This provision identifies Duo Security as a subsidiary of Cisco Systems and asserts that Cisco's group-level privacy commitments extend to Duo's websites, products, and direct user interactions.
This analysis describes what Duo Security's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that the legal entity responsible for privacy governance over Duo's services is Cisco Systems rather than Duo Security as a standalone entity. This has implications for identifying the data controller, the applicable dispute resolution contact, and the governing privacy framework in enterprise vendor assessments.
Interpretive note: The specific legal entity serving as data controller for Duo-specific processing, and whether Duo Security operates as a separate controller or as a processor acting on behalf of enterprise customers, cannot be determined from this page alone.
Under this provision, users of Duo's products and websites operate under Cisco Systems' privacy framework rather than under a separate Duo-specific privacy regime. The applicable data controller identity, rights contact, and governing terms are those of the Cisco parent entity.
Cross-platform context
See how other platforms handle Subsidiary Privacy Governance Structure and similar clauses.
Compare across platforms →"Cisco Duo, as a subsidiary of Cisco Systems, is committed to protecting your privacy and providing you with a positive experience when directly interacting with us, engaging with our websites, and while using our products and services.Excerpt from Duo Security's Duo Privacy
(1) REGULATORY LANDSCAPE: Under GDPR, identifying the correct data controller is a foundational compliance requirement; this provision directs that identification toward Cisco Systems rather than Duo Security as a distinct entity.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes that the legal entity responsible for privacy governance over Duo's services is Cisco Systems rather than Duo Security as a standalone entity. This has implications for identifying the data controller, the applicable dispute resolution contact, and the governing privacy framework in enterprise vendor assessments.
Under this provision, users of Duo's products and websites operate under Cisco Systems' privacy framework rather than under a separate Duo-specific privacy regime. The applicable data controller identity, rights contact, and governing terms are those of the Cisco parent entity.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Duo Security.