Security Stack Logo
Ethyca Fides logo

Privacy & Data Governance

Ethyca Fides

Privacy engineering platform automating DSARs with open-source core and enterprise features.

Ethyca Fides Overview

What it does

Ethyca Fides is a privacy engineering platform built on an open-core model: the Apache 2.0 licensed Fides taxonomy and policy language describe data categories, uses, and subjects in machine-readable form, and the commercial Fides Cloud and Fides Enterprise tiers run Data Subject Request (DSR) fulfillment, consent orchestration, and data mapping on top of it. Since August 2026 the same stack also underpins Astralis, the runtime layer that evaluates purpose-based access policies when models, agents, and analysts request data.

How it works

Helios monitors connect to databases, warehouses, SaaS applications, identity providers, and AWS accounts, classify discovered fields with pattern recognition and Large Language Model (LLM) assistance, and generate data maps and Records of Processing Activities. Lethe executes access, deletion, and correction requests through 100+ SaaS and 10 database connectors, applying masking strategies such as hashing, encryption, and null rewrite to preserve referential integrity. Janus serves privacy notices through the FidesJS SDK, supports the IAB Transparency and Consent Framework and Global Privacy Platform, and syncs preferences bidirectionally with downstream systems. Eleven templates cover DPIAs, CPRA risk assessments, and EU AI Act assessments.

Credentials and traction

Ethyca donated the Fideslang taxonomy to the IAB Tech Lab in early 2024, where it became the foundation of the IAB Tech Lab Privacy Taxonomy released for public comment in September 2024. More than 200 brands use the platform, including The New York Times, WeTransfer, Ramp, SurveyMonkey, Condé Nast, Axios, and Vercel; it processes 744 million preferences annually and has handled more than 4 million access requests. A Dublin European headquarters and research center opened in January 2026.

Key Capabilities

mapped to solution categories
Consent and Preference Management (CPM)

Exposes consent management through REST APIs, enabling custom front-end consent experiences without being constrained to the vendor's UI components.

Crawls the site to discover all cookies and tracking technologies in use, categorizes them by purpose (strictly necessary, analytics, marketing), and maintains the cookie declaration.

Stores an immutable record of consent transactions (what consent was given, when, to which version of the privacy notice, from which IP and session), as required for GDPR accountability.

Implements IAB Europe TCF v2.2, encoding user consent through the TC String and Global Vendor List for CMP certification in EU programmatic advertising.

Handles GDPR opt-in, CCPA/CPRA opt-out, LGPD, and other jurisdiction-specific consent regimes from a single implementation, applying the correct consent model based on visitor geolocation.

Hosts a self-service center where individuals manage granular communication and data-use preferences over time (channels, topics, and purposes), with those choices enforced across connected systems.

Pushes stored consent decisions into tag managers and ad platforms (Google Consent Mode v2, GTM) so downstream tags fire only for permitted purposes.

Privacy Management

Discovers personal data processing activities and their associated data flows, systems, and third-party transfers: the foundation for GDPR Article 30 Records of Processing Activities.

Provides structured DPIA workflows with pre-built templates for common processing activities, routing for DPO review, and documentation of risk mitigations.

Assesses third-party processors and sub-processors against GDPR data processing agreement requirements and privacy control standards before data sharing.

Monitors updates to privacy laws and regulatory guidance across jurisdictions and maps changes to affected data processing activities and controls in the program.

Serves compliant cookie consent banners, stores granular consent by category, and integrates with analytics and ad tech platforms to enforce user consent preferences.

Captures, stores, and versions consent records with purpose, legal basis, and timestamp, providing auditable proof of consent for data processing activities.

Automates intake, identity verification, routing to data owners, and fulfillment of GDPR, CCPA, and LGPD data subject requests, access, deletion, portability, and correction.

Automates timed deletion and lifecycle enforcement so personal data is erased across connected systems when its retention period or lawful purpose ends, independent of an inbound request.

Data Subject Request Automation

Handles data subject requests under GDPR, CCPA/CPRA, LGPD, and other privacy laws from a single intake workflow, applying jurisdiction-specific handling rules and response timeframes.

Verifies data subject identity using configurable verification methods (email OTP, ID document check, account authentication), before disclosing or deleting personal data.

Queries connected data sources (CRM, email, databases, SaaS apps) to locate personal data for a given subject, automating the data retrieval step of access and deletion requests.

Tracks regulatory response deadlines (GDPR 30-day, CCPA 45-day) per request, escalates overdue items to named owners, and generates compliance reporting.

AI Governance Platforms (AIGP)

Provides comprehensive audit trails of platform actions and activities across the AI life cycle.

Connects across the AI and data stack, including data governance, model observability, AI discovery and AI security tools.

Classifies, assesses and mitigates AI-specific risks such as bias and robustness, with content libraries for regulations and frameworks including the EU AI Act, NIST AI RMF and ISO 42001.

Documents trust, risk and security assessments, testing and validation results, and remediation evidence for AI systems.

Maintains a centralized, discoverable registry of all AI use cases, applications, agents and models with metadata, ownership and deployment status.

Enforces AI policies at runtime through guardrails, access controls and use-case validation, with remediation recommendations and compliance reporting.

Captures and tracks the data used by AI entities over time, including training-data provenance and lineage via data governance integration.

Integrations

compatible tools
Ada ChatbotAdobe CommerceAdobe SignAdyenAfterShipAircallAlchemerAlgoliaAmazon DynamoDBAmazon RDS PostgreSQLAmazon RedshiftAmplitudeAppsFlyerAttentiveAuth0AWSAzureBazaarvoiceBigQueryBloomreachBoostrBraintreeBrazeCheckrDatadogDataHubDelightedDigiohDockerDomoDoorDashDynamics 365 CRMErplyFirebaseForterFriendbuyFriendbuy NextgenFullStoryGCPGitHub ActionsGladlyGongGoogle AnalyticsGoogle BigQueryGoogle Consent Mode v2Google Tag ManagerGorgiasGreenhouseHeapHighspotHubSpotIterableIterateJiraKlaviyoKubernetesKustomerLoop ReturnsMailchimpMailchimp TransactionalMariaDBMarigold EngageMedalliaMeta MarketingMicrosoft AdvertisingMicrosoft EntraMicrosoft SQL ServerMongoDBMovable InkMySQLNetSuiteOktaOneSignalOpenWebOracle ResponsysOutreachPardotPayPalPostgreSQLPower ReviewsQualtricsRechargeRecurlyRedshiftRollbarSaleorSalesforceSegmentSendGridSentryServiceNow ITSMShipStationShopifySimon DataSlack EnterpriseSnapSnowflakeSparkPostSplashSprigSquareStatsig EnterpriseStripeStytch ConsumerSurveyMonkeyTalkableTwilio ConversationsTwilio SMSTypeformUnbounceVendWunderkindYotpo LoyaltyYotpo ReviewsZendeskZenoti

Implementation & support

Deployment model
CloudOn-PremisesSaaS
Support channels
Community ForumDocumentation

Info last updated on September 7, 2026

Buyers

Start a shortlist with Ethyca Fides

Compare options, add your notes, and run informed evaluations.

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

Resources

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.