Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This privacy policy governs Okta's collection and use of personal information from individuals who visit Okta's website, register for trials, attend events, or use Okta's identity and access management services. The policy establishes that Okta collects name, email, company information, device identifiers, and behavioral data, and authorizes sharing this information with advertising partners and third-party service providers. Individuals in California, the EU, and the UK may submit requests to access, delete, or opt out of certain data processing activities by contacting privacy@okta.com.
This document is Okta's Privacy Policy governing the collection, use, sharing, and retention of personal data by Okta, Inc. and its subsidiaries including Auth0, across Okta's websites, marketing activities, and customer-facing identity platforms; the stated legal bases for processing include contractual necessity, legitimate interests, consent, and compliance with legal obligations. The policy states that Okta collects personal data including identifiers, usage data, device and log data, and professional information, and the terms authorize sharing this data with service providers, business partners, advertising networks, and in connection with corporate transactions such as mergers or acquisitions. Notably, the policy covers both Okta's own website visitor data and its role as a data processor for enterprise customers deploying Okta or Auth0 products, creating a layered data relationship where end users of enterprise deployments are governed by their employer's or developer's privacy terms rather than this policy directly; the practical scope of Okta's data controller role versus processor role may require independent evaluation depending on the specific product context. The policy engages GDPR and UK GDPR for EU and UK residents, CCPA and CPRA for California residents, and other applicable global privacy frameworks; material compliance considerations include the adequacy of disclosed cross-border data transfer mechanisms, the granularity of consent for marketing and analytics cookies, and the clarity of data subject rights procedures for individuals accessing Okta or Auth0 services through enterprise deployments.
The policy permits Okta to collect personal identifiers, usage patterns, device data, and professional information from website visitors, trial registrants, and customers, and to share this information with advertising networks, analytics providers, and business partners. For individuals whose access to services occurs through an enterprise Auth0 or Okta deployment, Okta's policy may not be the governing instrument; instead, the terms established by the employing organization or application developer apply. Individuals subject to this policy may exercise data access, deletion, or processing opt-out rights through privacy@okta.com or the privacy rights form specified in the policy.
Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.
2 important changes detected
5 versions captured · Last updated: June 2026
Auth0 has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.
Cross-platform context
See how other platforms handle Product Data Carve-Out and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.