The vendor that made enterprise-grade security work for the mid-market— the platform organisations run privacy, risk and compliance on, with a Gartner Leader placement for third-party risk. This hub is your complete intel file.
Buy through TechBag
Same software. Better outcome — at a lower cost.
The company, at a glance
Quick answer
The complete OneTrust platform — every linked card is a full intel page, from the privacy core to the third-party risk line Gartner named a Leader.
Run the privacy programme, not a spreadsheet.
Privacy Operations, DSR Automation and DataGuidance in one place: build and maintain data maps, automate data subject requests end to end, and track regulatory change across jurisdictions. This is the operational core most buyers start from — it turns a privacy programme from a set of spreadsheets and email threads into a workflow with an audit trail. For Indian organisations it is the piece that carries DPDP data-principal rights.
Collect consent, and prove you did.
Universal Consent & Preference Management plus the Consent Management Platform: capture consent across web, app and marketing channels, honour withdrawal, and keep a defensible record of what was agreed and when. Under DPDP the consent notice and the right to withdraw are explicit obligations, so this is where an Indian compliance programme meets its customers. Integrates into existing marketing and IT stacks rather than replacing them.
Know who your vendors are, and their risk.
Third-Party Risk Management, Third-Party Due Diligence and the Third-Party Risk Exchange: centralise the vendor inventory, automate privacy and security assessments, and keep automated records for audit. This is the line Gartner named a LEADER in the 2026 Magic Quadrant for Third-Party Risk Management Tools for Assurance Leaders. It maps directly onto RBI and IRDAI outsourcing and vendor-risk obligations for Indian BFSI.
One control, evidenced once, across frameworks.
Compliance Automation and IT Risk Management: map controls to frameworks, collect evidence once and reuse it, and run IT risk registers against the same control set. The argument is that a control tested for ISO 27001 should not be tested again from scratch for SOC 2 or DPDP. Honest scope — this is a GRC workflow platform, not an auditor: the certificate still comes from a licensed firm, and that engagement is priced separately.
Inventory the AI you already run.
Discover and inventory AI systems and models in use, assess them for risk, and hold an approval and oversight record. Gartner placed OneTrust as a VISIONARY — not a Leader — in the inaugural 2026 Magic Quadrant for AI Governance Platforms, where IBM is a Leader. The category itself is new, which cuts both ways: there is now a real analyst frame to evaluate against, and the products in it are young. Most useful where AI use has already outrun the policy.
OneTrust lists Data Use Governance as a sixth solution area, but its own products page details no separate products under it. TechBag does not build a page for a category label: under the granularity rule a page must be a real, separately-licensed product, never a marketing grouping. If it becomes a distinct buy with its own SKUs, it gets a page then. Ask TechBag to scope it as part of the platform quote in the meantime.
Three things, none of which OneTrust leads with. Pricing is QUOTE-ONLY — no figure appears anywhere on its site, and the pricing pages that surface on aggregator sites are generated rather than vendor-published, so do not budget from them. Some buyers have reported steep renewal increases after a metering change, so fix the metric and the renewal terms in the first contract rather than the second. And ownership is unsettled: OneTrust was reported in November 2025 to be exploring a private-equity sale at a rumoured valuation above $10B, and as of September 2026 no deal has closed. That is not a reason to avoid the platform, but it is a reason to ask about roadmap and partner terms across a multi-year commitment.
Point tools from different vendors don’t talk, and most mid-sized organisations can’t staff a a compliance deadline. OneTrust bet on one data inventory under every obligation— one data inventory under every obligation — and a Gartner Leader placement for third-party risk doubled down on it.
Every module reads the same data inventory and control set. That is the platform argument: the map you build for privacy is the map that answers a DPDP request, evidences a control and scopes a vendor assessment. Where it pays off is breadth — with one module it is a point tool.
Consent and preference capture sits in your web, app and marketing stack, not behind it. Under DPDP the notice and the withdrawal path are explicit obligations, so this is the module a regulator's questions land on first. It integrates with what you run rather than replacing it.
Vendor due diligence, privacy impact assessments and AI reviews are the same shape: a questionnaire, a reviewer, a record. Running them on one engine is why the TPRM line earned its Leader placement, and why evidence collected once can serve several frameworks.
DataGuidance tracks regulatory change across jurisdictions and feeds it into the programme, which matters in a year when India's DPDP Rules were notified in November 2025 with a phased timeline. A compliance platform that does not track the law is a filing cabinet.
Start with the obligation that is actually forcing the decision — a DPDP consent notice, a regulator asking about vendors — then expand across the platform from evidence rather than from a diagram.
Every claim on this hub traces to one of these public signals.
Assurance Leaders
inaugural MQ; not a Leader
mapping, DSR, regulatory feed
one inventory underneath
privacy-first from the start
Rules notified Nov 2025
no published figure
PE sale explored, none closed
Data mapping, DSR automation and privacy operations.
The MQ Leader line — inventory, assessment, records.
AI-assisted assessments for privacy programmes.
Two company-level views you won’t find on any vendor site — tap any dot for the rationale. The category-level grid lives on the product page.
Each dot is a OneTrust solution area: competitive position vs category momentum.
Leader on the 2026 Gartner MQ for TPRM.
Depth in privacy and risk vs breadth across the platform — where OneTrust sits against the alternatives.
Broadest privacy-to-risk platform; quote-only.
Positions are TechBag’s illustrative synthesis of public review-platform standings and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Zero-jargon starting points, in reading order. Each links into the deep education on the product page.
Answer three questions; we’ll point you at the right starting product. No email required — this isn’t that kind of quiz.
1. What is forcing the decision?
2. Where does the work sit today?
3. How broad is the mandate?
Consent notice, the right to withdraw, data-principal requests and breach reporting — the obligations a platform has to carry.
Read →A cookie banner is the visible part. The obligation is proving what was agreed, when, and honouring withdrawal.
Read →Outsourcing and vendor-risk obligations mean an Indian regulated buyer has to evidence who its vendors are and how they were assessed.
Read →OneTrust is a Leader for TPRM and a Visionary for AI Governance. They are different reports and the difference matters.
Read →It collects and organises evidence. The certificate still comes from a licensed audit firm, priced separately.
Read →No published price. Fix the metering metric and renewal terms in the first contract, not the second.
Read →The procurement playbook TechBag runs with IT buyers — steps, licensing cheat-sheet, and the pitfalls that cost quarters.
DPDP consent? Data-principal requests? Vendor risk for a regulator? The obligation decides the module, and buying the platform before naming it is how shelfware happens.
Every module reads one inventory. Scoping which systems must be mapped, and who owns that work, is the real project — the licence is the easy part.
The platform argument pays off across modules. With one obligation to close, a point tool may be the better buy, and TechBag will say so.
OneTrust publishes no pricing. Aggregator figures are generated, not vendor numbers. TechBag returns a scoped quote in INR with GST.
Some buyers have reported steep increases after a metering change. Settle the metric and the renewal terms in the first contract, not at renewal.
A PE sale was reported as explored in Nov 2025 and has not closed. Ask what it means for roadmap and partner terms over a multi-year commitment.
| Product | Licensing model | How you enter | Best for |
|---|---|---|---|
| Privacy Automation | Quote-only — scoped by programme | Data mapping, DSR automation, DataGuidance | Make DPDP operational |
| Consent & Preferences | Quote-only — scoped by volume | Consent capture, preference centre, withdrawal | Meet DPDP at the customer edge |
| Third-Party Management | Quote-only — scoped by vendors | Inventory, assessments, due diligence | Evidence vendor risk to a regulator |
| Tech Risk & Compliance | Quote-only — scoped by frameworks | Control mapping, evidence reuse, IT risk | Stop re-testing the same control |
| AI Governance | Quote-only — newest line | AI inventory, assessment, oversight record | Govern AI already in use |
Quote-only, scoped by module and volume — TechBag models which obligations actually need which modules, in INR with GST.
OneTrust holds TWO Gartner placements and they are not the same. It is a LEADER in the 2026 Magic Quadrant for Third-Party Risk Management Tools for Assurance Leaders. It is a VISIONARY in the inaugural 2026 MQ for AI Governance Platforms, where IBM is a Leader. Quoting the TPRM placement to support the AI product is the claim that collapses in a technical evaluation.
Six solution areas is genuine breadth, and also how organisations pay for modules nobody operates. The platform argument only pays off when several obligations share one inventory. If the real driver is a single thing, scope that module and expand from evidence. TechBag would rather sell one module that gets used than five that sit idle.
Tech Risk & Compliance collects evidence and runs the workflow. It does NOT issue a certificate. SOC 2, ISO 27001 and every attestation still need a licensed audit firm, engaged and paid separately, often at a fee comparable to the licence. True of the whole category, and the most common budgeting surprise in it.
OneTrust publishes no pricing anywhere. Figures on aggregator sites are generated from reported contracts, not vendor list prices, and vary hugely with scope. Worse, some buyers report steep renewal increases after a metering change — so fix the metric and the renewal terms in the FIRST contract, because that leverage is gone by renewal.
OneTrust was reported in Nov 2025 to be exploring a PE sale, rumoured above $10B against a ~$4.5B last valuation. As of Sep 2026 no deal has closed. Not a reason to avoid the platform — the products and the placements are real — but on a multi-year commitment, ask what changes for roadmap, partner terms and support if it does.
The flagship intel page carries an 8-question vendor checklist and an automation-savings calculator:
Bring your requirements and current tool bills — a TechBag advisor models the whole decision for you.
Book a discovery call →Six trends with momentum scores (TechBag’s read of analyst and market signals) — and what each means for your next decision.
*Directionally consistent with public analyst forecasts; verify exact figures before quoting. The takeaway: privacy, vendor risk and AI governance are converging onto one inventory, which is the ground OneTrust is built on.
The DPDP Rules were notified on 13 November 2025 with a phased implementation timeline.
What it means for you
Consent notices, withdrawal paths and data-principal requests stop being a policy discussion and become a system with a date attached.
RBI and IRDAI outsourcing expectations mean a regulated Indian buyer must show who its vendors are and how they were assessed.
What it means for you
This is the ground OneTrust's Leader placement sits on — the assessment workflow and the audit record, not the questionnaire itself.
Gartner published the first Magic Quadrant for AI Governance Platforms in June 2026.
What it means for you
A brand-new category now has a reference point. It also means the products in it are young — OneTrust is a Visionary here, not a Leader.
Organisations increasingly carry several frameworks at once — ISO 27001, SOC 2, DPDP, sector rules.
What it means for you
Testing one control once and reusing the evidence is the practical argument for a GRC platform over a folder of spreadsheets.
Open any of the five intel pages for the deep dive, or let a TechBag advisor build the case with you — DPDP-obligation scoping, quotes, trials, GST invoicing and lifecycle support included.
Stats, positions and figures are illustrative syntheses of public materials; verify before purchase.