Jump to a category
- 1. Cookie consent banners — 10 tools
- 2. Privacy policy generators — 6 tools
- 3. DSAR & consent management platforms — 6 tools
- 4. Data discovery & mapping — 4 tools
- 5. Breach monitoring & data leak detection — 4 tools
- 6. Business VPN & secure access — 4 tools
- 7. Employee privacy & security training — 4 tools
- 8. Audit & certification automation — 4 tools
How to read this page
Each entry includes a one-line description and the starting price (or a note that pricing is gated, with a third-party procurement source where independent data exists). Pricing was verified on vendor pricing pages in June 2026. Tools with an existing in-depth PrivacyComply review link to it.
1. Cookie consent banners
Cookie consent management platforms (CMPs) display compliant banners, scan for trackers, record consent choices, and satisfy GDPR, CCPA, and similar laws. The category spans free tiers for personal blogs through six-figure enterprise contracts. For most SMB sites the decision is between three or four self-serve tools; for publishers and large enterprises the shortlist is different.
CookieYes
Self-serve cookie consent banner for SMBs — easy setup, generous free tier, used by 1.5M+ sites.
iubenda
All-in-one compliance suite (consent + policy + cookie banner + T&C) for agencies and developers across 170+ countries.
Termly
US-focused privacy policy and cookie consent tool aimed at small businesses; auto-updating policies and Free tier with watermark.
Osano
Privacy platform for mid-market — cookie consent plus DSAR, data mapping, and vendor monitoring in one product.
Cookiebot (by Usercentrics)
Scan-based CMP priced by subpage count per domain; TCF 2.2 certified. Base prices doubled in August 2025 after the Usercentrics acquisition.
Usercentrics
Enterprise CMP from the parent of Cookiebot; session-based pricing for Web, App, and CTV channels.
OneTrust Cookie Consent
Enterprise consent module within the OneTrust platform. Minimum $10,000/year ACV as of Q2 2026 — impractical as a standalone banner.
TrustArc Cookie Consent
Enterprise cookie consent and privacy management from a 1997-founded vendor; sales-led, no self-serve pricing.
Didomi
European enterprise CMP with strong media and publisher integrations; IAB TCF and GPP certified.
Secure Privacy
GDPR/CCPA cookie consent plus privacy policy generator; SOC 2 certified; aimed at SMBs that want both bundled.
Enzuzo
Mid-market CMP with the strongest multi-domain pricing on the market — 10 domains for $59/mo on the Pro plan. Native Shopify and Webflow apps, real DSAR workflow from $22/mo, Google CMP Gold, IAB TCF 2.3. Canadian-built, Quebec Law 25 covered.
Complianz
WordPress-native CMP with hybrid server-side script blocking and a free WP.org plugin. Flat annual licenses with no per-site recurring or traffic caps — the Agency plan covers 25 sites for $399/yr. WordPress and Shopify only.
2. Privacy policy generators
Privacy policy generators produce the legal text that GDPR, CCPA, and similar laws require websites to display. The spectrum runs from free static templates to dynamically updating, attorney-drafted policies that auto-adjust when laws change. Key considerations: does the policy auto-update, is it hosted (so you can link to it), and does it cover multiple regulations.
Termly
Auto-updating privacy policies, cookie policies, and terms for small business websites; US-centric but covers GDPR.
iubenda
Lawyer-drafted, auto-updating privacy policy for websites and apps; covers 170+ jurisdictions with a modular clause library.
Termageddon
Attorney-authored, auto-updating privacy policies; built for small businesses and the web agencies that serve them.
FreePrivacyPolicy
Free generator for basic privacy policies, terms, and disclaimers; static output, no subscription required.
PrivacyPolicies.com
Free hosted privacy policy, T&C, EULA, and refund policy generator with optional one-time premium clause add-ons.
GetTerms.io
Subscription privacy policy and terms generator with strong agency reseller pricing (40–70% bulk discounts).
3. DSAR & consent management platforms
Data Subject Access Request (DSAR) and enterprise consent management platforms automate the process of receiving, verifying, and responding to privacy rights requests (access, deletion, portability) mandated by GDPR, CCPA, and similar laws. Enterprise-grade CMPs extend further into data inventory, vendor assessments, and AI governance. This category skews enterprise — most tools require a sales conversation before pricing is disclosed.
OneTrust
Broadest enterprise privacy, GRC, and consent platform on the market — DSAR, data mapping, vendor risk, AI governance. Min $10K/yr as of Q2 2026.
TrustArc
Modular enterprise privacy management; strong on DSAR automation and assessments; all pricing sales-led.
Securiti.ai (also Cat 4)
AI-powered data command center covering DSAR, consent, data discovery, breach response, and AI governance across hybrid cloud.
DataGrail
Agentic data privacy platform with 2,500+ integrations for DSR automation and data mapping; AI agent ("Vera") for ongoing privacy tasks.
Transcend (also Cat 4)
Developer-first privacy platform for DSR automation, consent, and data discovery; API-native, built for engineering-led privacy programs.
Ethyca
Open-source-rooted data governance and consent platform (Fides); embeds privacy policy enforcement into application infrastructure.
4. Data discovery & mapping
Data discovery and mapping tools scan structured and unstructured data across cloud, on-premise, and SaaS environments to find where personal and sensitive data lives, classify it, and maintain a live data inventory. This is foundational to GDPR Article 30 records-of-processing compliance and to minimising breach exposure. All tools here are enterprise-priced with custom quotes.
BigID
Enterprise data intelligence for discovery, classification, privacy, and AI governance across hybrid and multi-cloud. Typically $100K+/yr.
Securiti.ai (also Cat 3)
Unifies discovery with downstream privacy automation (consent, DSAR, breach response) — reduces multi-tool stitching.
Spirion
Sensitive data platform focused on accurate PII discovery at endpoint and repository level; agent-based deployment.
Transcend (also Cat 3)
API-native discovery and classification layered onto Transcend's broader privacy platform; engineering-first.
5. Breach monitoring & data leak detection
Breach monitoring tools alert organisations (or individuals) when their email addresses, credentials, or company data appear in known breach datasets, dark web markets, or data leak repositories. The category spans free consumer tools through enterprise identity threat protection platforms with active dark web recapture.
Have I Been Pwned
The original breach notification service; free personal email search; paid API and domain monitoring for businesses.
SpyCloud
Enterprise identity threat protection using recaptured dark web data; account takeover, ransomware, and session hijacking defence.
UpGuard
Cyber risk and vendor risk management; combines external attack surface monitoring with third-party risk assessments.
BitSight
Security ratings and third-party cyber risk; ratings widely used by cyber insurance underwriters as an objective benchmark.
6. Business VPN & secure access
Business VPNs and zero-trust network access (ZTNA) tools give remote employees and contractors secure access to internal resources without exposing the full network. The category has shifted from traditional VPN toward SASE and software-defined perimeter models. Full deep-dive coming soon in our dedicated business VPN guide.
NordLayer
Business VPN from Nord Security; familiar consumer-grade UX with business controls; designed for SMB-to-mid-market.
Check Point Harmony SASE (Perimeter 81)
Formerly Perimeter 81 (acquired 2023); full SASE platform now backed by Check Point's enterprise security ecosystem.
Twingate
Zero-trust network access (ZTNA) replacement for VPN; developer-friendly, no infrastructure required at the network edge.
Tailscale
WireGuard-based mesh VPN; widely adopted by developers and small engineering teams; unusually generous free tier.
7. Employee privacy & security training
Security awareness training platforms reduce phishing, social engineering, and accidental data exposure through simulated attacks, interactive modules, and behavioural analytics. Pricing is almost universally per-seat per-year, with SMB entry points in the $2–$8/user/year range. The category has consolidated — most enterprise buyers shortlist 3–4 vendors.
KnowBe4
Largest security awareness platform globally; phishing simulations, 1,000+ modules, AI coaching; channel-first sales model.
Hoxhunt
Gamified, AI-driven phishing simulation; adaptive difficulty engine that adjusts to each employee's skill level.
Curricula (by Huntress)
Story-based security awareness training; genuinely free for up to 1,000 employees; acquired by Huntress in 2022.
usecure
Human risk management built for MSPs and IT teams; per-user monthly billing, no minimums, white-label support.
8. Audit & certification automation
Compliance automation platforms accelerate the path to SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR certifications by continuously monitoring cloud infrastructure, auto-collecting evidence, and managing auditor workflows. All four major players operate on similar models — annual contracts, custom pricing, cloud-provider integrations — with pricing that is almost universally quote-only.
Vanta
Trust management for SOC 2, ISO 27001, HIPAA, and other frameworks; largest market share in compliance automation.
Drata
Continuous compliance for SOC 2, ISO 27001, and 20+ frameworks; strong on automated evidence collection and auditor portal.
Secureframe
Compliance automation for SOC 2, ISO 27001, HIPAA, and PCI; offers human Compliance Success Managers alongside software.
Sprinto
Compliance automation for startups and growth-stage companies; strong traction in India and APAC; fastest time-to-audit-ready.
FAQ
Why is so much pricing on this page marked “custom quote”?
Enterprise privacy tools (OneTrust, TrustArc, Securiti.ai, BigID, Vanta, Drata, Secureframe) almost universally hide pricing behind a sales call. We cite third-party procurement sources (Vendr, CheckThat.ai, Spendflo) where independent pricing data exists so you can benchmark before that call.
Do I need tools from every category?
No. A small business website typically needs a cookie banner and a privacy policy generator. As you grow, you add DSAR tooling, then training, then audit automation. Data discovery and breach monitoring become relevant once you process large volumes of personal data or pursue formal certifications.
Which categories overlap?
Several tools span multiple categories. iubenda and Termly cover both cookie consent and privacy policy. Securiti.ai and Transcend cover both DSAR and data discovery. Osano combines cookie consent with light DSAR and vendor monitoring. We flag dual-listed tools inline with (also Cat X).
Is this list complete?
It covers the dominant tools we see in each category as of mid-2026. There are smaller and regional players in every category that we have not listed. If a tool you use is missing and you think it deserves coverage, email corrections@privacycomply.io.
How current is this pricing?
All pricing was verified directly on vendor pricing pages in June 2026. Privacy and compliance pricing changes quickly — OneTrust raised its minimum contract from open self-serve to $10,000/year in Q2 2026, and Cookiebot doubled base prices in August 2025. We re-verify quarterly. Always confirm with the vendor before signing.
Why are some categories thinner than others?
Data discovery, breach monitoring, and business VPN are dominated by 3–5 players each at the enterprise level — adding more tools would mean listing point solutions that few buyers actually evaluate. Cookie consent has 10+ credible options because the category is younger, more SMB-accessible, and more crowded.