California residents have the right to see, delete, correct, and opt out of sharing of their personal data, and can exercise these rights by contacting Okta at privacy@okta.com.
This analysis describes what Auth0's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
CPRA significantly expanded California privacy rights including the right to correct inaccurate data and limit use of sensitive personal information, and Okta's acknowledgment of these rights means California residents have concrete, enforceable options beyond what users in other US states may have.
California residents can request access to, deletion of, or correction of their personal data held by Okta, and can opt out of Okta sharing their data for behavioral advertising, with Okta prohibited from discriminating against users who exercise these rights.
How other platforms handle this
If you are a California resident, you may have certain rights under the California Consumer Privacy Act (CCPA). These rights may include: the right to know about personal information collected, disclosed, or sold; the right to delete personal information collected from you; the right to opt-out of t...
California law gives residents the right to know what personal information we collect, use, share or sell; to delete personal information under certain circumstances; to opt-out of the sale or sharing of their personal information; to correct inaccurate personal information; to limit the use and dis...
If you are a California resident, you have the right to know what personal information we collect, use, disclose, and sell about you. You have the right to request deletion of your personal information, subject to certain exceptions. You have the right to opt out of the sale or sharing of your perso...
Monitoring
Auth0 has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.
"If you are a California resident, you have the right to: know what personal information we collect about you and how it is used and shared; delete personal information we collected from you (with certain exceptions); correct inaccurate personal information; opt-out of the sale or sharing of your personal information; limit the use and disclosure of sensitive personal information; and not be discriminated against for exercising these rights. To exercise these rights, you may submit a verifiable consumer request to us at privacy@okta.com.— Excerpt from Auth0's Auth0 Privacy Policy
REGULATORY LANDSCAPE: This provision implicates the California Consumer Privacy Act as amended by the California Privacy Rights Act (CPRA), enforced by the California Privacy Protection Agency (CPPA) and the California Attorney General. Key CPRA rights include access, deletion, correction, opt-out of sale and sharing, and sensitive personal information limitations. The CPRA also requires that businesses honor Global Privacy Control opt-out signals. The FTC Act may also apply to material misrepresentations about privacy rights. GOVERNANCE EXPOSURE: Medium. The accuracy and operational completeness of Okta's rights fulfillment process is a key compliance requirement. Response timelines under CPRA require acknowledgment within 10 business days and substantive response within 45 days (extendable by 45 days). Verification mechanisms for consumer requests must be proportionate and not unduly burdensome. Organizations deploying Okta or Auth0 to authenticate California-resident end users should assess whether those users' rights flow through Okta's own policy or through the enterprise customer's obligations. JURISDICTION FLAGS: Applies to California residents. Organizations with California employees or customers who use Okta or Auth0 should assess whether their own CPRA obligations are affected by Okta's role as a service provider. Other US states with comprehensive privacy laws (Virginia, Colorado, Texas, and others) may create analogous obligations not fully addressed in this section. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers should confirm that Okta's role as a service provider under CPRA is formalized in their contract, limiting Okta's ability to use California resident data for purposes beyond the contracted service. Service provider agreements should restrict Okta from using California resident personal data for its own advertising or analytics purposes without appropriate disclosure. COMPLIANCE CONSIDERATIONS: Legal teams should test Okta's privacy request submission process to confirm response timelines and verification steps meet CPRA requirements. Confirm whether Okta honors Global Privacy Control signals on its website properties. Assess whether sensitive personal information categories collected through Okta or Auth0 deployments are covered by the limitation rights described.
Full compliance analysis
Regulatory citations, enforcement risk, and due diligence action items.
Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.
Professional Governance Intelligence
Need to monitor specific governance provisions?
Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
CPRA significantly expanded California privacy rights including the right to correct inaccurate data and limit use of sensitive personal information, and Okta's acknowledgment of these rights means California residents have concrete, enforceable options beyond what users in other US states may have.
California residents can request access to, deletion of, or correction of their personal data held by Okta, and can opt out of Okta sharing their data for behavioral advertising, with Okta prohibited from discriminating against users who exercise these rights.
ConductAtlas has identified this type of provision across 11 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Auth0.