A look at OneTrust, BigID, TrustArc, and others that help companies navigate the increasingly fragmented rules and privacy policies of the global internet
Companies have sprouted up to help others navigate the varied laws around the world governing websites. Tweets: @paulnemitz Tweets: Paul Nemitz / @paulnemitz : #GDPR and #Privacy laws drive new technologies and business models respecting individual rights. Here are some of those who make money in assisting corporations to comply and evade enforcement. Does the market now drive individual rights? @dmccabe https://www.nytimes.com/...
Context & Ripple Effects
This story lands at the intersection of two arcs already in the related coverage: a regulatory one and a commercial one. On the regulatory side, governments worldwide are moving against big tech with an urgency no single industry had seen before, while Congress stalls and state governments pass their own privacy and gig-work laws, multiplying jurisdictions instead of consolidating them. On the commercial side, the vendor category is not new — back in early 2020, hundreds of startups were already scrambling to help enterprises comply with the California Consumer Privacy Act.
What changed by late 2021 is scale and stakes: OneTrust, BigID, and TrustArc now sell navigation of a rulescape spanning dozens of countries — a landscape that efforts by 50+ countries to control digital data keep expanding. Paul Nemitz's framing in the piece sharpens the question for analysts: these vendors assist corporations both in complying and in evading enforcement, so does the market now drive individual rights, or manage them?
First-order effects
- Companies operating across borders become dependent on OneTrust, BigID, and TrustArc as de facto translators of fragmented privacy law — compliance capability is bought, not built.
- Regulators like those Nemitz cites gain a new intermediary layer between law and enforcement: vendors can route corporate behavior toward genuine rights-respecting design or toward minimal-compliance workarounds.
Second-order effects
- Every new jurisdiction — from state-level US privacy bills filling Congress's vacuum to national data-control regimes abroad — enlarges the addressable market for these vendors, meaning regulatory fragmentation itself subsidizes the compliance industry.
- The model spreads to adjacent trust functions: as the Sero AI story shows after Big Tech cut thousands of trust and safety staff, outsourcing compliance-adjacent judgment to vendors becomes a template across governance work.
Third-order effects
- If the pattern holds, governance becomes market access: the practical ability to operate globally runs through compliance platforms, giving private intermediaries structural power over how privacy law is actually interpreted.
- Whether individual rights strengthen or hollow out may depend less on each new statute than on how the vendor layer operationalizes it — a question regulators have barely begun to treat as its own policy problem.
The trend: As privacy and data rules fragment across dozens of jurisdictions faster than regulators can enforce them, a private compliance-vendor layer is becoming the de facto interpreter of digital-rights law.