OneTrust vs TrustArc: how they compare in 2026
OneTrust and TrustArc both sell privacy management to in house privacy, legal and compliance teams: consent, data mapping, assessments and regulatory research, now with AI added. The grid does not separate them. Each sits in the top two bands on ten of fifteen axes. The tie splits once you know what the buyer needs to see. A procurement team that runs on paperwork will find more from OneTrust, which holds A grades on security certifications, data stewardship and liability: its SOC 2 Type II report, ISO certificates and a Statement of Applicability download with no form, and its versioned Master Terms cap each side at a full year of fees across the platform. A privacy team whose first question is the AI itself will find more from TrustArc. Its Terms of Use for AI Features, part of the customer agreement, state that customer data will not be used for model training or improvement, and map each AI feature to its provider, with Microsoft, OpenAI, Google Cloud and Anthropic among them. On the same question, OneTrust's published documents say nothing either way.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
Artificial intelligence is present, shipped and contractually confirmed, and it is a layer on a product whose value stands entirely without it. The core is registry and workflow software: a data and activity map, consent banners and preference centres, data subject request automation, vendor and third-party inventories, assessment templates across more than fifty standards, and policy approval workflows. Remove every model and all of that continues to work, which is the distinction this axis asks about. Where AI appears it accelerates an existing step rather than constituting one, with an AI-assisted risk assessment producing a summary and key findings that then route to human approval. Worth separating two things that are easy to conflate here: OneTrust sells AI governance as a subject matter, maintaining registers of a customer's models, agents and datasets and applying runtime controls to them, and that is the product managing someone else's AI rather than the product being AI. The Master Terms confirm the vendor's own use, answering the question of whether AI is used in the services with a plain yes.
Artificial intelligence is present and peripheral by the vendor's own construction. The Terms of Use for AI Features state that use of any AI-enabled feature is strictly optional, that no customer data is processed by AI technologies unless the customer uses such a feature, and that the customer may discontinue them at any time; Table 1 lists the features as assistants, lookups, autofill, similarity search, bulk record creation, translations and summaries layered onto PrivacyCentral, Data Mapping, Assessment Manager, Cookie Consent Manager, Trust Center and Nymity Research, each of which functions as a privacy management, assessment or research product without them. Arc Intelligence reached general availability in December 2025 on a platform in operation for decades. This is the legacy-platform case the brief asks the axis to discriminate, and it does. AI Terms, legal centre index and product navigation read 6 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is not asserted loudly and it is not measured either, and the document that would answer it is obtainable rather than published. The AI-assisted assessment shown on the home page produces a risk summary and graded findings across personal data processing, model accuracy and transparency, which is an output a compliance officer will act on, and no accuracy rate, benchmark, test set or error mode for it was located on any public surface. Several limbs of this axis do not bite: the product does not retrieve primary legal authority, so grounding to openable sources and citator checking are not the relevant questions, and the applicable risk is a wrong risk rating rather than a fabricated citation. The AI Systems Transparency Report is the artifact that would carry this and the Master Terms describe it as available upon request, which under the gated-is-not-absent rule is the middle tier rather than an absence, but its contents could not be read on 1 September 2026. Checked the home page, the trust centre, the pricing and packaging page and the published contracting explainer.
Accuracy is disclaimed without measurement, and grounding is to a subscription corpus the reader cannot open. The AI Terms state that TrustArc takes measures designed to ensure accuracy but is not responsible for the quality, accuracy or effectiveness of AI-generated output and that every output must be reviewed, with a subject-matter expert if needed, before use; the NymityAI research chatbot answers over the Nymity library of regulatory summaries and templates, which is licensed content rather than primary law a reader can verify without a subscription. No accuracy figure, test set, evaluation or description of how answers cite their sources is published on the surfaces read. AI Terms, product navigation and trust centre privacy notice read 6 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A review point is not merely claimed but drawn, with named roles, and the surrounding control structure is incomplete. The AI use case workflow published on the home page runs intake, then AI risk assessment, then a review and approve stage showing three pending reviewers identified as Privacy, Security and Legal, then continuous monitoring described as real-time oversight and alerts after workflow completion. That places the machine output before a human gate and says who holds it, which is more than most vendors in this lane publish. The AI Governance package reinforces it commercially, listing configurable approvals, attestations and evaluation gates before AI systems move to production, and runtime controls across prompts, outputs, data access and allowed AI actions. What is missing is the rest: nothing states what the assessment does unattended, at what confidence it defers, or what happens after it is wrong, and no statement was located about the behaviour of OneTrust's own models as distinct from the governance gates it sells.
A written commitment to human oversight with real review surfaces, short of the full control structure. AI Terms section 2.1 requires the customer to review and validate AI outputs and not rely on them for decision-making without human oversight, section 1.1 requires notice before any AI technology processes customer data and makes every AI feature optional and revocable on request, and the features themselves are assistive, with suggestions, lookups, autofill and an evidence analyser that a user accepts into an assessment or record. What is not published is any threshold at which the system acts without a person, any description of what executes automatically, or a stated route back after an output is wrong beyond the customer's own review. AI Terms and product navigation read 6 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
A named customer, a named individual and real figures are published, and nothing carries a date. The GOL customer story quotes Bruna Boccini, Head of Compliance and Data Protection Officer at the airline, and gives specific before-and-after numbers in her own account: vendor approval falling from almost thirty days to between five and zero, and request completion falling from fourteen or fifteen days to a few minutes, against a described estate of seven billion identifiers and thousands of data flows and vendors. A commissioned Forrester Total Economic Impact study adds a 227 per cent three-year return and a seven-month payback, which is a figure attached to a documented methodology a reader can assess. Around those sit a large named logo set including Adobe, Samsung, Pfizer, Walgreens, Aetna, Atlassian, Maersk and Bristol Myers Squibb, and a claim of more than 14,000 customers with more than half the Fortune 500. What holds this below the top band is dating: no located customer story or study carries a date, and the operational figures are the interviewee's own account rather than a measured study.
A named customer without figures, and figures without a named customer. A published case study names the New England Journal of Medicine and its data protection officer, Sean McInnis, describing a migration of a cookie consent tool and the support received, with no measured outcome; a second case study attributes figures to an unnamed Fortune 500 consumer products company: time to compliance cut by up to fifteen per cent, privacy programme operating expenses reduced by sixteen to thirty per cent, and more than three quarters of privacy processes automated, with no method stated. Nothing joins a named customer to a figure, and the AI features are not the subject of either study. Two case study PDFs read 6 September 2026; the customers index was not opened.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
The published commitments are substantive and contractual, and the training question is not answered. What a buyer can read before signing: a Data Processing Addendum published openly with version history, purpose limitation providing that personal data is processed only for the limited purposes described in the agreement and that OneTrust will not buy or sell customer personal data, customer retention of ownership of all data input into the services, tenant separation with data held in a logically-separated cloud database and a single production environment per customer, ISO 27701 certification for privacy information management, and deletion or export rights exercisable at any time during the term and for sixty days after it ends. Against that, nothing located states whether customer content is used to train or improve models, which is the first question this axis asks and a conspicuous silence for a company selling AI governance; the position on third-party model providers is equally absent; and privilege and work product are never mentioned, which matters because the platform is sold to privacy counsel and the workflow assigns a legal reviewer.
Substantive published commitments on training use, third-party providers and deletion, short of the full picture on segregation and privilege. No training: AI Terms section 1.1(b), incorporated into the customer agreement, states that customer data will not be used for AI model training, model improvement or any similar purpose, and 1.1(d) that the third-party AI technologies are explicitly opted out of LLM training and used solely to generate responses for authenticated users within the TrustArc environment. Third-party providers: Table 1 names them feature by feature. Retention and deletion: the subscription agreement gives a thirty-day retrieval window after termination followed by deletion, and the AI Terms commit to ceasing AI processing promptly on request. Not located: any statement on segregation between customers or matters, since the technical and organisational measures document was not opened, and any treatment of privilege or work product. AI Terms, subscription agreement fragments and trust centre privacy notice read 6 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
Nothing located addresses the line between an information tool and legal advice, on a product that produces compliance determinations for a professional audience. The platform assigns risk ratings, generates assessments against named regimes including the EU AI Act, GDPR and US state privacy laws, and routes them to a reviewer identified as Legal, so the output is consumed as a compliance judgement. What is published in its place is a performance commitment rather than an advice-line position: the Master Terms warrant that the cloud services will materially conform to the OneTrust User Guide throughout the subscription term. No statement was located that outputs are not legal advice, that OneTrust is not a law firm, that no professional relationship arises, or that a user should take advice on their own facts, and no jurisdiction limit or supervision and competence discussion appears. **This is the row most likely to move on this record**: the Master Terms PDF itself and the Legal and Compliance Information page were not opened on 1 September 2026, and a disclaimer may sit in either, so the grade rests on the home page, trust centre, pricing page and published contracting explainer.
A real position on tooling versus expertise, short of a drawn advice line and jurisdiction limits. AI Terms section 1.2(b) requires the customer to review all AI output before use, suggesting consultation with an internal or external subject-matter expert, and section 2.1 bars relying on outputs for decision-making without human oversight; the buyer is stated as privacy and compliance teams. The Nymity library publishes legal summaries and the research chatbot answers from them, and no located surface states whether those outputs are or are not legal advice; the subscription agreement, which a third-party summary describes as stating that use of the solutions does not guarantee compliance, could not be fetched in full because the site blocks automated retrieval, so that line is not credited. No jurisdiction limit is named. AI Terms and subscription agreement fragments read 6 September 2026.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
A governance framework with real substance is published and its results are not. The trust centre states that OneTrust's AI governance programme is managed by an interdisciplinary AI Governance Committee, supported by AI governance processes across the organisation and the AI systems lifecycle, an internal AI use policy and employee training. That is an accountable body, a lifecycle scope and two named instruments rather than a list of adjectives, and it is backed by a dedicated Responsible AI section, a published Journey to AI Governance toolkit and an AI Systems Transparency Report. Two things keep it below the top band. No individual is named as accountable, the committee being identified only by function. And nothing has been disclosed about uneven output: no bias evaluation, no testing regime and no result appears on any public surface, which is a notable gap for a vendor whose own product sells bias and drift monitoring to others. The AI Systems Transparency Report is available on request rather than published, so it sits in the middle disclosure tier and its contents were not read.
Published AI-use commitments without a governance mechanism, testing regime or accountable owner. The AI Terms are substantive on data use, provider transparency, opt-out and change notice, but they say nothing about who inside TrustArc is accountable for the AI features, what is tested before a feature ships, or what has been found about uneven output; no responsible AI page, ISO 42001 or equivalent certification, or model evaluation is published on the surfaces read. The Assessment Manager product sells AI risk assessment to customers, which is governance of the customer's AI rather than TrustArc's own. AI Terms, product navigation and trust centre read 6 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Every limb this band names is published, current and specific enough to hold the vendor to, and this is the strongest stewardship record located in the corpus. Retention is customer-configurable rather than merely stated, with services shipping built-in data minimisation functionality including auto-deletion and retention periods, and OneTrust expressly encouraging customers to configure them down. Deletion is contractual and time-bounded: customers may delete or export their data in a structured, commonly used and machine-readable format at any point during the term and for up to sixty days after termination, after which remaining data is deleted under a destruction policy. Access control runs through customer-administered user access plus ISO 27001, 27017 and 27701 certification, with the security obligations set out in Appendix 1 of the published DPA. Subprocessors are maintained on a list with a thirty-day advance notice commitment for changes and a right to object on reasonable data protection grounds, remedied by an alternative provider or termination of the affected subscription. Incident practice is stated: notification without undue delay, continuing updates on material developments, and cooperation with the customer's own reporting obligations. Encryption is given concretely at AES-256 at rest and in backup and a minimum of TLS 1.2 in transit, and the trust centre publishes a 2026 penetration test executive summary alongside disaster recovery and business continuity exercise memos. The one soft edge is that the subprocessor list itself sits on the customer portal rather than the open trust centre.
Substantive published policy covering most of the ground, with access control not read. Retention: the subscription agreement retains customer data for thirty days after termination for retrieval, then permits deletion except for legally required copies; the trust centre privacy notice retains personal information only as long as necessary and places data about individuals named in customer assessments under customer control. Deletion: the AI Terms commit to ceasing AI processing on request. Sub-processors: a public disclosure lists each with location, purpose and transfer mechanism, with emailed notice thirty days before any addition and a subscription to receive it, plus a separate affiliate list. Incident practice: AI Terms section 1.3 commits to prompt notice of any security incident involving AI-related processing under the agreement or DPA. Access control: the technical and organisational measures document and DPA of February 2024 exist in the legal centre and were not opened; the trust centre security page states TLS 1.2 in transit and AES-256 at rest with intrusion detection and logging. Surfaces read 6 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
What the vendor stands behind is published, specific, versioned and independently assessed, which no other record in this pull matches. The Master Terms of Service are published in full at a dedicated legal centre, currently version 5.1 effective 23 March 2026, with every prior version back to August 2020 downloadable alongside the DPA, Standard Contractual Clauses, Business Associate Agreement and product-specific supplemental terms. The liability position is stated and benchmarked rather than buried: a cap on each party's liability equal to the total annual fees paid or payable in the preceding year, which OneTrust expressly notes is broader than the more common cap tied to fees for the applicable service only, with willful misconduct and intellectual property claims carved out and uncapped. An indemnity with stated scope covers third-party IP infringement claims arising from use of the cloud services, with OneTrust controlling the defence. A warranty a buyer can invoke commits the cloud services to conform materially to the User Guide throughout the term. OneTrust also publishes a plain-language explainer, Contracting with OneTrust, setting all of this out for a reviewer, and states plainly what it will not do, refusing uncapped liability for data breach and giving its reasoning. The Master Terms carry an independent TermScout assessment rating them 70 per cent customer favourable with a perfect score against buy-side deal breakers. What is absent is anything specific to AI output being wrong and any insurance position.
A real published position on liability, short of the full picture because the subscription agreement could not be read end to end. Recovered through the search index from the subscription agreement: section 8.1 gives a TrustArc defence and indemnity for third-party claims stated to be its entire liability and the customer's exclusive remedy for such claims, with exclusions for modifications, combinations and non-compliant use; section 8.2 has the customer indemnify TrustArc for customer data and other matters; section 7.2 warrants core functionality against documentation, no material decrease during the term, malicious-code measures and diligent services. The end-user terms for partner channels cap either party's liability at fees paid for the applicable solution in the preceding twelve months. AI Terms section 2.1 provides the AI features with the same warranties and exclusions as the solutions and section 1.2(b) disclaims responsibility for the quality and accuracy of AI output. The agreement's own cap, consequential-loss exclusions and carve-outs were not readable because the site returned bot detection on fetch on 6 September 2026; that is a limit on this reading and the agreement is the rebuttal route.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Integration is plainly a real part of the offering and no individual connection could be named from the surfaces read. A dedicated Integrations page sits in the platform navigation and is described as an extensive set of integrations for adding data management to existing workflows, the Third-Party Management package refers to automating vendor assessments with ecosystem integrations, the Consent product is described as scaling through APIs to collect and enforce consent across emerging channels, and some services ship components that a customer implements on its own systems and websites such as cookie consent scripts and data discovery agents. OneTrust is additionally distributed through the Azure Marketplace, which has its own published supplemental terms. What is missing is the naming and the depth: no specific system is identified anywhere on the pages read, no API reference or developer documentation was located, and nothing describes what moves in which direction. **The Integrations page was not opened on 1 September 2026**, so this grade is rebuttable upward on one fetch and is recorded conservatively rather than assumed.
Integrations are referred to without documentation an implementer could use on the surfaces read. The subscription agreement contemplates customer-enabled Third-Party Applications with data exchange on the customer's behalf, and the Trust Center product page describes pushing documents from content systems, notifying Slack and creating ServiceNow tasks through TrustArc Integrations. No integrations page or documentation was opened, no practice, document or matter system is named in the material read, and nothing describes what syncs or in which direction for the privacy applications. Subscription agreement fragments and Trust Center product page read 6 September 2026; the integrations surface is the rebuttal route.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The tenancy model is stated plainly, residency is offered, and the processing question is left open. The published contracting explainer describes cloud services delivered on a shared architecture, codebase and infrastructure, with customer data held in a logically-separated cloud database and each customer receiving a single production tenant environment, with non-production environments included in some subscriptions and further environments purchasable. Residency is a customer choice: customers can select from various geographic hosting locations for their tenant environment. What changes between tiers is also addressed, with HIPAA-compliant and PCI-compliant environments available for customers with specialised requirements, backed by a published PCI attestation of compliance and a HITRUST certification. Two things hold it below the top band. The available regions are referred to collectively rather than enumerated, so a buyer cannot see the list without asking. And where processing happens is nowhere distinguished from where data is stored, which matters for the AI features specifically since no model or provider is identified.
Cloud delivery is stated with partial residency detail and the tenancy model is not addressed. The sub-processor disclosure gives a location for each processor, including Microsoft in Washington and Canada Central for logging and messaging and Mailgun in Texas for research alerts, and the AI Terms place one feature, Ask Arc, on Anthropic in the United States or Bedrock in the EU, which is a region choice stated for that feature alone; the trust centre security page names an enterprise-grade cloud hosting provider without naming it. Nothing states whether customers share infrastructure or where the platform's primary data store sits, and no residency option is described for the platform as a whole. Sub-processor disclosure, AI Terms and trust centre security page read 6 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
This is the trust centre the band describes and the first record in this pull to reach the top of this axis. Attestations are current, independent, and downloadable directly as PDFs with no form, no email capture and no NDA click-through: a SOC 2 Type II report, a second SOC 2 Type II for Certification Automation, ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 27017 and ISO 9001 certificates, and, decisively for the scope limb, **a published Statement of Applicability** setting out which controls are in scope. Industry and sector records sit alongside them: a PCI DSS attestation of compliance signed November 2025 with a third-party responsibility matrix, a HITRUST certification letter, TISAX, TX-RAMP, the Spanish ENS conformity statement, and a CAIQ v4.0.3 self-assessment lodged on the Cloud Security Alliance STAR registry. Security documentation goes beyond certificates to a 2026 penetration test executive summary, a completed standard SIG questionnaire, a security, privacy and architecture whitepaper, and disaster recovery and business continuity exercise memos, with a live system status page. Under the gated-is-not-absent tiers this is open publication rather than the self-serve request tier, which is what separates it from every other record graded on this axis so far.
Certification is real and stated on a trust centre that renders, short of a report reachable without asking. The trust centre security page states an annual assessment by a qualified external third-party auditor against the AICPA SOC 2 Type II standard, alongside TLS 1.2 in transit, AES-256 at rest, intrusion detection, logging and incident response plans; the trust centre carries privacy, security, availability and legal sections. No auditor is named, no coverage period is stated, and the report itself sits behind the trust centre's permissions, which the vendor's own Trust Center product page describes as keeping SOC 2 reports behind confidentiality requirements; no request was submitted. No ISO certification is stated on the surfaces read. Trust centre security page and Trust Center product page read 6 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
AI use is confirmed and nothing underneath it is identified publicly. The Master Terms answer the question of whether OneTrust uses artificial intelligence in the services with a plain yes, and direct the reader to the AI Systems Transparency Report, described as available upon request. No model, model family, provider or architecture is named on any public surface read on 1 September 2026, and no statement excludes a third-party foundation model either, so a customer cannot tell from published material whose model processes the assessments and documentation it generates. Where inference runs is not addressed separately from where data is stored. No commitment to notify customers when the model set changes was located, though the subprocessor change process does carry a thirty-day notice commitment and would capture a model provider engaged as a subprocessor. This sits above the bottom band because a dedicated transparency artifact exists and is obtainable rather than absent, which is the middle disclosure tier, and below the band above because nothing is actually named where a reader can see it.
The most granular provider disclosure in the pull, held off A because the models themselves are not named. Table 1 of the AI Terms maps every AI-enabled feature to its AI technology and third-party provider: the Azure AI Platform from Microsoft for the Nymity research chatbot and lookups, the OpenAI API for autofill, similarity search, bulk record creation, evidence analysis, summaries and cookie research, the Gemini API from Google Cloud for translations and assisted upload, and for Ask Arc either Anthropic in the United States and Bedrock from Amazon in the EU or the OpenAI API, depending on which of the two versions of the table the page renders. Section 2.2(b) commits to thirty days' notice and a right to object before any modification that materially and adversely affects the customer, including changes to provider relationships, and section 1.1(d) states the providers are opted out of LLM training. The page carries two versions of Table 1 with different entries for Ask Arc, which is recorded as an inconsistency a buyer will see. The technology column names platforms and APIs rather than models. AI Terms read 6 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
The unit and the structure are published in more detail than anywhere else in this corpus, and no figure appears. A dedicated pricing and packaging page sets out nine named packages across five solution families, each with its key capabilities listed so the feature split between base and suite editions is visible, and, unusually, **each with its own charging meter stated explicitly**: AI Governance priced on admin users and AI inventory; the Consent Management Platform on average daily visitors aggregated across channels and properties; Universal Consent and Preference Management on total data subject profiles captured; Privacy Automation on users and privacy asset inventory; Tech Risk and Compliance on admin users and asset inventory; and Third-Party Management on admin users and third-party inventory. Published FAQs explain what a solution package is, that pricing runs on value-based usage meters, and that a tiered model applies with an account executive moving a customer up a tier when usage consistently exceeds limits. What is absent is the number: no rate, band, floor or currency appears anywhere, every package routes to a Get Pricing form, and nothing states what implementation or professional services add.
No pricing information was located on any surface read, at any level. The legal centre lists agreements and policies with no pricing document, the subscription agreement refers fees to the order, the AI Terms refer to usage limits such as daily query caps without a charge, and the supplier's pre-screen recorded no pricing page. The home page navigation was read only in excerpt, so the existence of a pricing page was not established by inventory, and this row is rebuttable on that page if one exists. Legal centre index, AI Terms, subscription agreement fragments and end-user terms fragments read 6 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Coverage is described across three deliberate axes with substance behind each, and the boundary is left open. Solutions are organised by function into six families, by role into data, marketing, privacy, and security and risk teams, and by regulation with dedicated pages for GDPR, US privacy law and the EU AI Act plus a wider regulatory index. Practice depth is real: the Tech Risk and Compliance package cites templates and guidance across more than fifty standards, regulations and frameworks, the AI Governance package names the EU AI Act, NIST and ISO 42001 as the frameworks assessments align to, and third-party screening reaches politically exposed persons, sanctions and watchlists through Dow Jones data. The customer base spans regulated industry, retail, pharmaceutical, technology and non-profits on the published logo set. Two gaps keep it here. Nothing states where the product stops, with no statement of organisation size, data volume or the situations it does not fit. And the By Role navigation, which is where a legal buyer would look, offers privacy, security and risk, data and marketing teams and **no page for legal or counsel**, even though the product's own published workflow assigns a legal reviewer.
Segment and coverage described with substance; the boundaries are left open. The buyer is stated as privacy, legal, security and compliance teams in enterprises, with the Nymity library covering privacy regulations, legal summaries and operational templates globally and product navigation naming the EU AI Act, India's data protection law and the EU-US Data Privacy Framework among covered regimes; case studies span healthcare and publishing and consumer products, and the TRUSTe assurance programmes serve a separate certification market. What is not stated is where the product stops: no jurisdiction or regulation is named as unsupported and no law firm use is described. Product navigation, case studies and AI Terms read 6 September 2026.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
No located term or policy addresses the question either way, which is the single most surprising gap on this record. OneTrust publishes a Master Terms of Service, a Data Processing Addendum and Standard Contractual Clauses openly with full version histories, confirms in the contracting explainer that artificial intelligence is used in the services, and states that personal data is processed only for the limited purposes described in the agreement and that customer personal data will not be bought or sold.
None of that reaches model training. The purpose limitation is the nearest thing and it is a general processing restriction rather than a training prohibition, and it is expressed over personal data rather than over the assessments, policies and inventories a customer builds in the platform. The document that would answer it, the AI Systems Transparency Report, is described as available upon request rather than published.
Searched the trust center, the legal center including the contracting explainer, the pricing page and the home page on 1 September 2026.
The commitment is in the agreement. The Terms of Use for AI Features, last updated November 2025 and incorporated into the customer's agreement, state at section 1.1(b) that TrustArc will not use customer data for AI model training, model improvement or any similar purpose beyond the authorized use of the AI-enabled features, and at 1.1(d) that the third-party AI technologies reached through API calls are explicitly opted out of large language model training and used solely to generate responses for authenticated users inside the TrustArc environment; the trust center privacy notice repeats that AI services are opted out of LLM training by default. No aggregation or de-identification qualifier appears. Surfaces checked 6 September 2026.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Retention is under the customer's control as a product configuration rather than a contractual instruction, which is rarer than the value name suggests. The published contracting explainer states that some services include built-in functionalities for data minimization including auto-deletion and retention periods, and that OneTrust encourages customers to configure the services to reduce the amount of personal data held in its environment at any point.
Alongside that sits an explicit deletion and portability right: customers may delete or export their data in a structured, commonly used and machine-readable format at any time during the subscription term and for up to sixty days after termination, after which remaining data is deleted under a destruction policy. What is not stated is a zero-retention option, and no separate window is published for AI prompts or generated assessments as distinct from customer records generally.
A specific period is published and the customer cannot change it during the term. Subscription agreement section 11.5 keeps customer data available for retrieval for thirty days after termination, after which TrustArc has no obligation to maintain it and may delete or destroy all copies except any it must retain for legal purposes; the AI Terms add that AI processing under any disabled feature ceases promptly on request and that AI services process data only to generate responses, and the trust center privacy notice retains personal information only as long as necessary.
Nothing states a configurable window for prompts and outputs during the term. The subscription agreement was recovered in fragments through the search index because the site blocks automated fetching. Surfaces checked 6 September 2026.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
OneTrust operates its own documented permission and separation model, and it is described at the tenant and user level rather than below it. The contracting explainer states that customer data is held in a logically-separated cloud database, that each customer receives a single production tenant environment for all subscribed services, and that the customer's own users control access to the cloud services as well as the volume and types of data submitted, with OneTrust not having specific access to what a customer chooses to submit.
ISO 27701 certification covers the privacy information management system around it. What is not addressed is separation inside a single customer account: nothing describes walls between teams, business units or matters, which is a live question because the published workflow routes a single AI use case to privacy, security and legal reviewers who sit in different functions.
No located public material addresses segregation between customers or matters. The AI Terms state that AI services generate responses only for authenticated users within the TrustArc environment, which is an access statement rather than a description of how one customer's data is walled from another's, and the technical and organisational measures document and DPA of February 2024 in the legal center, where such a description would sit, were not opened on 6 September 2026 and are the rebuttal route. AI Terms, trust center privacy notice and security page checked.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
A position is published, a transparency report exists, and the notice limb rests on a document other than the customer agreement. The contracting explainer states that OneTrust does not voluntarily disclose or grant access to any personal data of its customers to government authorities unless required by law, and directs the reader to a published policy and transparency report on government and law enforcement requests.
The notice commitment located sits in the Mutual Nondisclosure Agreement, which provides that confidential information may be disclosed as required by law or valid legal order after using reasonable efforts to provide notice of the disclosure; that document governs pre-contract confidential information rather than platform data. The Data Processing Addendum PDF, which is where a notice commitment for customer data would sit, was not opened on 1 September 2026, so this row may move up to notice and report on reading it.
A published Government Request Policy for Customer Data in the legal center commits to notice: TrustArc will not disclose customer data to government authorities unless required by law or to prevent serious injury or death, will alert customers with as much advance notice as possible so they may object unless prohibited, will give notice as soon as permissible where advance notice is not possible, and will typically ask a government to submit requests for customer-controlled personal data to the customer directly.
Whether the DPA of February 2024 carries a matching contractual term was not established, since that document was not opened. No transparency report is published. Surfaces checked 6 September 2026.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
The product does not retrieve primary law, and the reference datasets it does carry are named, which is more than most vendors manage. Three are identified on the pricing page: a database of more than 45 million categorized cookies and trackers behind the consent product; risk intelligence data on millions of third parties behind third-party management; and, named to its provider, Dow Jones ethics and compliance databases supplying politically exposed person, sanctions and watchlist screening in the Third-Party Management Suite.
Regulatory change intelligence is attributed to DataGuidance within Privacy Automation. What is absent is the rights basis: no license, ownership or public-domain footing is stated for any of them, and no update cadence is published beyond the claim that inventories are evergreen. Checked the pricing and packaging page, the home page and the trust center on 1 September 2026.
The source behind the research answers is identified without a stated rights basis. The NymityAI research chatbot answers over the Nymity Research library, described by the vendor as more than fifty thousand expert privacy references, legal summaries and operational templates updated daily; the library is TrustArc's own subscription content, so the corpus is named, but nothing states the primary-law sources it summarizes, the license or public-domain basis for them, or the update method beyond the daily claim. Product navigation and AI Terms read 6 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No citator applies and the row is recorded rather than skipped. The platform does not return legal authority whose subsequent history could be checked; it maintains registers, runs assessments and enforces controls. The nearest analog is regulatory currency rather than treatment: Privacy Automation is described as helping customers understand the operational impact of regulatory changes through DataGuidance intelligence, and the AI Governance package aligns assessments to named frameworks including the EU AI Act, NIST and ISO 42001, so the platform tracks whether a requirement has moved without purporting to tell a user whether an authority still stands.
Searched the pricing and packaging page, the home page, the trust center and the published contracting explainer on 1 September 2026.
No located public material addresses whether authority is checked for subsequent history. The research product summarizes regulations and guidance rather than citing case law, and no citator or treatment signal is described. Recorded as the honest value for a product without that function. Surfaces checked 6 September 2026.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
Nothing located describes what the AI does when it cannot assess reliably. The published workflow shows an AI-assisted assessment returning a risk summary graded medium with findings graded medium and low, so the output carries a severity rating, but a risk grade is a conclusion about the subject rather than a statement of the model's own confidence, and nothing indicates what a user sees when the system cannot reach one.
No abstention path, confidence score or coverage indicator is documented. The structural mitigation is the approval gate rather than a model behavior: every assessment routes to named human reviewers before a use case proceeds, so an uncertain output is caught by process rather than flagged by the system. Searched the home page, the pricing and packaging page, the trust center and the contracting explainer on 1 September 2026.
No located public material describes what the AI features do when they cannot ground an answer. The AI Terms warn that outputs may contain errors and require review, and impose usage limits such as daily query caps, but describe no abstention path or confidence signal. Surfaces checked 6 September 2026.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
Searched the AI Hallucination Cases database maintained by Damien Charlotin at HEC Paris, together with 2026 sanctions trackers and trade coverage, on 1 September 2026, on the company name. No court order, opinion or disciplinary record naming OneTrust was located. This is a statement about the public record rather than a finding about the product. The failure mode this signal tracks fits poorly: the platform's AI output is a risk rating or a piece of model documentation consumed inside a governance workflow and gated by human approval, not a citation to legal authority prepared for filing, so the analogous exposure would be a mis-rated assessment surfacing in a regulatory examination rather than in a court.
No court order, opinion or disciplinary record naming TrustArc, Nymity or TrustArc Inc. was located as of 6 September 2026. The AI Hallucination Cases database maintained by Damien Charlotin was searched on both product names together with a general search for court findings; results returned sanctions involving general-purpose chatbots, none of which is this product. This is a statement about the public record, not a finding about the product.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No engagement with professional responsibility or ethics guidance was located, which is worth separating carefully from what OneTrust does publish. The company engages extensively with regulation as subject matter, naming GDPR, US state privacy laws, the EU AI Act, NIST, ISO 42001, DORA and more than fifty standards and frameworks in its packages, and maintains a public glossary of AI governance and privacy terms. None of that is guidance binding the professional who relies on the output.
Nothing references ABA Formal Opinion 512, any state bar opinion, Law Society or SRA guidance, or any equivalent addressed to counsel using AI tools, and no general statement that a user's own professional obligations survive use of the platform was found. Searched the home page, the trust center, the pricing page, the legal center and the published contracting explainer on 1 September 2026.
No located public material engages with bar or ethics guidance. The AI Terms require human oversight and expert review of outputs and the product content engages extensively with privacy statutes, but no ethics opinion, bar rule or professional responsibility framework is named on any surface read. AI Terms, legal center and product navigation checked 6 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Savings are quantified and billing treatment is never addressed. A commissioned Forrester Total Economic Impact study is promoted with a 227 percent three-year return on investment and a seven-month payback, and the GOL customer story gives operational time reductions from thirty days to five or fewer for vendor approval and from a fortnight to minutes for request completion. The buyer is an in-house privacy, legal or risk function rather than a firm billing a client, so the fee question lands obliquely, but it is not absent: outside counsel and consultancies use platforms of this kind on client engagements, and nothing published addresses how AI-assisted assessment work should be disclosed or billed where that happens.
No per-matter record of AI-assisted work is described for that purpose, as distinct from the audit-ready evidence the product generates about a customer's own AI systems.
The buyer is an in-house privacy, legal or compliance function that bills no client, so the product sits outside a lawyer-to-client fee relationship. The published savings claims are operational and attributed to an unnamed Fortune 500 customer, privacy program operating expenses reduced by sixteen to thirty percent and more than three quarters of processes automated; nothing addresses how AI-assisted work is recorded or disclosed on any bill, and no law firm is a named buyer segment. Surfaces checked 6 September 2026.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
Half of what a client's AI clause asks for is openly published and the half about AI is obtainable rather than public. On the open side, and this is unusually strong: the Data Processing Addendum, the Standard Contractual Clauses and the Master Terms are all downloadable from the legal center without an agreement in place, with full version histories, which is precisely the forwardable contractual material the signal contemplates.
On the gated side, the subprocessor list is maintained on the customer portal rather than the open trust center, though with a thirty-day advance notice commitment for changes and a right to object on reasonable data protection grounds. And **no model provider is named anywhere**: the AI Systems Transparency Report is described as available upon request. Under the coverage test a firm therefore cannot tell its client which systems see its content without first contracting or requesting, which is what places this at the request tier rather than higher.
A sub-processor list, a model provider list and client-facing disclosure material are all published without an agreement in place. The sub-processor disclosure lists each processor with location, purpose and transfer mechanism, with thirty days' emailed notice of additions and a subscription for it; Table 1 of the AI Terms maps every AI feature to its provider, Microsoft, OpenAI, Google Cloud and, for one feature in one version of the table, Anthropic and Amazon; and the AI Terms, the government request policy and the DPA are published in the legal center in a form a firm could forward. Surfaces checked 6 September 2026.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
There is an inversion worth naming here: OneTrust sells the capability to produce exactly this record about a customer's own AI, while its own equivalent is available on request. The AI Governance package automates model documentation, audit-ready evidence and regulatory reporting outputs, configures approvals, attestations and evaluation gates, and correlates runtime behavior with purpose, data sensitivity and regulatory obligations, which is a disclosure record about the customer's systems.
For OneTrust's own AI, the published workflow logs a review and approve step naming privacy, security and legal reviewers, so who signed off is captured. What is not established is whether that record identifies which output was machine-generated or which model produced it, and no document-level export covering model, sources and verification is described. OneTrust's own AI Systems Transparency Report is available upon request rather than published.
No located public material addresses court disclosure or verification certification of AI-assisted work. The product produces privacy assessments, records and research summaries rather than court-facing work product, and nothing describes a per-document record of model used, sources retrieved and human verification. Surfaces checked 6 September 2026.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.
- Good Law Verification
- Refusal and Uncertainty Behavior
- Bar Guidance Alignment
Which one fits
Choose OneTrust if
- Your security review wants the reports in hand before the first call. OneTrust's trust center lets you download its SOC 2 Type II report, ISO 27001, 27701 and 27017 certificates, a Statement of Applicability showing which controls are in scope, and a 2026 penetration test summary, with no form and no NDA.
- You want to read and compare the contract before negotiating. OneTrust publishes its Master Terms, currently version 5.1 of 23 March 2026, with every prior version back to August 2020, alongside its Data Processing Addendum, Standard Contractual Clauses and a plain language explainer. Its liability cap equals a full year of fees across all services, with intellectual property claims uncapped.
- You need to forecast cost as usage grows. OneTrust publishes the charging meter for each of its nine packages, such as admin users and AI inventory for AI Governance or average daily visitors for consent, and explains that a customer moves up a tier when usage consistently exceeds its limits. No figure is published.
Choose TrustArc if
- You need a contract term that your data will not train the AI. TrustArc's Terms of Use for AI Features, incorporated into the customer agreement, state that customer data will not be used for model training, model improvement or any similar purpose, and that the third party AI services it calls are opted out of training.
- Your clients ask which AI providers touch the data. TrustArc's AI terms map every AI feature to its technology and provider, including Microsoft's Azure AI Platform, the OpenAI API and Google Cloud's Gemini API, and commit to 30 days' notice and a right to object before a provider change that materially and adversely affects you.
- You want the vendor to say what its AI output is for. TrustArc's AI terms require every output to be reviewed before use, suggest a subject matter expert where needed, and bar relying on outputs for decisions without human oversight, and every AI feature is optional and off until a customer chooses to use it.
In summary
OneTrust
OneTrust is a governance platform for privacy, data and AI, sold to privacy, security, risk, data and marketing teams across five solution families, from consent and data subject requests to AI governance and third party management, and it reports more than 14,000 customers. The AI Legal Index grades it in the top two bands on ten of fifteen capability axes, with A grades on data stewardship, liability and security certifications: its SOC 2 Type II report and ISO certificates download from its trust center without a form, and its versioned Master Terms are published in full. AI assists inside the platform, with AI generated risk assessments routed to privacy, security and legal reviewers before a use case proceeds. As of 1 September 2026 the index located no published statement on whether customer data trains models and no named model provider.
TrustArc
TrustArc is a privacy management platform for privacy, legal and compliance teams, headquartered in Walnut Creek, California, selling PrivacyCentral, data mapping, assessments, cookie consent, a customer facing Trust Center and the Nymity Research library, with AI features branded Arc Intelligence and Nymity AI. The AI Legal Index grades it in the top two bands on ten of fifteen capability axes. Its Terms of Use for AI Features, part of the customer agreement, state that customer data will not be used for model training or improvement, map each AI feature to its provider, and make every AI feature optional. A published Government Request Policy commits to advance notice of demands for customer data. As of 6 September 2026 the index located no published pricing, no AI governance framework and no named auditor for its SOC 2 Type II assessment.
Questions buyers ask
OneTrust vs TrustArc: which is better for a privacy team?
Neither, on the totals. The AI Legal Index places both in the top two bands on ten of fifteen capability axes. OneTrust publishes more for a security and procurement review: downloadable certifications, versioned contract terms and a stated charging meter for every package. TrustArc publishes more about its own AI: a contractual bar on training with customer data and a map of which provider runs each AI feature. Which matters more depends on who in your organization signs off first.
Does TrustArc train AI on customer data?
No, by contract. TrustArc's Terms of Use for AI Features, last updated November 2025 and incorporated into the customer agreement, state that customer data will not be used for AI model training, model improvement or any similar purpose, and that the third party AI technologies it calls are explicitly opted out of large language model training. Its trust center privacy notice repeats that AI services are opted out of training by default. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
How much do OneTrust and TrustArc cost?
Neither publishes a price. OneTrust publishes the structure in detail: nine named packages, the capabilities in each, and the meter each is charged on, from admin users and AI inventory to average daily visitors, with a tiered model and every package routed to a pricing form. TrustArc publishes no pricing information at any level located; its agreement refers fees to the order, and its AI terms mention usage limits such as daily query caps without a charge. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
Which AI models does TrustArc use?
TrustArc's AI terms name providers feature by feature: Microsoft's Azure AI Platform for the Nymity research chatbot and lookups, the OpenAI API for autofill, similarity search, bulk record creation, evidence analysis and summaries, and Google Cloud's Gemini API for translations. For its Ask Arc assistant the page shows two versions of the table, one naming Anthropic in the United States and Amazon Bedrock in the EU, the other the OpenAI API. Specific models are not named. OneTrust names no provider. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
What do OneTrust and TrustArc both leave unpublished?
An accuracy figure for their AI. Neither measures or publishes how often its AI assessments, summaries or research answers are right, and neither describes what the AI does when it cannot answer reliably. Neither names an ethics opinion or bar guidance for the lawyers who rely on its output. Neither publishes integration documentation an implementer could work from, and neither describes walls between teams or business units inside one customer account. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.
Three readings to weigh. OneTrust's silence on training covers the documents it publishes; it describes an AI Systems Transparency Report as available on request, which may address the question and was not public to read. TrustArc's AI terms carry two versions of the table mapping features to providers, with different providers for its Ask Arc assistant, so a buyer should confirm which applies. TrustArc's subscription agreement could only be read in part, so its liability grade rests on the indemnity and warranty clauses that could be read rather than on a full reading of the cap. OneTrust was verified on 1 September 2026 and TrustArc on 6 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.