Skip to main content

Data Privacy & Governance

56 martech vendors in Data Privacy & Governance, part of Governance, Privacy & Compliance. Each record carries the date we last verified it, so you can see how current it is before you rely on it.

Last verified:

Procurement-readiness profiles — SOC 2, ISO 27001, GDPR and DPA posture, data residency, AI-training policies — are available when you sign in.

Data privacy governance software maps where personal data lives across a company's systems, runs privacy impact checks, and handles subject-access and deletion requests at scale. Privacy and legal teams run the whole compliance program through it, not just one consent banner. That scope means its own data handling deserves the same scrutiny it applies to others.

Who it is for

  • Privacy and legal leads shortlisting a platform to run data mapping, impact assessments, and subject-request handling from one system.
  • IT and data governance reviewers confirming how a tool holding an inventory of every other system's personal data is itself secured.
  • Procurement and vendor-risk teams using the platform's own vendor register to track processor and sub-processor exposure across the stack.

What your No-Committee will ask

IT security
Is the data-inventory and request-handling database encrypted at rest? Is admin access to the full data map locked behind MFA rather than a single shared login? We log both as their own claim per vendor, marked verified, self-attested, or not found.
Data governance
Where does the platform itself store the personal-data inventory it builds, and is a Data Processing Agreement available covering that inventory? Data residency and DPA availability are pulled from the vendor's own legal pages, with a source link on the claim.
AI governance
If the platform uses AI to auto-classify data types or draft a subject-access response, is that disclosed, and can a reviewer check its output before it goes out? AI-feature disclosure and human-review support are tracked as a single evidenced claim.
Legal / compliance
Does the vendor publish its own sub-processor list, and does the platform track deletion-request fulfillment through to every connected downstream system? Sub-processor disclosure and deletion-propagation claims are each recorded with a source link.
Risk / finance
Does the vendor publish an uptime SLA, and what's the data-export path if the contract ends, given that the inventory itself would need to migrate intact? Exit-strategy and SLA claims are captured wherever the vendor addresses them.

How we verify

Every claim above comes from the vendor's own public pages — trust center, privacy policy, or security page — never assumed from what a privacy platform is generally capable of, since the subject being audited is compliance itself. The full definitions of verified, self-attested, and not-found live on our methodology page.

Frequently asked questions

How is data privacy governance different from consent management?

Consent management captures a visitor's real-time cookie and marketing choices at the point of collection. Data privacy governance runs the wider program those choices feed into — data mapping across every system, privacy impact assessments, and fulfilling subject-access or deletion requests once they're made. Many privacy teams run both together.

Do data-privacy governance vendors typically publish SOC 2 or ISO 27001 certification?

Vendors serving enterprise privacy and legal teams, who tend to ask for it during evaluation, more often publish a SOC 2 report behind a dedicated trust center. Smaller or newer platforms in this category more often rely on a general security page without independent certification, which our audits mark as self-attested.

Does this category usually publish a self-serve price list?

Rarely. Most vendors price against the number of data subjects, mapped systems, or requests handled per month, all of which scale too much by organization size for a flat published tier. Expect a quote built around program scope rather than a self-serve page.

What should I check beyond a DSAR-automation demo before shortlisting a platform?

Confirm whether a deletion request actually propagates to every connected downstream system or just marks a record complete internally, where the platform's own data inventory is stored, and what the vendor's sub-processor list looks like. Those gaps are what a review board finds months after go-live, not during the demo.

Data Privacy & Governance vendors, newest verification first. 25 shown on this page.
VendorLast verified
secureprivacy.ai
gryphon.ai
blackbox.email
datastreams.io
trust-hub.com
dataguard.de
brolly.io
incountry.com
datalegaldrive.com
onetrustpro.com
usercentrics.com
akira.ai
ideagen.com
wirewheel.io
circus.io
attrilab.com
sonarsoftware.com
smarsh.com
transcend.io
dmarcly.com
caralegal.eu
private-ai.com
ketch.com
trackingplan.com
emailconsul.com