Vendor hubPrivacy · Consent · TPRM · Risk · AITechBag Intel Hub

OneTrust

The vendor that made enterprise-grade security work for the mid-market— the platform organisations run privacy, risk and compliance on, with a Gartner Leader placement for third-party risk. This hub is your complete intel file.

5 intel pages insideLeader · 2026 Gartner MQ for TPRMDPDP-ready via TechBag

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

The company, at a glance

Founded2016 · Atlanta, Georgia
OwnershipIndependent — PE sale unresolved
Solution areasSix, on one data inventory
Gartner 2026LEADER — MQ for TPRM
IndiaDedicated DPDP Act solution

Quick answer

OneTrust (founded 2016, Atlanta) builds the platform organisations run privacy, risk and compliance on. Its six solution areas — Privacy Automation, Consent & Preferences, Third-Party Management, Tech Risk & Compliance, AI Governance and Data Use Governance — cover consent, data subject requests, vendor risk and AI oversight from one place. Gartner named it a Leader in the 2026 Magic Quadrant for Third-Party Risk Management Tools for Assurance Leaders, and a Visionary in the inaugural 2026 Magic Quadrant for AI Governance Platforms. Read more ↓ Show less ↑
The portfolio

Five intel pages. One integrated platform.

The complete OneTrust platform — every linked card is a full intel page, from the privacy core to the third-party risk line Gartner named a Leader.

The coreIntel page →

Privacy Automation

Run the privacy programme, not a spreadsheet.

Privacy Operations, DSR Automation and DataGuidance in one place: build and maintain data maps, automate data subject requests end to end, and track regulatory change across jurisdictions. This is the operational core most buyers start from — it turns a privacy programme from a set of spreadsheets and email threads into a workflow with an audit trail. For Indian organisations it is the piece that carries DPDP data-principal rights.

Data mapping · DSR automation · DataGuidanceExplore
The front doorIntel page →

Consent & Preferences

Collect consent, and prove you did.

Universal Consent & Preference Management plus the Consent Management Platform: capture consent across web, app and marketing channels, honour withdrawal, and keep a defensible record of what was agreed and when. Under DPDP the consent notice and the right to withdraw are explicit obligations, so this is where an Indian compliance programme meets its customers. Integrates into existing marketing and IT stacks rather than replacing them.

Web · app · marketing · withdrawalExplore
The MQ Leader lineIntel page →

Third-Party Management

Know who your vendors are, and their risk.

Third-Party Risk Management, Third-Party Due Diligence and the Third-Party Risk Exchange: centralise the vendor inventory, automate privacy and security assessments, and keep automated records for audit. This is the line Gartner named a LEADER in the 2026 Magic Quadrant for Third-Party Risk Management Tools for Assurance Leaders. It maps directly onto RBI and IRDAI outsourcing and vendor-risk obligations for Indian BFSI.

Leader — 2026 Gartner MQ for TPRMExplore
The GRC lineIntel page →

Tech Risk & Compliance

One control, evidenced once, across frameworks.

Compliance Automation and IT Risk Management: map controls to frameworks, collect evidence once and reuse it, and run IT risk registers against the same control set. The argument is that a control tested for ISO 27001 should not be tested again from scratch for SOC 2 or DPDP. Honest scope — this is a GRC workflow platform, not an auditor: the certificate still comes from a licensed firm, and that engagement is priced separately.

Controls · evidence · IT risk registersExplore
Newest lineIntel page →

AI Governance

Inventory the AI you already run.

Discover and inventory AI systems and models in use, assess them for risk, and hold an approval and oversight record. Gartner placed OneTrust as a VISIONARY — not a Leader — in the inaugural 2026 Magic Quadrant for AI Governance Platforms, where IBM is a Leader. The category itself is new, which cuts both ways: there is now a real analyst frame to evaluate against, and the products in it are young. Most useful where AI use has already outrun the policy.

Visionary — inaugural 2026 AI Governance MQExplore

Data Use Governance — a category, not a page

Platform & engine

OneTrust lists Data Use Governance as a sixth solution area, but its own products page details no separate products under it. TechBag does not build a page for a category label: under the granularity rule a page must be a real, separately-licensed product, never a marketing grouping. If it becomes a distinct buy with its own SKUs, it gets a page then. Ask TechBag to scope it as part of the platform quote in the meantime.

What to settle before you sign

Platform & engine

Three things, none of which OneTrust leads with. Pricing is QUOTE-ONLY — no figure appears anywhere on its site, and the pricing pages that surface on aggregator sites are generated rather than vendor-published, so do not budget from them. Some buyers have reported steep renewal increases after a metering change, so fix the metric and the renewal terms in the first contract rather than the second. And ownership is unsettled: OneTrust was reported in November 2025 to be exploring a private-equity sale at a rumoured valuation above $10B, and as of September 2026 no deal has closed. That is not a reason to avoid the platform, but it is a reason to ask about roadmap and partner terms across a multi-year commitment.

The thesis

Why “one inventory, many obligations” is the whole story

Point tools from different vendors don’t talk, and most mid-sized organisations can’t staff a a compliance deadline. OneTrust bet on one data inventory under every obligation— one data inventory under every obligation — and a Gartner Leader placement for third-party risk doubled down on it.

01
The architecture

One inventory, many obligations

Every module reads the same data inventory and control set. That is the platform argument: the map you build for privacy is the map that answers a DPDP request, evidences a control and scopes a vendor assessment. Where it pays off is breadth — with one module it is a point tool.

02
Where it meets customers

Consent at the edge

Consent and preference capture sits in your web, app and marketing stack, not behind it. Under DPDP the notice and the withdrawal path are explicit obligations, so this is the module a regulator's questions land on first. It integrates with what you run rather than replacing it.

03
How the work gets done

Assessments as workflow

Vendor due diligence, privacy impact assessments and AI reviews are the same shape: a questionnaire, a reviewer, a record. Running them on one engine is why the TPRM line earned its Leader placement, and why evidence collected once can serve several frameworks.

04
What keeps it current

The regulatory feed

DataGuidance tracks regulatory change across jurisdictions and feeds it into the programme, which matters in a year when India's DPDP Rules were notified in November 2025 with a phased timeline. A compliance platform that does not track the law is a filing cabinet.

Start with the obligation that is actually forcing the decision — a DPDP consent notice, a regulator asking about vendors — then expand across the platform from evidence rather than from a diagram.

The trophy wall

Peer & market recognition

Every claim on this hub traces to one of these public signals.

Gartner 2026

LEADER — MQ for TPRM

Assurance Leaders

Gartner 2026

Visionary — AI Governance

inaugural MQ; not a Leader

The core

Privacy Automation

mapping, DSR, regulatory feed

Breadth

Six solution areas

one inventory underneath

Founded

2016 · Atlanta

privacy-first from the start

India

Dedicated DPDP solution

Rules notified Nov 2025

Honest gap

Quote-only pricing

no published figure

Honest gap

Ownership unsettled

PE sale explored, none closed

By the numbers

The company in six figures

2016
founded — Atlanta, Georgia
Vendor
6 solution areas
privacy, consent, TPRM, risk, AI, data use
Vendor
2 Gartner MQs
Leader on TPRM; Visionary on AI Governance
Gartner
2025
India DPDP Rules notified — 13 Nov, phased timeline
Gazette
0 published prices
quote-only; aggregator figures are not vendor figures
TechBag
0 deals closed
the reported PE sale remains unresolved
TechBag

See the platform, hear the pitch

OneTrust (official)·Demo

OneTrust Privacy Automation solution demo

Data mapping, DSR automation and privacy operations.

OneTrust (official)·Demo

OneTrust Third-Party Management solution demo

The MQ Leader line — inventory, assessment, records.

OneTrust (official)·Release

Winter Release 2026: AI Assessment Automation

AI-assisted assessments for privacy programmes.

The market maps

Where OneTrust sits — the grids

Two company-level views you won’t find on any vendor site — tap any dot for the rationale. The category-level grid lives on the product page.

Grid 01 · The portfolio

OneTrust Across Its Solution Areas

Each dot is a OneTrust solution area: competitive position vs category momentum.

Emerging betsCrown jewelsSteady nicheAnchor strengths
Third-Party ManagementOneTrust

Leader on the 2026 Gartner MQ for TPRM.

Grid 02 · The industry

The Depth × Breadth Map

Depth in privacy and risk vs breadth across the platform — where OneTrust sits against the alternatives.

Focused specialistsDeep & broadPoint toolsBroad but shallow
OneTrustOneTrust

Broadest privacy-to-risk platform; quote-only.

Positions are TechBag’s illustrative synthesis of public review-platform standings and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Track 01 · Beginner guides

New to this? Learn it properly.

Zero-jargon starting points, in reading order. Each links into the deep education on the product page.

Interactive · 30 seconds

Where should you start with OneTrust?

Answer three questions; we’ll point you at the right starting product. No email required — this isn’t that kind of quiz.

1. What is forcing the decision?

2. Where does the work sit today?

3. How broad is the mandate?

The acronym decoder

Every term on these pages, in one place
OneTrust
A privacy, risk and compliance platform (founded 2016, Atlanta) spanning privacy automation, consent, third-party risk, IT risk and AI governance.
DPDP Act
India's Digital Personal Data Protection Act. The Rules were notified on 13 November 2025 with a phased implementation timeline.
Data principal
The DPDP term for the individual whose personal data is processed — the person exercising rights of access, correction and erasure.
DSR
Data Subject Request. A person asking what you hold, or asking you to correct or delete it, with a statutory clock attached.
Consent notice
The notice presented when consent is collected. Under DPDP it must be clear, specific, and paired with an equally easy way to withdraw.
TPRM
Third-Party Risk Management — knowing who your vendors are, assessing them, and evidencing that assessment to a regulator or auditor.
Magic Quadrant
A Gartner report placing vendors on Ability to Execute and Completeness of Vision. Leaders sit top-right; Visionaries have strong vision, less proven execution.
Data map
The record of what personal data you hold, where it sits, why, and who can reach it. Everything else in a privacy programme depends on it.
Evidence reuse
Testing a control once and using that evidence across several frameworks, rather than re-testing the same control for each.
Track 02 · Buying guides

Buy it like you’ve done this before

The procurement playbook TechBag runs with IT buyers — steps, licensing cheat-sheet, and the pitfalls that cost quarters.

01

Name the obligation first

DPDP consent? Data-principal requests? Vendor risk for a regulator? The obligation decides the module, and buying the platform before naming it is how shelfware happens.

02

Check what the data map needs

Every module reads one inventory. Scoping which systems must be mapped, and who owns that work, is the real project — the licence is the easy part.

03

Decide breadth honestly

The platform argument pays off across modules. With one obligation to close, a point tool may be the better buy, and TechBag will say so.

04

Get the quote — there is no list price

OneTrust publishes no pricing. Aggregator figures are generated, not vendor numbers. TechBag returns a scoped quote in INR with GST.

05

Fix the metering and the renewal

Some buyers have reported steep increases after a metering change. Settle the metric and the renewal terms in the first contract, not at renewal.

06

Ask about ownership

A PE sale was reported as explored in Nov 2025 and has not closed. Ask what it means for roadmap and partner terms over a multi-year commitment.

The licensing cheat-sheet

ProductLicensing modelHow you enterBest for
Privacy AutomationQuote-only — scoped by programmeData mapping, DSR automation, DataGuidanceMake DPDP operational
Consent & PreferencesQuote-only — scoped by volumeConsent capture, preference centre, withdrawalMeet DPDP at the customer edge
Third-Party ManagementQuote-only — scoped by vendorsInventory, assessments, due diligenceEvidence vendor risk to a regulator
Tech Risk & ComplianceQuote-only — scoped by frameworksControl mapping, evidence reuse, IT riskStop re-testing the same control
AI GovernanceQuote-only — newest lineAI inventory, assessment, oversight recordGovern AI already in use

Quote-only, scoped by module and volume — TechBag models which obligations actually need which modules, in INR with GST.

Five pitfalls that cost buyers quarters

1

Reading Visionary as Leader

OneTrust holds TWO Gartner placements and they are not the same. It is a LEADER in the 2026 Magic Quadrant for Third-Party Risk Management Tools for Assurance Leaders. It is a VISIONARY in the inaugural 2026 MQ for AI Governance Platforms, where IBM is a Leader. Quoting the TPRM placement to support the AI product is the claim that collapses in a technical evaluation.

2

Buying the platform before naming the obligation

Six solution areas is genuine breadth, and also how organisations pay for modules nobody operates. The platform argument only pays off when several obligations share one inventory. If the real driver is a single thing, scope that module and expand from evidence. TechBag would rather sell one module that gets used than five that sit idle.

3

Expecting a GRC platform to be an auditor

Tech Risk & Compliance collects evidence and runs the workflow. It does NOT issue a certificate. SOC 2, ISO 27001 and every attestation still need a licensed audit firm, engaged and paid separately, often at a fee comparable to the licence. True of the whole category, and the most common budgeting surprise in it.

4

Budgeting from an aggregator price

OneTrust publishes no pricing anywhere. Figures on aggregator sites are generated from reported contracts, not vendor list prices, and vary hugely with scope. Worse, some buyers report steep renewal increases after a metering change — so fix the metric and the renewal terms in the FIRST contract, because that leverage is gone by renewal.

5

Ignoring the ownership question

OneTrust was reported in Nov 2025 to be exploring a PE sale, rumoured above $10B against a ~$4.5B last valuation. As of Sep 2026 no deal has closed. Not a reason to avoid the platform — the products and the placements are real — but on a multi-year commitment, ask what changes for roadmap, partner terms and support if it does.

Skip the homework entirely

Bring your requirements and current tool bills — a TechBag advisor models the whole decision for you.

Book a discovery call →
FAQ

Questions buyers ask about OneTrust

OneTrust is a privacy, risk and compliance platform, founded in 2016 and headquartered in Atlanta. Its own products page lists six solution areas: Privacy Automation (privacy operations, data subject request automation, and the DataGuidance regulatory feed), Consent & Preferences (universal consent and preference management, and a consent management platform), Third-Party Management (third-party risk management, due diligence, and a risk exchange), Tech Risk & Compliance (compliance automation and IT risk management), AI Governance, and Data Use Governance. They run on one underlying data inventory, which is the platform argument: the map you build for privacy is the map that answers a DPDP request and scopes a vendor assessment. TechBag scopes it and quotes in INR with GST.

Ready to shortlist OneTrust?

Open any of the five intel pages for the deep dive, or let a TechBag advisor build the case with you — DPDP-obligation scoping, quotes, trials, GST invoicing and lifecycle support included.

Stats, positions and figures are illustrative syntheses of public materials; verify before purchase.