If you live in the EU, UK, or California, you have legal rights to see, fix, delete, or get a copy of your personal data that Okta holds, and Okta cannot penalize you for exercising these rights.
This analysis describes what Auth0's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The clause operationalizes Auth0's compliance obligations under privacy regulations (GDPR, CCPA) by establishing a formal mechanism for data subject requests. The provision conditions the availability of these rights on user location, meaning the substantive rights triggered depend on applicable jurisdictional law rather than Auth0's discretionary grant.
Replaced by separate, jurisdiction-specific provisions for California (CCPA/CPRA) and EU/UK/Swiss rights, allowing for more tailored regulatory compliance disclosures.
View full change record →EU/UK residents can invoke GDPR rights including erasure (Art. 17) and portability (Art. 20), while California residents can request deletion of personal information and opt out of data sharing under CPRA — these are enforceable legal rights, not merely policy commitments.
How other platforms handle this
Further, you may take legal actions in relation to any potential breach of your rights regarding the processing of your Personal Information, as well as to lodge complaints before the competent data prot...
Where ZipRecruiter processes your Personal Data in the capacity of a service provider (data processor), and you seek access, or want to correct, amend, or delete your Personal Data...we will provide you with the data controller's contact information, so you can contact them directly.
to request that your data be transferred to a third party (data portability)
"Depending on your location, you may have the right to access, correct, delete, or receive a copy of your personal data, the right to restrict or object to certain processing, the right to opt out of the sale or sharing of your personal information, and the right to non-discrimination for exercising your privacy rights. To exercise these rights, please submit a request through our privacy request form.Excerpt from Auth0's Privacy Policy
(1) REGULATORY FRAMEWORK: This provision directly implements GDPR Arts.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The clause operationalizes Auth0's compliance obligations under privacy regulations (GDPR, CCPA) by establishing a formal mechanism for data subject requests. The provision conditions the availability of these rights on user location, meaning the substantive rights triggered depend on applicable jurisdictional law rather than Auth0's discretionary grant.
EU/UK residents can invoke GDPR rights including erasure (Art. 17) and portability (Art. 20), while California residents can request deletion of personal information and opt out of data sharing under CPRA — these are enforceable legal rights, not merely policy commitments.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Auth0.