Privacy Tech & Data Governance
Privacy technology exists because regulation created it: GDPR (2018) and the state-privacy wave that followed (16) manufactured a compliance obligation — consent management, data-subject requests, records of processing, vendor assessments — that enterprises could not meet manually. A software category formed around the obligation, and it has been converging with security GRC (03i) ever since, because the underlying question is shared: what data do we hold, where is it, who can touch it, and can we prove it?
The market and its players
OneTrust is the category's platform company — privacy, consent, GRC, third-party risk and now AI governance in one suite, built through aggressive M&A and last publicly valued at ~$4.5B (2023 round; label: dated). Vanta is the compliance-automation breakout: $4.15B valuation on a $150M July 2025 round, an estimated ~$220M ARR, and a CrowdStrike strategic investment that signals how security platforms view the category (SiliconANGLE · CNBC). Drata — past $100M ARR — acquired SafeBase for $250M (February 2025), extending from audit automation into trust centers, the customer-facing layer where security posture becomes a sales asset. BigID and Securiti approach from data discovery/DSPM, straddling this page and Data Security; Transcend, Osano, Ketch and Didomi serve consent and DSR automation; TrustArc and Exterro hold the legacy/legal end; AuditBoard (Hg-owned after a ~$3B 2024 take-private) anchors the audit-and-risk side.
| Player | Position | Convergence read |
|---|---|---|
| OneTrust | Privacy → platform (~$4.5B, 2023) | Absorbing GRC, TPRM, AI governance into one suite |
| Vanta | $4.15B (Jul 2025), ~$220M ARR | Compliance automation as the SMB/mid-market security wedge |
| Drata (+SafeBase) | >$100M ARR | Audit automation → trust infrastructure |
| BigID / Securiti | Data discovery | The bridge to DSPM and security data teams |
| AuditBoard | Hg (~$3B) | PE validation of the audit/risk layer |
The convergence mechanics
Compliance automation became the security on-ramp. For a mid-market company, the first structured security work it ever does is often a SOC 2 audit driven by a customer contract — which makes Vanta and Drata the entry point to the security budget, upstream of any security product purchase. The platforms know it: continuous control monitoring is expanding from audit evidence into live security posture, colliding with SPM and the "manage-the-security-program" layer tracked on AI Security (Discern, Balance Theory, Sophos CISO Advantage — the same layer approached from three directions).
AI governance is the growth front. The EU AI Act and emerging US frameworks are doing for AI what GDPR did for data — manufacturing a compliance category. OneTrust, Vanta and the GRC incumbents are all shipping AI-governance modules, contesting the same ground as the Security-for-AI startups (42i, 20d) — a rerun of the pattern where the regulatory layer and the technical-security layer start separate and converge.
Updated 2026-08-16 18:47 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.