Data privacy software is the category of tools that operationalise an organisation's compliance with data protection regulations — GDPR, UK GDPR, CCPA, and their equivalents. It is distinct from information security software (which prevents unauthorised access) and from privacy policy generators (which produce documents). Data privacy software manages the processes that regulations require: consent, subject rights, records of processing, assessments, and breach response.
This guide covers the market structure, the functional requirements for enterprise selection, and the decision criteria that separate platforms suited to a regulatory audit from those that produce only the appearance of compliance.
Market structure
Data privacy software spans five functional categories. Most enterprise platforms cover several; pure-play tools cover one deeply.
Consent management platforms
Manage cookie consent on digital properties and marketing consent in CRM and email systems. Pure-plays: OneTrust Consent & Preferences, Cookiebot, TrustArc. CRM-native: Salesforce Privacy Center, Dynamics 365 Customer Insights consent model.
Data subject rights management
Automate the intake, routing, identity verification, and response assembly for DSARs (access, erasure, portability, rectification, objection). Embedded in OneTrust, TrustArc, and Exterro. Standalone players include DataGrail and Transcend.
Data mapping and ROPA
Discover and document what personal data the organisation holds, where it is, and who it flows to. Auto-discovery from system integrations is table stakes for organisations with more than a handful of systems. Platforms: OneTrust Data Mapping, Collibra, Informatica Privacy.
Privacy assessment automation
Automate DPIAs, LIAs, and TIAs. Triggered by screening questionnaires, routed to stakeholders, approved and archived. OneTrust Assessment Automation, TrustArc, Nymity.
Breach and incident management
Log incidents, classify severity, manage 72-hour notification obligations, and track regulatory filings. Often embedded in privacy platforms or in GRC tools (ServiceNow GRC, RSA Archer).
Functional requirements
Enterprise procurement requires a requirements matrix. These are the non-negotiable functions for GDPR compliance:
| Function | Requirement | Failure mode if absent |
|---|---|---|
| Consent capture | Records exact notice text, timestamp, purpose, channel | Consent record cannot be produced to auditor |
| Withdrawal propagation | Withdrawal reaches all downstream systems within defined SLA | Continued processing after withdrawal — enforcement trigger |
| ROPA | Live inventory auto-updated from connected systems | Stale ROPA — most common audit finding |
| DSAR workflow | 30-day deadline tracking with escalation | Missed deadlines — automatic supervisory authority notification |
| DPIA screening | Triggered for high-risk processing, documented output | Missing DPIAs — significant audit exposure |
| TIA | Cross-border transfer assessment with Schrems II safeguards | Unlawful transfer to non-adequate country |
| Breach notification | 72-hour regulatory notification workflow | Missed breach notification — fines at Article 83(4) level |
| Audit evidence export | Structured export of consent records, ROPA, DSAR logs | Cannot respond to regulatory inquiry in required timeframe |
| Multi-jurisdiction | Separate models for GDPR, UK GDPR, CCPA, Swiss nDSG | Single policy applied to all jurisdictions — wrong for most |
Make vs buy vs embedded
Three architectural choices apply to data privacy software at the enterprise level:
Buy a dedicated privacy platform
OneTrust, TrustArc, and Exterro are built specifically for this function. Strongest audit trail, deepest regulatory coverage, most regulator familiarity. Requires integration with every system that processes personal data. Total cost of ownership is license plus integration plus ongoing configuration.
Use embedded privacy modules in existing platforms
Salesforce Privacy Center, Dynamics 365's consent model, and ServiceNow's Privacy Management module handle consent and DSARs within those ecosystems. Integration cost is lower; coverage is limited to data processed within the platform. External processing — email platforms, ad networks, analytics tools — still requires a separate mechanism.
Build custom
Viable for organisations with unusual data architectures or regulatory environments not covered by commercial platforms. Higher initial cost, full control over the audit trail, requires ongoing maintenance. Rarely the right choice for the consent and DSAR layer; sometimes the right choice for bespoke data mapping in complex multi-entity structures.
The choice is not binary. Most enterprise implementations use a dedicated CMP for consent, the CRM's native DSAR workflow for subject rights, and a privacy platform's assessment automation for DPIAs and TIAs.
Vendor evaluation process
Step 1 — Define your data estate
The number and type of systems that hold personal data determines which integration capabilities matter. An organisation with Salesforce, Marketo, and a data warehouse needs different connectors than one with Oracle ERP, Workday, and a custom portal.
Step 2 — Map your jurisdictions
List every country in which you collect data from individuals. Your software must handle the most restrictive regulation applicable in each. GDPR is not the most restrictive for all purposes — CCPA and Swiss nDSG have differences that require explicit configuration, not just a generic "global privacy" setting.
Step 3 — Security requirements
Data privacy software processes sensitive personal data. Security requirements include: SOC 2 Type II audit, ISO 27001, EU data residency where required, penetration test cadence, and sub-processor list. Request these documents before a vendor demo — they eliminate candidates faster than feature comparisons.
Step 4 — Reference checks
Ask for references from organisations in your industry with similar data estate complexity. Consent management for a publisher is a different problem from consent management for a B2B SaaS company. Feature parity at the product level does not mean implementation parity.
Step 5 — Total cost of ownership
License cost is typically 20–40% of total first-year cost. Add: implementation services (internal and external), integration development, data migration, training, and annual maintenance. Get a fixed-scope implementation proposal before contracting.
Frequently asked questions
A Privacy Information Management System (PIMS) — ISO 27701 uses this term — is the broader governance framework of which data privacy software is one component. The software automates the operational layer; the PIMS includes the policies, roles, training, and audit processes that the software supports.
Related guides
GDPR Compliance Software
A practical guide to GDPR compliance software selection and implementation. Book an assessment with a specialist.
Consent Management Platform
Evaluate and implement a consent management platform for GDPR. Book an assessment with a data privacy specialist.
OneTrust Consent Management
Configure and optimise OneTrust consent management for GDPR compliance. Book an assessment with a certified specialist.