OneTrust
The large incumbent in privacy and governance tooling, now extended to cover AI systems.
Highlights
- AI governance module with automated discovery and inventory of AI agents, models, and datasets
- AI policy manager and library with prebuilt, standards-aligned policies plus custom rules
- Real-time AI guardrail enforcement that validates configurations and flags violations at runtime
- Privacy management for consent, data subject requests, and assessments (DPIAs)
- Data discovery and mapping to track personal data across systems
- Third-party and vendor risk management with regulatory intelligence built in
- Compliance automation spanning 300+ jurisdictions and major frameworks
- Centralized policy and reporting that connects governance intent to operational controls
External link — opens onetrust.com in a new tab. OneTrust is a third-party product; we are not affiliated with it.
About OneTrust
What it is
OneTrust unifies privacy management, data governance, risk and AI governance in one platform. It inventories the data and AI systems an organisation actually has, enforces policy against them, and maps obligations across hundreds of jurisdictions — the machinery behind consent banners, data subject requests, vendor risk assessments and records of processing.
Why it's different
It is the incumbent, and that is both the argument and the objection. Its breadth and jurisdictional coverage are genuinely hard to replicate, and for a multinational with obligations under a dozen regimes that coverage is the product. The other side: it is large, expensive, and widely described by the people who use it as heavy going — the kind of platform that needs someone whose job is operating it. Smaller organisations frequently buy far more than they need because it was the name that came up. The AI governance module is newer than the regulatory expectations it addresses, so it is best judged on what it actually inventories rather than on the framework list.
How people use it
It is used by organisations with a real privacy function: running data subject requests at volume, maintaining processing records for regulators, assessing vendors, and now cataloguing AI systems ahead of the EU AI Act and similar. A company handling consent for one website and a handful of requests a year does not need this, and the honest alternative for them is a much smaller tool and a written process.
Written by the n3os team. We are not affiliated with OneTrust.
This listing was written from public information, without OneTrust’s involvement. If you own it and something here is wrong — or you would rather not be listed at all — email us and we will correct or remove it.
Get the ones worth knowing about
We write one of these for every tool worth the trouble. Get the new ones, plus what we have found genuinely useful lately.
Your address goes to Buttondown, who send the emails on our behalf. One click unsubscribes, and the list is never sold or shared.