9 Total
0 High severity
6 Medium severity
3 Low severity
Summary

This is Cisco's privacy policy covering Duo Security products and websites, explaining what personal data Cisco collects about you when you use Duo's authentication services, visit its website, or contact its sales and support teams. Most importantly, Cisco may use your authentication logs, device identifiers, and usage data to improve its products and train internal systems, and may share that data with its global network of affiliates and service providers. If you are in the EU or California, you have specific rights to access, correct, or delete your personal data, and you can exercise those rights through Cisco's Privacy Request portal.

Technical / Legal Breakdown

This document is the Cisco Online Privacy Statement governing Cisco's collection, use, and sharing of personal data across Cisco and Duo Security websites, products, and services, with legal bases including consent, legitimate interests, contractual necessity, and legal obligation depending on jurisdiction. The statement asserts that Cisco collects a broad range of personal data including identifiers, authentication logs, device information, usage data, and geolocation, and the terms authorize sharing this data with Cisco affiliates, business partners, service providers, and in connection with corporate transactions such as mergers or acquisitions. The statement reserves the right to use personal data for product improvement, security research, and AI/ML model development, which extends beyond transactional service delivery and may warrant scrutiny under data minimization principles applicable in certain jurisdictions. The policy engages GDPR and EU adequacy frameworks for EEA residents, CCPA and CPRA for California residents, and references compliance with sector-specific frameworks relevant to Duo's authentication and identity management context; applicability of specific protections depends on user location and applicable law. Organizations deploying Duo as a B2B security product should note that employee authentication data processed through Duo may be governed by separate data processing agreements rather than this consumer-facing statement, creating a dual-layer governance structure that compliance teams should map carefully.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial
Medium — 6 provisions
Low — 3 provisions

Monitoring

Duo Security has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Controller vs. Processor Distinction for Enterprise Users and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
DMA
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 5, 2026 06:38 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000696
Version ID CA-V-001332
SHA-256 d9afe9414eec7f10260f8f51aa0af6749bf99c73c9dde080aa8f0cda89f6e6f3
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans