Sorry, you have been blocked
This website is using a security service to protect itself from online attacks. The action you just performed triggered the security solution. There are several actions that could trigger this block including submitting a certain word or phrase, a SQL command or malformed data.
What can I do to resolve this?
You can email the site owner to let them know you were blocked. Please include what you were doing when this page came up and the Cloudflare Ray ID found at the bottom of this page.
Cloudflare Ray ID: 81950426daf027c0 • Your IP: Click to reveal 45.84.122.38 • Performance & security by Cloudflare
OneTrust

OneTrust is privacy, security, and data governance software that marketing uses as our privacy and compliance solution on our websites. The marketing operations team works closely with our legal team and is primarily responsible for our privacy and compliance on our websites including cookie preferences.
Support
- Technical assistance: Slack #digital-experience-team (requires separate account/login)
- [email protected]
Access
To access OneTrust, please create an access request. OneTrust is provisioned through Okta SSO via a Google group. A user is added via the Google group which is directly connected to Okta SSO and OneTrust. All users are added as a Project Manager . Please specify the role needed in OneTrust in the access request so it can be updated once you have access. See system default roles available below.
Training
Cookie Compliance module
Data Subject Access Requests (DSAR) module
System default roles
- Assessments Manager: Assessments Managers are business users who have access to most everyday and some administrative functions in the Assessment Automation module. By default, Assessments Managers have limited access to destructive and configuration functions.
- Audit Manager: Audit Managers are business users who have access to most everyday and some administrative functions in the Audit Management module. By default, Audit Managers have limited access to destructive and configuration functions.
- Auditor: Auditor users are business users who have access to a limited set of functions in the Audit Management module. By default, Auditors can contribute to workpaper results and log findings and have no access to destructive and configuration functions.
- Awareness Training Learner: Awareness Training Learners are low-level users who can only access training courses that have been assigned to them. Awareness Training Learners do not have access to any administrative functions.
- Awareness Training Manager: Awareness Training Managers are business users who have access to most everyday and some administrative functions in the Awareness Training module. By default, Awareness Training Managers have limited access to destructive and configuration functions.
- Consent Manager: Consent Managers are business users who have access to most everyday and some administrative functions in the Universal Consent & Preference Management module. By default, Consent Managers have limited access to destructive and configuration functions.
- Cookie Manager: Cookie Managers are business users who have access to most everyday and some administrative functions in the Cookie Compliance module. By default, Cookie Managers have limited access to destructive and configuration functions.
- Data Mapping Manager: Data Mapping Managers are business users who have access to most everyday and some administrative functions in the Data Mapping module. By default, Data Mapping Managers have limited access to destructive and configuration functions.
- Data Subject Requests Manager: Data Subject Requests Managers are business users who have access to most everyday and some administrative functions in the Data Subject Requests module. By default, Data Subject Requests Managers have limited access to destructive and configuration functions.
- Enterprise Policy Manager: Enterprise Policy Managers are business users who have access to most everyday and some administrative functions in the Enterprise Policy module. By default, Enterprise Policy Managers have limited access to destructive and configuration functions.
- Incidents Manager: Incidents Managers are business users who have access to most everyday and some administrative functions in the Incidents module. By default, Incidents Managers have limited access to destructive and configuration functions.
- Invited: Invited users have minimal access to the application. By default, Invited users can only access assessments which they have been invited to complete. The application is only accessible to these users through the link provided to them via email. Invited users are added by email address from an assessment. Invited users cannot be created on the Users screen.
- IT Risk Manager: IT Risk Managers are business users who have access to most everyday and some administrative functions in the IT Risk Management module. By default, IT Risk Managers have limited access to destructive and configuration functions.
- Maturity & Planning Manager: Maturity & Planning Managers are business users who have access to most everyday and some administrative functions in the Maturity & Planning module. By default, Maturity & Planning Managers have limited access to destructive and configuration functions.
- Privacy Notice Author: Privacy Notice Authors are business users who have access to creating, viewing, and editing all privacy notices. By default, Privacy Notice Authors have no access to destructive and configuration functions.
- Privacy Notice Manager: Privacy Notice Managers are business users who have access to most everyday and some administrative functions in the Policy & Notice Management module. By default, Privacy Notice Managers have limited access to destructive and configuration functions.
- Privacy Notice Viewer: Privacy Notice Viewers are business users who have access to viewing current versions of privacy notices. By default, Privacy Notice Viewers have no access to destructive and configuration functions.
- Privacy Officer: Privacy Officer users are high-level users who have access to most functions in the application. By default, Privacy Officer users do not have access to administrative and destructive functions such as audit logging, deletion, and integrations.
- Program Benchmarking Manager: Program Benchmarking Managers are business users who have access to most everyday and some administrative functions in the Program Benchmarking module. By default, Program Benchmarking Managers have limited access to destructive and configuration functions.
- Project Owner: Project Owner users are business users who have access to everyday functions in the application. By default, Project Owner users have limited access to administrative, destructive, and configuration functions. Project Owner users can launch assessments, review inventory data, view scan results, and complete other everyday business tasks.
- Project Respondent: Project Respondent users can create a password to log into the application and access a list of all assessments assigned to them. Project Respondents can be assigned assessments, risks, and needs more information requests, respond to assigned assessments, and add comments to assessments.
- Project Viewer: Project Viewer users have read-only access to the application. By default, Project Viewer users can view information, but cannot make any changes or respond to assessments. Project Viewer users cannot be selected as the respondent for an assessment.
- Site Admin: Site Admin users have complete access to the application. By default, all permissions are enabled for Site Admin users.
- Vendor Manager: Vendor Managers are business users who have access to most everyday and some administrative functions in the Vendor Risk Management Module. By default, Vendor Managers have limited access to destructive and configuration functions.
Custom roles can also be created. More in this support article (login required).
Implementation
See the epic for more information.
Cookie Compliance
Scanning a Website
The scanner simulates a user from Ireland (where OneTrust servers are located).
- Navigate to the cookie compliance module via the «home screen» after login and clicking on the cookie compliance tile or by clicking the «launchpad» icon in the top left corner next to the home icon.
- Click the Add Website button.
- Best practice: Add the root domain to scan without www . If you scanned a domain with www it will not capture domains with prefixes.
- Choose the GitLab organization to assign the domain scan to.
- Under More Details , you have additional options to use in the scan including limiting the scan to a number of pages (default is 1,000), limiting to a specific path within the site, clearing previous scan history, scanning pages with query parameters, targeting pages to scan within the site, or including sitemaps URIs.
Website scan menu
In the list of websites that have been scanned, you can hover over any domain and click the 3-dot icon on the right-hand side. Clicking this icon provides additional options for that particular website scan including:
- Re-scan: re-scans the website and provides additional options for the re-scan.
- Re-process
- Reassign: reassign to a different organization
- Login: This option gives you the ability to scan behind a login or web form; if clicked, you’ll be redirected to the website details to provide additional information; you can gather the web form HTML attributes by using the Inspect feature in Google Chrome
- Schedule: schedule a future scan (default: every 3 months for every quarter of the year); option to notify a user once completed
- Stop: stop a pending scan
- Delete: delete a scan
- Export scan results
- Get help
Configuring a Website Scan
More scan details
- Limit scan to 1000 pages: If you want to limit the scan to a number of pages. Note that as you increase the amount of pages to scan, the longer the scan will take to complete.
- Limit to this path within site: OneTrust considers about.gitlab.com/fr and about.gitlab.com 2 separate domains with this option enabled.
- Clear previous scan history: Does not delete previous data; scanner treats the domain as if its the first time scanning; (use case: significant cookie or design change on the website)
- Scan pages with query parameters: scan URLs with query parameters (ex: about.gitlab.com?utm_source=marketo); Input field example: name=first,name=last . Separate multiple parameters with commas. The scan will search through the domain with those noted parameters. Ensure the domain you enter includes ? at the end of the URL.
- Target pages to scan: Input exact URL site with full https:// ; use case: certain pages that might not be accessible to users or you want to scan this specific web page. For multiple pages, add a line break.
- Sitemap URIs: Input sitemap URL with https:// with .xml .
Scheduling Cookie Scans
- From the website scan menu, highlight the domain you wish to create scan schedule for.
- Click the 3-dot menu.
- Select Schedule .
- The default is set to every 3 months for every quarter of the year; You can also select a specific date.
- Optional: enter an email address to notify a user once a scheduled scan is completed.
Viewing Scan Results
When a scan is completed, you can view the results by clicking into the scan from the Websites menu. You’ll be taken to a scan dashboard that visualizes the results of the scan which includes information about:
- Tracking technology
- Cookies with category
- Tags
- Forms
- Pages
- Local storage
On the Show dropdown, you can view a summary of all scans for that particular domain and view previous individual scans with a date/time stamp.
From the main scan results page, you can also select these 6 categories to dive further into those specific results.
Cookie scan results
View categories of cookies including the name of the specific cookie. This information comes from and is compared to OneTrust’s cookie database. You can export these results by clicking Export in this view. After clicking Export you can choose the specific scan to export results from. When the export is ready for download, a notification will appear within the OneTrust tenant as the bell icon in the top-most menu.
Exporting Scan Results
From the bell icon, you can download the results ( .xlsx ).
Categorizing Cookies
- Navigate to Categorizations in the left-hand menu of the cookie compliance module.
- Click Categories .
- Clicking the arrow on a respective category will expand the description of this cookie category. This description is what users will see.
- Click the pencil icon to edit the cooke category description. Important: You must confer with the GitLab legal team before updating these descriptions as they must strictly align with our policies regarding cookie use.
These cookie categories are standard and the defaults provided by OneTrust:
- Strictly necessary cookies ID C0001: the website needs these cookies in order to function properly (example: identify items placed into a shopping cart)
- Performance cookies ID C0002: get information about how site visitors are using the website (example: Google analytics)
- Functional cookies ID C0003: provide additional enhancement of the experience of site visitors (example: language selector for localization)
- Targeting cookies ID C0004: cookies that attempt to gather more information about a user in order to personalize marketing (example: remarketing)
- Social media cookies ID C0005: social media services added to the site that enable users to share content with their friends and networks easily
You also have the ability to create a new cookie category.
Cookies in the Unknown category need to be categorized manually with help from developers, third-party vendors, or through a Google search.
Adding, Editing, and Removing Cookies
- Navigate to the Cookies tab under the Categorizations menu.
- View the list of cookies that have been identified and categorized, including the domain where it was identified, the lifespan of the cookie, the hostname, and the description.
- Click into each cookie individually to view more information about that cookie.
- In the Edit Cookie overlay, you can select a different category for the cookie, add a description for the cookie, update the lifespan of the cookie, note whether it’s a first-party or third-party cookie, and select the domains to manually assign the cookie to. Changing the lifespan of the cookie is for auditing purposes and does not change the functionality on the website.
- Manually add a cookie to a particular domain if you don’t wish to run the domain through a scan in order to pick it up. Click Add Cookie to manually add a cookie and input all the information regarding that cookie from step 4. Note: Host is not necessarily the domain where the cookie is but where the cookie is hosted. This will not add the cookie to the domain you input, but rather an existing cookie on the domain that is not part of the audit.
- You also have the option to bulk categorize cookies by selecting multiple cookies from the list. Select all cookies or specific cookies from the list, then click the double-arrow icon to bulk edit the categories of those cookies.
- Use the search bar to search for specific cookies by the cookie name or the host name.
- Use the filter icon to filter down to specific types of cookies by their category, domain, lifespan, or hostname (example: only view functional cookies).
Adding, Editing, and Managing Cookie Compliance Templates
Base templates
- Generic Cookie Banner: template that is not specific to a framework. It is meant to be used to create a global template.
- GDPR (General Data Protection Regulation): template with only cookie categories. You may enable IAB at any time. This template is GDPR compliant.
- IAB Transparency and Consent Framework 1.0: template for IAB Transparency and Consent Framework 1.0 based on recommended settings from the policy’s user interface guidelines. This will sunset in the first half of 2020.
- IAB Transparency and Consent Framework 2.0: template for IAB Transparency and Consent Framework 2.0 based on recommended settings from the policy’s user interface guidelines
- CCPA Template (California): template with verbiage, category groupings, and settings that match more closely with the California Consumer Privacy Act.
Add new template
- Click Templates .
- Click Add New Template .
- Select framework and laws that apply to the site.
- Name the template.
- Choose the GitLab organization.
- Add the default language.
- On the next screen, configure the layout, styling, content, and behavior fo the cookie banner. The right pane shows a preview of the cookie banner.
Customizing the Banner Template
Layout options
Most popular: Flat, bottom position
- Center rounded
- Flat
- Floating flat
- Floating rounded
- Floating rounded corner
- Floating rounded icon
- Position: bottom or top
Styling options
Colors are in RGB or hexadecimal code.
- Accept & reject button color
- Button text color
- Text color
- Background color
- Link text color
- Accordion background color
- Manage preferences button color
- Manage preferences link color
There are also options for custom CSS (not available in preview).
Content options
- Title & description (HTML supported) — the description may need customizing to match the consent model for the site, so as not to risk misleading visitors.
- Cookie policy link (link text and URL)
- Button set: show allow all button, show cookie settings button, cookie settings button name, cookie settings button style (link or button), show reject all button, show close button
Behavior options
- Require banner interaction: displays overlay that forces a choice by the visitor
Manage languages
Select the languages which you want to localize the cookie banner to. Also select the default language. You can set up different cookie banner options by language. Ensure that the language matches our policies. Toggling the show advanced langauges option shows country-specific versions of languages.
Preference center
In styling , you can choose to override the styling from the cookie banner to have a different styling for the preference center. This includes an option to add a logo and changing the accordion type for the cookie categories.
Notice there are different options in the preference center under layout as well. Depending on the options chosen, some features may not be available (example: choosing the tab layout removes the accordion feature for the cookie categories). Custom CSS is also available for the preference center.
There are options for WCAG (Web Content Accessibility Guidelines) best practices for accessibility in the preference center.
Advanced configuration
- Toggle Show cookies list to show a link to the user with cookie details related to the category they selected in the preference center.
- Select whether you want to show the user the various information about specific cookies including host, duration, type, category, and description. There are options here for linking to Cookiepedia as well as allowing the user to opt-out of a particular cookie host.
You can group the cookie categories as well as adding another group of cookie categories for a better user experience (example: new group called «ads» with the targeting and social media cookie categories grouped underneath).
Cookie list
This is the comprehensive list of cookies that is available to the user to view. In styling , you can adjust color options for title, cookie group name, table header text, table header background, and primary text. Toggle the table format on or off. There are options for custom CSS here as well. In content , you can adjust the options for the cookie list title, description, host, cookies column, and cookies used label. Toggle the show lifespan on or off.
Ensure any changes you make are approved by legal and saved within the OneTrust tenant.
Adding, Editing, and Deleting Geolocation Rules
- Click Geolocation Rules in the cookie compliance menu.
- A Default Consent Policy exists out of the box.
- Click Create New to create a new geolocation rule group.
- Name the rule group.
- Choose GitLab organization.
- Enter a description.
- In the rule group details , a default global rule exists which would apply these settings globally regardless of country. To add a country or region specific rule, click Add rule and update the options accordingly.
- Name the rule. (example: GDPR)
- Select the regions you would like to assign the policy to. Multiple regions can be included for a specific rule. Note: Geolocation for mobile devices uses coordinates reported by the internet-connected device. Users at or near borders may experience reduced accuracy for this function.
- Toggle Show Banner on or off. If unchecked, no banner will display but settings take effect.
- Input the template to use for this geolocation rule.
- Choose the consent model for this geolocation rule. Clicking the dropdown here, you can select a consent model for all cookie categories or specify the consent model for each cookie category. Toggle Do Not Track by the cookie category.
- In Behaviors you can toggle the behavior for this rule in conjunction with the cookie banner and whether that particular behavior will accept all cookies or not as well as closing the banner.
- Reconsent will occur after: this will prompt the banner again for users to capture reconsent. The default is 1 year but can be configured by months, years, and days.
- Capture records of consent: cookie ID associated with each user; the consent module logs those preferences.
- Advanced analytics: sends browser type, device type, and country where the user consented. This information will be shown in the dashboard. Toggle this to a specific cookie category (example: performance cookies for Google analytics).
- Google Consent Mode is a feature that controls how Google services, such as Google Analytics and Google Ads, collect and use data from website visitors based on their consent preferences. The Storage Type column contains the fixed consent type from Google. Each Storage Type should map to the OneTrust cookie category to ensure Google platforms aligns with OneTrust.
Assigning a Geolocation Rule Group to Domains
Assigned domains
- Click Assign to Domains .
- Select the domains you would like to assign the geolocation rule to.
- Click Assign .
Consent models
- Opt-in consent model: If you select Opt-in, all cookie categories (besides Strictly Necessary) will be set to Inactive. These cookies will not be set on the visitor’s device unless they are enabled in the preference center.
- Opt-out consent model: If you select Opt-out, all cookie categories (besides Strictly Necessary) will be set to Active. These cookies will be automatically enabled when the visitor lands on the website. The website visitor can disable the non-Strictly Necessary cookies in the preference center.
- Implied consent: all cookie categories (besides Strictly Necessary) will be set to Inactive Landing Page. These cookies are not set until the website visitor clicks the OK button on the cookie banner or continues browsing the website. The website visitor can disable cookie categories in the preference center.
- Notice only: If you select Notice Only as the default consent model, all cookie categories will be set to Always Active and cannot be disabled by website visitors. A banner informing the visitor that the website uses cookies will be displayed on the landing page of the website.
- Custom: If you select this option, you can set a different default status for each category of cookie on your site. You can customize the consent model to suit your organization’s needs and can set the Do Not Track status for each category of cookie.
Banner Rules
The OneTrust banner is only visible to new website visitors based on a set of logic listed below. In regions where the banner does not display, the user can still consent to cookie categories from the Preference Center window by clicking on the «Cookie Settings» or «Do not sell…» link located in the footer section.
| Region | Consent Model | Banner Visibility | Buttons |
|---|---|---|---|
| California | Opt out | Not visible | |
| Colorado | Opt out | Not visible | |
| US | Opt out | Not visible | |
| Europe, Colombia, Russia, Liechtenstein, United Kingdom, Iceland, Norway, Peru | Opt in | Visible to new users | Cookie Settings, Accept All Cookies |
| Korea, Brazil, Canada, South Africa, Macao | Opt out | Visible to new users | Cookie Settings, Accept All Cookies |
| France, Spain | Opt in | Visible to new users | Cookie Settings, Reject All, Accept All Cookies |
| Global | Opt out | Not visible |
Accessing Scripts
- To access the scripts, click Scripts in the left menu of the Cookie Compliance module.
- Click the domain where the script will be implemented.
- Any time a change is made to a domain within the OneTrust tenant, those changes must be published to production in order for the users to see those changes reflected in the cookie banner, preference center, etc.
Testing
Test scripts are available to roll out new changes. The test scripts are not domain specific. The test script matches the production script functionality except:
- There is no cache, meaning changes can be viewed immediately.
- This script will function on your test site and should be used for testing purposes only.
Publishing the test scripts will not affect the live production scripts.
Production
Production scripts are for use in live websites. Fastest page load speed. Published changes will take up to 4 hours to show.
The script tags need to be placed as the first element in the <head> of the site. It is important that the OneTrust script is placed before other scripts on the site to ensure users have a chance to consider their cookie preferences before cookies are potentially dropped on their machines.
Scripts implemented in root domains are also applied to subsequent subdomains and paths. Scripts implemented on subdomains are only applied to subdomains.
In order to push changes to production, click Publish Production Scripts and note any changes to the script as you may have to re-copy and re-implement the script in the <head> of the site.
Script Version
Click Publish Test . Here you can choose which version of the script to publish. You will also be alerted to which features may or may not be compatible with a script version including the field name, old value, and new value. Click Confirm .
Publication Settings
Here you can confirm the publication settings of the script. Note: enabling or disabling some of these settings may change the embed script and would have to be re-implemented on the site.
- Publish individual languages: when toggle is off , all languages will be published
- Do you require users to re-consent? Switching to IAB TCF 2.0 requires that your users re-consent, as preferences have changed. TCF 2.0 is not backwards compatible with TCF 1.0
- Prevent fetching banner: When toggle is on , the banner template HTML and CSS will not be fetched from server as the otSDKStub.js loads
- Prevent fetching preference center: When toggle is on , the preference center template HTML and CSS will not be fetched from server as the otSDKStub.js loads
- Enable automatic blocking of cookies: If enabled, cookies will automatically be blocked until user has consented. Auto-blocking will block scripts that drop cookies categorized outside of strictly necessary on page load automatically
- Enable language detection on scripts: if the language cannot be determined, the templates default language will be used (options: determine the language from the site visitor’s browser settings or determine the language from HTML page)
Click Publish Test Scripts . Implement the script into the HTML of your staging site.
Auto-Blocking
When the Auto-blocking feature is toggled ON under publication settings, an optanon. class is appended to all script tags that store cookies on the browser. The script will only load if the user consent to the cookie category. For example, the following Vimeo script contains the optanon-category-C0002 class value, meaning the Vimeo script will only load if the user consent to the Performance cookie category: <script src=»https://extend.vimeocdn.js/» >
To override the optanon class and remove the autoblocking feature from certain scripts, the script will need to be removed from the cookie’s source on OneTrust:
- Under Setup > Categorizations > select All Cookies
- Click on the filter icon > click on Add Filter > click on Add Field: Default Category > select the category from the optanon script > click Apply
- Click into each cookie > click Source
- Remove the desired script from the cookie’s source
- Publish the script
Do Not Sell & Cookie Setting Button
This will display either Do Not Sell My Data button or Cookie Settings button based on where the site visitors come from according to the geolocation rule group associated with the domain. The script has a class that can be customized through CSS.
Cookie List Script
These two methods initialize the OneTrust Publisher SDK. The initializeOneTrustPublishersSDK method fetches all of the resources configured in geolocation rules, templates, and vendors. The loadPreferenceCenter method is used to load the banner or preference center. By passing in true , the preference center will always load. By passing in false , the banner will be displayed for initial consent and re-consent.
OneTrust enhances Trust Intelligence Platform to empower responsible data use
OneTrust announces new innovations across the Trust Intelligence Platform to help organizations responsibly use data and drive trust intelligence at scale.
As companies tackle the challenges of data sprawl, OneTrust’s enhancements provide companies with the discovery, automation, and intelligence to manage data responsibly across the entire life cycle, enable regulatory agility, and implement privacy by design. New capabilities also help organizations gain better visibility into their third parties and streamline their compliance programs.
Most organizations already recognize the intrinsic value of being a trustworthy business, but research shows that the value of trust is measurable. According to IDC, “Prioritized investment in trust programs is significantly associated with improved business resilience, operational efficiency, and sustainability worldwide.”
“Companies want to unlock the value of trust, but they need the scalability and visibility of an integrated platform,” said Blake Brannon, Chief Product and Strategy Officer at OneTrust. “With these new capabilities, our customers have the foundation to build a resilient business and become good stewards of data – fostering trust with customers, employees, and stakeholders. Rather than reacting to constantly changing privacy, risk, and compliance requirements, we’re helping organizations differentiate with trust to drive their business forward.”
The Trust Intelligence Platform provides a single, comprehensive foundation to consolidate solutions across privacy, security, ethics, and ESG. Going beyond standalone tools and point solutions gives organizations the improved collaboration across departments and teams, centralized intelligence, and better decision-making capabilities to see the measurable benefits of trust.
OneTrust continues to enhance its privacy management, data discovery and governance, and consent and preferences solutions to enable regulatory agility and responsible use of data across the entire life cycle:
AI-driven document classification for improved governance: Effective data governance requires full visibility into all data in the organization and where it resides. Now, OneTrust Data Discovery is becoming more intelligent by using machine learning to identify documents with sensitive data which can’t be detected through traditional pattern matching.
Powerful classification capabilities identify data by its content and structure, such as sensitive data within a resume, and automatically apply a retention or deletion policy. This context, intelligence, and automation means less manual work for privacy and security teams to protect and responsibly use data across the organization.
Streamlined Privacy by Design projects: OneTrust has added a new Projects inventory and Privacy by Design template to the assessment template library. This enables users to assess the privacy impact of internal and external products and embed privacy by design into the product or project life cycle.
In combination with Data Mapping, this template can be used to associate risks with projects in the data inventory and create relationships across other inventory objects, including assets, vendors, processing activities, and risks. With heightened scrutiny on the development of AI, this new functionality can also help assess privacy risk against AI products and projects to drive responsible AI.
Data transfer enhancements: As organizations navigate continually evolving compliance requirements for safeguarding cross-border data transfers, OneTrust helps them more accurately and efficiently track, manage, and evaluate data transfers.
Users can achieve visibility across the entire transfer life cycle thanks to an improved cross-border map to visualize transfers, a new data graph visualization, and the ability to directly assess transfer records for risk. This enables organizations to ensure the appropriate measures have been taken, such as delivering appropriate notice to consumers, conducting transfer impact assessments, and implementing safeguards.
Optimized consent management throughout the data life cycle: OneTrust’s consent platform has been enhanced to help organizations deliver the optimal user experience, capture consent, and manage data at scale more effectively and efficiently.
Teams can now import historical data and capture new records of consent and data using forms or APIs, and integrate consent-based activation across systems including Adobe Experience Platform (AEP) and Tealium. Acting as an organization’s central consent library, OneTrust’s consent and preferences solution provides enterprise-grade speed and scale to manage data throughout the life cycle.
The global regulatory and threat landscape changes each day, requiring organizations to understand and manage a multitude of new requirements and risks. OneTrust is also announcing several new innovations designed to scale security and compliance programs, manage regulatory and reputational risk, drive effective ethics and compliance programs, and foster organizational resiliency:
Expanded frameworks for Certification Automation: The fast-expanding compliance landscape means businesses must now navigate a growing number of frameworks and requirements.
Now offering 31 frameworks across privacy and security, Certification Automation has added six new frameworks including a proprietary US State Privacy Legislations framework covering US state privacy acts: California (CCPA and CPRA), Virginia (VCDPA), Colorado (CPA), Utah (UCPA), and Connecticut (CTDPA).
In addition, InfoSec coverage has been expanded to include NERC CIP, ISO 27017, ISO 27018, NIS 2, and Cyber Essentials (UK). With the ability to automate evidence collection and test once, comply many, organizations can gain efficiency at scale and better plan and report on their privacy and InfoSec programs.
New intelligence data in the Third-Party Risk Exchange: Organizations need recent and relevant risk data to evaluate their third parties with accuracy and confidence. The OneTrust Third-Party Risk Exchange provides instant access to risk intelligence data from numerous data sources, including Supply Wisdom. Supply Wisdom brings compliance, financial, operations, location based ESG, and cyber risk data about third parties directly into the Third-Party Risk Exchange.
Organizations can use this data, along with granular data from SecurityScorecard, RiskRecon, DataGuidance, and ISS Corporate Solutions, to monitor third parties over time and automate actions when risk scores change – enabling more scalable, efficient third-party management programs.
Leverage HR data for workflows in OneTrust Disclosure Management: An employee’s management hierarchy is often best positioned to manage disclosure and conflict of interest risks due to their understanding of the individual and job requirements. Implementing this manually can be time intensive and ineffective.
With OneTrust Disclosure Management, organizations can now use their HR data to intelligently route disclosures to different workflows and automate the assignment of approvers within those workflows. This ensures that disclosures are sent to the appropriate individuals at the appropriate time, delivering effective risk management and reducing the need for manual intervention.
Beneficial owner screening in Third-Party Due Diligence: Regulations such as the OFAC 50% rule require organizations to verify whether beneficial owners with 50% or greater individual or combined ownership are sanctioned when screening third parties.
The new Linked Entities functionality within the OneTrust Third-Party Due Diligence solution allows customers to add and screen beneficial owners against sanctions lists and adverse media concerns. Organizations now have the tools to meet regulatory expectations tied to beneficial ownership while protecting their brand against harmful third-party relationships.
One trust что это
«Строго конфиденциально»: самая быстрорастущая компания США заработала $70 млн на cookie-баннерах
Текст: Том Фостер

Кабир Бардай из Атланты собирался торговать пиццей по франшизе, но вовремя разглядел огромный рыночный потенциал совсем в другой сфере. Как раз тогда Евросоюз и некоторые американские штаты стали разрабатывать законы о защите персональных данных, к чему бизнес был совершенно не готов. Стартап Бардая OneTrust разработал линейку продуктов, которые помогают компаниям обрабатывать информацию о пользователях, не нарушая законодательство. Как результат — годовая выручка в $70 млн и первое место в списке самых быстрорастущих американских компаний Inc. 5000.
«За cookie-баннером скрывается много интересного», — говорит основатель и CEO компании OneTrust Кабир Бардай. Речь идет о тех самых всплывающих окнах, которыми сайты уведомляют, что собирают наши данные о посещениях и действиях ради персонализации контента. Ну или чтобы продать информацию о нас третьей стороне. Сookie-баннер — пожалуй, самая узнаваемая и заметная часть софта OneTrust, за которой скрывается много сложных и невидимых пользователю процессов.
Сейчас стартап Бардая — один из мировых лидеров в сфере работы с конфиденциальной информацией о пользователях (за последние три года он вырос на рекордные 48337,2%). Цифровые инструменты OneTrust позволяют компаниям получать более чёткое представление о собранных ими пользовательских данных. И благодаря этому — не нарушать законы и нормативные акты вроде Общего регламента Евросоюза по защите данных (GDPR), который гарантирует пользователям контроль над использованием их персональной информации.
OneTrust в цифрах
место в рейтинге Inc. 5000 в 2020 году.
— выручка за 2019 год.
тыс. человек — количество сотрудников компании.
тыс. клиентов у компании в 2020 год.у
технологий запатентовала OneTrust.
В арсенале большинства компаний никогда не было технологий для защиты конфиденциальных сведений об их клиентах. Но теперь, когда законодатели обращают всё больше внимания на жалобы пользователей о злоупотреблении их данными, бизнес просто обязан обзавестись таким инструментарием. В январе в Калифорнии вступил в силу свой закон о персональных данных пользователей (CCPA) — и это лишь один из множества подобных правовых актов. В будущем их станет ещё больше, а значит, в геометрической прогрессии вырастут и потенциальные убытки компаний, которые не соблюдают принятые нормы.
Вот почему технологии OneTrust стали решением для примерно половины фигурантов списка Fortune 500. Сейчас у компании Бардая около 6 тыс. клиентов из самых разных сфер бизнеса, включая Aetna, Oracle, Raytheon, Bertelsmann и Maersk. Да, у всех на слуху другие, куда более раскрученные технологические стартапы. Но с точки зрения бизнеса нет ничего лучше, чем незаметно взять под контроль крупную и постоянно растущую нишу.

В погоне за американской мечтой
Каждый предприниматель проходит проверку на прочность, когда ищет для себя рыночную нишу, а затем борется за неё. Мягкий в общении и напористый по жизни Бардай смог разглядеть будущий гигантский рынок, когда тот находился ещё в зачаточном состоянии. Он ухватился за эту возможность, так что в этом смысле может служить примером усердия, энергичности и умения произвести верный расчёт.
По словам Бардая, его родители приехали в Атланту из Индии в 1983 году с надеждой воплотить в жизнь типичную американскую мечту — «достичь всего, чего захочешь». Отец занимался разработкой ПО и записал 10-летнего Кабира на компьютерные курсы в местном колледже. Вскоре Бардай-старший ушёл с работы и открыл несколько заправок и закусочных, после чего помог и сыну создать собственную компанию по веб-разработке. Это был не слишком прибыльный, зато непыльный бизнес, — всяко лучше, чем стричь соседский газон. «Я обошёл все фирмы в своем районе и стал делать для них сайты за $5—7 тыс.», — вспоминает Кабир.
Родители с самого детства учили Бардая мыслить масштабно. Когда он стал бойскаутом, ему сразу поставили задачу-максимум — заслужить высшее звание Игл-Скаута. «Если не планируешь стать лучшим в своем деле, лучше не начинай», — вспоминает Кабир слова родителей. Именно поэтому он всегда избегал командных видов спорта — боялся не дотянуть до завышенных стандартов. Совсем другое дело — стремительная карьера в сфере технологий, где сын полностью оправдал ожидания своих родителей.
Кабир отучился в Технологическом институте Джорджии и получил место в одной из самых быстроразвивающихся компаний Атланты — AirWatch. Фирма занималась корпоративной безопасностью мобильных устройств. На дворе стоял 2010 год — самый разгар революции телекоммуникаций. К тому времени трендом на рынке труда стала концепция BYOD (bring your own device) — сотрудники получили возможность работать в офисе на своих собственных устройствах вместо выданных работодателем.
Раньше IT-отделы крупных компаний выдавали своим сотрудникам служебные мобильные телефоны и полностью контролировали их использование. Но по мере удешевления этих гаджетов ими стало обзаводиться (и пользоваться на работе) всё больше людей. Это позволило AirWatch занять в 2012 году 467 строчку в списке Inc. 5000.
Вместе с компанией рос и сам Бардай. Он всё чаще работал с крупнейшими международными партнёрами и устанавливал им ПО AirWatch. А после того как в 2014 году компанию за $1,5 млрд купил софтверный гигант VMware, Кабир занялся разработкой и запуском новых продуктов.
В шаге от собственной пиццерии
В какой-то момент Бардай понял, что больше не хочет быть наёмным работником, и решил заняться предпринимательством. По сути, единственным вариантом, который он тогда рассматривал, было скооперироваться с отцом и открыть по франшизе несколько пиццерий Pizza Studio на юго-востоке страны. Но прежде чем подписать контракт, Бардай погрузился в размышления: действительно ли его призвание — торговать пиццей? Сможет ли он стать лучшим в этом деле?
«Я, конечно, люблю пиццу, но не уверен, что хочу ею заниматься, — рассуждал Кабир тогда. — Кто угодно с дипломом колледжа может пойти и открыть закусочную по франшизе. А для чего создан я?»
Примерно в то же время Бардай всерьез задумался об обратной стороне технологий AirWatch, которые защищали конфиденциальность данных на личных девайсах сотрудников. Специальное ПО мониторило установленные приложения и уведомляло, если в них обнаруживалась потенциальная угроза для корпоративной информации. Но сам по себе мониторинг мог стать не меньшей угрозой. Если компания знает, какие приложения устанавливает сотрудник, то автоматически получает доступ к конфиденциальной информации, например о его вероисповедании, сексуальной ориентации или финансовом положении. Кому захочется, чтобы начальство знало, какими дейтинговыми сервисами вы пользуетесь или от какой зависимости пытаетесь избавиться.
Бардай убедил руководство отдать ему на откуп разработку «инструментов, приоритезирующих безопасность данных сотрудников». В результате софт Кабира завоевал приз Международной ассоциации специалистов в области конфиденциальности (IAPP). Его пригласили на большую тематическую конференцию, где и зародилась идея создать OneTrust. Бардай ходил между залами, слушал выступления спикеров на тему управления данными и осознал, что бизнес совершенно не готов работать в новых условиях европейского законодательства.
В работе с персональной информацией европейцы сильно обогнали американцев, которые долго оставались цифровым Диким Западом, живущим по принципу «никаких секретов». Технологические гиганты бросили все свои лоббистские ресурсы против принятия законов о конфиденциальности вроде европейского GDPR. Но Бардай быстро осознал, что эти нормы неизбежно начнут действовать. А у бизнеса по-прежнему не было никаких разработок, способных обеспечить необходимую по закону защиту.
«Я никогда ранее не видел индустрию, которая росла бы быстрее, — говорит Кабир. — И где-то тут была явная несостыковка. Множество компаний из индустрии данных занимались консалтингом, но даже из проекта GDRP было видно, что грядут фундаментальные изменения, которые перевернут индустрию с ног на голову. Требовалось не просто внесение правок в политику конфиденциальности, а наличие технических возможностей для удаления и сокрытия данных».
«Кабир — настоящий визионер, — отзывается о коллеге многолетний глава IAPP Тревор Хьюз. — Все понимали, что придётся иметь дело со сложными материями и риски возрастут по мере увеличения объёмов данных. Но в те времена большинство компаний ещё вели отчётность по конфиденциальной информации в таблицах Excel и электронных письмах. Кабир сразу понял, что рынок нуждается в единой платформе, через которую можно было бы отслеживать процесс сбора данных и управлять им».
В общем, идея открыть пиццерию отпала сама собой.

Через два года Бардай уже был готов официально запустить OneTrust. Как раз к тому времени сделка между AirWatch и VMware вступала в силу безвозвратно. Поэтому Кабир просто переманил к себе большую часть топ-менеджмента поглощённой компании, включая её основателей. «Я выбрал самое подходящее для этого время», — говорит он, чуть ухмыляясь.
На старте Бардай вкладывал в компанию собственные деньги. Но позже в команду пришли основатели AirWatch Алан Дебири и Джон Маршалл. Ещё до AirWatch они создали миллиардную компанию и успешно вывели её на IPO. Теперь Дебири и Маршалл своими кредитами финансировали агрессивный выход OneTrust на рынок. «Мои партнёры разбирались в том, как работает корпоративное ПО, доверяли мне и понимали, что рынок можно завоевать только играя по-крупному», — рассказывает Бардай.
Вместо того чтобы обивать пороги венчурных фондов и с тревогой ждать, чем закончится каждый новый раунд инвестиций, OneTrust смогла разработать всю линейку своих продуктов, полагаясь только на себя и будущую выгоду.
Кабиру ещё не было 30, но он уже накопил достаточно опыта и знаний, чтобы предугадывать желания клиентов и подгонять предложение под их нужды. Работа в AirWatch подарила ему полезную привычку постоянно работать «в полевых условиях».
Европейский регламент GDPR приняли в 2016 году, буквально за считаные дни до запуска OneTrust. Закон вступил в силу в 2018 году, когда у Кабира и его коллег уже всё было наготове. И ровно в том же году законодатели в Калифорнии приняли аналогичный акт — CCPA.
Сегодня собственное законодательство по защите данных пользователей разрабатывают многие страны. Требования к компаниям становятся всё жё стче и запутаннее, и поэтому гибкие технологии управления конфиденциальностью нужны буквально всем.
По прогнозу Gartner, к 2023 году 65% населения планеты будет подпадать под действие национальных законов о конфиденциальности персональных данных. Сегодня эта цифра несколько скромнее — всего 10%. Более того, «глобальная цифровая экономика распространяется по миру за доли секунды и компаниям для спокойствия уже недостаточно соблюдать закон какой-то одной страны, где бы они ни были зарегистрированы. Приходится подстраиваться под целый ряд зачастую противоречащих друг другу нормативных актов в разных юрисдикциях», — говорит Хьюз. И стоит помнить, что нарушение одного лишь пресловутого регламента GDPR обойдётся вам штрафом в 4% от годовой выручки.
Все эти факторы вкупе дают бесконечно растущий рынок. По оценке Market Study Report, к 2025 году объём рынка ПО для управления конфиденциальными данными превысит $3 млрд.
Магнит для проблем
Стартап Бардая уже запатентовал более 100 технологий и обслуживает больше cookie-баннеров (а значит, и операций с данными), чем любая другая компания в мире.
Конкуренцию OneTrust составляют давно укоренившиеся на рынке и адаптировавшиеся под новые реалии компании вроде TrustArc, стартапы с поддержкой венчурных фондов (например Privitar из Лондона) и, конечно, старые добрые гиганты SAP и IBM. Но OneTrust пока удаётся удерживать лидерство — согласно последнему докладу Forrester Research, стартап из Атланты занимает первые строчки во всех категориях: спектр услуг, стратегия и присутствие на рынке.
«Мы, словно гигантский магнит, вытягиваем и собираем все иголки, спрятанные в стоге сена. Под иголками я подразумеваю скрытые проблемы, — объясняет Бардай. — Может случиться что угодно. Например, кто-то скачает таблицы с данными из ваших систем управления и разошлёт всем на почту. Ваши разработчики пользуются кучей инструментов, включая Facebook и Google, и любая из платформ может начать собирать данные вашей компании (вы и не заметите). Да, в конце концов, вы могли просто выступить организатором мероприятия и ваши сотрудники заранее поинтересовались у гостей, нет ли у кого-то особых предпочтений по меню. Теперь им известно, кто предпочитает кошерную пищу, а кто — халяльную. А это уже сбор информации о вероисповедании».
Полторы тысячи сотрудников OneTrust, которые работают в восьми разных точках планеты, с трудом справлялись со скачкообразным ростом спроса во время принятия новых законов о защите данных. «Когда в силу вступали GDPR и CCPA, абсолютно все игроки на рынке пытались закупить ПО в последний момент. В таких случаях нужно любой ценой успеть заключить сделку, другого шанса не будет. Мы, конечно, могли расширить штат только на этот конкретный период, но что потом? Просто выкинуть сотрудников на улицу? Я бы так никогда не поступил. Поэтому мы просто поднажали в темпах работы с уже имеющейся командой. Конечно, мы выписывали им премии, закупали в офисы обеды, ужины, мороженое и даже оплачивали массаж. Делали всё, что можем», — вспоминает Кабир.
Пока всё работает исправно. Три года стартап неуклонно рос с поддержкой основателей AirWatch. За последний год OneTrust смогла привлечь $410 млн венчурного капитала в двух раундах, проведённых Insight Partners. В итоге рыночная стоимость компании составила $2,7 млрд.
Бардай остался верен американской мечте своих родителей и лишь приумножил ценность компании, которую он сам называет «полноценной инфраструктурой, способной стать интегральной частью бизнеса». Сейчас его стартап — это платформа, во многом похожая на Saleforce, но только в мире управления пользовательскими данными.
Директор Insight Ричард Уэллс убеждён, что получившаяся концепция теперь «затрагивает бизнес в любой точке планеты и любого формата — от малого до крупного». Казалось, OneTrust уже достаточно доказала свою живучесть, но тут грянул COVID-19. Во время пандемии темпы работы компании только ускорились — ведь теперь глобальный бизнес ещё более погрузился в диджитал.
Четыре года гиперроста и постоянные разъезды сильно сказались и на самом основателе OneTrust. Половина выручки компании приходит из-за рубежа — посещая клиентов, Бардай успел налетать более миллиона миль. «Я недооценивал последствия работы для психики и организма, — признаётся он, не углубляясь в детали. — Я сделал ряд непоправимых ошибок, всё это подорвало моё здоровье. Теперь, видимо, буду жить с этим до конца жизни. Оно того стоило?»
Этот вопрос задают себе многие предприниматели, чьи компании взлетели. Бардаю придётся найти ответ самостоятельно. Впрочем, не похоже, что он собирается останавливаться. А рынок и так уже сказал свое слово.
Что скрывается за cookie-баннером (по версии основателя OneTrust)
1. «С помощью искусственного интеллекта мы сканируем внутреннюю сеть компании и помогаем ей найти и проанализировать все скрытые там пользовательские данные. Казалось бы, бизнесу и так известно всё о собранной им же информации. На самом деле всё гораздо сложнее — среди множества отделов, подрядчиков, партнёров, продуктов и тонн рекламы очень непросто найти нужное»
2. «Мы помогаем компаниям проверить все собранные данные на соответствие законодательству в их юрисдикциях и определить риски. Если есть проблемы, помогаем их устранить: какие данные нужно зашифровать, а какие — лучше не собирать».
3. «Мы раскрываем системы контроля над данными и делаем их прозрачными для пользователей. И знаете что? Каждый раз, когда вы запрашиваете удаление данных на сайте, компания должна не просто удалить их, но и перенаправить запрос всем третьим лицам, которые когда-либо и как-либо взаимодействовали с вашими данными. На деле это невероятно сложная задача».