Alternative
Ethyca Alternative for DSAR Fulfillment, Without the Engineering Project
Ethyca is a privacy engineering platform, and that phrase is the whole comparison. Founded in 2018 in New York by Cillian Kieran and Miguel Burger-Calderon, it raised a $13.5M Series A in June 2020 and another $10M in December 2024, and it built its product on Fides, the open-source privacy framework it released publicly in 2021 under the Apache 2.0 license. Fides is serious work. Ethyca donated its taxonomy, fideslang, to the IAB Tech Lab in early 2024, and it became the basis of the IAB Tech Lab Privacy Taxonomy released for public comment that September. If you have engineers who want privacy expressed as code, annotated in your repositories, enforced in your runtime and checked in CI, Ethyca is the best-designed thing in this category and you should look hard at it.
The catch is who it is built for. Running Fides yourself means Docker, Python, a PostgreSQL database, a Redis instance and a web server, and then the real work: labeling your systems and datasets in the Fides taxonomy so request automation knows where to look. That is an engineering project with an owner and a sprint, and Ethyca does not publish pricing for the commercial platform, so the managed path starts with a sales call.
Obtainer is for the other situation, the common one, where the person responsible for privacy requests is in legal, compliance or operations and has no engineering time to requisition. A request arrives, and the hard part is finding every place that one person's data actually lives before the clock runs out. Obtainer intakes the request, uses AI-native discovery to surface where the data sits, compiles a single reviewable manifest with source badges, drafts a deadline-safe response, and tracks the GDPR one-month and CCPA 45-day clocks, with a human redaction-and-approval gate in front of anything that leaves. Self-serve from a planned $49/mo, no deployment, no annotation pass. Where Ethyca wins: privacy-as-code enforcement, AI governance, an open-source core you can read and fork, and the standards pedigree, none of which Obtainer offers. Obtainer helps you comply; it is not legal advice, and you stay in control of what is disclosed.
Last updated August 2026
Side by side
Obtainer vs Ethyca
| Capability | Obtainer | Ethyca |
|---|---|---|
| DSAR fulfillment focus | One capability in a privacy engineering and AI governance platform | |
| Open-source core you can self-host | Fides, Apache 2.0 licensed | |
| Works without an engineering deployment | Self-hosting needs Docker, Python, PostgreSQL and Redis | |
| Works without annotating your systems first | Datasets are labeled in the Fides taxonomy | |
| Privacy-as-code enforcement in your runtime | Core strength | |
| AI model and data governance | ||
| Reviewable manifest with source badges | Varies | |
| Human redaction and approval gate | Varies | |
| Self-serve, no sales call | Open source is self-serve, the platform is sales-led | |
| Published pricing | From $49/mo | Not published on any major aggregator |
Comparison reflects general product positioning and is provided in good faith. Verify current capabilities with each vendor.
See it live
Find the data, draft the response, hit the deadline, self-serve
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
Questions
Common questions about Ethyca and the alternatives
How much does Ethyca cost?
Ethyca does not publish list pricing, and unusually for a company this established, neither does anyone else. Capterra, GetApp and Software Advice all list Ethyca with no starting price and no user reviews as of August 2026, so there is no aggregated buyer data to quote the way there is for OneTrust or TrustArc. The reported model is a flat annual fee based on how many websites, apps and backend systems you connect, with no visitor tiers and no overage mechanics, which is a sane way to price it. The practical answer is that you will need a sales conversation to get a number, and that the open-source path costs nothing in license fees and something real in engineering time.
Is Ethyca open source, and is Fides free?
Fides is genuinely open source under the Apache 2.0 license, and the taxonomy it is built on, fideslang, is licensed CC BY 4.0. You can clone it, run it, modify it and deploy it in production without paying Ethyca anything. That is a real offer, not a crippled community edition. What it is not is free of cost. You are taking on hosting, upgrades, connector maintenance and the annotation work, and you need someone on staff who can own it. Ethyca sells the managed platform, support and the governance features on top.
What is Fides?
Fides is the open-source privacy engineering platform underneath Ethyca, released publicly in 2021. It has three parts you interact with: a webserver with an admin UI for reviewing and approving privacy requests, a Privacy Center where consumers submit them, and a taxonomy for labeling what data a system holds and what it is used for. Once your systems are described in that taxonomy, Fides can orchestrate an access or deletion request across them programmatically. Ethyca donated the taxonomy to the IAB Tech Lab in early 2024, and it became the basis of the IAB Tech Lab Privacy Taxonomy.
What do I need to run Fides myself?
Per the project documentation, the quick-start sample project needs Docker 20.10.11 or later, Python 3.13 and the uv package manager, and it will run a full request against sample databases on your laptop in a few minutes. A real deployment needs more: a PostgreSQL 12 or later database for persistent configuration, a Redis 6.2.0 or later instance used as a cache and task queue, and a general purpose web server for the Fides webserver itself, which the docs say fits comfortably on something the size of an AWS t3.small. None of that is exotic. It is just infrastructure somebody has to own, patch and monitor.
What is the best Ethyca alternative?
It depends which part of Ethyca you are replacing. If you want privacy enforced in code and checked in your pipeline, there is not a close substitute and you should probably stay. If you want a full privacy program platform with consent, assessments and inventory, the comparables are OneTrust, DataGrail, Transcend, Osano, Ketch and TrustArc, all sales-led. If the actual job is receiving access and deletion requests and answering them correctly inside 45 days, without a deployment and without borrowing an engineer, a focused fulfillment tool fits better. Obtainer does that one job, self-serve from a planned $49/mo.
Can I run Fides and a separate DSAR tool at the same time?
Yes, and for some teams that is the sensible arrangement. Fides earns its place where your engineers want data labeling and policy enforcement living alongside the code, which is a long-horizon investment in how your systems are built. Request fulfillment is a shorter loop with a statutory deadline on it, and it does not have to wait for the annotation project to finish. Running the requests in a focused tool while the engineering work proceeds means you are answering on time this quarter rather than after the rollout.
See Obtainer run a request end to end
Obtainer finds where a person's data lives across your systems, drafts the deadline-safe response, and tracks the GDPR and CCPA clock, focused on DSAR fulfillment and self-serve. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice. Decide for yourself.