Forrester's framing of the current market opens by naming a narrative and rejecting it.

In response to a narrative that pits innovation against risk management and regulation, privacy leaders are focusing on making privacy a critical enabler of innovation. Classic compliance use cases remain crucial, and privacy leaders are hungry for a toolkit that lets them ethically unlock data for analytics and AI.

That is a reversal of the function's historic position. Privacy has spent two decades as the department that says no, or more accurately as the department consulted after a decision was made, whose objections arrived too late to be useful and too early to be ignored.

The argument now is that a privacy function with good tooling says yes faster, because it knows what data exists, what basis it is held under, and what it can lawfully be used for. That is a different job, and it explains what these platforms have become.

What the software covers

Forrester's evaluation covers consent management, data discovery and classification, privacy rights management, risk assessments, third-party risk management, and emerging AI governance capabilities.

Six functions, and the ordering is roughly the historical sequence in which they became urgent.

Consent management arrived with cookie rules and marketing regulation. Data discovery and classification became necessary once organisations realised they could not honour obligations about data they could not locate. Rights management handles access, deletion, portability, and objection requests from individuals. Assessments cover impact assessments and legitimate interest balancing tests. Third-party risk covers processors and the chain behind them.

AI governance is the newest and the reason the category is being re-examined.

Worth distinguishing this from data governance, which Forrester evaluates separately. Data governance asks whether data is trustworthy, findable, and understood. Privacy management asks whether you are permitted to use it, for what, and for how long. Both hold metadata about the same data and answer different questions, and organisations that deploy one expecting the other discover the gap when someone asks for the lawful basis behind a dataset.

Fifteen vendors to nine

Forrester has scored this market four times, and the trajectory is unusually clean.

The Forrester Wave: Privacy Management Software, Q1 2020 evaluated fifteen providers against twenty six criteria: Crownpeak, DataGrail, LogicGate, LogicManager, Nymity, OneTrust, Poslovna inteligencija, Privacy Company, SAI Global, SAP, Securiti, Smart Global Privacy, Syrenis, TrustArc, and WireWheel.

The Q4 2021 edition scored twelve against thirty criteria: BigID, Collibra, DataGrail, Exterro, Ketch, MEGA International, OneTrust, Osano, Securiti, TrustArc, Truyo, and WireWheel. OneTrust placed as a Leader with the highest scores in strategy and market presence.

The Q4 2023 edition scored eleven against thirty four criteria, with Securiti placing as a Leader and characterised by Forrester as the most innovative vendor in the market.

The Q4 2025 edition scored nine providers across current offering, strategy, and customer feedback.

Fifteen, twelve, eleven, nine. Criteria rising from twenty six to thirty four while the vendor count fell by forty percent.

That combination describes a market where the bar rose faster than the participants, and where the surviving vendors absorbed adjacent functions rather than competing on the original one. Consent management, which was a business for several 2020 entrants, is now a feature.

Inside the Q4 2025 evaluation

OneTrust placed as a Leader with the highest scores in both current offering and strategy and maximum marks in twenty two criteria. Forrester described its vision as centring on governing risks to enable innovation and harnessing technology-driven disruption for better outcomes, and assessed its approach of tying privacy, governance, and AI risk management together as comprehensive and pragmatic, delivering more than the sum of its parts.

BigID placed as a Leader with above-average customer feedback, characterised by Forrester as the ideal partner for organisations shifting from manual oversight to intelligent, scalable privacy operations.

That phrasing points at the operational reality this category serves. Privacy programmes were built on manual review: a person assessing each new processing activity, each vendor, each data transfer. That model does not scale to the volume of systems, integrations, and now AI use cases that a modern organisation generates, and the failure mode is a queue.

Purpose limitation meets model training

The genuinely hard problem in this category is the collision between how privacy law is constructed and how AI systems are built, and it is worth being precise about it.

European data protection law rests on purpose limitation. Personal data is collected for specified, explicit, and legitimate purposes, and not further processed in a manner incompatible with those purposes. The lawful basis is tied to the purpose, and so is the retention period.

Model training sits awkwardly against that. Training data is valuable precisely because it is abundant, and the value frequently comes from data collected for something else. Whether training constitutes a compatible further purpose is a question that regulators have been working through, and the answers vary by context and jurisdiction.

The practical consequence for a privacy management platform is that it has to answer a question the previous generation of tooling never faced: for this dataset, under what basis was it collected, for what purposes, and does the proposed AI use fall inside or outside them.

That requires the purpose and basis to be recorded against the data at the level of granularity where the answer differs, which most organisations have not done. Records of processing activities exist as documents describing systems, not as metadata attached to datasets.

Which reframes what the discovery and classification capability is for. Finding personal data was originally about being able to respond to deletion requests. It is now about being able to answer whether a dataset can lawfully be used to train something, which is a considerably more consequential question and requires richer metadata.

Rights requests do not scale by hiring

Privacy rights management deserves attention because it is where the operational cost concentrates and where automation genuinely pays.

An access request requires an organisation to find every piece of personal data about an individual across every system, compile it, redact third-party information, and deliver it within a statutory window. A deletion request requires the same search followed by removal, with exceptions for data retained under other legal obligations.

Done manually, each request consumes hours across multiple teams. Organisations receiving hundreds of requests monthly cannot staff that, and the response quality degrades under volume in ways that are themselves a compliance risk.

The automation depends entirely on the discovery layer being accurate. A rights platform that searches the systems someone remembered to connect produces a response that is confident and incomplete, which is worse than a slow one.

There is a second-order problem arriving with AI. If personal data was used to train a model, a deletion request raises the question of what deletion means. Removing the record from the source system is straightforward. The model's weights are not a record, and cannot be edited to remove one individual's contribution. Approaches to this exist and none are simple, which is a reason to be careful about what personal data enters training in the first place.

Consent is harder than the banner

Consent management is the most visible part of this category and the least well done across the industry.

The legal requirement is that consent be freely given, specific, informed, and unambiguous, with withdrawal as easy as granting. The observable reality across the web is a decade of interfaces designed to make acceptance easy and refusal tedious, and enforcement action across several European jurisdictions has addressed exactly that gap.

For a buying organisation the implication is that consent tooling has to do more than display a banner. It has to record what was consented to, when, under which policy version, propagate withdrawal to every downstream system that received the data, and produce evidence of all of it years later.

The propagation requirement is where most implementations fail. Consent collected at the web layer and never transmitted to the marketing platform, the analytics warehouse, and the customer data platform produces an organisation that honoured a withdrawal in the interface and continued processing everywhere else.

That is a data plumbing problem wearing a compliance label, and it is the reason integration breadth matters more in this category than the feature comparison suggests.

Where this leaves the function

The shift Forrester describes, from privacy as constraint to privacy as enabler, is real and it is conditional.

It works where the privacy function has current, accurate knowledge of what data the organisation holds, under what basis, and can answer questions about proposed uses quickly. In that situation privacy genuinely accelerates, because the alternative to a fast informed answer is a slow uninformed one or a decision made without asking.

It does not work where the underlying records are stale documents maintained annually. There, better tooling produces faster access to unreliable information, and the function's answers get quicker without getting more trustworthy.

The distinction is not about the software. It is about whether the organisation treats its data inventory as infrastructure that is maintained continuously or as a compliance artefact refreshed before an audit.

The vendors have converged on the same conclusion, which is why discovery and classification appear at the centre of every Leader's positioning rather than the rights and consent workflows that defined the category five years ago. Knowing what you have turned out to be the prerequisite for everything else, and it is the part that cannot be bought as a project.

Analyst Source

Forrester Research

Category definition, vendor inclusion, and evaluation findings in this article draw on Forrester's coverage of privacy management software, scored in Q1 2020 against 26 criteria covering 15 providers, in Q4 2021 against 30 criteria covering 12 providers, in Q4 2023 against 34 criteria covering 11 providers, and in Q4 2025 covering nine providers across current offering, strategy, and customer feedback. Forrester evaluates data governance as a separate market.

Source research

Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy. Nothing here is legal advice, and regulatory positions change frequently.