# OneTrust MCP for AI Agents AI Agent Connect

> OneTrust MCP lets you manage privacy compliance, vendor risks, and data governance directly from your AI agent. It handles DSARs, privacy assessments, data inventory, and incident tracking for GDPR and CCPA. Automate your compliance workflows and get real-time visibility into your risk register and vendor security status without switching tabs. This is the fastest way to turn your privacy data into actionable answers.

## Overview
- **Category:** fort-knox
- **Price:** Free
- **Endpoint:** https://edge.vinkius.com/vk_preview_QyXYX8Uk9tWgyP2uTUFoAEIPmCJb73Dix0eWInrc/ai-agent-connect
- **Tags:** gdpr, ccpa, hipaa, data-privacy, compliance-automation, risk-assessment, consent-management

## Description

OneTrust MCP connects your account to any AI agent so you can manage privacy compliance, vendor risks, and data governance through natural conversation. This connection lets you handle the heavy lifting of privacy work without jumping between tabs. Instead of hunting for specific records or manually updating risk scores, you just ask your agent to pull the latest data. You can check which vendors have overdue security questionnaires or see exactly which systems are processing personal data for a specific purpose. It turns a complex compliance environment into a searchable, actionable workspace. When you connect this to your workflow via Vinkius, you're essentially putting a privacy expert in your pocket who knows your specific data map and compliance deadlines by heart. You get to spend less time on data entry and more time on actual risk mitigation. It's about having the right answers at the right moment without the friction of manual navigation. You can quickly pull up a list of all open requests to see what's pending, or dive into a specific project to see the risk findings and recommendations from a recent impact assessment. Whether you're dealing with a sudden request from a customer or trying to get a clear picture of your third-party risk, this connection gives you the visibility you need without the headache of manual navigation.

## Tools

### onetrust_create_dsar
Register a new GDPR or CCPA privacy request on behalf of an individual. This automatically starts the fulfillment workflow and calculates regulatory deadlines.

### onetrust_get_assessment
Get full details on privacy impact assessments, including risk findings and recommendations. This helps you understand the privacy risk landscape for a specific project.

### onetrust_get_dsar
Retrieve complete details on a specific data subject request, including its audit trail and deadline. Use this for detailed investigation or compliance reporting.

### onetrust_list_assessments
View all privacy impact assessments with their current status, risk scores, and assigned owners. Use this to review your assessment pipeline or check GDPR compliance.

### onetrust_list_assets
View your data inventory to see which systems process personal data and their legal bases. This helps you quickly answer questions about your data map.

### onetrust_list_consent_purposes
Review the cookie categories and marketing preferences configured in your consent management system. This is great for auditing your privacy banner settings.

### onetrust_list_dsars
List all pending privacy rights requests, including their current status and regulatory deadlines. Use this to track your total DSAR volume and compliance posture.

### onetrust_list_incidents
View security and privacy incidents with severity levels and regulatory notification statuses. This helps you monitor breach response and incident trends.

### onetrust_list_risks
Access your risk register to see identified risks, impact levels, and treatment plans. Use this for board-level risk summaries or identifying areas that need attention.

### onetrust_list_vendors
See your list of third-party vendors along with their security risk ratings and assessment status. This is useful for vendor due diligence and subprocessor management.

## Prompt Examples

**Prompt:** 
```
How many open data subject requests do we have?
```

**Response:** 
```
You have **7 open DSARs**:

🔴 **2 overdue** — Both are deletion requests (GDPR Art. 17) past the 30-day deadline
🟡 **3 in progress** — 1 access request, 2 portability requests (due in 12, 18, 22 days)
🟢 **2 new** — Submitted today, auto-routed to the Privacy Team

The 2 overdue requests need immediate attention. Shall I show the details?
```

**Prompt:** 
```
Which vendors have overdue security assessments?
```

**Response:** 
```
There are currently 4 vendors with overdue security assessments:
1. CloudHost Inc. (High Risk) - Overdue by 15 days
2. DataFlow Analytics (Medium Risk) - Overdue by 8 days
3. MailSender Corp (Low Risk) - Overdue by 3 days
4. CDN Partners (Medium Risk) - Overdue by 1 day
Would you like me to trigger automated reminders for these vendors?
```

**Prompt:** 
```
Show the data map for our CRM system.
```

**Response:** 
```
Here is the data map for the CRM System:
- **Personal Data Processed:** Names, email addresses, phone numbers, purchase history.
- **Purpose:** Customer relationship management, direct marketing.
- **Legal Basis:** Legitimate interest (CRM), Consent (Direct Marketing).
- **Retention Period:** 5 years after last contact.
The CRM system is fully compliant with current policies.
```

## Capabilities

### Process DSARs
Create and track access, deletion, and opt-out requests automatically.

### Review Privacy Assessments
Browse PIAs and DPIAs to see risk scores and findings.

### Map Data Inventory
See which systems process personal data and their legal bases.

### Monitor Vendor Risk
Track security questionnaires and risk ratings for third-party partners.

### Audit Consent
Review cookie categories and consent purposes for privacy banners.

### Track Incidents
View security and privacy incidents with severity levels and regulatory notification statuses.

### Analyze Risk Register
Get summaries of impact, likelihood, and treatment plans for identified risks.

## Use Cases

### Checking overdue privacy requests
A user asks how many DSARs are overdue. The agent uses onetrust_list_dsars to identify the 2 overdue requests and alerts the user immediately.

### Identifying high-risk vendors
A risk manager asks for a list of risky partners. The agent uses onetrust_list_vendors to pull a list of high-risk partners and their current assessment status.

### Mapping CRM data flow
A developer needs to know where customer data lives. The agent uses onetrust_list_assets to show the data map for the CRM system including legal basis.

### Reviewing specific request history
A privacy officer needs to see the status of a specific request. The agent uses onetrust_get_dsar to show the audit trail and fulfillment steps.

## Benefits

- Stop hunting for DSARs. Use onetrust_list_dsars to see every pending request and its deadline in one view.
- Faster vendor onboarding. Use onetrust_list_vendors to quickly identify which partners need security questionnaires.
- Instant data mapping. Use onetrust_list_assets to see exactly what systems process personal data and why.
- Real-time incident tracking. Use onetrust_list_incidents to monitor breach statuses and regulatory requirements.
- Easier risk oversight. Use onetrust_list_risks to get a high-level summary of enterprise risks and treatment plans.
- Simplified assessment review. Use onetrust_get_assessment to pull risk findings for specific projects without opening the dashboard.

## How It Works

The bottom line is you get a conversational interface for your entire OneTrust compliance suite.

1. Get your OneTrust API token from your Admin Console.
2. Connect your OneTrust account to the Connector via Vinkius.
3. Ask your agent to list open DSARs or check vendor compliance status.

## Frequently Asked Questions

**Can OneTrust MCP help me with GDPR requests?**
Yes, it allows your AI agent to list, create, and track DSARs like access and deletion requests, including their regulatory deadlines.

**Can I use OneTrust MCP to check vendor risks?**
Yes, you can ask your agent to show you your third-party vendors, their risk ratings, and whether their security questionnaires are complete.

**How does OneTrust MCP handle data privacy assessments?**
It lets you browse PIAs and DPIAs to see risk scores, findings, and recommendations without having to navigate the dashboard.

**Can I see my data inventory with OneTrust MCP?**
Yes, your agent can pull the data map to show which systems process personal data and what the legal basis is for each.

**Can OneTrust MCP track security incidents?**
It can list all security and privacy incidents, showing you the severity, status, and whether they've been reported to regulators.

**Is OneTrust MCP good for tracking DSAR deadlines?**
It specifically pulls the regulatory context and deadlines for each request, making it easy to see what's coming due.

**How do I get started with OneTrust?**
Subscribe, then enter your OneTrust API token (from **Admin Console → Integration → API Access**) and your base URL (e.g., app.onetrust.com or app-eu.onetrust.com). Your AI agent connects instantly. No code, no SDK — just connect and start managing privacy compliance.

**Can my AI agent handle GDPR data subject access requests?**
Yes. Create DSARs directly from conversation — specify the subject's name, email, and request type (access, deletion, rectification, portability, opt-out). OneTrust automatically calculates regulatory deadlines (30 days for GDPR, 45 days for CCPA) and routes the request to the right handler.

**How do I check which vendors have overdue security assessments?**
Ask your agent "show me vendors with overdue assessments" and it lists every third-party vendor with their risk score, questionnaire status, and last review date. You see exactly which processors need follow-up — all without logging into OneTrust or switching tabs.

**Is this suitable for multi-regulation compliance (GDPR + CCPA + HIPAA)?**
Absolutely. OneTrust is built for multi-regulation environments. Browse your entire data inventory mapped to processing purposes and legal bases, track DSARs across any regulation, manage privacy impact assessments, and monitor incidents with regulatory notification requirements — perfect for enterprises, healthcare organizations, and global companies operating across jurisdictions.