Search is no longer the only front door. A founder who needs a Data Protection Officer increasingly asks an assistant first, gets three or four names, and starts the shortlist there. That makes one question worth measuring: when an assistant answers a question about outsourced DPO and GDPR services, whose pages does it actually cite?
Key takeaways
- Across six AI assistants and 124 tracked prompts, engagecompliance.co was the most-cited domain on every one of the six.
- Measured against the most-cited specialist privacy provider on each assistant, our citation density averaged 2.2 times theirs.
- The gap is widest on the assistants that cite more widely, and narrowest on Google AI Mode, where the second-placed provider was within one citation.
- Regulators and legislative sources (the ICO, the EDPB, the European Commission, EUR-Lex) are cited heavily throughout and are counted separately here, because a regulator answers a different question than a provider does.
- Every figure below comes from a single measurement round. Assistants re-sample their sources continually, so treat these as a dated reading rather than a stable score.
What we measured
The measurement covers six assistants: ChatGPT, Google AI Overviews, Google AI Mode, Gemini, Claude and Copilot. Behind it sits a fixed set of 124 prompt and country combinations covering the questions a buyer actually asks, so questions about appointing a DPO, what outsourcing one costs, whether a company needs one at all, EU Representative obligations under Article 27, and sector-specific versions of each.
For every assistant we counted the number of tracked responses that cited each domain. A response counts once per domain however many pages of that domain it links to, so a page-heavy citation does not inflate the count.
The result
engagecompliance.co was the most-cited domain on all six assistants.
| Assistant | Responses citing us | Rank | Most-cited specialist provider |
|---|---|---|---|
| Copilot | 44 | 1 | 11 |
| ChatGPT | 39 | 1 | 11 |
| Google AI Mode | 33 | 1 | 32 |
| Google AI Overviews | 30 | 1 | 24 |
| Claude | 29 | 1 | 15 |
| Gemini | 18 | 1 | 11 |
Dividing our count by the leading specialist provider on each assistant and averaging the six ratios gives a citation density of 2.2 times. The spread behind that average matters more than the average does. On Google AI Mode the nearest provider was within a single citation, so the lead there is not meaningful. On Copilot and ChatGPT the ratio was closer to four.
What the method deliberately excludes
Three exclusions are worth stating, because each one would flatter the number if we made the opposite choice.
Regulators and legislative sources are counted separately. The ICO, the EDPB, the European Commission and EUR-Lex are cited constantly and correctly, and comparing a consultancy’s citation count to a supervisory authority’s would be meaningless.
General platforms are also held out. Community and video sites appear frequently in these answers, and they are not competing to be anyone’s DPO.
Named competitors are not published here. The comparison is against the leading specialist provider on each assistant, without naming it. Competitor facts drift, and a public league table of named firms built on one measurement round is not something we would stand behind.
Limits, stated plainly
The figures come from one measurement round. There is no re-run, so no confidence interval can be put around them, and a second round would produce somewhat different numbers.
Citation counts are not traffic. An assistant citing a page is not the same as a person reading it, and we make no claim here about how many of these citations turned into visits or enquiries.
The prompt set is ours. It reflects the questions we see buyers ask, which is a reasonable basis and still a choice. A different prompt set would produce a different picture, and anyone repeating this should say what they asked.
Why we publish the method
Numbers about AI visibility circulate quickly and are almost never accompanied by a sample size or a date. A ratio with no method behind it cannot be checked, and a figure that cannot be checked should not change anyone’s decision. Everything needed to repeat this measurement is on the page: the assistants, the sample size, the counting rule, the exclusions and the date.
Measured August 2026. We expect to re-measure and republish, including if the numbers move against us.