Privacy Services: What They Cover and How to Choose One
A practical guide to privacy services: what data protection vendors actually deliver, what they cost, and how to choose the right privacy service for your business.
Privacy services cover everything a business buys or hires to meet its data protection obligations, from consent banners and document generators to outsourced Data Protection Officers and privacy audits. The category is crowded and the marketing is vague, so it is easy to overpay for a consultant when you needed a $12 subscription, or to buy a scanner when your real gap was a data processing agreement. This guide breaks down what each type of privacy service actually delivers, what it costs, and how to decide which ones you need. It is educational rather than legal advice, so consult a qualified attorney for guidance specific to your business.
What Are Privacy Services?
A privacy service is any product or professional engagement that helps an organization collect, use, store, and disclose personal data in a way that satisfies data protection law. That definition is deliberately broad because the market is broad. The same phrase gets used by a $9 per month cookie banner vendor and by a Big Four consultancy running a six-figure privacy program assessment.
The useful distinction is between software services and human services. Software privacy services automate repeatable work: scanning a website for trackers, presenting a consent banner, generating a policy, logging consent records, and processing deletion requests. Human privacy services apply judgment: deciding whether your legal basis holds up, negotiating a data processing agreement, or defending you during a regulator inquiry.
Most businesses need both, but in wildly different proportions. A five-person e-commerce store selling to EU customers needs a lot of automation and roughly zero hours of a privacy consultant's time. A health technology company processing special category data under Article 9 of the GDPR needs the reverse.
The Main Categories of Privacy Services
The privacy services market splits into six recognizable categories. Knowing which one a vendor sits in tells you what problem they can genuinely solve.
- Consent management platforms (CMPs): Show a cookie banner, block non-essential scripts before consent, and store a consent record you can produce during an investigation.
- Legal document services: Generate and host privacy policies, cookie policies, terms of service, and related legal pages.
- Privacy compliance and governance software: Data mapping, Records of Processing Activities (ROPA) under Article 30, Data Protection Impact Assessments (DPIAs) under Article 35, and vendor risk registers.
- Data subject request (DSR) automation: Intake portals, identity verification, and workflow tools for access, deletion, and opt-out requests.
- Outsourced Data Protection Officer and privacy consulting: A named external DPO, gap assessments, staff training, and policy drafting.
- Privacy legal counsel: Licensed attorneys giving advice you can rely on, negotiating contracts, and representing you before authorities.
Categories one through four are usually sold as subscriptions. Categories five and six are sold as retainers or hourly work. Vendors frequently blur the line, so read carefully when a software product describes itself as offering "compliance services."
What CMPs and Document Services Actually Do
These two categories cover the obligations most small and mid-sized businesses are actually failing. Article 5(3) of the ePrivacy Directive requires consent before storing or accessing information on a user's device, which is why the cookie banner exists at all. Articles 13 and 14 of the GDPR require you to tell people what you do with their data, which is why the privacy policy exists.
The failure mode here is drift. You add a new analytics tool, a chat widget, or a retargeting pixel, and your published policy no longer matches reality. A privacy policy that omits a tracker you are running is a transparency violation, not a paperwork issue.
What Governance Software Adds
Governance tools become worthwhile once you have multiple systems holding personal data and more than a handful of vendors. Article 30 of the GDPR requires most organizations to maintain a written record of processing activities, and doing that in a spreadsheet stops scaling somewhere around 20 systems. If you have three systems and four vendors, a spreadsheet is genuinely fine and buying a platform is waste.
Which Privacy Services Does Your Business Actually Need?
Work from your obligations, not from a vendor's feature list. Three questions determine almost everything.
Question one: whose data do you process? The GDPR applies to any organization processing the personal data of people in the EU, regardless of where the organization is based, per Article 3(2). The CCPA, as amended by the CPRA, applies to for-profit businesses doing business in California that meet at least one of three thresholds: $25 million or more in annual gross revenue, buying, selling, or sharing the personal information of 100,000 or more consumers or households, or deriving 50 percent or more of annual revenue from selling or sharing personal information.
Question two: what kind of data? Special category data under Article 9 of the GDPR (health, biometrics, race, religion, sexual orientation, political opinions, trade union membership) raises the bar sharply. So does children's data, which triggers COPPA in the United States and Article 8 of the GDPR in the EU.
Question three: how many systems and vendors touch that data? Complexity, not headcount, drives the need for governance tooling and human oversight.
Here is how the answers typically map to spend:
| Business profile | Software services | Human services |
|---|---|---|
| Blog or brochure site with analytics | Consent banner, privacy policy, cookie policy | None |
| E-commerce store, EU and US customers | Consent banner, policies, DSR intake, compliance scanning | Occasional counsel review |
| SaaS with enterprise customers | All of the above plus data mapping and subprocessor register | DPA negotiation, annual assessment |
| Health, finance, or children's data | All of the above plus DPIA tooling | Named DPO, ongoing counsel |
| 250+ employees or large-scale monitoring | Full governance platform | DPO required under Article 37(1) |
When You Need a Data Protection Officer
Article 37(1) of the GDPR requires a DPO in three cases: when processing is carried out by a public authority, when core activities involve regular and systematic monitoring of data subjects on a large scale, or when core activities involve large-scale processing of special category data under Article 9 or criminal conviction data under Article 10.
Note what is not in that list. There is no employee-count trigger in the GDPR itself. The commonly cited figure of 250 employees comes from Article 30(5), which relates to record-keeping exemptions, not to the DPO requirement. Some national laws add their own triggers: Germany's BDSG requires a DPO once 20 or more people are constantly engaged in automated data processing.
If you do need one, Article 37(6) permits the DPO to be an external service provider under a service contract. Outsourced DPO services typically cost between $500 and $5,000 per month depending on scope, which is far cheaper than a full-time hire and is why the model is popular with mid-market companies. The external DPO must still satisfy Articles 38 and 39: independence, no conflict of interest, direct reporting to the highest management level, and published contact details filed with your supervisory authority.
How to Evaluate Privacy Services Vendors
Marketing in this space rewards confident claims, so evaluate against evidence rather than copy. Use these criteria when comparing privacy services providers:
- Prior blocking, not just banner display. Ask whether the CMP prevents non-essential scripts from executing before consent. A banner that appears while Google Analytics has already fired does not satisfy Article 5(3) of the ePrivacy Directive. The CNIL has fined companies specifically for depositing cookies before consent.
- Consent record retention. You need to be able to demonstrate consent under Article 7(1). Ask what is stored, for how long, and whether you can export it.
- Granular refusal. Rejecting must be as easy as accepting. The CNIL fined Google 150 million EUR and Meta 60 million EUR in January 2022 precisely because refusing cookies took more clicks than accepting them.
- Coverage of laws you are actually subject to. GDPR, UK GDPR, CCPA/CPRA, and the growing set of US state laws (Virginia's VCDPA, Colorado's CPA, Connecticut's CTDPA, and others) have different requirements. A tool built only for the EU will not produce a compliant "Do Not Sell or Share My Personal Information" link.
- Update mechanism. Laws change and so does your website. Ask how the vendor handles both.
- Data residency and subprocessors. A privacy vendor that ships your consent logs through undisclosed subprocessors is itself a compliance problem. Ask for their subprocessor list.
Warning Signs
Treat these as reasons to walk away:
- Claims of being "GDPR certified." No certification scheme under Article 42 of the GDPR is broadly operational, so the claim is at best marketing.
- Guarantees of compliance or of immunity from fines.
- A generated privacy policy that does not ask what tools your site runs. A policy produced without knowing your actual trackers cannot be accurate.
- No consent log export. If you cannot produce the record, you cannot demonstrate consent.
- Pricing that hides per-domain or per-pageview limits until after signup.
The Cost of Privacy Services
Budget expectations vary by an order of magnitude across the categories, which is why vague quotes are so common.
| Service | Typical cost | Best for |
|---|---|---|
| Document generator plus consent banner | $0 to $25 per month per site | Small businesses, blogs, single-site stores |
| Mid-market compliance platform | $200 to $2,000 per month | Multi-site companies, agencies |
| Enterprise privacy governance suite | $20,000 to $150,000 per year | Large organizations with dedicated privacy teams |
| Outsourced DPO | $500 to $5,000 per month | Companies triggered by Article 37(1) |
| Privacy counsel | $250 to $700 per hour | Contract negotiation, regulator contact, high-risk processing |
| One-time gap assessment | $5,000 to $50,000 | Pre-funding, pre-acquisition, post-incident |
TermsBox sits in the first row: a compliance scanner that detects the cookies and third-party services running on your site, a consent management platform, and eight document generators, with a free tier covering 5,000 banner views per month and paid tiers at $12 per month (Starter) and $25 per month (Pro), or $9 and $19 per month billed annually. Documents are hosted at clean URLs and, on paid tiers, update automatically when the scanner detects new trackers.
Privacy Policy Generator
Create a comprehensive privacy policy for your website or app. Create yours in minutes with TermsBox.
Generate NowCompare that against the cost of getting it wrong. Article 83(5) of the GDPR allows fines of up to 20 million EUR or 4 percent of global annual turnover, whichever is higher. Under the CCPA, Section 1798.155 sets penalties at up to $2,500 per unintentional violation and $7,500 per intentional violation, and the per-violation structure means counts multiply fast across affected consumers.
Building Your Own Privacy Program Instead
You can assemble much of what privacy services sell, particularly if your processing is straightforward. The work breaks into six steps.
- Inventory your data. List every system that holds personal data, what fields it holds, why you hold them, and how long you keep them. This becomes your Article 30 record.
- Scan your website. Identify every cookie, tracker, pixel, and third-party script actually loading. Most teams find services they forgot they installed.
- Assign a legal basis. Every processing activity needs one of the six bases in Article 6(1): consent, contract, legal obligation, vital interests, public task, or legitimate interests. Write it down for each activity.
- Publish accurate documents. Your privacy policy must describe what you actually do. A privacy policy generator that asks about your specific tools and jurisdictions produces something far closer to accurate than a copied template. Pair it with a cookie policy listing the cookies your scan found.
- Implement consent properly. Block non-essential scripts until consent, make refusal as easy as acceptance, and log the outcome. See the cookie consent banner guide for implementation detail.
- Set up request handling. Publish a route for access, deletion, correction, and opt-out requests, and meet the deadlines: one month under Article 12(3) of the GDPR (extendable by two further months), and 45 days under CCPA Section 1798.130 (extendable by another 45).
The step people skip is the second one. Without knowing what is actually running on your site, everything downstream is guesswork.
What You Should Not Do Yourself
Some work genuinely needs a lawyer. Negotiating data processing agreements with enterprise customers, assessing international transfer mechanisms after the Schrems II ruling, responding to a supervisory authority inquiry, and handling a personal data breach under Article 33 (72-hour notification deadline) all carry consequences that software cannot absorb.
How Privacy Services Are Changing
Three shifts are worth planning around.
US state law fragmentation. Beyond California, more than a dozen states now have comprehensive privacy laws in force, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana. Several require honoring universal opt-out signals such as Global Privacy Control, which is a technical requirement your consent tooling either meets or does not.
Enforcement moving to real-time behavior. Regulators increasingly test what your site does rather than what your policy says. The CNIL, the Spanish AEPD, and the Italian Garante have all issued decisions based on observed cookie behavior. This favors privacy services that continuously monitor a live site over ones that produce a document and stop.
AI processing disclosures. The EU AI Act and existing GDPR provisions on automated decision-making under Article 22 mean that if you feed customer data into AI tools, your privacy notice needs to say so, including the logic involved and the consequences for the individual.
Frequently Asked Questions
What are privacy services?
Privacy services are the products and professional engagements businesses use to meet data protection obligations under laws like the GDPR and CCPA. They range from software (consent management platforms, data mapping tools, document generators) to human services (outsourced Data Protection Officers, privacy counsel, and audits).
How much do privacy services cost?
Software-based privacy services typically run from $0 to a few hundred dollars per month per website, with entry tiers around $9 to $25 per month. Human services cost far more: outsourced DPO retainers commonly range from $500 to $5,000 per month, and privacy counsel bills $250 to $700 per hour.
Do small businesses need privacy services?
Most do, but usually only the software layer. A small business that runs a website with analytics and a contact form needs an accurate privacy policy, a cookie consent banner, and a way to handle data subject requests. It rarely needs a full-time privacy consultant or a formally appointed Data Protection Officer.
Is an outsourced Data Protection Officer allowed under GDPR?
Yes. Article 37(6) of the GDPR explicitly permits a DPO to be an external service provider fulfilling the role under a service contract. The external DPO must still meet the independence and expertise requirements in Articles 37 to 39, and you must publish their contact details and notify your supervisory authority.
What is the difference between privacy services and cybersecurity services?
Privacy services address what data you collect, why you collect it, and the rights people have over it. Cybersecurity services address how that data is protected from unauthorized access. They overlap at Article 32 of the GDPR, which requires security measures appropriate to the risk, but a well-secured system can still be unlawful if there is no valid legal basis for the processing.
Can a privacy service guarantee compliance?
No legitimate provider can guarantee compliance, and claims of certified GDPR compliance should be treated as a warning sign. No official GDPR certification scheme under Article 42 is broadly operational, and compliance depends on your actual practices, not on the tools you buy.