Solution Finder

Interactive PII solution recommender: 46 solutions compared across 78 pain points, 6 structural driver categories, and 240 jurisdictions worldwide.

FILTERS
EU
European Union
3 regulations
US
United States
6 regulations
UK
United Kingdom
1 regulation
Asia-Pac
Asia-Pacific
3 regulations
LatAm
Latin America
1 regulation
Africa
African Union
1 regulation
Middle East
MENA Region
1 regulation
Global
International
3 regulations
DRIVER CATEGORIES
Filter by root cause — select one or more structural driver categories
T1 LINKABILITYThe foundational operation of PII risk14
T2 IRREVERSIBILITYThe one-way function of data exposure12
T3 POWER ASYMMETRYThe structural imbalance of data power13
T5 COMPLEXITY CASCADEThe compounding failure of layered defense13
T6 KNOWLEDGE ASYMMETRYThe gap between knowledge and practice13
T7 JURISDICTION FRAGMENTATIONThe mismatch between data speed and legal speed13
PROBLEM EXPLORER
T1 LINKABILITYThe foundational operation of PII risk14
T1.01Browser Fingerprintingdevice identifiers, advertising IDs, tracking cookies, user agent stringsGDPRePrivacy Directive
T1.02Quasi-identifier Re-identificationzip codes, dates of birth, gender markers, demographic quasi-identifiersGDPR
T1.03Metadata Correlationemail addresses, timestamps, IP addresses, communication metadata, geolocation markersGDPRePrivacy Directive
T1.04Phone Number as PII Anchorphone numbers, IMSI numbers, SIM identifiers, mobile network codesGDPRePrivacy Directive
T1.05Social Graph Exposurenames, email addresses, phone numbers, social media handles, organizational affiliationsGDPR
T1.06Behavioral Stylometrytext content, writing patterns, timestamps, posting metadata, timezone indicatorsGDPR
T1.07Hardware IdentifiersMAC addresses, device serial numbers, CPU identifiers, TPM keys, hardware UUIDsGDPRePrivacy Directive
T1.08Location DataGPS coordinates, street addresses, zip codes, city names, country codesGDPR
T1.09RTB Broadcastingadvertising IDs, cookie identifiers, browsing interests, location markers, bid request parametersGDPRePrivacy Directive
T1.10Data Broker Aggregationnames, addresses, financial records, purchase history, app usage data, credit informationGDPRCCPA
T1.11Discord DAVE E2EE Gapvoice stream metadata, video call identifiers, unencrypted text message content, Discord user IDs, channel namesGDPRePrivacy Directive
T1.12AI Chat Extension Theftbrowser session tokens, chat content, DOM-captured text, extension-readable page data, user identifiersGDPRePrivacy Directive
T1.13SaaS Credential Abusevalid credential tokens, MFA bypass indicators, session identifiers, SaaS application data, access logsGDPRISO 27001
T1.14Discord Persona Breachgovernment ID scans, biometric age verification data, age verification vendor records, minor identifiersGDPRHIPAA
T2 IRREVERSIBILITYThe one-way function of data exposure12
T2.01Biometric Immutabilitybiometric references, facial descriptions, fingerprint mentions, DNA identifiersGDPRHIPAA
T2.02Backup Persistencepersonally identifiable records, database field names, system identifiersGDPR
T2.03Third-party Propagationnames, email addresses, advertising IDs, device identifiers, behavioral profilesGDPR
T2.04Shadow Profilesnames, email addresses, phone numbers, contact information, browsing identifiersGDPR
T2.05Git HistoryAPI keys, access tokens, passwords, database credentials, private keysGDPRISO 27001
T2.06ML Model Memorizationnames, emails, phone numbers, medical records, training data with PIIGDPR
T2.07De-indexing Illusionnames, addresses, contact details, identifying descriptions, biographical informationGDPR
T2.08Breach Databasesemail addresses, passwords, usernames, IP addresses, account identifiersGDPR
T2.09Cache/Index/Warehouse Copiesuser records, analytics data, behavioral logs, transaction recordsGDPR
T2.10Surveillance Advertising Recordsadvertising IDs, browsing history, location data, interest profiles, bid parametersGDPRePrivacy Directive
T2.11Discord eDiscovery PreservationDiscord message content, user IDs, channel timestamps, server metadata, message attachment identifiersGDPR
T2.12LangChain CVE-2025-68664LangChain serialized chain data, environment variables, API keys, SSRF-extracted credentials, chain configurationGDPRISO 27001
T3 POWER ASYMMETRYThe structural imbalance of data power13
T3.01Dark Patternsconsent records, user preferences, interaction logsGDPR
T3.02Default Settingsdevice identifiers, telemetry data, advertising IDs, location markersGDPRePrivacy Directive
T3.03Surveillance Advertising Economicsadvertising identifiers, browsing history, purchase records, interest profilesGDPR
T3.04Government Exemptionsgovernment records, tax identifiers, health records, immigration documentsGDPR
T3.05Humanitarian Coercionbiometric references, identity documents, refugee registration data, aid recordsGDPR
T3.06Children's Vulnerabilitystudent records, minor identifiers, school attendance data, family informationGDPRFERPACOPPA
T3.07Legal Basis Switchingconsent records, processing justifications, legitimate interest assessmentsGDPR
T3.08Incomprehensible Policiesfull-text documents, policy language, consent forms, terms of serviceGDPR
T3.09Stalkerwarelocation coordinates, message contents, call logs, photo metadata, keystroke dataGDPR
T3.10Verification Barriersgovernment IDs, notarized documents, identity verification data, biometric proofsGDPR
T3.11A5 PII Anonymizer Market Entrynames, email addresses, phone numbers, postal addresses, dates of birth processed by limited-entity toolsGDPR
T3.12Nightfall AI Browser DLPchat prompt content, form field inputs, uploaded document text, API request payloads, browser session dataGDPRHIPAACCPA
T3.13Discord Age Verification Backlashminor government IDs, biometric proofs, age verification documents, minor account identifiersGDPRCOPPA
T5 COMPLEXITY CASCADEThe compounding failure of layered defense13
T5.01Tor + Facebook Loginaccount identifiers, login credentials, session tokens, social media handlesGDPR
T5.02E2EE + iCloud Backupmessage content, contact names, conversation metadata, attachment identifiersGDPR
T5.03Perfect Encryption + Pegasusmessage content, contact information, file attachments, communication recordsGDPR
T5.04VPN + DNS LeakDNS queries, browsing history, search terms, visited URLs, IP addressesePrivacy DirectiveGDPR
T5.05Anonymized Dataset + External Dataquasi-identifiers, demographic fields, behavioral attributes, medical recordsGDPR
T5.06Encrypted Messages + Metadatasender/receiver names, timestamps, IP addresses, location metadata, device identifiersGDPRePrivacy Directive
T5.07SecureDrop + Journalist Emailssource names, contact information, email addresses, organizational affiliationsGDPREU Whistleblower Dir.
T5.08Printer Tracking Dotsprinter metadata, document timestamps, device serial numbers, creator namesGDPR
T5.09OS Telemetry + Tor BrowserOS telemetry identifiers, hardware UUIDs, background service identifiersGDPRePrivacy Directive
T5.10Hardware IDs + Software AnonymizationMAC addresses, Intel ME identifiers, UEFI serial numbers, TPM keysGDPR
T5.11MCP Server Security CrisisMCP tool call parameters, server authentication tokens, SSRF request targets, prompt injection payloads, API credentialsGDPRISO 27001
T5.12Cursor IDE MCP VulnerabilitiesIDE project files, code context with credentials, MCP tool outputs, auto-start service data, Privacy Mode session dataGDPRISO 27001
T5.13Microsoft Copilot DLP Bypassemail body content, sensitivity-labeled document text, Copilot-generated summaries, confidential meeting notesGDPRHIPAA
T6 KNOWLEDGE ASYMMETRYThe gap between knowledge and practice13
T6.01Developer Misconceptionshashed emails, pseudonymized records, incorrectly anonymized fieldsGDPR
T6.02DP Misunderstandingepsilon values, noise parameters, aggregate statistics, privacy budget dataGDPR
T6.03Privacy vs Security Confusionsecurity credentials, access logs, antivirus configs, network settingsGDPR
T6.04VPN DeceptionVPN connection logs, browsing history, IP addresses, DNS queriesGDPRePrivacy Directive
T6.05Research-Industry Gapresearch data, PII in academic datasets, experimental records, publication draftsGDPR
T6.06Users Unaware of ScopeISP browsing logs, app location data, email scans, incognito metadata, ad profilesGDPR
T6.07Password Storagepasswords, credential hashes, API keys, access tokens, authentication secretsGDPRISO 27001
T6.08Unused Cryptographic ToolsMPC keys, FHE parameters, ZKP data, cryptographic configurationsGDPR
T6.09Pseudonymization ConfusionUUID mappings, pseudonymized records, data with retained mapping tablesGDPR
T6.10OPSEC FailuresSecureDrop URLs, Tor metadata, API keys in code, browser window dimensionsGDPREU Whistleblower Dir.
T6.11dbt Snowflake Pipeline Masking Gapraw PII in staging tables before tag-based masking, unmasked dbt models, Snowflake ingestion recordsGDPRHIPAA
T6.12Reversible Anonymization LLM Validationtokenized text with deanonymization mapping, LLM prompt content, AI output with re-identified entitiesGDPR
T6.13Shadow AI Governance Crisisemployee AI prompt content, company data pasted into AI tools, policy violation logs, shadow AI session dataGDPRHIPAACCPA
T7 JURISDICTION FRAGMENTATIONThe mismatch between data speed and legal speed13
T7.01US Federal Law AbsenceSSNs, state-specific identifiers, HIPAA records, FERPA data, financial accountsHIPAAFERPACOPPACCPA
T7.02GDPR Enforcement BottleneckEU citizen data, cross-border transfer records, processing logs, consent recordsGDPR
T7.03Cross-border Conflictsdata subject records under multiple jurisdictions, CLOUD Act responsive dataGDPRCLOUD ActPIPL (China)
T7.04Global South Law Absencetelecom subscriber data, banking records, government IDs, biometric registrationsMalabo Convention
T7.05ePrivacy Stalematecookie identifiers, tracking pixels, device fingerprints, communication metadataePrivacy DirectiveGDPR
T7.06Data Localization Dilemmadata center location identifiers, cloud provider metadata, transfer recordsGDPR
T7.07Whistleblower Jurisdiction Shoppingsource identifiers, whistleblower documents, cross-jurisdictional evidenceEU Whistleblower Dir.
T7.08DP Regulatory UncertaintyDP outputs, epsilon parameters, aggregate statistics, privacy budget recordsGDPR
T7.09Surveillance Tech Exportsurveillance target identifiers, spyware indicators, Pegasus artifactsWassenaar Arrangement
T7.10Government PII Purchasinglocation data, broker records, government purchase orders, third-party doctrine dataFourth AmendmentGDPR
T7.11EU AI Act High-Risk RequirementsAI system training data, high-risk system output logs, biometric system outputs, automated decision recordsGDPR
T7.12California AB 2013 AI DisclosureAI training dataset inventories, dataset provenance records, training data labels, model lineage documentationCCPA
T7.13CFPB Financial Data Rights Ruleconsumer financial account data, transaction records, financial data transfer requests, open banking payloadsHIPAACCPA
ANALYSIS ENGINE
SOLUTION RECOMMENDATIONS
SOLUTIONS DIRECTORY
Comparison based on publicly documented capabilities as of March 2026. Same 0/1/2 scoring methodology applied to all solutions including ecosystem products. Sources linked per solution.
Sort:
solutionsEcosystem260+48Dual-layer: 210+ regex + 3 NLP enginesReplace, Redact, Mask, Hash, EncryptSaaS, Managed Private, Self-Managed Docker€0–€29/mo
152/156
businessEcosystem390+48317 custom regex + 3 NLP (all self-hosted)Replace, Redact, Mask, Hash, EncryptZero-storage microservices (in-memory only)Quote
134/156
legalEcosystem267+483-layer hybrid: Presidio + NLP + Stance classificationReplace, Redact, Mask, Hash, EncryptCloud-based, 6 platform access methods€0–€29/mo
152/156
plusEcosystem200+48Presidio 2.2.357 + spaCy 3.8.11 (local)Replace, Redact, Mask, Hash, Encrypt100% local Tauri desktop + FastAPI sidecar€0–€29/mo
134/156
PresidioAnonymization~20 default6NER + regexRedact, Replace, Mask, Hash, EncryptSelf-hosted, Docker, API$0 + engineering
71/156
Google DLPCloud DLP150+25ML + regex + dictionaryRedact, Replace, Mask, Hash, Encrypt, BucketingCloud API$1–3/GB
31/156
PrivitarAnonymization100+5ML + pattern matchingMask, Generalize, Hash, Encrypt, Tokenize, SuppressOn-premise, K8s$200K–$500K/yr
30/156
InformaticaEnterprise100+20ML (CLAIRE AI) + profilingMask, Tokenize, Encrypt, Generalize, SynthesizeSaaS, On-premise, Hybrid$100K–$500K/yr
28/156
SecuritiSpecialized200+15ML + NER + graphMask, Redact, Tokenize, ClassifySaaS$75K–$300K/yr
24/156
GretelAnonymization~40+3Transformer NER + regexReplace, Redact, Hash, Synthesize, MaskSaaS, Hybrid VPC, Docker$0–$300+/mo
22/156
BigIDEnterprise100+10ML + NER + correlationMask, Tokenize, DeleteSaaS, On-premise, Hybrid$100K–$300K/yr
22/156
ProtegrityEnterpriseConfigurablePolicy-driven classificationTokenize, Encrypt, Mask, HashOn-premise, Cloud, Hybrid$200K–$1M+/yr
19/156
SpirionEnterprise300+2Pattern + context + validationRedact, Mask, Quarantine, Delete, EncryptOn-premise, Endpoints$50K–$150K/yr
18/156
VoltageSpecializedConfigurable10Pattern matchingEncrypt (FPE), Tokenize, Mask, HashOn-premise, Cloud$150K–$500K/yr
18/156
ImmutaEnterprise100+5Policy-based + MLMask, Anonymize, Restrict, GeneralizeSaaS, On-premise$100K–$400K/yr
17/156
Azure IPCloud DLP300+40Regex + ML classifiers + fingerprintingEncrypt, Restrict, LabelSaaS, On-premise scanner$12–57/user/mo
16/156
Ground LabsSpecialized300+5Pattern + validationRedact, Quarantine, ReportOn-premise, SaaS$30K–$100K/yr
16/156
OneTrustEnterprise200+100ML + pattern matchingRedact, MaskSaaS$50K–$300K/yr
14/156
TrustArcEnterprise50+30Pattern + ML + assessmentsAssess, Classify, GovernSaaS$30K–$200K/yr
13/156
AWSCloud DLP~20 + 100+5NLP/ML + pattern matchingRedactCloud API$0.0001/unit
11/156
SkyflowTokenization/VaultPII vault5Polymorphic encryptionTokenize, Encrypt, Mask, RedactSaaS, APIUsage-based
11/156
VGSTokenization/VaultPII vaultProxy-based aliasingTokenize, AliasSaaS, Proxy$500+/mo
11/156
EvervaultTokenization/VaultPII vaultRelay encryptionEncrypt, TokenizeSaaS, SDK$0–$500+/mo
11/156
TokenExTokenization/VaultPII vaultCloud tokenizationTokenize (format-preserving)SaaSQuote
11/156
ARXAnonymizationN/A (tabular)StatisticalGeneralize, Suppress, k-Anon, l-Div, t-Close, DPDesktop, Java library$0
9/156
sdcMicroStatisticalN/A (tabular)Statistical disclosure controlk-Anon, l-Div, Suppress, Microagg, RecodeR package$0
9/156
Mostly AISynthetic DataN/A (synthetic)10Generative AISynthesizeSaaS, On-premise$0–$500+/mo
8/156
OpenDPStatisticalN/A (DP)Differential PrivacyDP noise, DP queriesPython library, SQL proxy$0
7/156
TumultPrivacy ComputationN/A (DP)Differential PrivacyDP queries (Spark-based)Python library, Spark$0
7/156
CollibraEnterpriseConfigurable10ML classification + lineageClassify, Govern, MaskSaaS, On-premise$100K–$300K/yr
6/156
HF NERNLP/NER4–18 (per model)100Transformer NER(NER only)Python library, Inference API$0 (Pro $9/mo)
6/156
AmnesiaStatisticalN/A (tabular)Statisticalk-Anon, Generalize, SuppressWeb app, Self-hosted$0
5/156
spaCyNLP/NER4–18 (NER)25CNN / Transformer NER(NER only)Python library$0
4/156
StanzaNLP/NER4–18 (NER)70BiLSTM-CRF(NER only)Python library$0
4/156
FlairNLP/NER4–18 (NER)15BiLSTM-CRF + stacked embeddings(NER only)Python library$0
4/156
AllenNLPNLP/NER4–18 (NER)5Transformer NER(NER only)Python library$0
4/156
SDVSynthetic DataN/A (synthetic)Statistical + GANSynthesizePython library$0
4/156
PySyftPrivacy ComputationN/A (PPC)Federated learning + MPCEncrypt (homomorphic), FederatedPython library$0
3/156
DualityPrivacy ComputationN/A (HE)Homomorphic EncryptionCompute on encrypted dataSaaS, On-premiseQuote
3/156
DelphixSpecialized50+5Profiling + algorithmsMask, Replace, Shuffle, NullifySaaS, On-premise$100K–$400K/yr
3/156
SyntegraSynthetic DataClinical data1Medical AISynthesize (clinical)SaaSQuote
2/156
MDCloneSynthetic DataClinical data1Statistical synthesisSynthesize (clinical)SaaS, On-premiseQuote
2/156
MedSpaCyNLP/NERClinical NER1spaCy + clinical rules(Clinical NER only)Python library$0
1/156
LexNLPNLP/NERLegal entities1Regex + NER(Legal NER only)Python library$0
1/156
FakerSynthetic Data200+ providers40Fake data generationReplace (fake data)Python library$0
1/156
TesseractNLP/NERN/A (OCR)100OCR engine(OCR only — text extraction)CLI, Library$0
0/156
PAIN POINT COVERAGE
AGGREGATE COVERAGE
solutions
152/156
legal
152/156
business
134/156
plus
134/156
Presidio
71/156
Google DLP
31/156
Privitar
30/156
Informatica
28/156
Securiti
24/156
Gretel
22/156
BigID
22/156
Protegrity
19/156
Spirion
18/156
Voltage
18/156
Immuta
17/156
Azure IP
16/156
Ground Labs
16/156
OneTrust
14/156
TrustArc
13/156
AWS
11/156
Skyflow
11/156
VGS
11/156
Evervault
11/156
TokenEx
11/156
ARX
9/156
sdcMicro
9/156
Mostly AI
8/156
OpenDP
7/156
Tumult
7/156
Collibra
6/156
HF NER
6/156
Amnesia
5/156
spaCy
4/156
Stanza
4/156
Flair
4/156
AllenNLP
4/156
SDV
4/156
PySyft
3/156
Duality
3/156
Delphix
3/156
Syntegra
2/156
MDClone
2/156
MedSpaCy
1/156
LexNLP
1/156
Faker
1/156
Tesseract
0/156
DPA INVENTORY
240 Jurisdictions·179 DPA·188 Legislation·18 GDPR·11 Pending·51 No Coverage
240 jurisdictions
Afghanistan
No Coverage
No data protection authority or comprehensive privacy legislation identified.
The IAPP is unaware of a data protection authority or comprehensive data protection legislation for Afghanist
Asia-PacificIAPP profile →
Åland Islands
DPALaw
Data Protection Authority
Privacy Legislation
American Samoa
No Coverage
No data protection authority or comprehensive privacy legislation identified.
The IAPP is unaware of a data protection authority or comprehensive data protection legislation for American Samo
Anguilla
No Coverage
No data protection authority or comprehensive privacy legislation identified.
The IAPP is unaware of a data protection authority or comprehensive data protection legislation for Anguill
Antigua and Barbuda
DPALaw
Data Protection Authority
Privacy Legislation
Aruba
DPALaw
Data Protection Authority
Privacy Legislation
Barbados
DPALaw
Data Protection Authority
Privacy Legislation
Belgium
GDPRDPALaw
Data Protection Authority
Privacy Legislation
Act of 3 December 2017 Establishing the , Act of 30 July 2018 on the Protection of Natural Persons with Regard to the Processing of Personal Data Belgium is subject to the
Belize
DPALaw
Data Protection Authority
Privacy Legislation
Data Protection Commissioner
Bolivia (Plurinational State of)
No Coverage
No data protection authority or comprehensive privacy legislation identified.
The IAPP is unaware of a data protection authority or comprehensive data protection legislation for Bolivi
Bonaire, Sint Eustatius and Saba
DPALaw
Data Protection Authority
Privacy Legislation
Botswana
DPA PendingLaw
Data Protection Authority
Privacy Legislation
Not yet established, but will be the Information and Data Protection Commissio
British Virgin Islands
DPA PendingLaw
Data Protection Authority
Privacy Legislation
Not yet established, but will be the Office of the Information Commissioner
Burundi
No Coverage
No data protection authority or comprehensive privacy legislation identified.
The IAPP is unaware of a data protection authority or comprehensive data protection legislation for Burundi
Cameroon
DPALaw
Data Protection Authority
Privacy Legislation
Cayman Islands
DPALaw
Data Protection Authority
Privacy Legislation
Central African Republic
No Coverage
No data protection authority or comprehensive privacy legislation identified.
The IAPP is unaware of a data protection authority or comprehensive data protection legislation for Central African Republic
Chile
Law
Privacy Legislation
The IAPP is unaware of a data protection authority for Chile
Comoros
No Coverage
No data protection authority or comprehensive privacy legislation identified.
The IAPP is unaware of a data protection authority or comprehensive data protection legislation for Comoros
Cook Islands
Law
Privacy Legislation
Asia-PacificIAPP profile →
Cuba
DPALaw
Data Protection Authority
Privacy Legislation
Curaçao
DPALaw
Data Protection Authority
Privacy Legislation
Personal Data Protection Boar
Democratic People's Republic of Korea
No Coverage
No data protection authority or comprehensive privacy legislation identified.
The IAPP is unaware of a data protection authority or comprehensive data protection legislation for the Democratic People's Republic of Kore
Democratic Republic of the Congo
Law
Privacy Legislation
The IAPP is unaware of a data protection authority for the Democratic Republic of the Congo
Diego Garcia
No Coverage
No data protection authority or comprehensive privacy legislation identified.
The IAPP is unaware of a data protection authority or comprehensive data protection legislation for Diego Garci
Djibouti
No Coverage
No data protection authority or comprehensive privacy legislation identified.
The IAPP is unaware of a data protection authority or comprehensive data protection legislation for Djibouti
Dominica
No Coverage
No data protection authority or comprehensive privacy legislation identified.
The IAPP is unaware of a data protection authority or comprehensive data protection legislation for Dominic