The Business of Cyber Security

Privacy Tech & Data Governance

Privacy technology exists because regulation created it: GDPR (2018) and the state-privacy wave that followed (16) manufactured a compliance obligation — consent management, data-subject requests, records of processing, vendor assessments — that enterprises could not meet manually. A software category formed around the obligation, and it has been converging with security GRC (03i) ever since, because the underlying question is shared: what data do we hold, where is it, who can touch it, and can we prove it?

The market and its players

OneTrust is the category's platform company — privacy, consent, GRC, third-party risk and now AI governance in one suite, built through aggressive M&A and last publicly valued at ~$4.5B (2023 round; label: dated). Vanta is the compliance-automation breakout: $4.15B valuation on a $150M July 2025 round, an estimated ~$220M ARR, and a CrowdStrike strategic investment that signals how security platforms view the category (SiliconANGLE · CNBC). Drata — past $100M ARR — acquired SafeBase for $250M (February 2025), extending from audit automation into trust centers, the customer-facing layer where security posture becomes a sales asset. BigID and Securiti approach from data discovery/DSPM, straddling this page and Data Security; Transcend, Osano, Ketch and Didomi serve consent and DSR automation; TrustArc and Exterro hold the legacy/legal end; AuditBoard (Hg-owned after a ~$3B 2024 take-private) anchors the audit-and-risk side.

Player Position Convergence read
OneTrust Privacy → platform (~$4.5B, 2023) Absorbing GRC, TPRM, AI governance into one suite
Vanta $4.15B (Jul 2025), ~$220M ARR Compliance automation as the SMB/mid-market security wedge
Drata (+SafeBase) >$100M ARR Audit automation → trust infrastructure
BigID / Securiti Data discovery The bridge to DSPM and security data teams
AuditBoard Hg (~$3B) PE validation of the audit/risk layer

The convergence mechanics

Compliance automation became the security on-ramp. For a mid-market company, the first structured security work it ever does is often a SOC 2 audit driven by a customer contract — which makes Vanta and Drata the entry point to the security budget, upstream of any security product purchase. The platforms know it: continuous control monitoring is expanding from audit evidence into live security posture, colliding with SPM and the "manage-the-security-program" layer tracked on AI Security (Discern, Balance Theory, Sophos CISO Advantage — the same layer approached from three directions).

AI governance is the growth front. The EU AI Act and emerging US frameworks are doing for AI what GDPR did for data — manufacturing a compliance category. OneTrust, Vanta and the GRC incumbents are all shipping AI-governance modules, contesting the same ground as the Security-for-AI startups (42i, 20d) — a rerun of the pattern where the regulatory layer and the technical-security layer start separate and converge.


Updated 2026-08-16 18:47 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.