CA-C-001969 Top 5%
OneLogin — OneLogin Privacy Policy
Entity
Date detected
May 5, 2026
Effective date
May 5, 2026
Severity
Direction
Negative
Affected users
all users customers who interact via phone calls customers who use chatbot support customers who contact sales via email
Taxonomy
Transparency removal
Changes
−7 sentences removed · 6 sentences modified
Share 𝕏 Share in Share 🔒 PDF
Watch OneLogin Get alerts when this policy changes.
Watch — Free

Event Summary

OneLogin removed detailed disclosures about AI-powered analysis of customer communications, including call recording practices, chatbot interactions, and email analysis. The updated policy no longer explicitly describes how AI is used to analyze call transcripts, identify follow-up tasks, summarize conversations, or analyze sales emails. Additionally, the policy modified language about how collected data will be used, narrowing one stated purpose from 'answers or services you have asked or licensed' to 'services you have purchased,' and updated the security contact email from webmaster@oneidentity.com to webmaster@quest.com.

HIGH

Consumer Impact

The updated policy removes explicit language describing how OneLogin uses AI to analyze customer communications. Previously, the policy stated that call audio and video would be recorded with consent and analyzed using AI to identify follow-up tasks, summarize calls, and conduct sales analytics; that chatbot conversations would be analyzed and saved; and that sales emails would be analyzed to determine communication efficacy and forecast next steps. These specific AI analysis practices are no longer described in the updated policy. The revised language also narrows one stated data use purpose, changing 'answers or services you have asked or licensed' to 'services you have purchased.' No consumer opt-out mechanisms or alternative disclosures are provided in the change text.

Governance Analysis

The updated policy removes specific disclosures of AI-powered analysis of customer communications, which were previously stated purposes for data collection and processing. This removal creates ambiguity about how OneLogin processes call, chat, and email data going forward and may affect the transparency of OneLogin's data practices under GDPR, CCPA, and FTC standards. Organizations that rely on OneLogin's published privacy terms to inform their own vendor disclosures and Data Processing Agreements should evaluate whether they remain accurate.

Available Actions

Contact OneLogin security team at webmaster@quest.com to request written confirmation of whether call recording, transcript analysis, and email analysis practices continue under the updated policy.

If No Action Is Taken

Consumers will not have visibility into whether OneLogin continues to perform AI analysis of their calls, chats, and emails, as these practices are no longer explicitly described in the policy.

Organizations relying on OneLogin's privacy disclosures to populate their own customer-facing privacy notices may inadvertently publish inaccurate vendor data processing descriptions.

Key Clauses Affected

AI analysis of communications (removed)

Policy no longer explicitly discloses AI-driven analysis of call transcripts, chatbot conversations, or sales emails.

Data use scope (modified)

Narrowed stated purpose from 'answers or services you have asked or licensed' to 'services you have purchased'.

Security contact (updated)

Changed from webmaster@oneidentity.com to webmaster@quest.com.

Full clause-by-clause analysis available with Professional.
These clauses may change again. Get alerted when they do. Watch OneLogin — Free

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
632189e2a9ad8217101dfa942396127b2a6421e5aa908b71324036c3925e9a3a
May 6, 2026 09:59 UTC
✓ Verified
Current Version
9fa832f0cf5da65293f2c0447318a16e8c46b6302056b99b2f1e62163aaaa10b
May 5, 2026 06:38 UTC
✓ Verified
Change Detected
May 5, 2026 06:38 UTC
Analysis Methodology
✓ Verified
Source Document
https://www.onelogin.com/privacy
Citation Record
Entity: OneLogin
Document: OneLogin Privacy Policy
Record ID: CA-C-001969
Captured: 2026-05-05 06:38:26 UTC
URL: https://conductatlas.com/change/2026-05-05-onelogin-onelogin-privacy-policy-1969/
Accessed: May 20, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.

Impact Summary

1
Protection removed
Consumers Removed

The policy no longer explicitly states how OneLogin uses AI to analyze customer communications, removing transparency about an automated data processing practice.

For legal and compliance teams

Institutional Analysis

Assessment

OneLogin removed explicit disclosures of AI-driven data processing practices from its privacy policy, including analysis of call transcripts, chatbot interactions, and sales emails. This removal may create compliance risk under GDPR Article 13/14 (transparency obligations for data processing), CCPA requirements for clear disclosure of automated decision-making, and general FTC Act Section 5 standards requiring honest and non-deceptive privacy disclosures. Organizations that contract with OneLogin may need to evaluate whether vendor privacy disclosures in their own customer-facing notices remain accurate and complete. The removal of detail about AI processing does not necessarily mean the company has ceased these practices; rather, it means they are no longer disclosed in the policy. Clarification from OneLogin on whether these practices continue under unstated terms may be warranted.

Regulatory Exposure

GDPR (Articles 13, 14 — transparency and information obligations; Article 6 — lawfulness of processing; Recital 47 — automated decision-making); CCPA (Cal. Civ. Code § 1798.100 et seq. — disclosure of automated decision-making and profiling); FTC Act Section 5 (unfair or deceptive practices); state privacy laws (Virginia VCDPA, Colorado CPA, Connecticut CTDPA — transparency requirements)

Full compliance analysis

Obligation analysis, escalation trigger, board language, and recommended action.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations + obligations. Professional: full compliance memo.

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-001969.

Full Changes

See the full side-by-side comparison of every sentence added, removed, and modified.

🔒 Full diff — Watcher

Document Context

Version history → Policy drift analysis → Document page →
Document
OneLogin Privacy Policy
Entity
OneLogin
Captured
May 5, 2026
Source URL
https://www.onelogin.com/privacy
Other changes to OneLogin Privacy Policy
Next change May 6, 2026
OneLogin updated its privacy policy on May 6, 2026 to disclose new data collection and processing practices around recorded communications. …
Medium Neutral
View full version history →
More from OneLogin
May 6, 2026 Medium
OneLogin Privacy Policy

OneLogin updated its privacy policy on May 6, 2026 to disclose new data collection and processing practices around recorded communications. …

Track OneLogin policy changes

Get alerted when this policy changes again — including what changed and why it matters.

Prefer a weekly summary instead?

Get the biggest policy changes across 320+ platforms every Sunday.