Provision record
Duo Security · Duo Privacy · View original document ↗

Subsidiary Privacy Governance Structure

Low severity Medium confidence Explicit document language Unique · 0 of 352 platforms
Stay ahead of the changes
Track Duo Security and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

This provision identifies Duo Security as a subsidiary of Cisco Systems and asserts that Cisco's group-level privacy commitments extend to Duo's websites, products, and direct user interactions.

This analysis describes what Duo Security's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that the legal entity responsible for privacy governance over Duo's services is Cisco Systems rather than Duo Security as a standalone entity. This has implications for identifying the data controller, the applicable dispute resolution contact, and the governing privacy framework in enterprise vendor assessments.

Interpretive note: The specific legal entity serving as data controller for Duo-specific processing, and whether Duo Security operates as a separate controller or as a processor acting on behalf of enterprise customers, cannot be determined from this page alone.

Clause Stability Stable

0
Changes
3
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this provision, users of Duo's products and websites operate under Cisco Systems' privacy framework rather than under a separate Duo-specific privacy regime. The applicable data controller identity, rights contact, and governing terms are those of the Cisco parent entity.

Cross-platform context

See how other platforms handle Subsidiary Privacy Governance Structure and similar clauses.

Compare across platforms →
▸ View Original Clause Language DOCUMENT RECORD
"
Cisco Duo, as a subsidiary of Cisco Systems, is committed to protecting your privacy and providing you with a positive experience when directly interacting with us, engaging with our websites, and while using our products and services.

Excerpt from Duo Security's Duo Privacy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: Under GDPR, identifying the correct data controller is a foundational compliance requirement; this provision directs that identification toward Cisco Systems rather than Duo Security as a distinct entity.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →

Provision details

Document information
Document
Duo Privacy
Entity
Duo Security
Document last updated
May 5, 2026
Tracking information
First tracked
May 7, 2026
Last verified
July 9, 2026
Record ID
CA-P-016362
Document ID
CA-D-00696
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
d9afe9414eec7f10260f8f51aa0af6749bf99c73c9dde080aa8f0cda89f6e6f3
Analysis generated
May 7, 2026 07:36 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Duo Security
Document: Duo Privacy
Record ID: CA-P-016362
Captured: 2026-05-07 07:36:01 UTC
SHA-256: d9afe9414eec7f10…
URL: https://conductatlas.com/platform/duo-security/duo-privacy/provision/CA-P-016362/subsidiary-privacy-governance-structure/
Accessed: Aug. 11, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Duo Security's Subsidiary Privacy Governance Structure clause do?

This provision establishes that the legal entity responsible for privacy governance over Duo's services is Cisco Systems rather than Duo Security as a standalone entity. This has implications for identifying the data controller, the applicable dispute resolution contact, and the governing privacy framework in enterprise vendor assessments.

How does this clause affect you?

Under this provision, users of Duo's products and websites operate under Cisco Systems' privacy framework rather than under a separate Duo-specific privacy regime. The applicable data controller identity, rights contact, and governing terms are those of the Cisco parent entity.

Is ConductAtlas affiliated with Duo Security?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Duo Security.