Full-Time
Subscription-based data privacy and governance platform
No salary listed
Bengaluru, Karnataka, India
Hybrid
Three days in office per week required.
Bachelor's, Master's
See people who can refer or advise you
OneTrust provides a cloud-based platform that helps organizations manage data privacy, governance, risk and compliance (GRC), ethics, and environmental, social, and governance (ESG) needs. It inventories and visualizes data (data sprawl), tracks where data is stored and how it’s used, and supports policies, consent, vendor risk, audits, and ESG reporting. Its subscription-based software combines multiple modules so customers can govern their data, comply with laws across regions, and address ethics and ESG responsibilities in one system. The company differentiates itself by offering a broad, integrated suite that covers privacy, governance, ethics, and ESG in a single platform rather than relying on piecemeal tools, enabling customers to manage data responsibly at scale. Its goal is to help businesses understand their data, stay compliant with regulatory requirements, and build trust with customers by governing data ethically and transparently.
Company Size
1,001-5,000
Company Stage
Late Stage VC
Total Funding
$1.1B
Headquarters
Atlanta, Georgia
Founded
2016
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Health Insurance
Unlimited Paid Time Off
Stock Options
Performance Bonus
401(k) Retirement Plan
401(k) Company Match
Parental Leave
Professional Development Budget
AI Video Background Plugins and deepfake detection: new standards and industry moves in 2026. New standards target deepfake risks in AI Video Background Plugins: what's changing in 2026. In June 2026, a wave of new standards and compliance frameworks has hit the AI video tooling sector, signaling an industry-wide response to mounting deepfake risks. Major plugin vendors - including Zoom, NVIDIA, and Agora - have announced upgraded deepfake detection features for their AI video background plugins, rolling out updates ahead of incoming regulatory deadlines. The focus: AI video background deepfake detection 2026 is shifting from an experimental add-on to a commercial and legal necessity. Why AI Video Background deepfake detection matters in 2026. The surge in adoption of AI video background plugins - used in everything from remote work to telehealth - has brought a parallel rise in deepfake abuse. Security incidents in late 2025, such as the high-profile impersonation of a banking CEO during a virtual board meeting, have fueled regulatory scrutiny. The U.S. Federal Trade Commission and the European Data Protection Board both issued formal warnings in Q1 2026, urging vendors to "implement robust, transparent deepfake detection in all virtual background tools by Q4 2026." According to a World Economic Forum report published in May, deepfake incidents involving AI video backgrounds increased 240% year-over-year in the enterprise sector. The report cites that 68% of surveyed CISOs now list AI video background risks, including deepfake impersonation, as a top-three threat for remote teams. The stakes are not limited to security. As detailed in its analysis of FERPA compliance for AI video background plugins, privacy and regulatory exposure are equally critical. Organizations are being forced to rethink their video plugin procurement and review processes, with deepfake detection now a mandatory checklist item. Industry analysis: standards, features, and expert reactions. The market response to the regulatory drumbeat has been swift. In April, the Video Communications Standards Consortium (VCSC) unveiled its "Background Authenticity Protocol 1.0," an open standard for embedding tamper-evident cryptographic signatures into AI-generated video backgrounds. The standard - already adopted by Zoom and Microsoft Teams - enables real-time verification that video feeds haven't been manipulated by unauthorized deepfake-generating plugins. NVIDIA's May update to its Maxine SDK introduced a deep learning-based detector that flags suspicious facial and voice artifacts in real time. According to NVIDIA's developer blog, the new detector demonstrated a 94.6% accuracy rate in identifying known deepfake attack patterns during internal testing. "We're seeing a clear demand for native, on-device deepfake detection," said Dr. Priya Suresh, NVIDIA's Director of Video AI, in a statement to AI Daily Shot. "It's about trust - organizations need to know their video workflows haven't been tampered with at any point." Meanwhile, compliance automation vendors such as OneTrust have launched new modules that integrate with AI video background plugins to log and audit all deepfake detection events. This feature is crucial for regulated sectors, supporting automated compliance reports as described in its technical how-to on compliance automation. Security experts remain cautiously optimistic. "The standards are a big step forward, but the real challenge is enforcement and vendor transparency," said Lena Zhou, a security architect at Deloitte. "We recommend organizations require third-party audit reports on deepfake detection efficacy before approving any new video plugin." Zhou pointed to a recent case where a vendor's proprietary detection model failed to catch a custom deepfake, highlighting the need for open, benchmarked approaches. The competitive landscape is shifting as well. Smaller plugin vendors are racing to certify their products against the new VCSC protocol, while established players tout their deepfake detection as a differentiator in high-compliance markets like finance and telehealth. For a broader view of non-deepfake use cases and the evolving plugin ecosystem, see The Complete Guide to Non-Deepfake Use Cases for AI Video Background Plugins in 2026. Publicidade What to watch next: timeline and recommendations for 2026. The regulatory clock is ticking. The FTC's mandatory compliance guidance for "all enterprise-grade AI video background tools" takes effect on October 1, 2026, with the EU's Digital Identity Act setting a similar deadline for European vendors. Both frameworks require not only deepfake detection but also transparent reporting and end-user notification mechanisms. Upcoming milestones include: * July 2026: Public release of VCSC's Background Authenticity Protocol 2.0, with expanded forensic logging features. * September 2026: First round of third-party audits for leading plugin vendors due, with results to be published by the end of the month. * October 2026: FTC and EDPB enforcement begins; non-compliant vendors face penalties up to $5M per incident. For organizations evaluating AI video background plugins, security consultants recommend: * Mandating VCSC protocol support and cryptographic background signing in all new deployments * Requiring independent test results for deepfake detection models, with published false positive/negative rates * Implementing continuous audit trails and automated compliance reporting, as outlined in recent best practice guides for ethical deployment in remote workplaces As the AI video background deepfake detection 2026 landscape matures, the burden of proof is shifting to vendors. Buyers should expect a clear, standardized assurance of deepfake detection capabilities - not just a marketing claim. With high-profile enforcement actions likely later this year, the message is clear: plugin safety is no longer optional, and transparency is the new baseline. Master AI with its complete guide collection 8 guides, 375+ prompts, instant download. Save 41% with the All-Access Bundle. Senior AI Reporter Senior AI Reporter covering product launches, funding rounds, and industry moves.
UK DUAA implementation: practical changes for consent, cookies, and compliance. Here's what organizations should review as implementation continues and how OneTrust has translated those changes into practical capabilities. Harry Chambers Regulatory Content Strategist July 27, 2026 Table of contents. The UK Data (Use and Access) Act 2025 (DUAA) entered into effect in stages, introducing a series of targeted amendments to the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR). Rather than overhauling the UK's privacy framework, the legislation refines specific areas where organizations have long sought greater clarity, particularly around storage and access technologies, privacy rights, complaint handling, and automated processing. The latest implementation milestone arrived on June 19, 2026, when new data protection complaint handling requirements became effective. Individuals must now raise complaints with organizations before escalating them to the Information Commission, which will replace the Information Commissioner's Office (ICO) creating new operational responsibilities for handling, investigating, and documenting complaints. Many of the broader DUAA changes require a similar operational response. Organizations must review how consent experiences are configured, how cookies are classified, how privacy requests are managed, and where UK-specific approaches may begin to diverge from EU practices. Key takeaways. * The DUAA introduces targeted amendments to UK privacy law, with practical implications for consent, complaint handling, and privacy operations. * New PECR exceptions create greater flexibility for some analytics and functionality cookies when statutory conditions are met. * Purpose classification, transparency, and meaningful user choice remain central to compliant consent experiences. * OneTrust has introduced UK-specific Consent & Preferences features and updates, and supports operational changes through Privacy Automation capabilities. Where the DUAA changes day-to-day privacy operations. Organizations need formal complaint handling processes. The most immediate operational change is the new complaint handling process. Under the DUAA, organizations must provide a way for individuals to submit complaints directly, acknowledge receipt within the required timeframe, investigate the complaint, communicate progress where appropriate, and provide an outcome before the matter reaches the ICO. For organizations with mature privacy rights programs, this introduces a new workflow alongside existing DSAR and incident response processes. For others, it creates a need to establish documented intake, investigation, approval, and recordkeeping procedures that demonstrate complaints are handled consistently and within the required timelines. Consent models are becoming more granular. The DUAA introduces several new PECR exceptions where consent is no longer required for specific storage and access technologies, including certain statistical and appearance or functionality purposes, provided the statutory conditions are satisfied. On the surface, this appears to simplify cookie compliance. In practice, it shifts the focus toward more precise consent configuration. Consider two common examples. A website uses a cookie solely to remember a visitor's language preference. That activity may fall within the appearance exception, allowing the organization to configure the experience differently from a traditional opt-in model. Now consider an analytics technology that measures user journeys. If that technology is used exclusively for qualifying statistical purposes, it may benefit from the statistical exception. If the same technology also contributes data for advertising measurement or profiling, the exception no longer applies and consent requirements change. These distinctions place greater emphasis on understanding how each technology is used rather than relying on broad cookie categories. One of the most significant operational shifts introduced by the DUAA is the increased importance of purpose limitation. The ICO's updated approach makes clear that exceptions apply only where storage or access takes place solely for the qualifying purpose. Once a technology serves multiple purposes, organizations should reassess whether the exception still applies. That creates practical work for consent and digital teams. Existing cookie inventories may need to be reviewed. Vendor configurations may need updating. Tagging strategies may need to separate activities that were previously grouped together under a single implementation. The result is a more accurate consent model that reflects the actual purpose of each technology. Stronger enforcement raises the importance of consent governance. The DUAA also aligns maximum PECR fines with the UK GDPR, significantly increasing the potential consequences for non-compliance. Alongside the new exceptions to requiring consent, the legislation reinforces expectations around transparency and user control. Organizations relying on the new exceptions still need to provide clear information and appropriate mechanisms for individuals to exercise choice where required. Consent experiences should continue to present balanced options, including clear access to granular controls. Turning DUAA requirements into operational controls. Configure uk-specific consent without rebuilding your strategy. OneTrust has introduced a dedicated UK GDPR CMP template that reflects the DUAA's amendments to PECR rather than treating the UK as an extension of EU consent requirements. This enables organizations to apply UK-specific consent configurations while maintaining consistent governance across broader privacy programs. For multinational organizations operating across both the UK and EU, this provides greater flexibility as the two regulatory frameworks gradually diverge in selected areas while continuing to share the same underlying principles. Apply cookie exceptions with greater precision. OneTrust has embedded DUAA exception logic into CMP configuration, supporting scenarios where qualifying functionality or performance cookies may be enabled by default when organizations determine they satisfy the appearance or statistical exceptions. Equally important is what remains under the organization's control: the platform reflects legal decisions, it does not make them. Organizations remain responsible for determining whether a technology genuinely qualifies for an exception based on its purpose and use. That distinction supports greater flexibility while reducing the risk of applying exceptions too broadly. Preserve user choice across digital experiences. The DUAA continues to place significant weight on transparency and meaningful user choice. OneTrust supports these expectations through consent experiences that include equally prominent Accept All and Reject All options, clear pathways to granular preference centers, and user experiences designed to avoid nudging individuals toward a particular decision. When an individual updates their preferences, the preference center provides the customer-facing experience for expressing those choices. Behind the scenes, the underlying consent and preference management layer captures those signals and helps ensure they are applied consistently across connected systems, creating a stronger foundation for enforcement, governance, and auditability. Support evolving privacy workflows. The DUAA's complaint handling requirements also increase the importance of structured privacy operations. OneTrust Privacy Automation supports organizations as they manage complaint workflows, privacy rights requests, documentation, and internal processes that help demonstrate how privacy obligations are handled consistently over time. Five practical steps before updating your UK privacy program. As implementation continues, organizations should review how the DUAA affects existing operational practices rather than treating the legislation as a simple legal update. * Review whether analytics and functionality technologies qualify for the new PECR exceptions based on their actual purpose. * Revisit cookie inventories and vendor configurations where technologies support multiple processing activities. * Validate UK-specific CMP configurations and consent experiences. * Establish documented complaint handling processes that align with the new requirements. * Finally, assess whether differences between UK and EU privacy requirements warrant separate operational approaches for your organization. Continue your DUAA readiness. Review your UK consent configuration. See how OneTrust Consent & Preferences helps organizations configure UK-specific consent experiences, apply purpose-based controls, and operationalize customer choice across websites and applications. Strengthen privacy operations. Learn how OneTrust Privacy Automation supports complaint handling, privacy rights workflows, and the documentation needed to manage evolving regulatory requirements with greater consistency. Key questions about the UK Data (Use and Access) Act.
OneTrust recognized as a Leader in Snowflake's Modern Marketing Data Stack report. Monday, July 6th, 2026 OneTrust, the AI-Ready Governance Platform(TM), today announced that it has been recognized by Snowflake, the AI Data Cloud company, as a Leader in the Privacy and Consent category in The Modern Marketing Data Stack 2026: Governing the Agentic Enterprise. This recognition marks the fourth consecutive year OneTrust has been named a Leader in the report. Now in its fifth year, Snowflake's Modern Marketing Data Stack report reflects a major shift in how marketing organizations operate - from fragmented tools toward AI-driven, agentic systems built on governed data foundations. This edition draws on insights from more than 11,500 Snowflake customers and ecosystem partners across 13 categories, highlighting how organizations are bringing industry-leading applications directly to their data to drive faster execution and proven business outcomes across the marketing lifecycle, while addressing the growing demands of data gravity, privacy and trust. "Governance is not separate from - or slowing down - innovation. It is what makes scalable, reliable and accountable AI-driven action possible." - The Modern Marketing Data Stack, 5th Edition, Snowflake The Modern Marketing Data Stack 2026 Names OneTrust a Leader Powering around two billion consent transactions a day, OneTrust provides the privacy, consent, and governance layer that helps marketers use customer data responsibly at scale. As AI increases demand for high-quality first-party data and third-party signals continue to decline, marketing teams use OneTrust to capture consent across digital touchpoints and apply those choices wherever customer data is used, enabling more personalized engagement while supporting compliance and responsible AI adoption. "Governance has long been foundational to the modern marketing stack, and it is even more important as teams bring AI and agents deeper into their workflows," said Ojas Rege, SVP of Emerging Products and Technologies at OneTrust. "It is what helps companies understand whether AI can be trusted to scale throughout the business and deliver value. OneTrust's recognition as a Privacy and Consent Leader highlights how marketing teams view governance as essential to innovating with AI." "Marketing teams are under pressure to move faster with data, but speed only creates value when it is grounded in governance," said Denise Persson, Chief Marketing Officer at Snowflake. "Together, OneTrust and Snowflake help enterprises turn trusted data into stronger customer experiences, more effective engagement, and durable business impact." How OneTrust Consent & Preferences Integrates with Snowflake The OneTrust Consent Management Snowflake Native App aligns customer consent policies with native data security controls in the Snowflake AI Data Cloud, enabling downstream marketing and data teams to work with permissioned data that reflects real-time consumer preferences. By embedding consent and governance controls more directly into data workflows, organizations can streamline compliance and improve access to governed data for AI and personalization use cases. As AI drives businesses to use data faster and more collaboratively, this functionality now extends to Snowflake Data Clean Rooms. The integration applies OneTrust consent signals to the data in Snowflake Data Clean Rooms to make consent enforceable across queries, analytics, and activation use cases. This empowers companies to operationalize consent within Snowflake, supporting fast and responsible data collaboration across brands, publishers, and partners.
OneTrust recognized as a Leader in Snowflake's Modern Marketing Data Stack report. OneTrust privacy and consent solutions enable marketers to use customer data responsibly at scale. June 25, 2026 10:40 ET | Source: OneTrust LLC ATLANTA, June 25, 2026 (GLOBE NEWSWIRE) - OneTrust, the AI-Ready Governance Platform(TM), today announced that it has been recognized by Snowflake, the AI Data Cloud company, as a Leader in the Privacy and Consent category in The Modern Marketing Data Stack 2026: Governing the Agentic Enterprise. This recognition marks the fourth consecutive year OneTrust has been named a Leader in the report. "OneTrust's recognition as a Privacy and Consent Leader highlights how marketing teams view governance as essential to innovating with AI." - Ojas Rege Now in its fifth year, Snowflake's Modern Marketing Data Stack report reflects a major shift in how marketing organizations operate - from fragmented tools toward AI-driven, agentic systems built on governed data foundations. This edition draws on insights from more than 11,500 Snowflake customers and ecosystem partners across 13 categories, highlighting how organizations are bringing industry-leading applications directly to their data to drive faster execution and proven business outcomes across the marketing lifecycle, while addressing the growing demands of data gravity, privacy and trust. "Governance is not separate from - or slowing down - innovation. It is what makes scalable, reliable and accountable AI-driven action possible." - The Modern Marketing Data Stack, 5th Edition, Snowflake The Modern Marketing Data Stack 2026 Names OneTrust a Leader Powering around two billion consent transactions a day, OneTrust provides the privacy, consent, and governance layer that helps marketers use customer data responsibly at scale. As AI increases demand for high-quality first-party data and third-party signals continue to decline, marketing teams use OneTrust to capture consent across digital touchpoints and apply those choices wherever customer data is used, enabling more personalized engagement while supporting compliance and responsible AI adoption. "Governance has long been foundational to the modern marketing stack, and it is even more important as teams bring AI and agents deeper into their workflows," said Ojas Rege, SVP of Emerging Products and Technologies at OneTrust. "It is what helps companies understand whether AI can be trusted to scale throughout the business and deliver value. OneTrust's recognition as a Privacy and Consent Leader highlights how marketing teams view governance as essential to innovating with AI." "Marketing teams are under pressure to move faster with data, but speed only creates value when it is grounded in governance," said Denise Persson, Chief Marketing Officer at Snowflake. "Together, OneTrust and Snowflake help enterprises turn trusted data into stronger customer experiences, more effective engagement, and durable business impact." How OneTrust Consent & Preferences Integrates with Snowflake The OneTrust Consent Management Snowflake Native App aligns customer consent policies with native data security controls in the Snowflake AI Data Cloud, enabling downstream marketing and data teams to work with permissioned data that reflects real-time consumer preferences. By embedding consent and governance controls more directly into data workflows, organizations can streamline compliance and improve access to governed data for AI and personalization use cases. As AI drives businesses to use data faster and more collaboratively, this functionality now extends to Snowflake Data Clean Rooms. The integration applies OneTrust consent signals to the data in Snowflake Data Clean Rooms to make consent enforceable across queries, analytics, and activation use cases. This empowers companies to operationalize consent within Snowflake, supporting fast and responsible data collaboration across brands, publishers, and partners. About OneTrust OneTrust, the AI-Ready Governance Platform(TM), enables innovation through the responsible use of data and AI. Trusted by thousands of companies, including over half of the Fortune 500, we help businesses govern well and move fast, turning responsible data use into a catalyst for growth. To learn more, follow OneTrust on LinkedIn or visit www.onetrust.com. (C) 2026 OneTrust LLC. All rights reserved. OneTrust and the OneTrust logo are trademarks or registered trademarks of OneTrust LLC in the United States and other jurisdictions. All other brand and product names are trademarks or registered trademarks of their respective holders.
OneTrust named a Visionary in the inaugural Gartner(R) Magic Quadrant(TM) for AI Governance Platforms. * 3 hrs ago ATLANTA, June 22, 2026 (GLOBE NEWSWIRE) - OneTrust, the AI-Ready Governance Platform(TM), today announced it has been named a Visionary in the 2026 Gartner(R) Magic Quadrant(TM) for AI Governance Platforms. This report represents the first Gartner Magic Quadrant for the AI governance platforms market. "We believe this recognition reflects a broader evolution in AI governance - from static reviews to runtime control," said DV Lamba, OneTrust's Chief Product & Technology Officer. "To scale AI adoption safely, companies must create value without creating unacceptable risk. That requires the ability to know, understand, and act on their AI estate while enabling innovation velocity. OneTrust's platform helps companies translate AI risk into enforceable controls across the lifecycle so governance moves at the speed of AI." OneTrust AI Governance Helps Teams Scale AI Faster, Reduce Risk, and Maintain Trust As AI evolves faster than most organizations are prepared to govern, organizations need governance that keeps pace - continuous, automated, enforceable, and audit-ready. OneTrust AI Governance helps organizations build that foundation through: * Scalable Compliance and Risk Management: OneTrust helps companies translate evolving laws, standards, and internal policies (such as the EU AI Act, NIST AI RMF, and ISO 42001) into operational controls, evaluations, and guardrails that teams can apply in day-to-day AI programs. * Governance Embedded into Repeatable Business Processes: OneTrust enables organizations to operationalize AI governance through structured workflows for intake, assessment, approvals, enforcement, and evidence collection. Observability capabilities put runtime signals like drift, hallucinations, and anomalous behavior in policy and compliance context so teams can take action before issues become incidents or audit findings. * Connected Oversight Across Modern AI Ecosystems: OneTrust gives teams centralized visibility and control across models, data, and agents, while embedding programmatic enforcement across development, deployment, and runtime environments - integrating directly with Azure Foundry, Azure ML Studio, AWS SageMaker, AWS Bedrock, Databricks MLflow, Databricks Unity Catalog, and Google Vertex to extend governance into the tools teams already use. Guardrails are applied consistently, and AI systems operate within approved, compliant boundaries. Together, these capabilities help organizations move from fragmented, manual AI oversight to governance that is continuous, embedded, and evidence-ready. But effective AI governance requires more than software alone. Many organizations are still defining what good AI governance looks like, from the policies and processes they need to the controls they should apply across real AI programs. OneTrust brings a decade's worth of experience helping customers build world-class privacy, risk, and compliance programs that stay ahead of constant change. As AI becomes the latest challenge facing these teams, OneTrust gives organizations a trusted foundation for shaping, scaling, and proving responsible AI governance, with practical approaches for translating emerging AI standards into governance programs that work across real AI use cases. How Organizations Operationalize Responsible AI Standards with OneTrust AI Governance Blackbaud, the world's leading provider of AI-powered solutions for social impact, uses OneTrust to align AI practices with NIST's AI Risk Management Framework. OneTrust enables AI governance to scale with Blackbaud's pace of innovation by integrating with data platforms like Databricks to accelerate stakeholder reviews and embed oversight at every phase of the AI lifecycle. Lumen Technologies, the trusted network for AI, leverages OneTrust automation, workflows, and centralized controls to scale its privacy operations, accelerate regulatory compliance, and reduce risk exposure. Citation: Gartner, Magic Quadrant for AI Governance Platforms, Sumit Agarwal, Lauren Kornutick, Priya Sundararaman, Nader Henein, Brandon Medford, June 2026 Gartner Disclaimer Gartner and Magic Quadrant are trademarks of Gartner, Inc. and/or its affiliates. Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose. About OneTrust OneTrust, the AI-Ready Governance Platform(TM), enables innovation through the responsible use of data and AI. Trusted by thousands of companies, including over half of the Fortune 500, Wdfx LLC help businesses govern well and move fast, turning responsible data use into a catalyst for growth. To learn more, follow OneTrust on LinkedIn or visit www.onetrust.com. (C) 2026 OneTrust LLC. All rights reserved. OneTrust and the OneTrust logo are trademarks or registered trademarks of OneTrust LLC in the United States and other jurisdictions. All other brand and product names are trademarks or registered trademarks of their respective holders. Media Contact Ainslee Shea +1 (404) 855-0803