Duo Security · Duo Privacy · View original document ↗

Personal Data Collection Scope

Medium severity Medium confidence Explicitdocumentlanguage Uncommon · 10 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Duo Security Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Cisco collects a wide range of personal information about you including your name, contact details, device identifiers, IP address, and detailed logs of every time you authenticate through Duo including what device you used and what application you accessed.

This analysis describes what Duo Security's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Authentication logs are sensitive because they reveal patterns of behavior, work hours, device usage, and application access, and this data is collected automatically every time you log in using Duo.

Interpretive note: The exact retention period for authentication log data is not specified in the public privacy statement and may depend on the applicable DPA for enterprise deployments.

Consumer impact (what this means for users)

Every Duo authentication event you complete generates a log entry containing your device type, operating system, IP address, and the application you accessed, and this data is held by Cisco under the terms of this policy.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Navigate to Cisco's Privacy Request portal and submit a request to access or delete your personal data including authentication logs.

How other platforms handle this

Ledger Medium

At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.

Discord Medium

We collect the following information when you register for and use our services: Account information. You can create a Discord account by providing an email address and creating a username and password. When you create an account, we will assign you a unique identifier. If you choose to, you may pro...

Egnyte Medium

We collect information you provide directly to us, such as when you create an account, contact us for support, sign up for marketing emails, or otherwise communicate with us. The types of information we may collect include your name, email address, postal address, phone number, company name, job tit...

See all platforms with this clause type →

Monitoring

Duo Security has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We collect personal data about you in the following circumstances: (a) you directly provide it to us, (b) we collect it automatically when you use our websites or products, (c) we obtain it from third parties, or (d) we create it ourselves. The types of personal data we collect include: identifiers (such as name, email address, phone number, postal address, IP address, device identifiers); authentication and usage data (such as login events, authentication method, device type, operating system, and application accessed); geolocation data; and professional information.

— Excerpt from Duo Security's Duo Privacy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: The breadth of data collected, particularly authentication event logs and device identifiers, engages GDPR Article 5 data minimization and purpose limitation principles for EEA users. The FTC Act is relevant to the adequacy and accuracy of disclosures to US consumers about automatic data collection. CCPA/CPRA requires that California residents be informed of the categories of personal information collected at or before the point of collection. GOVERNANCE EXPOSURE: Medium. The collection of authentication logs including device identifiers and application access patterns is operationally expected for an MFA provider but may raise employee privacy concerns in jurisdictions with strong workplace privacy laws such as Germany, France, and the Netherlands. Organizations deploying Duo for employee authentication should assess whether this collection is disclosed in their own employee privacy notices. JURISDICTION FLAGS: EU and EEA users have rights under GDPR to receive specific information about automated data collection at the time of collection. German Works Council co-determination rights may apply to the deployment of Duo for employee monitoring purposes. California residents have CPRA rights to know the specific categories of personal information collected. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers should verify that their Data Processing Agreement with Cisco accurately reflects the full scope of authentication log collection described in this provision. Procurement teams should confirm that data retention periods for authentication logs are defined in the DPA and align with organizational retention policies. COMPLIANCE CONSIDERATIONS: Organizations should update internal employee privacy notices to reflect that Duo authentication generates event logs processed by Cisco. Data mapping exercises should include authentication log data flows. Legal teams should confirm whether authentication logs containing IP addresses and device identifiers constitute personal data under applicable law in all deployment jurisdictions.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has jurisdiction over unfair or deceptive data collection practices affecting US consumers under the FTC Act.
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
DMA
European Union
ePrivacy Directive
European Union
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Duo Privacy
Entity
Duo Security
Document last updated
May 5, 2026
Tracking information
First tracked
May 7, 2026
Last verified
May 9, 2026
Record ID
CA-P-007436
Document ID
CA-D-00696
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
76697f41b9802295d06a87d1528973ffe114cdf77c5e038c903ecb798ac000bc
Analysis generated
May 7, 2026 07:36 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Duo Security
Document: Duo Privacy
Record ID: CA-P-007436
Captured: 2026-05-07 07:36:01 UTC
SHA-256: 76697f41b9802295…
URL: https://conductatlas.com/platform/duo-security/duo-privacy/personal-data-collection-scope/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Duo Security's Personal Data Collection Scope clause do?

Authentication logs are sensitive because they reveal patterns of behavior, work hours, device usage, and application access, and this data is collected automatically every time you log in using Duo.

How does this clause affect you?

Every Duo authentication event you complete generates a log entry containing your device type, operating system, IP address, and the application you accessed, and this data is held by Cisco under the terms of this policy.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 10 platforms. See the full comparison.

Is ConductAtlas affiliated with Duo Security?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Duo Security.