Skip to content
    August 18, 2026| Top Floor Team| 12 min read

    Privacy Compliance Software vs a Consultant: What Do You Need?

    Privacy tooling is cheap and getting cheaper, and that changes the buying decision. Termly publishes a Pro+ tier at $15 a month billed annually with unlimited policies, unlimited banner views and consent logging. Osano publishes a Plus tier at $199 a month covering three domains and 30,000 monthly visitors, which bundles UK and GDPR representative appointments. Usercentrics publishes an Essential web tier at EUR 7 a month, in euros because that is the unit its price list uses. Those are the vendors' own list prices and you can buy them today without a sales call. What none of them sells is the judgment: which of the nineteen comprehensive US state privacy laws and the GDPR actually reach you, what your lawful bases are, what belongs in your Article 30 records, and what to do when a regulator or an unusual deletion request arrives. Buy the cheapest tool that does your consent and notice mechanics, then buy hours rather than seats for the rest.

    This article separates the two purchases, names the three ways tool-only programmes fail, and states the case where the software genuinely is enough on its own.

    Key takeaways

    • Consent and notice tooling is a commodity: the self-service tiers publish at EUR 7 a month (Usercentrics), $15 (Termly) and $199 (Osano), and they do the mechanical work well.
    • What software cannot do is scope, lawful basis, records of processing, and regulator response, which is where privacy programmes actually fail.
    • The three recurring failure modes: a banner that blocks nothing, a policy that describes a company you no longer are, and a request queue nobody owns.
    • Buy in this order: scope decision, then data map and records, then tooling configured against what you found, then a review cadence.
    • If you have one website, no EU exposure and no sensitive data, software plus an afternoon of reading may be the whole correct answer.

    What the software is genuinely good at

    Take the vendors at their word about what they do, because on the mechanics they are right.

    A consent management platform detects and categorises the cookies and tags on your site, blocks non-essential ones until consent is given where that is required, presents a banner and a preference centre, records what each visitor chose and when, and hands you a log you can produce later. Doing that by hand is miserable and error-prone, and it is exactly the kind of repetitive, auditable work software should own.

    The same platforms usually generate and host your privacy notice, cookie notice and terms, and they update the boilerplate when a law changes. Termly publishes automatic policy updates and regulation monitoring on its paid tiers. Osano's Plus tier bundles UK and GDPR representative appointments alongside the consent tooling, which is an unusually concrete piece of value at $199 a month.

    Most also provide a data subject request intake form and a queue. That is genuinely useful, and it is where the honest description of the category starts to run out.

    At these prices there is no serious argument for building any of it yourself. Buy it.

    What the software cannot do

    Four things, and every one of them is upstream of the tool.

    Decide which laws reach you. The IAPP's US state comprehensive privacy laws report is the reference point, and it counts nineteen states with comprehensive privacy laws passed, noting that no new state added one in 2025 while half of those with laws already on the books amended them. A static count is not a static obligation. Whether a given law reaches you turns on revenue thresholds, consumer counts, share of revenue from selling data, and in some states no threshold at all. That analysis produces a list of applicable laws. No platform performs it, and several will happily configure themselves for all of them, which is how companies end up honouring rights they do not owe while missing one they do.

    Choose your lawful bases. Under the GDPR every processing purpose needs a basis under Article 6, and special categories need a condition under Article 9. Consent is one of six options and frequently the worst of them, because it is withdrawable and because bundling it with a service makes it unfree. A tool cannot tell you that your product analytics run on legitimate interests and your marketing emails do not. That is a judgment with a written balancing test behind it.

    Write your records of processing. Article 30 requires a record of processing activities: purposes, categories of data subjects and data, recipients, transfers, retention periods, security measures. Software can hold the record. It cannot know that your support team exports tickets to a spreadsheet once a quarter, or that the growth team stood up a new analytics vendor in March. Records of processing are produced by asking people what they do, and they go stale the moment nobody asks again.

    Answer a regulator, or an unusual request. When a supervisory authority or a state attorney general writes, the response is a legal and factual document with deadlines. When a request arrives that is not a normal access or deletion (a request on behalf of a deceased person, a request from someone whose identity you cannot verify, a deletion that collides with a legal hold), the tool routes it to a human who has to decide. If nobody in your company can make that decision, the tool has automated the easy 90 percent and left the part that carries the risk.

    The three ways tool-only programmes fail

    We see the same three, in roughly this order of frequency.

    The banner that blocks nothing. A consent banner installed after the tag manager, or with the auto-blocker off, or with the analytics tag categorised as strictly necessary. The visitor clicks reject, the trackers fire anyway, and the company now has a documented record of consents it did not honour. That is worse than no banner, because the log is evidence. This is a configuration failure, not a product failure, and it is found by testing the site with the tools open, not by reading a dashboard.

    The policy that describes a company you no longer are. Generated notices are accurate on the day they are generated. Eighteen months and four new vendors later, the notice lists three subprocessors and the company uses eleven. Regulation monitoring updates the boilerplate; nothing updates the facts. Every state privacy law and the GDPR require the notice to describe actual practice, and the gap between generated text and current practice is where misrepresentation claims live.

    The request queue nobody owns. The intake form works. Requests arrive. Then they sit, because the form was bought by marketing, the deletion has to be executed by engineering, and no deadline is on anyone's calendar. The GDPR gives you one month under Article 12(3), extendable by two further months for complex or numerous requests if you notify inside the first month. A queue without a named owner is a missed deadline with a timestamp on it.

    None of these is fixed by buying a more expensive platform. All three are fixed by a person deciding something and writing it down.

    What a practitioner does that a platform cannot

    The honest version of our own value, stated as tasks rather than adjectives.

    Scope: producing the written applicability analysis that says which laws reach you and why, with the thresholds and the reasoning, signed and dated, so that it can be handed to a regulator or an acquirer.

    Data mapping: sitting with the people who actually touch the data and finding the shadow systems. The spreadsheet, the shared inbox, the analytics tool someone trialled and never turned off.

    Lawful basis and balancing tests: writing the assessment for each purpose, which is a document with a defensible structure, not a dropdown.

    Vendor and contract terms: reading the data processing agreements you sign and the ones you send, and knowing which clauses matter.

    Judgment under pressure: the deletion request that collides with a retention obligation, the breach that might or might not be notifiable, the enterprise customer demanding a term you should not accept.

    That is a few days of work up front and then a recurring review, not a full-time role for most companies. The pattern that works is a modest tool plus periodic practitioner time, and the companies that overspend are the ones who buy an enterprise suite and then discover that configuring it requires the same practitioner they were trying to avoid hiring.

    Buy in this order

    The order matters more than the components, because buying the tool first means configuring it against assumptions.

    First, the scope decision. Which laws, and why. One document.

    Second, the data map and the Article 30 records. This is the work that tells you what the tool has to be configured to do, and it is the deliverable everything else depends on.

    Third, the tooling, configured against what you found. At this point you know how many domains, whether you need geolocation-based rules, and whether your request volume justifies a workflow or a shared inbox with a calendar reminder.

    Fourth, a review cadence. Quarterly is enough for most companies: what changed, what new vendors, does the notice still describe us.

    Reversing steps two and three is the single most common and most expensive mistake in this category.

    When the software alone is enough

    This is the section that costs us work, so read it as the honest boundary of our pitch.

    If you run one marketing website, sell only to US customers, collect nothing more sensitive than an email address and a support ticket, use a handful of well-known vendors, have no European exposure, and have checked that your revenue and your consumer counts sit under the applicability thresholds of the state laws where you sell, then a paid consent tier, a generated privacy notice you actually read, and a working deletion inbox is a defensible programme. That is $15 to $199 a month and an afternoon of your time. Hiring anyone for that is over-buying, and we would tell you so.

    That last condition is doing more work than the others, so do not wave it through. The state comprehensive laws set their own applicability thresholds, and they are written on annual revenue and on the number of consumers whose personal data you process or sell, which is exactly why a US-only company with a simple stack can still be squarely inside one. Read the thresholds in the IAPP's overview against your own numbers first. If any of them catches you, you owe scope-specific notices, request rights, an appeals process and opt-outs of sale and targeted advertising, and none of that is a purchasing decision a tool can make for you.

    The threshold where it stops being enough is not headcount. Once you are past the applicability question above, it is any one of these: you are in GDPR scope, you handle special-category data such as health or biometrics, your product's core function involves tracking people, you sell to enterprises whose procurement asks privacy questions, or you have more than about ten systems holding personal data. Any one of those, and the judgment work has become real.

    There is a related decision on the security side that follows the same logic, which we have written up in do you need a consultant if you have a compliance platform and in GRC platform vs people. The pattern repeats across categories: automation owns the evidence, people own the decisions.

    Where Top Floor fits

    We sell the judgment half, and we are explicit that we do not sell the software half or take a cut of it. Buy the tool direct, at list price.

    What we do is global privacy programme design across the state laws and the EU as one programme rather than several, GDPR scoping and Article 30 records, CCPA applicability and rights handling, and where you want the calendar and the evidence operated rather than advised on, compliance as a service. The typical shape is a few days of work up front and a quarterly review afterwards, not a permanent retainer, and if your answer to the previous section is that software alone is enough, the right outcome of a call with us is that we say so.

    How to decide this week

    Test your current banner before anything else. Open your site in a clean browser, reject everything, and watch the network requests. If analytics or advertising tags still fire, you have a configuration problem that no purchase will fix and it is the highest-risk thing on your list.

    Count your systems next. Every place personal data lands: CRM, support desk, warehouse, product analytics, email, billing, the spreadsheet. Under ten and simple, you are probably in tool-only territory. Over ten, or with any European or sensitive-data exposure, you need the scope work.

    Read your own privacy notice against that list. If it names fewer vendors than your list does, or describes retention periods nobody enforces, that gap is your first deliverable and it is not a software feature.

    Then buy the cheapest published tier that covers your domains and traffic, and put a quarterly reminder in a real calendar with a real name against it. If those four steps take you more than a week, that is the signal that you needed the practitioner rather than the platform.

    Frequently asked questions

    Do I need a privacy consultant if I already have a consent platform?

    Not necessarily, and the test is what kind of work is left over. Consent platforms handle the mechanics well: cookie scanning, blocking, banners, preference centres, consent logs, generated notices and request intake forms. They cannot decide which privacy laws reach you, choose your lawful bases under GDPR Article 6, build your Article 30 records of processing, or answer a regulator. If you run one US-only website with a handful of vendors and no sensitive data, the tool plus an afternoon of your own reading is defensible. If you are in GDPR scope, handle special-category data, track people as a core function, or hold personal data in more than about ten systems, the judgment work is real and a platform does not do it.

    How much does privacy compliance software cost?

    Self-service tiers are published and inexpensive as of August 2026. Termly lists a Pro+ tier at $15 a month billed annually with unlimited policies and banner views, Osano lists a Plus tier at $199 a month for three domains and 30,000 monthly visitors that includes UK and GDPR representative appointments, and Usercentrics publishes an Essential web tier at EUR 7 a month for up to 1,500 sessions. These are the vendors' own list prices, and the Usercentrics figure stays in euros because that is the unit its price list uses. Enterprise privacy suites cost far more and are bought for workflow scale, data mapping automation and vendor risk features rather than for additional legal coverage.

    What is the most common mistake companies make with consent tools?

    Installing the banner without verifying that it actually blocks anything. The three recurring failures we see are a banner that loads after the tag manager or has non-essential tags miscategorised as strictly necessary, so trackers fire despite a recorded rejection; a generated privacy notice that was accurate on the day it was made and now lists fewer vendors than the company uses; and a request intake form nobody owns, so requests sit past the GDPR Article 12(3) one-month deadline. All three are configuration and ownership problems, and none of them is solved by buying a more expensive platform.

    Should I buy the software or the help first?

    The help, or at least the scope decision, because buying the tool first means configuring it against assumptions you have not tested. The order that works is: write the applicability analysis saying which laws reach you and why; build the data map and Article 30 records so you know what personal data exists and where; then buy and configure tooling against what you actually found; then set a quarterly review with a named owner. Reversing the second and third steps is the most common and most expensive mistake in this category, because a platform configured for the wrong scope produces confident, documented, wrong output.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.