Try our new research platform with insights from 80,000+ expert users
reviewer2394882 - PeerSpot reviewer
Compliance Analyst at a computer software company with 1,001-5,000 employees
Real User
Top 20
Implements data privacy with good pricing and support
Pros and Cons
  • "We have data from Jira regarding addiction related to Europe as well as California. Additionally, we have data related to the Indian Data Protection Bill. Therefore, GDPR compliance is highly beneficial."
  • "There are several areas for improvement. One is the integration capability. Connecting various DSAR systems can be time-consuming if a single integration takes months to complete."

What is our primary use case?

We are using OneTrust to implement data privacy within our organization.

How has it helped my organization?

We have data from Jira regarding addiction related to Europe as well as California. Additionally, we have data related to the Indian Data Protection Bill. Therefore, GDPR compliance is highly beneficial. The CPA also benefits from this. Data subjects are granted specific rights, known as DSR, making DSI crucial. With OneTrust, communication with data subjects is streamlined, allowing them to make requests, which we then process and fulfill using Alpha OneTrust. If a supervisory authority requests documentation from our company, we prepare Article 30 documents.

What is most valuable?

Everything is interconnected. While it might seem overwhelming to select specific digital options, each feature offers benefits. They provide extensive settings and details.

What needs improvement?

There are several areas for improvement. One is the integration capability. Connecting various DSAR systems can be time-consuming if a single integration takes months to complete. This integration challenge becomes more pronounced as data volumes grow and spread across different systems. One potential solution could be dedicating resources to support integration efforts, preferably individuals familiar with the OneTrust platform and the systems it needs to integrate. This approach could streamline the integration process and mitigate potential missteps, even for non-technical personnel.

Buyer's Guide
OneTrust GRC
November 2024
Learn what your peers think about OneTrust GRC. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
815,854 professionals have used our research since 2012.

For how long have I used the solution?

I have been using OneTrust GRC for almost two and a half years.

What do I think about the stability of the solution?

If I'm in a meeting and presenting somebody on OneTrust. It takes some time to load from one page to another page.

I rate the solution's stability an eight out of ten.

What do I think about the scalability of the solution?

Scalability is not an issue.

How are customer service and support?

Technical support is good. Whatever knowledge they have, they are providing us. They come and perform the things we want exactly. We are in between the support of OneTrust and ServiceNow. Each time, we have to contact OneTrust, then the respective system owner. The process could become better than it is now.

How would you rate customer service and support?

Positive

What's my experience with pricing, setup cost, and licensing?

If we use a particular module and find it very beneficial, then it is a good value for the price. There have been instances where we haven't used some modules despite paying for them last year. The pricing is reasonable, but we need to ensure we're maximizing the value of what we're paying for.

What other advice do I have?

OneTrust GRC integration can present some challenges, particularly for those without a technical background. It involves instances that may require some knowledge. Connectivity issues might arise, leading to disruptions. Despite these hurdles, efforts are being made to address and manage these challenges more efficiently.

I recommend the solution because it is cheap and valuable. Also, companies are becoming more aware of privacy. Privacy is directly proportional to these tools. OneTrust provides free certifications.

Overall, I rate the solution a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
reviewer2093358 - PeerSpot reviewer
Senior Enterprise Risk Manager at a retailer with 10,001+ employees
Real User
Top 10
Effective privacy management, but the technical support could improve, and it is difficult to implement
Pros and Cons
  • "It does help in the automation of our privacy impact assessments."
  • "There are limitations to customized workflow automation, and they need to increase both the available automation and the customized workflow."

What is our primary use case?

We use OneTrust GRC to evaluate internal and external projects for risk.

How has it helped my organization?

It does help in the automation of our privacy impact assessments.

What needs improvement?

The product itself, and perhaps most importantly, is not truly designed to fit the way people and users do their work.

There are limitations to customized workflow automation, and they need to increase both the available automation and the customized workflow.

For how long have I used the solution?

I have been using OneTrust GRC for one year.

We are working with Athena, which is a specialized version of the OneTrust GRC platform.

What do I think about the stability of the solution?

OneTrust GRC is quite stable.

I would rate the stability of OneTrust GRC an eight out of ten.

What do I think about the scalability of the solution?

OneTrust GRC is a scalable product.

I would rate the scalability of this solution an eight out of ten.

How are customer service and support?

Technical support could be improved.

I would rate the technical support a three out of ten.

How was the initial setup?

There are weaknesses in the implementation team, just getting up and running is difficult.

What's my experience with pricing, setup cost, and licensing?

I am not aware of the pricing. I am not involved in the budgeting process.

What other advice do I have?

They need to evaluate it carefully because not all of the different functionalities are developed to the same level of sophistication.

I would rate OneTrust GRC a six out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
OneTrust GRC
November 2024
Learn what your peers think about OneTrust GRC. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
815,854 professionals have used our research since 2012.
Regional Security Officer at a comms service provider with 10,001+ employees
Real User
Top 5Leaderboard
Helps streamline audit and incident management processes and gives a good return on investment
Pros and Cons
  • "The product helps us streamline audit and incident management processes."
  • "The product is not that easy to set up."

What is our primary use case?

Initially, we used the product to ensure our company in Brazil followed the recent data protection guidelines. Brazil has data protection laws very similar to GDPR in Europe. We focus on managing data usage and management policies.

How has it helped my organization?

The product helps us streamline audit and incident management processes. There's also a focus on third-party risk management.

What is most valuable?

The workflow approval process is valuable.

What needs improvement?

The product is not that easy to set up. It is also not easy to get used to the naming convention. It requires in-depth training.

For how long have I used the solution?

I have been using the solution for three months. I am using the latest version of the solution.

What do I think about the stability of the solution?

I rate the solution’s stability a nine out of ten.

What do I think about the scalability of the solution?

The tool is very, very scalable. I rate the scalability a nine out of ten.

How was the initial setup?

The solution is deployed on the cloud. The initial setup is very, very hard.

What was our ROI?

We see a return on investment. We manage our console much faster.

What's my experience with pricing, setup cost, and licensing?

The solution is expensive.

What other advice do I have?

I would recommend the product to others. It's not a silver bullet. If someone doesn’t have the process in place, the tool won't help them. Overall, I rate the solution a nine out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1589922 - PeerSpot reviewer
Manager, Information Security Risk at a university with 1,001-5,000 employees
Real User
Increases productivity, multiple level vendor reviews, and is reliable
Pros and Cons
  • "One of the valuable features of this solution is it has the ability to review fourth and fifth parties to the nth degree."
  • "They could improve by offering free help. A solution, a lot of times, is not just the use of the solution. For example, it is the overall engagement, how well do they support the system, what is their SLA, and how long their response time is to an issue. It would be beneficial if they had some type of professional services where they offer the first five hours of professional services a year for free. That would be a substantial benefit rather than having to buy professional services or professional services packages."

What is our primary use case?

I use the solution when internal customers want to engage with a third party through some type of cloud-based system. Right away I start reviewing from that perspective and I get the vendor's information that they are looking to engage with, I input the information into this solution. This solution has a process where I can send questionnaires out to the new prospective vendor. That prospective vendor will provision themselves into the solution by inputting all their information. This prevents me from inputting any information incorrectly. 

At this stage, I review all the information. The vendor will also upload all of their security documentation. This includes anything they can show that they are performing security best practices on behalf of their customers like us. This solution gives me the ability to double-check that information. I can do a risk review and risk rate it. There is a backend that will do a crowdsourcing type feature. For example, if there are other customers that have reviewed this particular vendor before, I can actually piggyback on that collected information and make my own judgment on whether or not it is a good fit for our environment.

How has it helped my organization?

By using this solution it has allowed me to free up some of my time and use my resources in other areas. Prior to using this solution, everything was done through a spreadsheet. Now with this solution, a lot of it is relational databases rather than a spreadsheet flat table. This solution also allows automation. You can start automating a lot of your processes as opposed to the manual process of using spreadsheets.

What is most valuable?

One of the valuable features of this solution is it has the ability to review fourth and fifth parties to the nth degree. 

What this means is, a vendor that is going to engage with us is called a third party. However, sometimes these vendors have their own vendors. The first example, this solution is a third party to us, but this solution uses Azure as their backend database, this is the fourth party to us. I am fine with this because I know Azure is doing its best due diligence with security best practices.

The comparative example, this solution wanted to start using an unknown company, such as Mike and Bob's server farm in Bob's garage as a vendor. I do not know who Mike and Bob are, if they had followed security best practices, do they close that garage door at the end of the night, or do they leave it wide open. All of our data could be sitting on those servers in that garage exposed. I would want to review that fourth party.

As vendors, as our internal customers are bringing these vendors on board with us, they go through this committee. I look at the third party level and question if they have any significant fourth parties. I do not really care about all the small little vendors, such as the person that mows their lawn outside of their office building. However, I do care about a significant fourth party, for example, someone that may be hosting our data on behalf of this third party. This solution allows me to go deep into that information, where other third party risk management platforms that we have reviewed are not able to do. They typically only do the third party level and not the fourth.

What needs improvement?

They could improve by offering free help. A solution, a lot of times, is not just the use of the solution. For example, it is the overall engagement, how well do they support the system, what is their SLA, and how long their response time is to an issue. It would be beneficial if they had some type of professional services where they offer the first five hours of professional services a year for free. That would be a substantial benefit rather than having to buy professional services or professional services packages.

For how long have I used the solution?

I have been using the solution for two months.

What do I think about the stability of the solution?

I have not had any issue with the stability of the solution.

What do I think about the scalability of the solution?

The solution is in the cloud which allows it to scale very well.

How was the initial setup?

The initial installation is straightforward. However, it can be as complex as you want to make it depending on how many internal systems you want to add. The time for installation typically takes three weeks.

Which other solutions did I evaluate?

We have evaluated other similar solutions and we choose this solution because it allows reviews of more than just the third party vendors.

What other advice do I have?

I rate OneTrust GRC a ten out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Consultor GRC/IRM at ISH Tecnologia
Real User
Top 20
Has a simple process and good technical support services
Pros and Cons
  • "We receive notifications or cases and prioritize them accordingly, which helps us address issues promptly."
  • "We encounter difficulties creating multiple platforms or interfaces and manual processes for changing certain settings."

What needs improvement?

We encounter difficulties creating multiple platforms or interfaces and manual processes for changing certain settings. Additionally, they could work on the issue related to a controller release in the development environment.

For how long have I used the solution?

We have been using OneTrust GRC for three years.

What do I think about the stability of the solution?

The platform is stable.

What do I think about the scalability of the solution?

We have around more than 20 OneTrust GRC users in our organization.

How are customer service and support?

The technical support services are good.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup process is simple.

What's my experience with pricing, setup cost, and licensing?

The platform is expensive.

What other advice do I have?

The product's feature for automation assists them in workflow management. We receive notifications or cases and prioritize them accordingly, which helps us address issues promptly. It keeps them informed about the company's activities at all times.

Overall, I rate it an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer:
Flag as inappropriate
PeerSpot user
reviewer1945110 - PeerSpot reviewer
Governance, Risk Management & Compliance, Director IT at a tech services company with 1,001-5,000 employees
Real User
Stable solution but lacking flexibility and integration between modules
Pros and Cons
  • "OneTrust GRC is stable."
  • "OneTrust GRC's workflows aren't automated and need to be manually driven."

What is our primary use case?

I mainly use OneTrust GRC for our incident response workflow and third-party risk management.

What needs improvement?

OneTrust GRC's workflows aren't automated and need to be manually driven. Its audit and compliance also aren't very flexible, and the integration between its different modules isn't 100% and needs to be improved.

For how long have I used the solution?

I've been using OneTrust GRC for about a year and a half.

What do I think about the stability of the solution?

OneTrust GRC is stable. 

How are customer service and support?

OneTrust's technical support is very helpful and open to feedback, but their workflow means that their response can take anywhere from a week to months, depending on the issue.

How was the initial setup?

OneTrust GRC's initial setup wasn't difficult, but the problems with integration make it cumbersome.

What's my experience with pricing, setup cost, and licensing?

OneTrust GRC's licensing costs about $15,000 per module.

What other advice do I have?

I would advise those thinking of implementing OneTrust GRC to make sure they have all their requirements clearly defined and make sure they're met, bearing in mind that OneTrust GRC is not a mature tool. I would give OneTrust GRC a rating of six out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free OneTrust GRC Report and get advice and tips from experienced pros sharing their opinions.
Updated: November 2024
Product Categories
GRC IT Vendor Risk Management
Buyer's Guide
Download our free OneTrust GRC Report and get advice and tips from experienced pros sharing their opinions.