Solution Finder
Interactive PII solution recommender: 46 solutions compared across 78 pain points, 6 structural driver categories, and 240 jurisdictions worldwide.
FILTERS
EU
European Union
3 regulations
US
United States
6 regulations
UK
United Kingdom
1 regulation
Asia-Pac
Asia-Pacific
3 regulations
LatAm
Latin America
1 regulation
Africa
African Union
1 regulation
Middle East
MENA Region
1 regulation
Global
International
3 regulations
DRIVER CATEGORIES
Filter by root cause — select one or more structural driver categories
T1 LINKABILITYThe foundational operation of PII risk14
T2 IRREVERSIBILITYThe one-way function of data exposure12
T3 POWER ASYMMETRYThe structural imbalance of data power13
T5 COMPLEXITY CASCADEThe compounding failure of layered defense13
T6 KNOWLEDGE ASYMMETRYThe gap between knowledge and practice13
T7 JURISDICTION FRAGMENTATIONThe mismatch between data speed and legal speed13
PROBLEM EXPLORER
T1.01Browser Fingerprintingdevice identifiers, advertising IDs, tracking cookies, user agent stringsGDPRePrivacy Directive
T1.02Quasi-identifier Re-identificationzip codes, dates of birth, gender markers, demographic quasi-identifiersGDPR
T1.03Metadata Correlationemail addresses, timestamps, IP addresses, communication metadata, geolocation markersGDPRePrivacy Directive
T1.04Phone Number as PII Anchorphone numbers, IMSI numbers, SIM identifiers, mobile network codesGDPRePrivacy Directive
T1.05Social Graph Exposurenames, email addresses, phone numbers, social media handles, organizational affiliationsGDPR
T1.06Behavioral Stylometrytext content, writing patterns, timestamps, posting metadata, timezone indicatorsGDPR
T1.07Hardware IdentifiersMAC addresses, device serial numbers, CPU identifiers, TPM keys, hardware UUIDsGDPRePrivacy Directive
T1.08Location DataGPS coordinates, street addresses, zip codes, city names, country codesGDPR
T1.09RTB Broadcastingadvertising IDs, cookie identifiers, browsing interests, location markers, bid request parametersGDPRePrivacy Directive
T1.10Data Broker Aggregationnames, addresses, financial records, purchase history, app usage data, credit informationGDPRCCPA
T1.11Discord DAVE E2EE Gapvoice stream metadata, video call identifiers, unencrypted text message content, Discord user IDs, channel namesGDPRePrivacy Directive
T1.12AI Chat Extension Theftbrowser session tokens, chat content, DOM-captured text, extension-readable page data, user identifiersGDPRePrivacy Directive
T1.13SaaS Credential Abusevalid credential tokens, MFA bypass indicators, session identifiers, SaaS application data, access logsGDPRISO 27001
T1.14Discord Persona Breachgovernment ID scans, biometric age verification data, age verification vendor records, minor identifiersGDPRHIPAA
T2.01Biometric Immutabilitybiometric references, facial descriptions, fingerprint mentions, DNA identifiersGDPRHIPAA
T2.02Backup Persistencepersonally identifiable records, database field names, system identifiersGDPR
T2.03Third-party Propagationnames, email addresses, advertising IDs, device identifiers, behavioral profilesGDPR
T2.04Shadow Profilesnames, email addresses, phone numbers, contact information, browsing identifiersGDPR
T2.05Git HistoryAPI keys, access tokens, passwords, database credentials, private keysGDPRISO 27001
T2.06ML Model Memorizationnames, emails, phone numbers, medical records, training data with PIIGDPR
T2.07De-indexing Illusionnames, addresses, contact details, identifying descriptions, biographical informationGDPR
T2.08Breach Databasesemail addresses, passwords, usernames, IP addresses, account identifiersGDPR
T2.09Cache/Index/Warehouse Copiesuser records, analytics data, behavioral logs, transaction recordsGDPR
T2.10Surveillance Advertising Recordsadvertising IDs, browsing history, location data, interest profiles, bid parametersGDPRePrivacy Directive
T2.11Discord eDiscovery PreservationDiscord message content, user IDs, channel timestamps, server metadata, message attachment identifiersGDPR
T2.12LangChain CVE-2025-68664LangChain serialized chain data, environment variables, API keys, SSRF-extracted credentials, chain configurationGDPRISO 27001
T3.01Dark Patternsconsent records, user preferences, interaction logsGDPR
T3.02Default Settingsdevice identifiers, telemetry data, advertising IDs, location markersGDPRePrivacy Directive
T3.03Surveillance Advertising Economicsadvertising identifiers, browsing history, purchase records, interest profilesGDPR
T3.04Government Exemptionsgovernment records, tax identifiers, health records, immigration documentsGDPR
T3.05Humanitarian Coercionbiometric references, identity documents, refugee registration data, aid recordsGDPR
T3.06Children's Vulnerabilitystudent records, minor identifiers, school attendance data, family informationGDPRFERPACOPPA
T3.07Legal Basis Switchingconsent records, processing justifications, legitimate interest assessmentsGDPR
T3.08Incomprehensible Policiesfull-text documents, policy language, consent forms, terms of serviceGDPR
T3.09Stalkerwarelocation coordinates, message contents, call logs, photo metadata, keystroke dataGDPR
T3.10Verification Barriersgovernment IDs, notarized documents, identity verification data, biometric proofsGDPR
T3.11A5 PII Anonymizer Market Entrynames, email addresses, phone numbers, postal addresses, dates of birth processed by limited-entity toolsGDPR
T3.12Nightfall AI Browser DLPchat prompt content, form field inputs, uploaded document text, API request payloads, browser session dataGDPRHIPAACCPA
T3.13Discord Age Verification Backlashminor government IDs, biometric proofs, age verification documents, minor account identifiersGDPRCOPPA
T5.01Tor + Facebook Loginaccount identifiers, login credentials, session tokens, social media handlesGDPR
T5.02E2EE + iCloud Backupmessage content, contact names, conversation metadata, attachment identifiersGDPR
T5.03Perfect Encryption + Pegasusmessage content, contact information, file attachments, communication recordsGDPR
T5.04VPN + DNS LeakDNS queries, browsing history, search terms, visited URLs, IP addressesePrivacy DirectiveGDPR
T5.05Anonymized Dataset + External Dataquasi-identifiers, demographic fields, behavioral attributes, medical recordsGDPR
T5.06Encrypted Messages + Metadatasender/receiver names, timestamps, IP addresses, location metadata, device identifiersGDPRePrivacy Directive
T5.07SecureDrop + Journalist Emailssource names, contact information, email addresses, organizational affiliationsGDPREU Whistleblower Dir.
T5.08Printer Tracking Dotsprinter metadata, document timestamps, device serial numbers, creator namesGDPR
T5.09OS Telemetry + Tor BrowserOS telemetry identifiers, hardware UUIDs, background service identifiersGDPRePrivacy Directive
T5.10Hardware IDs + Software AnonymizationMAC addresses, Intel ME identifiers, UEFI serial numbers, TPM keysGDPR
T5.11MCP Server Security CrisisMCP tool call parameters, server authentication tokens, SSRF request targets, prompt injection payloads, API credentialsGDPRISO 27001
T5.12Cursor IDE MCP VulnerabilitiesIDE project files, code context with credentials, MCP tool outputs, auto-start service data, Privacy Mode session dataGDPRISO 27001
T5.13Microsoft Copilot DLP Bypassemail body content, sensitivity-labeled document text, Copilot-generated summaries, confidential meeting notesGDPRHIPAA
T6.01Developer Misconceptionshashed emails, pseudonymized records, incorrectly anonymized fieldsGDPR
T6.02DP Misunderstandingepsilon values, noise parameters, aggregate statistics, privacy budget dataGDPR
T6.03Privacy vs Security Confusionsecurity credentials, access logs, antivirus configs, network settingsGDPR
T6.04VPN DeceptionVPN connection logs, browsing history, IP addresses, DNS queriesGDPRePrivacy Directive
T6.05Research-Industry Gapresearch data, PII in academic datasets, experimental records, publication draftsGDPR
T6.06Users Unaware of ScopeISP browsing logs, app location data, email scans, incognito metadata, ad profilesGDPR
T6.07Password Storagepasswords, credential hashes, API keys, access tokens, authentication secretsGDPRISO 27001
T6.08Unused Cryptographic ToolsMPC keys, FHE parameters, ZKP data, cryptographic configurationsGDPR
T6.09Pseudonymization ConfusionUUID mappings, pseudonymized records, data with retained mapping tablesGDPR
T6.10OPSEC FailuresSecureDrop URLs, Tor metadata, API keys in code, browser window dimensionsGDPREU Whistleblower Dir.
T6.11dbt Snowflake Pipeline Masking Gapraw PII in staging tables before tag-based masking, unmasked dbt models, Snowflake ingestion recordsGDPRHIPAA
T6.12Reversible Anonymization LLM Validationtokenized text with deanonymization mapping, LLM prompt content, AI output with re-identified entitiesGDPR
T6.13Shadow AI Governance Crisisemployee AI prompt content, company data pasted into AI tools, policy violation logs, shadow AI session dataGDPRHIPAACCPA
T7.01US Federal Law AbsenceSSNs, state-specific identifiers, HIPAA records, FERPA data, financial accountsHIPAAFERPACOPPACCPA
T7.02GDPR Enforcement BottleneckEU citizen data, cross-border transfer records, processing logs, consent recordsGDPR
T7.03Cross-border Conflictsdata subject records under multiple jurisdictions, CLOUD Act responsive dataGDPRCLOUD ActPIPL (China)
T7.04Global South Law Absencetelecom subscriber data, banking records, government IDs, biometric registrationsMalabo Convention
T7.05ePrivacy Stalematecookie identifiers, tracking pixels, device fingerprints, communication metadataePrivacy DirectiveGDPR
T7.06Data Localization Dilemmadata center location identifiers, cloud provider metadata, transfer recordsGDPR
T7.07Whistleblower Jurisdiction Shoppingsource identifiers, whistleblower documents, cross-jurisdictional evidenceEU Whistleblower Dir.
T7.08DP Regulatory UncertaintyDP outputs, epsilon parameters, aggregate statistics, privacy budget recordsGDPR
T7.09Surveillance Tech Exportsurveillance target identifiers, spyware indicators, Pegasus artifactsWassenaar Arrangement
T7.10Government PII Purchasinglocation data, broker records, government purchase orders, third-party doctrine dataFourth AmendmentGDPR
T7.11EU AI Act High-Risk RequirementsAI system training data, high-risk system output logs, biometric system outputs, automated decision recordsGDPR
T7.12California AB 2013 AI DisclosureAI training dataset inventories, dataset provenance records, training data labels, model lineage documentationCCPA
T7.13CFPB Financial Data Rights Ruleconsumer financial account data, transaction records, financial data transfer requests, open banking payloadsHIPAACCPA
ANALYSIS ENGINE
SOLUTION RECOMMENDATIONS
SOLUTIONS DIRECTORY
Comparison based on publicly documented capabilities as of March 2026. Same 0/1/2 scoring methodology applied to all solutions including ecosystem products. Sources linked per solution.
Sort:
| solutions | Ecosystem | 260+ | 48 | €0–€29/mo | 152/156 | |||
| business | Ecosystem | 390+ | 48 | Quote | 134/156 | |||
| legal | Ecosystem | 267+ | 48 | €0–€29/mo | 152/156 | |||
| plus | Ecosystem | 200+ | 48 | €0–€29/mo | 134/156 | |||
| Presidio | Anonymization | ~20 default | 6 | $0 + engineering | 71/156 | |||
| Google DLP | Cloud DLP | 150+ | 25 | $1–3/GB | 31/156 | |||
| Privitar | Anonymization | 100+ | 5 | $200K–$500K/yr | 30/156 | |||
| Informatica | Enterprise | 100+ | 20 | $100K–$500K/yr | 28/156 | |||
| Securiti | Specialized | 200+ | 15 | $75K–$300K/yr | 24/156 | |||
| Gretel | Anonymization | ~40+ | 3 | $0–$300+/mo | 22/156 | |||
| BigID | Enterprise | 100+ | 10 | $100K–$300K/yr | 22/156 | |||
| Protegrity | Enterprise | Configurable | — | $200K–$1M+/yr | 19/156 | |||
| Spirion | Enterprise | 300+ | 2 | $50K–$150K/yr | 18/156 | |||
| Voltage | Specialized | Configurable | 10 | $150K–$500K/yr | 18/156 | |||
| Immuta | Enterprise | 100+ | 5 | $100K–$400K/yr | 17/156 | |||
| Azure IP | Cloud DLP | 300+ | 40 | $12–57/user/mo | 16/156 | |||
| Ground Labs | Specialized | 300+ | 5 | $30K–$100K/yr | 16/156 | |||
| OneTrust | Enterprise | 200+ | 100 | $50K–$300K/yr | 14/156 | |||
| TrustArc | Enterprise | 50+ | 30 | $30K–$200K/yr | 13/156 | |||
| AWS | Cloud DLP | ~20 + 100+ | 5 | $0.0001/unit | 11/156 | |||
| Skyflow | Tokenization/Vault | PII vault | 5 | Usage-based | 11/156 | |||
| VGS | Tokenization/Vault | PII vault | — | $500+/mo | 11/156 | |||
| Evervault | Tokenization/Vault | PII vault | — | $0–$500+/mo | 11/156 | |||
| TokenEx | Tokenization/Vault | PII vault | — | Quote | 11/156 | |||
| ARX | Anonymization | N/A (tabular) | — | $0 | 9/156 | |||
| sdcMicro | Statistical | N/A (tabular) | — | $0 | 9/156 | |||
| Mostly AI | Synthetic Data | N/A (synthetic) | 10 | $0–$500+/mo | 8/156 | |||
| OpenDP | Statistical | N/A (DP) | — | $0 | 7/156 | |||
| Tumult | Privacy Computation | N/A (DP) | — | $0 | 7/156 | |||
| Collibra | Enterprise | Configurable | 10 | $100K–$300K/yr | 6/156 | |||
| HF NER | NLP/NER | 4–18 (per model) | 100 | $0 (Pro $9/mo) | 6/156 | |||
| Amnesia | Statistical | N/A (tabular) | — | $0 | 5/156 | |||
| spaCy | NLP/NER | 4–18 (NER) | 25 | $0 | 4/156 | |||
| Stanza | NLP/NER | 4–18 (NER) | 70 | $0 | 4/156 | |||
| Flair | NLP/NER | 4–18 (NER) | 15 | $0 | 4/156 | |||
| AllenNLP | NLP/NER | 4–18 (NER) | 5 | $0 | 4/156 | |||
| SDV | Synthetic Data | N/A (synthetic) | — | $0 | 4/156 | |||
| PySyft | Privacy Computation | N/A (PPC) | — | $0 | 3/156 | |||
| Duality | Privacy Computation | N/A (HE) | — | Quote | 3/156 | |||
| Delphix | Specialized | 50+ | 5 | $100K–$400K/yr | 3/156 | |||
| Syntegra | Synthetic Data | Clinical data | 1 | Quote | 2/156 | |||
| MDClone | Synthetic Data | Clinical data | 1 | Quote | 2/156 | |||
| MedSpaCy | NLP/NER | Clinical NER | 1 | $0 | 1/156 | |||
| LexNLP | NLP/NER | Legal entities | 1 | $0 | 1/156 | |||
| Faker | Synthetic Data | 200+ providers | 40 | $0 | 1/156 | |||
| Tesseract | NLP/NER | N/A (OCR) | 100 | $0 | 0/156 | |||
PAIN POINT COVERAGE
AGGREGATE COVERAGE
solutions152/156
legal152/156
business134/156
plus134/156
Presidio71/156
Google DLP31/156
Privitar30/156
Informatica28/156
Securiti24/156
Gretel22/156
BigID22/156
Protegrity19/156
Spirion18/156
Voltage18/156
Immuta17/156
Azure IP16/156
Ground Labs16/156
OneTrust14/156
TrustArc13/156
AWS11/156
Skyflow11/156
VGS11/156
Evervault11/156
TokenEx11/156
ARX9/156
sdcMicro9/156
Mostly AI8/156
OpenDP7/156
Tumult7/156
Collibra6/156
HF NER6/156
Amnesia5/156
spaCy4/156
Stanza4/156
Flair4/156
AllenNLP4/156
SDV4/156
PySyft3/156
Duality3/156
Delphix3/156
Syntegra2/156
MDClone2/156
MedSpaCy1/156
LexNLP1/156
Faker1/156
Tesseract0/156
DPA INVENTORY
240 Jurisdictions·179 DPA·188 Legislation·18 GDPR·11 Pending·51 No Coverage
Afghanistan
No Coverage
The IAPP is unaware of a data protection authority or comprehensive data protection legislation for Afghanist
Asia-PacificIAPP profile →
American Samoa
No Coverage
The IAPP is unaware of a data protection authority or comprehensive data protection legislation for American Samo
OtherIAPP profile →
Anguilla
No Coverage
The IAPP is unaware of a data protection authority or comprehensive data protection legislation for Anguill
AmericasIAPP profile →
Austria
GDPRDPALaw
Data Protection Authority
Privacy Legislation
Austria is subject to the
EuropeIAPP profile →
Belgium
GDPRDPALaw
Data Protection Authority
Privacy Legislation
Act of 3 December 2017 Establishing the , Act of 30 July 2018 on the Protection of Natural Persons with Regard to the Processing of Personal Data Belgium is subject to the
EuropeIAPP profile →
Belize
DPALaw
Data Protection Authority
Data Protection Commissioner
Privacy Legislation
Data Protection Commissioner
AmericasIAPP profile →
Bolivia (Plurinational State of)
No Coverage
The IAPP is unaware of a data protection authority or comprehensive data protection legislation for Bolivi
OtherIAPP profile →
Bonaire, Sint Eustatius and Saba
DPALaw
Data Protection Authority
Privacy Legislation
OtherIAPP profile →
Botswana
DPA PendingLaw
Data Protection Authority
Not yet established, but will be the Information and Data Protection Commission.
Privacy Legislation
Not yet established, but will be the Information and Data Protection Commissio
AfricaIAPP profile →
British Virgin Islands
DPA PendingLaw
Data Protection Authority
Not yet established, but will be the Office of the Information Commissioner.
Privacy Legislation
Not yet established, but will be the Office of the Information Commissioner
AmericasIAPP profile →
Bulgaria
GDPRDPALaw
Data Protection Authority
Privacy Legislation
Bulgaria is subject to the
EuropeIAPP profile →
Burundi
No Coverage
The IAPP is unaware of a data protection authority or comprehensive data protection legislation for Burundi
AfricaIAPP profile →
Cameroon
DPALaw
Data Protection Authority
Personal Data Protection Authority
Privacy Legislation
AfricaIAPP profile →
Central African Republic
No Coverage
The IAPP is unaware of a data protection authority or comprehensive data protection legislation for Central African Republic
AfricaIAPP profile →
Chile
Law
Privacy Legislation
The IAPP is unaware of a data protection authority for Chile
AmericasIAPP profile →
Comoros
No Coverage
The IAPP is unaware of a data protection authority or comprehensive data protection legislation for Comoros
AfricaIAPP profile →
Croatia
GDPRDPALaw
Data Protection Authority
Privacy Legislation
Croatia is subject to the
EuropeIAPP profile →
Curaçao
DPALaw
Data Protection Authority
Personal Data Protection Board
Privacy Legislation
Personal Data Protection Boar
AmericasIAPP profile →
Cyprus
GDPRDPALaw
Data Protection Authority
Privacy Legislation
Cyprus is subject to the
EuropeIAPP profile →
Czechia
GDPRDPALaw
Data Protection Authority
Privacy Legislation
Czechia is subject to the
EuropeIAPP profile →
Democratic People's Republic of Korea
No Coverage
The IAPP is unaware of a data protection authority or comprehensive data protection legislation for the Democratic People's Republic of Kore
OtherIAPP profile →
Democratic Republic of the Congo
Law
Privacy Legislation
The IAPP is unaware of a data protection authority for the Democratic Republic of the Congo
AfricaIAPP profile →
Denmark
GDPRDPALaw
Data Protection Authority
Privacy Legislation
Denmark is subject to the
EuropeIAPP profile →
Diego Garcia
No Coverage
The IAPP is unaware of a data protection authority or comprehensive data protection legislation for Diego Garci
OtherIAPP profile →
Djibouti
No Coverage
The IAPP is unaware of a data protection authority or comprehensive data protection legislation for Djibouti
AfricaIAPP profile →
Dominica
No Coverage
The IAPP is unaware of a data protection authority or comprehensive data protection legislation for Dominic
AmericasIAPP profile →