Okta's services are not intended for anyone under 16, and Okta states it will delete personal data collected from under-16s if discovered, though it does not describe active age verification mechanisms.
This analysis describes what Auth0's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The policy sets a minimum age of 16 rather than the COPPA threshold of 13 for US users, aligning more closely with GDPR Article 8 standards, but does not describe how under-16 users are actively identified or prevented from accessing services.
Establishes clear COPPA-compliant policy regarding children's data collection and removal procedures for accidental collection.
View full change record →Individuals under 16 are not permitted to use Okta's services and their data should not be collected; parents who discover their child has created an account or provided data to Okta should contact privacy@okta.com to request deletion.
How other platforms handle this
When you use them, we'll validate your request by verifying your identity (for example, by confirming that you're signed in to your Google Account).
Not be Discriminated Against by us for exercising your privacy rights.
If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.
"Our websites and services are not directed to children under the age of 16, and we do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without verification of parental consent, we will take steps to remove that information from our servers.Excerpt from Auth0's Privacy Policy
REGULATORY LANDSCAPE: In the US, the Children's Online Privacy Protection Act (COPPA) prohibits collection of personal information from children under 13 without verifiable parental consent, enforced by the FTC.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The policy sets a minimum age of 16 rather than the COPPA threshold of 13 for US users, aligning more closely with GDPR Article 8 standards, but does not describe how under-16 users are actively identified or prevented from accessing services.
Individuals under 16 are not permitted to use Okta's services and their data should not be collected; parents who discover their child has created an account or provided data to Okta should contact privacy@okta.com to request deletion.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Auth0.