The OneTrust Product Usage Terms define the usage metrics that apply to certain OneTrust Cloud Services “as set forth on an Order Form”, and they contain an Overuse Policy. The document opens with a rule that matters for any review: “If no usage limit is specified on the Order Form, then no limit shall apply with respect to that usage metric.”[1] Capitalised terms not defined in it are defined in the Master Terms.[1] The version reviewed is headed “Last Updated: March 26, 2025”, and the myOneTrust page that lists it also still lists the Product Usage Terms of August 26, 2024, so older orders may be governed by the earlier wording.[6] The myOneTrust article on packaging explains that, before Spring 2025, usage meters applied to individual products and, afterwards, they apply at the package level.[3]
OneTrust’s pricing page shows the same measures from the sales side: each package is “based on” admin users and an inventory count, average daily visitors, or data subject profiles.[5] The Product Usage Terms are the contractual definitions behind those labels.
Metric definitions
Admin Users
“Admin Users” is “the maximum number of Authorized Users with the roles and permissions to create, administer, and initiate actions on key program elements and associated workflows.”[1] The same sentence appears for Privacy Automation and the Privacy Automation Suite, Tech Risk & Compliance (and standalone Compliance Automation), Third-Party Risk Management, the Third-Party Management Suite and Third-Party Due Diligence, and AI Governance.[1] The measure is therefore a count of users by role, not of every person who can view content. The Master Terms define Authorized Users as the customer’s and its Affiliates’ employees, contractors, vendors and consultants.[4] See Admin Users.
For DataGuidance Research, the applicable metric depends on how it is bought: as part of the Privacy Automation Suite, Admin Users; otherwise, “Authorized Users”.[1] The Authorized Users row records the Master Terms definition.
Inventory counts
Each inventory metric is a maximum number of records identified by a unique record number:[1]
| Metric | Package | Definition in the Product Usage Terms |
|---|---|---|
| Privacy Assets | Privacy Automation, Privacy Automation Suite | “the maximum number of asset records with associated processing activity as identified by a unique record number” |
| Assets | Tech Risk & Compliance, standalone Compliance Automation | “the maximum number of asset records as identified by a unique record number”; monitored through the Inventory tab |
| Third Parties | Third-Party Risk Management, Third-Party Management Suite, Third-Party Due Diligence | “the maximum vendor records inventories as identified by a unique record number”; monitored through the Vendors Inventory tab |
| AI Projects | AI Governance | “the maximum number of AI project inventory records as identified by a unique project inventory number” |
Because the unit is a record and not a device or a person, the count depends on how the customer models its estate in the application: the number of records created, not the number of underlying systems, suppliers or models discovered elsewhere. The documents do not say whether archived or inactive records count, so that point should be confirmed with OneTrust.
Visitors, profiles and volumes
- Average Daily Unique Visitors (ADUV), for the Consent Management Platform, is “the total number of unique daily visitors across all channels (e.g., web, mobile, and CTV), aggregated across multiple properties (e.g., domains, apps, and devices), averaged over a period of up to 365 days.” Customers may monitor it through the Consent Traffic reporting tab.[1] See Average Daily Unique Visitors.
- Data Subjects, for Universal Consent & Preference Management (UCPM), is “the total number of customer profiles with a primary identifier (such as an email or phone) that is logged by the Cloud Services, whether or not unique.”[1] Duplicates therefore count. See Data Subjects.
- Annual Scanned Volume, for Enterprise Data Discovery, is the total amount of data scanned within a 12-month period measured in terabytes.[1] See Annual Scanned Volume.
- Annual Screening Volume, for Third-Party Due Diligence and the Third-Party Management Suite, is the maximum count of data pulls from Dow Jones’ database related to a specific entity or individual that the customer may run within a 12-month period.[1] See Annual Screening Volume.
Cumulative and point-in-time meters
The myOneTrust article notes that “some usage meters are cumulative (e.g., annual scan volume), while others are point-in-time (e.g., average daily unique visitors)”.[3] For cumulative meters such as scanned volume and screening volume, usage accrues through the year and is measured against a 12-month limit; for ADUV, the figure is an average that moves with traffic and is read against a single limit. A licence manager should therefore monitor cumulative meters against the subscription year and averaged meters against the trailing window defined in the terms.
Package-specific limits
The Product Usage Terms add one limit that is not a metric of its own: use of Compliance Automation as part of the Privacy Automation Suite is “strictly limited to two (2) Admin Users and to the use of the privacy-related frameworks identified” by OneTrust. Additional Admin Users or non-privacy frameworks require either a standalone Compliance Automation subscription or Tech Risk & Compliance, which includes Compliance Automation.[1] The Solution Packages document repeats the limit in the Suite’s product list and adds that Privacy Notice Management is included in the Consent Management Platform package only if ADUV is 50k or more.[2] See Compliance Automation limit within Privacy Automation Suite.
Overuse Policy
The Overuse Policy governs what happens when usage exceeds a limit.[1] Its elements are:
- Monitoring. OneTrust may monitor the customer’s usage to verify that it does not exceed any applicable usage limitation under the metrics (a “Usage Limit”). The Master Terms add that OneTrust may collect and use Usage Data to “monitor usage limits”.[1][4]
- Customer choice. If the customer exceeds a Usage Limit during the Subscription Term it “shall either: (i) reduce its usage to conform to the Usage Limit; or (ii) purchase a higher usage tier to increase the applicable Usage Limit.”[1]
- Grace Period. If neither happens within three calendar months of the customer first exceeding the Usage Limit, that period is the “Grace Period”.[1]
- Additional Fee. After the Grace Period OneTrust “may invoice an additional fee” under the Order Form. The fee is “the difference in price between Customer’s purchased usage tier and the price for the next highest usage tier that would allow for Customer’s continued use without exceeding the Usage Limits”, calculated pro rata from the start of the Grace Period to the end of the then-current Subscription Term, and based on usage from the start of the Grace Period.[1]
Several features of the policy are worth noting. The remedy is a step to the next tier, not a rate per unit over the limit, so the fee depends on the tier structure on the Order Form. The fee is calculated from the start of the Grace Period, not from the date of invoice, so it accrues for the months in which the customer was already over the limit. The policy says OneTrust “may” invoice, which leaves the decision to OneTrust. And the myOneTrust article states more generally that exceeding licensed usage “may require a contract amendment or upgrade”, and lists as a step: “Monitor consumption through your admin console to ensure usage aligns with licensing.”[3] See Overuse Policy.
The Master Terms provide that payment obligations are non-cancellable and non-refundable, that OneTrust may suspend access on fourteen days’ notice if payment is past due, and that the customer’s payment obligations sit outside the liability cap.[4] An Additional Fee invoiced under the Overuse Policy is a payment obligation under the Order Form, so those terms would apply to it.
Monitoring in practice
The Product Usage Terms point to places in the application where counts can be seen: the Consent Traffic tab for ADUV, the Inventory tab for Assets, the Vendors Inventory tab for Third Parties, and the Cloud Services for Data Subjects.[1] The packaging article adds an admin console view of consumption.[3] The article also states that customers can enable all capabilities in a package without incremental licensing, “subject to meter limits”, so enabling a capability does not itself raise the licence quantity but may increase consumption of a meter.[3]
Out of scope
This article does not cover quantities or tiers, which are on the Order Form and not published, the metrics of any module-based subscription that predates Spring 2025 and is governed by the earlier Product Usage Terms, or the monitoring pages that OneTrust provides only to logged-in customers in its knowledge base.