DataGuard vs OneTrust: how they compare in 2026

D
DataGuard profile
O
OneTrust profile
Last verifiedSeptember 26, 2026

DataGuard and OneTrust both run privacy programs in one platform, from records of processing and subject requests to impact assessments and consent, with AI added as a layer rather than sold as the product. OneTrust sits in the top two bands on ten of fifteen axes and DataGuard on two of fifteen, identical on two. OneTrust's lead is published paper. Its master terms, data processing addendum and standard contractual clauses are downloadable with full version histories, and its trust center offers SOC 2 Type II and ISO reports with no form to fill in. It names an AI governance committee and routes each AI assessment to privacy, security and legal reviewers. DataGuard publishes no customer agreement, and its own footer disclaims its performance figures. Its counterweight is people: the Pro tier adds its own certified consultants, and separate options let a customer nominate DataGuard as its external data protection officer. Neither names the model behind its AI.

At a glance

Category
DataGuardRegulatory & Compliance Counsel
OneTrustRegulatory & Compliance Counsel
Founded
DataGuardNot published
OneTrustNot published
Headquarters
DataGuardMunich, Germany
OneTrustAtlanta, Georgia, United States
Last verified
DataGuardSep 4, 2026
OneTrustSep 1, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

DataGuard
CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.

Machine learning sits at the edges of a conventional compliance management platform. The substance of what is bought is a policy and control library, a risk register with pre-built treatment plans, an asset inventory, framework templates for ISO 27001, GDPR, NIS2, TISAX and the EU AI Act, evidence collection, and the statutory privacy workflows: record of processing, data subject requests, impact assessments and breach management. Strip the models out and all of that still functions, which is what the platform was before AI. Where AI actually appears is visible in the published plan comparison rather than in the marketing: an **AI co-pilot** listed as a feature line under Admin and Access Controls, and an **AI-assisted questionnaire processing tool for administrative support** under Trust Management, available only with the advanced security platform. AI-powered automation is named as a platform pillar included from the Base tier and the headline claim is up to forty per cent of tasks automated. That is a real layer and it is not the mechanism being sold. Recorded as a limit on this grade rather than glossed: the dedicated AI-Powered Automation page returned navigation and one line of body text, so the detail of the capability could not be read; the grade rests on the plan comparison table, which is explicit about where AI sits.

OneTrust
CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.

Artificial intelligence is present, shipped and contractually confirmed, and it is a layer on a product whose value stands entirely without it. The core is registry and workflow software: a data and activity map, consent banners and preference centres, data subject request automation, vendor and third-party inventories, assessment templates across more than fifty standards, and policy approval workflows. Remove every model and all of that continues to work, which is the distinction this axis asks about. Where AI appears it accelerates an existing step rather than constituting one, with an AI-assisted risk assessment producing a summary and key findings that then route to human approval. Worth separating two things that are easy to conflate here: OneTrust sells AI governance as a subject matter, maintaining registers of a customer's models, agents and datasets and applying runtime controls to them, and that is the product managing someone else's AI rather than the product being AI. The Master Terms confirm the vendor's own use, answering the question of whether AI is used in the services with a plain yes.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

DataGuard
DD on Citation Accuracy and Hallucination DisclosureNothing published on accuracy or grounding for a product that produces legal assertions, or a bare claim that the system does not hallucinate.

Nothing published addresses the accuracy or grounding of the AI features, and the numbers that are published are expressly disclaimed by the vendor. The AI capabilities located are an AI Co-pilot and an AI-assisted questionnaire processing tool for administrative support, the latter restricted to the Advanced tier in the published plan table. No accuracy figure, test set, evaluation, method, grounding description or hallucination statement attaches to either. The percentages the site does carry are operational rather than accuracy claims, running to automating up to 40 per cent of tasks, reaching certification 75 per cent faster and a 100 per cent first-try pass rate, and every page carrying them appends a statement that the data is for information only, based on internal estimates, is not indicative of KPIs, and is given without warranties or guarantees as to accuracy or reliability. A vendor disclaiming the reliability of its own published figures is the opposite of a measured accuracy position. Surfaces checked on 4 September 2026: the home page, the product and compliance product pages, the pricing plan table, the GDPR framework page and the DPIA and risk assessment page. The AI-Powered Automation page at /platform/ai-automation/ returned navigation, footer and a single body line across three attempts and was partially recovered through search; the Experts-in-the-Loop page and the Trust Center Controls section remain unread, and either could carry material that moves this row on amendment. Row written 4 September 2026.

OneTrust
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Accuracy is not asserted loudly and it is not measured either, and the document that would answer it is obtainable rather than published. The AI-assisted assessment shown on the home page produces a risk summary and graded findings across personal data processing, model accuracy and transparency, which is an output a compliance officer will act on, and no accuracy rate, benchmark, test set or error mode for it was located on any public surface. Several limbs of this axis do not bite: the product does not retrieve primary legal authority, so grounding to openable sources and citator checking are not the relevant questions, and the applicable risk is a wrong risk rating rather than a fabricated citation. The AI Systems Transparency Report is the artifact that would carry this and the Master Terms describe it as available upon request, which under the gated-is-not-absent rule is the middle tier rather than an absence, but its contents could not be read on 1 September 2026. Checked the home page, the trust centre, the pricing and packaging page and the published contracting explainer.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

DataGuard
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

Oversight is the explicit selling proposition and no mechanism is described. The published model is experts-in-the-loop: automate when you want it, get expert help when you need it, with certified consultants stepping in for complex decision-making and strategic review, and a dedicated platform page for the concept. That is a genuine position and it is unusual for being sold as a paid tier rather than asserted as a design principle. But the humans in that loop are **DataGuard's consultants, not the customer's own reviewers**, and access to them is what separates the Pro plan from Base, so on the Base plan the oversight described is simply absent from the purchase. Nothing published identifies a review point inside the product, no confidence or uncertainty signal is described against AI output, nothing states which automated actions require approval before taking effect, and nothing addresses what happens when the co-pilot is wrong in a record that later supports a certification audit. The dedicated Experts-in-the-Loop page was not opened in this pass.

OneTrust
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

A review point is not merely claimed but drawn, with named roles, and the surrounding control structure is incomplete. The AI use case workflow published on the home page runs intake, then AI risk assessment, then a review and approve stage showing three pending reviewers identified as Privacy, Security and Legal, then continuous monitoring described as real-time oversight and alerts after workflow completion. That places the machine output before a human gate and says who holds it, which is more than most vendors in this lane publish. The AI Governance package reinforces it commercially, listing configurable approvals, attestations and evaluation gates before AI systems move to production, and runtime controls across prompts, outputs, data access and allowed AI actions. What is missing is the rest: nothing states what the assessment does unattended, at what confidence it defers, or what happens after it is wrong, and no statement was located about the behaviour of OneTrust's own models as distinct from the governance gates it sells.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

DataGuard
CC on Operational and Outcome EvidenceCustomer logos and unattributed testimonials stand in for evidence, or results are quoted with no basis stated.

Scale is asserted at corporate level and every performance figure is disclaimed by the vendor itself. The published claims are specific: more than 4,000 organisations across 50 or more countries, up to forty per cent of tasks automated, certification and compliance seventy-five per cent faster, fifty per cent lower costs, compliance reached in as little as three months, and a hundred per cent first-try pass rate on certification. Third-party standing is real and independently checkable, with G2 category leadership badges for Data Privacy Management across Europe, EMEA and the United Kingdom, a Consent Management high performer badge, a 4.6 rating on both G2 and Capterra, and a Gartner Peer Insights listing. What undercuts the numbers is DataGuard's own footer, which appears on every page: **all data provided is for information only, based on internal estimates, not indicative of KPIs, and given without warranty as to accuracy or reliability.** The vendor is telling a reader not to rely on its own figures, which is candid and leaves the outcome claims without a stated basis. No named customer was read; the Success Stories page was not opened in this pass.

OneTrust
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

A named customer, a named individual and real figures are published, and nothing carries a date. The GOL customer story quotes Bruna Boccini, Head of Compliance and Data Protection Officer at the airline, and gives specific before-and-after numbers in her own account: vendor approval falling from almost thirty days to between five and zero, and request completion falling from fourteen or fifteen days to a few minutes, against a described estate of seven billion identifiers and thousands of data flows and vendors. A commissioned Forrester Total Economic Impact study adds a 227 per cent three-year return and a seven-month payback, which is a figure attached to a documented methodology a reader can assess. Around those sit a large named logo set including Adobe, Samsung, Pfizer, Walgreens, Aetna, Atlassian, Maersk and Bristol Myers Squibb, and a claim of more than 14,000 customers with more than half the Fortune 500. What holds this below the top band is dating: no located customer story or study carries a date, and the operational figures are the interviewee's own account rather than a measured study.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

DataGuard
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Confidentiality is evidenced through security posture rather than through a readable commitment about customer content. What is located and solid: a trust centre publishing an ISO 27001 Statement of Applicability and reports available on request, single sign-on and granular user permissions as published plan features, an Admin and Access Controls feature group, and a company operating from Munich under German and EU data protection law selling data protection compliance as its business. What is not located is the substance this axis measures. Nothing readable states whether customer content is used to train models, no retention or deletion position for customer data was found, and no model provider is identified. **The limit is mine and is stated rather than converted into a finding**: the privacy policy and the separate platform privacy policy both returned navigation and footer with no body across three fetch attempts on two URLs, while the home and pricing pages rendered normally, so this is page-specific rather than a site property. The commitments may well exist in those documents; they could not be read on 4 September 2026 and are not credited either way.

OneTrust
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

The published commitments are substantive and contractual, and the training question is not answered. What a buyer can read before signing: a Data Processing Addendum published openly with version history, purpose limitation providing that personal data is processed only for the limited purposes described in the agreement and that OneTrust will not buy or sell customer personal data, customer retention of ownership of all data input into the services, tenant separation with data held in a logically-separated cloud database and a single production environment per customer, ISO 27701 certification for privacy information management, and deletion or export rights exercisable at any time during the term and for sixty days after it ends. Against that, nothing located states whether customer content is used to train or improve models, which is the first question this axis asks and a conspicuous silence for a company selling AI governance; the position on third-party model providers is equally absent; and privilege and work product are never mentioned, which matters because the platform is sold to privacy counsel and the workflow assigns a legal reviewer.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.

DataGuard
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

No position on advice versus tooling was located, on a product that sells a regulated advisory role. This matters more here than on most records because of what is actually being offered: an add-on under which the customer **nominates DataGuard as its external Data Protection Officer**, a role with statutory duties and independence requirements under Articles 37 to 39 of the GDPR, alongside an equivalent external Information Security Officer offering and consultants providing information and advice on regulatory obligations and certification requirements. Nothing published addresses where the tooling stops and advice begins, whether the platform's guided workflows and template libraries constitute advice, how the independence of a nominated DPO is preserved when the same company also sells the compliance platform being assessed, or what the customer remains responsible for. Searched the home page, pricing page, product overview, trust centre and the published Consent and Preference Management documentation on 4 September 2026.

OneTrust
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

Nothing located addresses the line between an information tool and legal advice, on a product that produces compliance determinations for a professional audience. The platform assigns risk ratings, generates assessments against named regimes including the EU AI Act, GDPR and US state privacy laws, and routes them to a reviewer identified as Legal, so the output is consumed as a compliance judgement. What is published in its place is a performance commitment rather than an advice-line position: the Master Terms warrant that the cloud services will materially conform to the OneTrust User Guide throughout the subscription term. No statement was located that outputs are not legal advice, that OneTrust is not a law firm, that no professional relationship arises, or that a user should take advice on their own facts, and no jurisdiction limit or supervision and competence discussion appears. **This is the row most likely to move on this record**: the Master Terms PDF itself and the Legal and Compliance Information page were not opened on 1 September 2026, and a disclaimer may sit in either, so the grade rests on the home page, trust centre, pricing page and published contracting explainer.

AI Governance and Bias Disclosure

Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

DataGuard
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

No governance position for DataGuard's own artificial intelligence was located, on a vendor that sells AI governance to its customers. The product side is substantial and specific: EU AI Act is a named framework alongside GDPR, ISO 27001, TISAX and NIS2, the platform consolidates AI governance workflows with the customer's ISMS and privacy programme, and the assessment template library includes an AI system assessment. All of that is governance tooling the buyer operates over its own systems. Nothing published turns the same instrument on the vendor: no responsible AI statement, no named owner accountable for model behaviour, no pre-release evaluation regime, no testing results, and nothing at all on bias in the AI Co-pilot or the questionnaire processing tool. The distinction matters because it is the vendor's own mechanism that this axis asks about, and a customer-facing AI Act workflow is not a disclosure about the supplier. Surfaces checked on 4 September 2026: the home page, the product overview, the compliance product page, the pricing plan table, the GDPR framework page, the DPIA page and the site footer inventory, which lists no responsible AI or AI governance disclosure page. The AI-Powered Automation page did not render and was partially recovered through search; the Trust Center was not reached. Row written 4 September 2026.

OneTrust
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

A governance framework with real substance is published and its results are not. The trust centre states that OneTrust's AI governance programme is managed by an interdisciplinary AI Governance Committee, supported by AI governance processes across the organisation and the AI systems lifecycle, an internal AI use policy and employee training. That is an accountable body, a lifecycle scope and two named instruments rather than a list of adjectives, and it is backed by a dedicated Responsible AI section, a published Journey to AI Governance toolkit and an AI Systems Transparency Report. Two things keep it below the top band. No individual is named as accountable, the committee being identified only by function. And nothing has been disclosed about uneven output: no bias evaluation, no testing regime and no result appears on any public surface, which is a notable gap for a vendor whose own product sells bias and drift monitoring to others. The AI Systems Transparency Report is available on request rather than published, so it sits in the middle disclosure tier and its contents were not read.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

DataGuard
CC on AI Safety and Data StewardshipA generic privacy policy covers the product without addressing what happens to documents and prompts after processing.

Two limbs are answered and the rest could not be read. Access control is published as product substance rather than assertion, with single sign-on, granular user permissions and a dedicated Admin and Access Controls feature group in the plan comparison, plus role-based permissions reported in the platform's feature set. A trust centre exists at trust.dataguard.com, publishes an ISO 27001 Statement of Applicability and reports, and states its own access route plainly: documents are requested by entering an email address and the team reviews requests within 24 hours. Beyond that the set is unestablished. No retention period, no deletion commitment, no subprocessor list and no incident or breach notification practice for DataGuard's own processing was located, which is a conspicuous gap on a vendor whose product sells incident and breach management to others. As on the confidentiality axis, the reason is stated rather than dressed as an absence: both privacy policies returned no body text across three attempts, and the trust centre's Controls section did not render.

OneTrust
AA on AI Safety and Data StewardshipRetention, deletion, access control, subprocessors and incident practice are all published, current, and specific enough to hold the vendor to.

Every limb this band names is published, current and specific enough to hold the vendor to, and this is the strongest stewardship record located in the corpus. Retention is customer-configurable rather than merely stated, with services shipping built-in data minimisation functionality including auto-deletion and retention periods, and OneTrust expressly encouraging customers to configure them down. Deletion is contractual and time-bounded: customers may delete or export their data in a structured, commonly used and machine-readable format at any point during the term and for up to sixty days after termination, after which remaining data is deleted under a destruction policy. Access control runs through customer-administered user access plus ISO 27001, 27017 and 27701 certification, with the security obligations set out in Appendix 1 of the published DPA. Subprocessors are maintained on a list with a thirty-day advance notice commitment for changes and a right to object on reasonable data protection grounds, remedied by an alternative provider or termination of the affected subscription. Incident practice is stated: notification without undue delay, continuing updates on material developments, and cooperation with the customer's own reporting obligations. Encryption is given concretely at AES-256 at rest and in backup and a minimum of TLS 1.2 in transit, and the trust centre publishes a 2026 penetration test executive summary alongside disaster recovery and business continuity exercise memos. The one soft edge is that the subprocessor list itself sits on the customer portal rather than the open trust centre.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

DataGuard
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

No customer agreement is published anywhere on the site, and this rests on an established page inventory rather than on a failed fetch. The footer carries exactly four legal links: Privacy Policy, Legal Notice, Cookie Policy and Trust Center. The Legal Notice is the Impressum that German law requires of any commercial website and does not govern the customer relationship. There are no terms of service, no general terms and conditions or AGB, no master subscription agreement, no service level document and no acceptable use policy in the navigation, the footer or anywhere else in the site map. No indemnity, liability cap, warranty, uptime commitment or insurance position could therefore be located. A buyer evaluating a platform that will hold its record of processing, its breach register and its certification evidence, and that may supply its nominated Data Protection Officer, has nothing to read on allocation of loss before entering a sales conversation. Checked the full navigation and footer across four rendered pages on 4 September 2026.

OneTrust
AA on AI Liability and RecourseWhat the vendor stands behind when its output is wrong is published and specific: indemnity scope, caps, carve outs, and any insurance or warranty a buyer can actually invoke.

What the vendor stands behind is published, specific, versioned and independently assessed, which no other record in this pull matches. The Master Terms of Service are published in full at a dedicated legal centre, currently version 5.1 effective 23 March 2026, with every prior version back to August 2020 downloadable alongside the DPA, Standard Contractual Clauses, Business Associate Agreement and product-specific supplemental terms. The liability position is stated and benchmarked rather than buried: a cap on each party's liability equal to the total annual fees paid or payable in the preceding year, which OneTrust expressly notes is broader than the more common cap tied to fees for the applicable service only, with willful misconduct and intellectual property claims carved out and uncapped. An indemnity with stated scope covers third-party IP infringement claims arising from use of the cloud services, with OneTrust controlling the defence. A warranty a buyer can invoke commits the cloud services to conform materially to the User Guide throughout the term. OneTrust also publishes a plain-language explainer, Contracting with OneTrust, setting all of this out for a reviewer, and states plainly what it will not do, refusing uncapped liability for data breach and giving its reasoning. The Master Terms carry an independent TermScout assessment rating them 70 per cent customer favourable with a perfect score against buy-side deal breakers. What is absent is anything specific to AI output being wrong and any insurance position.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

DataGuard
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Named integrations with documentation an implementer could work from, scoped to one module. The published developer documentation covers the Consent and Preference Management product and names its integrations individually with setup guides for each: Salesforce, HubSpot and Microsoft Dynamics for CRM; Braze, Brevo, Mailchimp and Salesforce Marketing Cloud for marketing automation; Auth0 and Ping Identity for identity; Snowflake for data warehousing; FormAssembly, Formstack and WordPress Contact Form 7 for forms. Alongside those sit a documented REST API with an OpenAPI reference and Postman collection, webhooks, bulk data export, import and deletion endpoints, embeddable JavaScript widgets, native and webview mobile integration paths, and single sign-on via Azure Active Directory, SAML and OpenID Connect. Two limits hold this below the top band. The documentation covers the consent module only, which is sold as an add-on rather than as the core platform, and it sits on a separate domain carrying the branding of an acquired product, last updated November 2024. The main platform's own Integrations page was not opened in this pass.

OneTrust
CC on Practice Systems Integration DepthIntegrations are listed as logos or marked as coming, with no documentation an implementer could use.

Integration is plainly a real part of the offering and no individual connection could be named from the surfaces read. A dedicated Integrations page sits in the platform navigation and is described as an extensive set of integrations for adding data management to existing workflows, the Third-Party Management package refers to automating vendor assessments with ecosystem integrations, the Consent product is described as scaling through APIs to collect and enforce consent across emerging channels, and some services ship components that a customer implements on its own systems and websites such as cookie consent scripts and data discovery agents. OneTrust is additionally distributed through the Azure Marketplace, which has its own published supplemental terms. What is missing is the naming and the depth: no specific system is identified anywhere on the pages read, no API reference or developer documentation was located, and nothing describes what moves in which direction. **The Integrations page was not opened on 1 September 2026**, so this grade is rebuttable upward on one fetch and is recorded conservatively rather than assumed.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

DataGuard
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Cloud delivery is implied throughout and neither the tenancy model nor a region is stated. European positioning is heavy and consistent, with the company describing itself as the European leader in security and compliance software, operating from Munich, and marketing secure hosting and infrastructure built to meet strict GDPR requirements. None of that is a residency statement: no country, region or data centre is named for where customer data is stored or processed, and secure hosting built for GDPR describes an intention rather than a location. The nearest the published material comes is an enterprise-tier reference to multinationals needing region-specific configurations, which describes a configuration capability rather than a residency option a buyer could select. Nothing states whether the platform is single or multi-tenant, no dedicated or private deployment is offered at any tier, and no separation is drawn between where data sits and where any AI processing happens.

OneTrust
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

The tenancy model is stated plainly, residency is offered, and the processing question is left open. The published contracting explainer describes cloud services delivered on a shared architecture, codebase and infrastructure, with customer data held in a logically-separated cloud database and each customer receiving a single production tenant environment, with non-production environments included in some subscriptions and further environments purchasable. Residency is a customer choice: customers can select from various geographic hosting locations for their tenant environment. What changes between tiers is also addressed, with HIPAA-compliant and PCI-compliant environments available for customers with specialised requirements, backed by a published PCI attestation of compliance and a HITRUST certification. Two things hold it below the top band. The available regions are referred to collectively rather than enumerated, so a buyer cannot see the list without asking. And where processing happens is nowhere distinguished from where data is stored, which matters for the AI features specifically since no model or provider is identified.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

DataGuard
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

A real trust centre with a self-serve access route, short of the naming a top grade needs. The portal at trust.dataguard.com renders, is publicly linked from the site footer, and states its own access mechanism plainly, which is the thing most portals leave ambiguous: documents are requested by clicking the document and entering an email address, requests are reviewed by the team typically within 24 hours, and anything not listed can be requested by email. That is a self-serve request fulfilled without a sales conversation rather than a form promising an account executive, which is the distinction that earns credit. One artifact is named specifically and is DataGuard's own ISMS document rather than a badge: an **ISO 27001 Statement of Applicability**, alongside a Resources section listing Reports. What is missing from the top band: no certifying body or auditor is named, no certificate number, scope or observation period is published, no date or validity period appears, and the Reports entry is generic so a buyer cannot tell which reports exist before asking. The Controls section of the portal did not render.

OneTrust
AA on Security Certifications and Trust CenterCurrent independent attestation with named scope, reachable without a sales call: a trust center carrying reports, dates and the standards actually covered.

This is the trust centre the band describes and the first record in this pull to reach the top of this axis. Attestations are current, independent, and downloadable directly as PDFs with no form, no email capture and no NDA click-through: a SOC 2 Type II report, a second SOC 2 Type II for Certification Automation, ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 27017 and ISO 9001 certificates, and, decisively for the scope limb, **a published Statement of Applicability** setting out which controls are in scope. Industry and sector records sit alongside them: a PCI DSS attestation of compliance signed November 2025 with a third-party responsibility matrix, a HITRUST certification letter, TISAX, TX-RAMP, the Spanish ENS conformity statement, and a CAIQ v4.0.3 self-assessment lodged on the Cloud Security Alliance STAR registry. Security documentation goes beyond certificates to a 2026 penetration test executive summary, a completed standard SIG questionnaire, a security, privacy and architecture whitepaper, and disaster recovery and business continuity exercise memos, with a live system status page. Under the gated-is-not-absent tiers this is open publication rather than the self-serve request tier, which is what separates it from every other record graded on this axis so far.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

DataGuard
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

The vendor refers to its AI capability repeatedly and never identifies what sits underneath it. AI-Powered Automation is a named platform pillar, AI Co-pilot and an AI-assisted questionnaire processing tool appear as line items in the published plan table, and AI-powered automation is the phrase used in the organisation description carried in schema markup across every page. Against that, no model is named, no provider is identified, no version is given, no hosting or processing location is stated for the AI leg, and no commitment to notify customers when any of it changes was located. A buyer can establish that the platform uses AI and nothing about whose AI it is, which is the substance of this band. The company is DataCo GmbH of Munich and the platform is sold on European data protection positioning, which makes the absent processing location a more pointed gap than it would be elsewhere. Surfaces checked on 4 September 2026: the home page, the product overview, the compliance product page, the pricing plan table and the footer inventory. A Trust Center is linked in the footer and was not reached in this pass; it is the surface most likely to carry a subprocessor register naming a model provider, and is the cheapest available upgrade on this record. Row written 4 September 2026.

OneTrust
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

AI use is confirmed and nothing underneath it is identified publicly. The Master Terms answer the question of whether OneTrust uses artificial intelligence in the services with a plain yes, and direct the reader to the AI Systems Transparency Report, described as available upon request. No model, model family, provider or architecture is named on any public surface read on 1 September 2026, and no statement excludes a third-party foundation model either, so a customer cannot tell from published material whose model processes the assessments and documentation it generates. Where inference runs is not addressed separately from where data is stored. No commitment to notify customers when the model set changes was located, though the subprocessor change process does carry a thirty-day notice commitment and would capture a model provider engaged as a subprocessor. This sits above the bottom band because a dedicated transparency artifact exists and is obtainable rather than absent, which is the middle disclosure tier, and below the band above because nothing is actually named where a reader can see it.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

DataGuard
CC on Commercial TransparencyPricing is gated behind a demo request while tier names and feature splits are published, so the shape is visible and the number is not.

Unusually detailed package structure with no figure and no unit of charge anywhere. What is published is genuinely useful: three named tiers with stated audiences, Base as the platform alone for teams with internal expertise, Pro adding hands-on access to in-house experts, Enterprise for complex multi-entity needs; a feature comparison running across roughly fifteen areas covering ISMS documentation, training, risks, controls, vendor management, assets, trust management, admin controls, onboarding, expertise, the annual security programme and information security officer support; explicit markers showing which capabilities require the advanced platform or a dedicated expert; and seven named add-ons that establish what costs extra, including consent management, cookie management, whistleblowing, global legal analysis, exposure management, external Information Security Officer and external Data Protection Officer. A buyer can therefore work out precisely what is in and out of each tier. What no buyer can learn is what any of it costs, or even how it is metered: every tier and every route resolves to Get a quote, and no figure, band, range or charging unit appears anywhere. Nothing states whether pricing runs per seat, per entity, per framework or per employee.

OneTrust
BB on Commercial TransparencyReal pricing is published for part of the range, with enterprise tiers withheld, or the unit and structure are stated without the figure.

The unit and the structure are published in more detail than anywhere else in this corpus, and no figure appears. A dedicated pricing and packaging page sets out nine named packages across five solution families, each with its key capabilities listed so the feature split between base and suite editions is visible, and, unusually, **each with its own charging meter stated explicitly**: AI Governance priced on admin users and AI inventory; the Consent Management Platform on average daily visitors aggregated across channels and properties; Universal Consent and Preference Management on total data subject profiles captured; Privacy Automation on users and privacy asset inventory; Tech Risk and Compliance on admin users and asset inventory; and Third-Party Management on admin users and third-party inventory. Published FAQs explain what a solution package is, that pricing runs on value-based usage meters, and that a tiered model applies with an account executive moving a customer up a tier when usage consistently exceeds limits. What is absent is the number: no rate, band, floor or currency appears anywhere, every package routes to a Get Pricing form, and nothing states what implementation or professional services add.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

DataGuard
CC on Firm and Practice CoverageCoverage is claimed broadly, for all firms or all practice areas, without evidence that the breadth is real.

Coverage is described by regulatory framework and by company size, and the buyer this index cares about is never addressed. The framework dimension is precise and is the product's real organising principle: GDPR and UK GDPR, ISO 27001, NIS2, TISAX and the EU AI Act, each with its own page, with multi-entity and multi-framework operation named as a capability and 4,000 organisations across 50 or more countries claimed. The segmentation dimension is thin and revealing. **The Solutions menu contains exactly two entries, DataGuard for SMEs and DataGuard for Corporates**, so the only buyer axis the vendor publishes is headcount. No legal, in-house counsel, data protection officer or compliance function page exists, no role is addressed by title anywhere, and no case study was read that would identify who inside a customer owns the tool. That absence is what makes the membership screen turn on function rather than on the buyer surface, and it is recorded here because it is also a coverage finding: a reader of this index cannot learn from DataGuard's own material whether the legal department is the intended owner.

OneTrust
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Coverage is described across three deliberate axes with substance behind each, and the boundary is left open. Solutions are organised by function into six families, by role into data, marketing, privacy, and security and risk teams, and by regulation with dedicated pages for GDPR, US privacy law and the EU AI Act plus a wider regulatory index. Practice depth is real: the Tech Risk and Compliance package cites templates and guidance across more than fifty standards, regulations and frameworks, the AI Governance package names the EU AI Act, NIST and ISO 42001 as the frameworks assessments align to, and third-party screening reaches politically exposed persons, sanctions and watchlists through Dow Jones data. The customer base spans regulated industry, retail, pharmaceutical, technology and non-profits on the published logo set. Two gaps keep it here. Nothing states where the product stops, with no statement of organisation size, data volume or the situations it does not fit. And the By Role navigation, which is where a legal buyer would look, offers privacy, security and risk, data and marketing teams and **no page for legal or counsel**, even though the product's own published workflow assigns a legal reviewer.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

DataGuard
Terms silent

No statement either way could be located, and the reason is a retrieval limit rather than established vendor silence. DataGuard publishes two privacy documents, a general Privacy Policy and a separate Privacy Policy: Platform at /privacy-policy-platform/, and the second is the one that would govern customer content in the product. Both returned navigation, footer and schema markup with no body across three attempts on 4 September 2026, while the home page and pricing page rendered fully on the same day, so this is page-specific rather than a site-wide block.

A search built on the document titles recovered only the same schema markup and no clause text. Nothing on the readable estate addresses training on customer content: the AI Co-pilot and the AI-assisted questionnaire processing tool are described as plan features without any accompanying data commitment, and the Trust Center linked in the footer was not reached. This row records what could be located as of 4 September 2026 and is not a finding that DataGuard permits training or that it says nothing. Recovery of either privacy policy would be applied as an amendment with its own date.

OneTrust
Terms silent

No located term or policy addresses the question either way, which is the single most surprising gap on this record. OneTrust publishes a Master Terms of Service, a Data Processing Addendum and Standard Contractual Clauses openly with full version histories, confirms in the contracting explainer that artificial intelligence is used in the services, and states that personal data is processed only for the limited purposes described in the agreement and that customer personal data will not be bought or sold.

None of that reaches model training. The purpose limitation is the nearest thing and it is a general processing restriction rather than a training prohibition, and it is expressed over personal data rather than over the assessments, policies and inventories a customer builds in the platform. The document that would answer it, the AI Systems Transparency Report, is described as available upon request rather than published.

Searched the trust center, the legal center including the contracting explainer, the pricing page and the home page on 1 September 2026.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

DataGuard
Not addressed

No retention period for prompts, outputs or uploaded content was located on any readable surface. The documents that would carry it are the Privacy Policy and the Privacy Policy: Platform, both of which returned navigation, footer and schema only across three attempts on 4 September 2026 while other pages on the same domain rendered fully. The readable estate describes the AI features functionally and never touches retention: the plan table lists the AI Co-pilot and the AI-assisted questionnaire processing tool without any data handling terms, and the product pages cover evidence collection, control monitoring and assessment templates rather than what happens to material after processing.

No deletion route, no configurable window and no default period appears anywhere reachable. The Trust Center was not reached and may carry it. Recorded as located on 4 September 2026; this states the limit of what is establishable rather than asserting the vendor has published nothing.

OneTrust
Customer controlled, no zero option

Retention is under the customer's control as a product configuration rather than a contractual instruction, which is rarer than the value name suggests. The published contracting explainer states that some services include built-in functionalities for data minimization including auto-deletion and retention periods, and that OneTrust encourages customers to configure the services to reduce the amount of personal data held in its environment at any point.

Alongside that sits an explicit deletion and portability right: customers may delete or export their data in a structured, commonly used and machine-readable format at any time during the subscription term and for up to sixty days after termination, after which remaining data is deleted under a destruction policy. What is not stated is a zero-retention option, and no separate window is published for AI prompts or generated assessments as distinct from customer records generally.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

DataGuard
Own model, documented

DataGuard operates its own permission model and publishes it as product substance. The plan comparison names single sign-on and granular user permissions together under an Admin and Access Controls feature group available across tiers, and role-based permissions appear in the platform's documented feature set. The consent module's developer documentation adds the mechanics on that side, with single sign-on via Azure Active Directory, SAML and OpenID Connect, API authentication and separate environments.

Multi-entity operation is published as a capability, which is the mechanism by which a group separates one subsidiary's compliance program from another's. What is not published is how those permissions map to a wall in practice, and nothing addresses separation between engagements where DataGuard's own consultants have access under the Pro tier or as a nominated external Data Protection Officer, which is the segregation question this hybrid model actually raises.

OneTrust
Own model, documented

OneTrust operates its own documented permission and separation model, and it is described at the tenant and user level rather than below it. The contracting explainer states that customer data is held in a logically-separated cloud database, that each customer receives a single production tenant environment for all subscribed services, and that the customer's own users control access to the cloud services as well as the volume and types of data submitted, with OneTrust not having specific access to what a customer chooses to submit.

ISO 27701 certification covers the privacy information management system around it. What is not addressed is separation inside a single customer account: nothing describes walls between teams, business units or matters, which is a live question because the published workflow routes a single AI use case to privacy, security and legal reviewers who sit in different functions.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

DataGuard
Not addressed

Nothing located addresses compelled disclosure or customer notice. The evidence home for this signal is the confidentiality section of a master agreement or the law enforcement section of a privacy policy, and neither is reachable: DataGuard publishes no customer agreement on its site, and both privacy documents returned navigation, footer and schema only across three attempts on 4 September 2026. The readable surfaces carry nothing adjacent, with no transparency report, no government request statement and no disclosure practice described on the home page, the product pages, the framework pages or the pricing page.

The absence is worth stating precisely because the vendor is a German controller-side privacy specialist whose own customers buy it to handle data subject and authority interactions, so the question is squarely within its subject matter. Recorded as located on 4 September 2026, with the retrieval limit named; recovery of either policy or of a customer agreement would be applied as an amendment.

OneTrust
Notice committed

A position is published, a transparency report exists, and the notice limb rests on a document other than the customer agreement. The contracting explainer states that OneTrust does not voluntarily disclose or grant access to any personal data of its customers to government authorities unless required by law, and directs the reader to a published policy and transparency report on government and law enforcement requests.

The notice commitment located sits in the Mutual Nondisclosure Agreement, which provides that confidential information may be disclosed as required by law or valid legal order after using reasonable efforts to provide notice of the disclosure; that document governs pre-contract confidential information rather than platform data. The Data Processing Addendum PDF, which is where a notice commitment for customer data would sit, was not opened on 1 September 2026, so this row may move up to notice and report on reading it.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

DataGuard
Jurisdictions only

The regulatory material behind the product is described by framework rather than by source. The frameworks covered are named individually and consistently across the site: GDPR, UK GDPR, ISO 27001, NIS2, TISAX and the EU AI Act, delivered through pre-built policy templates, off-the-shelf risk and control libraries and guided workflows, with a global legal analysis add-on that tracks legal requirements and regulatory developments.

That tells a buyer which regimes are in scope, which is the jurisdictional description this value records. What is absent is identification of the underlying material: no regulatory data source, publisher or feed is named, no update cadence is published for the template and control libraries or for the legal analysis add-on, and no licensing basis is stated for any standard reproduced in the platform, which is a live question for ISO 27001 and TISAX content specifically since both are proprietary and the site separately disclaims any affiliation with the ENX Association that owns TISAX.

OneTrust
Sources named, basis unstated

The product does not retrieve primary law, and the reference datasets it does carry are named, which is more than most vendors manage. Three are identified on the pricing page: a database of more than 45 million categorized cookies and trackers behind the consent product; risk intelligence data on millions of third parties behind third-party management; and, named to its provider, Dow Jones ethics and compliance databases supplying politically exposed person, sanctions and watchlist screening in the Third-Party Management Suite.

Regulatory change intelligence is attributed to DataGuidance within Privacy Automation. What is absent is the rights basis: no license, ownership or public-domain footing is stated for any of them, and no update cadence is published beyond the claim that inventories are evergreen. Checked the pricing and packaging page, the home page and the trust center on 1 September 2026.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

DataGuard
Not addressed

Currency is addressed as a product capability rather than as verification of authority. The platform is sold on staying current with changing regulation, with a global legal analysis add-on that tracks legal requirements and regulatory development, framework libraries maintained across GDPR, ISO 27001, NIS2, TISAX and the EU AI Act, and continuous monitoring and periodic review workflows. None of that is the check this signal measures: nothing states how or how often the underlying regulatory content is updated, no effective-date or version indicator on template or control content is described, nothing flags when a requirement a customer has already mapped has changed, and no verification prompt exists.

The product does not retrieve or cite primary legal authority, so the question lands obliquely, but for a compliance platform the equivalent risk is real, since a control library that has fallen behind a regulation is the same failure in a different form.

OneTrust
Not addressed

No citator applies and the row is recorded rather than skipped. The platform does not return legal authority whose subsequent history could be checked; it maintains registers, runs assessments and enforces controls. The nearest analog is regulatory currency rather than treatment: Privacy Automation is described as helping customers understand the operational impact of regulatory changes through DataGuidance intelligence, and the AI Governance package aligns assessments to named frameworks including the EU AI Act, NIST and ISO 42001, so the platform tracks whether a requirement has moved without purporting to tell a user whether an authority still stands.

Searched the pricing and packaging page, the home page, the trust center and the published contracting explainer on 1 September 2026.

Refusal and Uncertainty Behavior

What does the product do when the answer is not in the corpus?

DataGuard
Not addressed

No located public material describes what the AI does when it cannot answer reliably. Nothing describes an abstention path, a no-answer state, or a confidence or grounding signal surfaced against output from the AI co-pilot or the AI-assisted security questionnaire tool. The nearest published concept is the experts-in-the-loop tier, under which DataGuard's certified consultants step in for complex decision-making and strategic review, but that is a commercial escalation to human help rather than a description of the system's own behavior under uncertainty, and it is available only from the Pro plan upward.

Recorded as a limit on this row: the dedicated AI-Powered Automation page returned navigation and a single line of body text, and the Experts-in-the-Loop page was not opened. Searched the home page, pricing page, trust center and the published consent documentation on 4 September 2026.

OneTrust
Not addressed

Nothing located describes what the AI does when it cannot assess reliably. The published workflow shows an AI-assisted assessment returning a risk summary graded medium with findings graded medium and low, so the output carries a severity rating, but a risk grade is a conclusion about the subject rather than a statement of the model's own confidence, and nothing indicates what a user sees when the system cannot reach one.

No abstention path, confidence score or coverage indicator is documented. The structural mitigation is the approval gate rather than a model behavior: every assessment routes to named human reviewers before a use case proceeds, so an uncertain output is caught by process rather than flagged by the system. Searched the home page, the pricing and packaging page, the trust center and the contracting explainer on 1 September 2026.

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

DataGuard
None located

The AI Hallucination Cases database maintained by Damien Charlotin was searched on 4 September 2026 on both the product name DataGuard and the corporate name DataCo GmbH. No court order, opinion or disciplinary record naming the product was located. The database tracks fabricated legal citations in court filings, and this product supports compliance program management rather than producing court submissions, so its exposure to that specific failure is structurally low. This records the state of the public record on that date and is not a finding about the product.

OneTrust
None located

Searched the AI Hallucination Cases database maintained by Damien Charlotin at HEC Paris, together with 2026 sanctions trackers and trade coverage, on 1 September 2026, on the company name. No court order, opinion or disciplinary record naming OneTrust was located. This is a statement about the public record rather than a finding about the product. The failure mode this signal tracks fits poorly: the platform's AI output is a risk rating or a piece of model documentation consumed inside a governance workflow and gated by human approval, not a citation to legal authority prepared for filing, so the analogous exposure would be a mis-rated assessment surfacing in a regulatory examination rather than in a court.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

DataGuard
Not addressed

No located public material engages professional guidance or any professional authority. The regulatory frameworks the product serves are named throughout, but a framework is the subject matter of the compliance work rather than guidance on how a professional should use software in that work. No bar association, law society, supervisory authority, data protection authority or professional body is named, no guidance or opinion is cited, and nothing addresses the professional obligations of a Data Protection Officer using the platform or of DataGuard's own personnel when nominated to that statutory role under the external Data Protection Officer add-on.

The European Data Protection Board and national supervisory authorities publish directly relevant guidance and none is referenced on any surface read. Searched the home page, pricing page, product overview, trust center and consent documentation on 4 September 2026.

OneTrust
Not addressed

No engagement with professional responsibility or ethics guidance was located, which is worth separating carefully from what OneTrust does publish. The company engages extensively with regulation as subject matter, naming GDPR, US state privacy laws, the EU AI Act, NIST, ISO 42001, DORA and more than fifty standards and frameworks in its packages, and maintains a public glossary of AI governance and privacy terms. None of that is guidance binding the professional who relies on the output.

Nothing references ABA Formal Opinion 512, any state bar opinion, Law Society or SRA guidance, or any equivalent addressed to counsel using AI tools, and no general statement that a user's own professional obligations survive use of the platform was found. Searched the home page, the trust center, the pricing page, the legal center and the published contracting explainer on 1 September 2026.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

DataGuard
Outside the fee relationship

Efficiency claims are published prominently and no billing question is engaged. The stated savings are specific and repeated across pages: up to forty percent of tasks automated, seventy-five percent less manual effort, fifty percent lower costs, and certification reached up to seventy-five percent faster. Nothing addresses what happens to a fee when that work compresses. The question has a particular shape here because DataGuard sells advisory time alongside software through the Pro tier, the dedicated expert upgrades and the external officer add-ons, so automation of the platform work bears directly on the advisory hours a customer buys, and nothing published addresses that relationship.

No per-engagement record of AI-assisted work is described. Recorded alongside the claims: DataGuard's own site footer states that all such figures are internal estimates given without warranty as to accuracy.

OneTrust
Outside the fee relationship

Savings are quantified and billing treatment is never addressed. A commissioned Forrester Total Economic Impact study is promoted with a 227 percent three-year return on investment and a seven-month payback, and the GOL customer story gives operational time reductions from thirty days to five or fewer for vendor approval and from a fortnight to minutes for request completion. The buyer is an in-house privacy, legal or risk function rather than a firm billing a client, so the fee question lands obliquely, but it is not absent: outside counsel and consultancies use platforms of this kind on client engagements, and nothing published addresses how AI-assisted assessment work should be disclosed or billed where that happens.

No per-matter record of AI-assisted work is described for that purpose, as distinct from the audit-ready evidence the product generates about a customer's own AI systems.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

DataGuard
On request only

A working request route exists and the artifacts behind it could not be established. The trust center at trust.dataguard.com is publicly linked, renders, and publishes its own access mechanism: documents are requested by entering an email address, requests are reviewed typically within 24 hours, and anything not listed can be requested by email to the company. An ISO 27001 Statement of Applicability is named and a Reports section exists.

That is a genuine on-request route fulfilled without a sales conversation, which is what this value records. What could not be established is whether it reaches the material a client's AI clause asks for: no subprocessor list was located, no data processing agreement is published, no model provider is identified anywhere, and the portal's Controls section did not render. Both privacy policies returned no body text across three attempts, so nothing forwardable on data handling could be read in advance.

OneTrust
On request only

Half of what a client's AI clause asks for is openly published and the half about AI is obtainable rather than public. On the open side, and this is unusually strong: the Data Processing Addendum, the Standard Contractual Clauses and the Master Terms are all downloadable from the legal center without an agreement in place, with full version histories, which is precisely the forwardable contractual material the signal contemplates.

On the gated side, the subprocessor list is maintained on the customer portal rather than the open trust center, though with a thirty-day advance notice commitment for changes and a right to object on reasonable data protection grounds. And **no model provider is named anywhere**: the AI Systems Transparency Report is described as available upon request. Under the coverage test a firm therefore cannot tell its client which systems see its content without first contracting or requesting, which is what places this at the request tier rather than higher.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

DataGuard
Partial record

Audit-grade recording is core product function and none of it is described as covering the AI. What the platform produces is substantial and is the point of buying it: automated evidence collection, control monitoring, audit-ready reporting, periodic reviews, internal audit functionality under the expert tiers, and, in the consent module, an explicit audit trail of consent transactions with a documented data export endpoint.

A customer can therefore evidence what its compliance program did and when. What is absent is the model dimension entirely: nothing states that output from the AI co-pilot or the AI-assisted questionnaire tool is marked as AI-generated in the record, no model or version is captured against an entry, no record of what a human reviewed or amended before an entry became evidence is described, and no guidance exists for disclosing AI involvement to a certification auditor or supervisory authority. That gap sits directly against the product's purpose, since the evidence it generates is presented to auditors.

OneTrust
Partial record

There is an inversion worth naming here: OneTrust sells the capability to produce exactly this record about a customer's own AI, while its own equivalent is available on request. The AI Governance package automates model documentation, audit-ready evidence and regulatory reporting outputs, configures approvals, attestations and evaluation gates, and correlates runtime behavior with purpose, data sensitivity and regulatory obligations, which is a disclosure record about the customer's systems.

For OneTrust's own AI, the published workflow logs a review and approve step naming privacy, security and legal reviewers, so who signed off is captured. What is not established is whether that record identifies which output was machine-generated or which model produced it, and no document-level export covering model, sources and verification is described. OneTrust's own AI Systems Transparency Report is available upon request rather than published.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.

Signals neither addresses in public material
  • Good Law Verification
  • Refusal and Uncertainty Behavior
  • Bar Guidance Alignment

Which one fits

Choose DataGuard if

  • You want consultants and software from one supplier. DataGuard's Pro plan adds hands on access to its own certified consultants, and separate options let you nominate DataGuard as your external data protection officer or information security officer.
  • You run several European frameworks at once. DataGuard supports GDPR and UK GDPR, ISO 27001, NIS2, TISAX and the EU AI Act together across multiple entities, with template libraries and guided workflows aimed at certification.
  • You need consent synced into marketing and CRM tools. DataGuard's consent module documents integrations with Salesforce, HubSpot, Microsoft Dynamics, Braze, Mailchimp and Snowflake, with a REST API, webhooks and setup guides for each.

Choose OneTrust if

  • Legal wants to read the contract before a demo. OneTrust publishes its master terms, data processing addendum and standard contractual clauses with every version since 2020, including a liability cap equal to a year's total fees and an intellectual property indemnity.
  • Security wants reports without a sales call. OneTrust's trust center offers its SOC 2 Type II report, ISO 27001, 27017 and 27701 certificates with a statement of applicability, and a 2026 penetration test summary as direct downloads.
  • You need to know what drives the bill. OneTrust publishes nine packages with the meter for each, such as admin users and AI inventory for AI Governance and average daily visitors for consent management, though no figure.

In summary

DataGuard

DataGuard, the trading name of DataCo GmbH of Munich, founded in 2018, is a European security and compliance platform that runs a privacy program and an information security management system together: records of processing, subject requests, impact assessments, breach and consent management, policies, controls, risk and training. It supports GDPR, ISO 27001, NIS2, TISAX and the EU AI Act, carries an AI copilot, and sells its own consultants and external officer roles alongside the software. The AI Legal Index grades it in the top two bands on two of fifteen capability axes, integration depth and security certifications. As of 4 September 2026 the index located no customer agreement, named model or price.

Source: AI Legal Index, 2026

OneTrust

OneTrust, based in Atlanta, sells a governance platform for privacy, data and AI across five solution families: privacy automation, consent and preferences, AI governance, technology risk and compliance, and third party management with Dow Jones screening data. AI assists inside the platform, with AI generated risk assessments routed to privacy, security and legal reviewers. The AI Legal Index grades it in the top two bands on ten of fifteen capability axes, with A grades on data stewardship, liability and security certifications. It publishes its master terms and data processing addendum with version histories and reports more than 14,000 customers. As of 1 September 2026 the index located no training position or named model.

Source: AI Legal Index, 2026

Questions buyers ask

DataGuard vs OneTrust: which privacy platform is better?

On published evidence OneTrust sits in the top two bands on ten of fifteen AI Legal Index capability axes and DataGuard on two of fifteen, identical on two, largely because OneTrust publishes its contracts and security reports. DataGuard's distinctive offer is people: its own consultants and an external data protection officer service sold with the software. Teams wanting outsourced expertise have reason to look at DataGuard.

Can DataGuard act as our data protection officer?

DataGuard sells an option under which a customer nominates DataGuard as its external data protection officer, with an equivalent external information security officer option. Nothing it publishes explains how the officer's independence is kept when the same company also supplies the compliance platform being assessed, and it publishes no customer agreement setting out the terms. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.

Does OneTrust train AI on customer data?

Its published agreements do not say either way. OneTrust's data processing addendum limits processing of personal data to the purposes in the agreement and rules out buying or selling it, but no term addresses model training, and its AI Systems Transparency Report is available only on request. DataGuard's privacy policies could not be read on this index's check. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.

Where can I get OneTrust's and DataGuard's security reports?

OneTrust's trust center offers its SOC 2 Type II report, ISO 27001, 27017 and 27701 certificates, a statement of applicability and a 2026 penetration test summary as direct downloads. DataGuard's trust center releases its ISO 27001 statement of applicability and reports when you enter an email address, with requests typically reviewed within 24 hours. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.

What do DataGuard and OneTrust both leave unpublished?

The price and the model. Neither publishes a rate or figure for any package, and neither names the model or provider behind its AI features. Neither states what its AI does when it cannot reach a reliable answer, and neither addresses where its tool stops and legal advice begins. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.

Disclosure

Three readings to weigh. DataGuard's privacy policies did not render on this index's check, so its training and retention positions may be answered there; its absent customer agreement is a published fact. OneTrust's published agreements do not say whether customer content trains its AI, and its AI Systems Transparency Report is available only on request. OneTrust's figures from a commissioned Forrester study and a named customer carry no dates. DataGuard was verified on 4 September 2026 and OneTrust on 1 September 2026. Neither vendor reviewed this page.

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 303 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 24, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746