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.

10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors, on-premises or sovereign-cloud options, and the whole chain documented publicly.

Report an error

The External DPO

This is a US entity — Atlanta headquarters, subject to Federal Trade Commission jurisdiction under the Data Privacy Framework, with US investment firms on the board — while a public DPA, SCCs, a Schrems II response and a subprocessor list do exist on the trust page. We found no public information on EU hosting or data residency for the platform that would hold thirty clients' records; SCC-and-DPF transfers under US jurisdictional reach are workable but not what jurisdictional cleanliness looks like. 6 4 5

Report an error

The In-House Counsel

This is a US entity — Atlanta headquarters, Data Privacy Framework self-certification under FTC enforcement, SCCs and the UK Addendum as transfer mechanisms — for the platform that would hold my most concentrated processing record. The data processing agreement and subprocessor list are published on the trust page, but I found no public information on a European entity, EU-default hosting, named data centers, or whether content-touching subprocessors sit within US CLOUD Act reach. 6 4 5

Report an error

The Drafted Generalist

The company is headquartered in Atlanta, with the privacy notice placing it under US Federal Trade Commission enforcement for the Data Privacy Framework; a DPA, standard contractual clauses, a Schrems II response paper and a subprocessor list are published. But I found no public information on where the platform and its data centers are hosted, and for the system that would hold my entire processing register, that unanswered question decides it. 6 4

Report an error

The Lead Auditor

The compliance record of the company would sit with a US entity — OneTrust LLC, headquartered in Atlanta, under FTC jurisdiction for Data Privacy Framework enforcement, relying on SCCs and the UK IDTA for transfers — though a DPA, SCCs, a subprocessor list and a Schrems II response paper are public. We found no public information on hosting residency, an EU region or named data centers, and subprocessor exposure to non-European jurisdictional reach is not confirmed on the vendor's own captured pages. 6 4 8

Report an error

The IT Integrator

The system that would map my processing belongs to a US company: OneTrust LLC, headquartered in Atlanta, participating in the EU-US, UK and Swiss Data Privacy Frameworks and subject to FTC enforcement for DPF disputes. A DPA, SCCs, a subprocessor list and a Schrems II response are published, which lifts it off the floor, but we found no public information confirming EU hosting as the default or where the compliance record is actually stored. 6 4 5 8

Report an error

The Skeptic

A buyer's entire processing record would sit with OneTrust, LLC of Atlanta: US headquarters, a US entity on the copyright and Data Privacy Framework certification, explicit FTC enforcement jurisdiction, and a board including US investors — with SCCs, the UK addendum and a Schrems II white paper as the transfer armor. The trust page does publish a DPA, SCCs and a subprocessor list, which is more than the floor. We found no public information on EU hosting as a default, named data centers, or where the subprocessor chain sits jurisdictionally. 6 8 4 5

Report an error

Pricing transparency not rated — the vendor publishes no price

Show reasoning
How this is scored

Whether a buyer can compute the real invoice — per module, per entity, per year, with consulting unbundled — from public pages alone. Unpublished pricing is the B2B norm in this market, so this criterion describes rather than condemns; the benches weight it accordingly.

0 — No public prices at all; every configuration is a sales conversation.

3 — An entry price exists, but module add-ons, entity counts or bundled consulting make the real total incomputable.

5 — Most editions carry real numbers with billing period stated and software separated from services; at least one commonly needed module or scale step is unpriced.

8 — Every edition and module priced publicly with entity/user boundaries and setup fees stated; only genuine corporate-group contracts are custom.

10 — Complete price computability: modules, scale steps, service packages and renewal rules public, so the invoice for a 100-employee company and a 10-client consultancy is a two-minute exercise.

Report an error

The External DPO

We found no public information on pricing — no edition, module or scale step carries a number on the captured pages, so every configuration is a sales conversation. Unpublished pricing is the norm in this market, but I cannot compute an invoice for a ten-client consultancy from what is public, and that costs my clients hours. 1 2

Report an error

The In-House Counsel

I found no public information on pricing of any kind — no edition prices, module prices, entity or user boundaries, or billing terms on the captured product and company pages. The real invoice is entirely a sales conversation, which is common in this market but leaves a buyer unable to compute anything from public pages. 2 5 7

Report an error

The Drafted Generalist

I found no public information on pricing anywhere — no editions, no module prices, no per-user or per-entity boundaries, no setup or consulting fees — so the product pages give me nothing to budget with. Every configuration starts as a sales conversation, which is exactly what I cannot spare time for. 2 7

Report an error

The Lead Auditor

We found no public pricing on any captured page — no edition figures, module prices, user or entity boundaries, or billing periods — so a buyer cannot compute any part of an invoice from public material alone. In this market that is a common posture rather than a unique fault, but it sits at the bottom of this criterion. 1 2

Report an error

The IT Integrator

We found no public pricing information on any captured product page — no editions, modules, user or entity boundaries, or figures of any kind — and the positioning is aimed at half the Fortune 500. Every real configuration is a sales conversation, so the invoice cannot be computed from public pages. 5 7

Report an error

The Skeptic

We found no public pricing on any captured page — no figures, edition boundaries, user or entity counts, or billing periods on the homepage, product pages, developer portal or about page. A buyer cannot compute even a rough invoice from public information; every configuration appears to begin with a sales conversation. 1 2 5

Report an error

European sovereignty — proven facts

0 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined ⚠ unverified — uncited Report an error
Data residency Not determined — uncited Report an error
Subprocessors Not determined ⚠ unverified — uncited Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (14)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor homepage www.onetrust.com Checked 15 Sep 2026 Details →
  2. 2 Privacy operations product page www.onetrust.com Checked 15 Sep 2026 +2 earlier captures: 11 Sep 2026, 31 Aug 2026 Details →
  3. 3 GDPR solution page www.onetrust.com Checked 15 Sep 2026 +1 earlier capture: 11 Sep 2026 Details →
  4. 4 Security/trust page www.onetrust.com Checked 15 Sep 2026 +1 earlier capture: 11 Sep 2026 Details →
  5. 5 About page www.onetrust.com Checked 15 Sep 2026 +1 earlier capture: 11 Sep 2026 Details →
  6. 6 Privacy policy www.onetrust.com Checked 15 Sep 2026 Details →
  7. 7 Data subject rights & incidents — found from sitemap www.onetrust.com Checked 1 Oct 2026 Details →
  8. 8 Data subject rights & incidents — found from sitemap developer.onetrust.com Checked 1 Oct 2026 Details →
  9. 9 Privacy regime coverage — found from sitemap developer.onetrust.com Checked 1 Oct 2026 Details →
  10. 10 Privacy regime coverage — found from sitemap developer.onetrust.com Checked 1 Oct 2026 Details →
  11. 11 Audit readiness & evidence — found from sitemap developer.onetrust.com Checked 1 Oct 2026 Details →
  12. 12 Audit readiness & evidence — found from sitemap developer.onetrust.com Checked 1 Oct 2026 Details →
  13. 13 Integrations & automation — found from sitemap www.onetrust.com Checked 1 Oct 2026 Details →
  14. 14 Integrations & automation — found from sitemap www.onetrust.com Checked 1 Oct 2026 Details →