Okta · Okta Privacy Policy · View original document ↗

Controller-Processor Bifurcation

High severity High confidence Explicitdocumentlanguage Unique · 0 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Okta Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

This privacy policy only covers data Okta collects on its own website and marketing activities. If you use Okta to log into your employer's systems, your employer's privacy policy governs that data, not this one.

This analysis describes what Okta's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Most people encounter Okta through workplace login, but this policy explicitly does not cover that context, meaning employees have no direct privacy rights against Okta for their authentication data under this document.

Consumer impact (what this means for users)

Workers who use Okta-powered single sign-on at work cannot rely on this policy to exercise data rights against Okta; they must look to their employer's privacy policy and the enterprise agreement between their employer and Okta. This limits the privacy recourse available directly from Okta for the most common use of its platform.

How other platforms handle this

Ledger Medium

At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.

Garmin Medium

If you are located in the European Economic Area, Switzerland, or the United Kingdom, you have the right to access, correct, or erase your personal data; the right to restrict or object to our processing of your personal data; the right to data portability; and, where our processing is based on your...

Strava Medium

We may display advertisements on our Services and those advertisements may be targeted to your interests based on your personal information. We may share your personal information with advertising partners for interest-based advertising purposes. You may opt out of interest-based advertising by visi...

See all platforms with this clause type →

Monitoring

Okta has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
This Privacy Policy applies to personal information that Okta collects and processes as a data controller ... It does not apply to personal information that Okta processes on behalf of our customers as a data processor or service provider. When Okta acts as a data processor or service provider, our customers are responsible for their own privacy practices, and their end users should refer to the relevant customer's privacy policy.

— Excerpt from Okta's Okta Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: This provision implicates GDPR Articles 4(7) and 4(8) (controller and processor definitions), Article 28 (processor obligations), and CCPA's parallel service provider framework. Under GDPR, the enterprise customer assumes controller obligations for end-user authentication data, and Okta's obligations flow through the Data Processing Addendum rather than this public policy. The relevant enforcement authority in the EU is the Irish Data Protection Commission (as Okta Ireland Limited is the designated EEA controller). Tension arises if a DPA is absent, incomplete, or does not cover all processing activities. GOVERNANCE EXPOSURE: High. The bifurcation places full controller liability on enterprise customers for data processed within Okta's identity platform. Organizations that have not executed a current DPA or whose DPA does not reflect the full scope of data categories and sub-processors in use face direct regulatory exposure under GDPR and CCPA. JURISDICTION FLAGS: EU/EEA organizations face heightened exposure given GDPR's explicit processor agreement requirements. California-based enterprises must ensure their service provider agreement with Okta includes the contractual restrictions required under CPRA to prevent Okta from using data for its own commercial purposes. Regulated industries (financial services, healthcare) may have additional obligations regarding third-party processor oversight. CONTRACT AND VENDOR IMPLICATIONS: This provision is a direct procurement trigger. Compliance teams should verify a current, signed DPA exists; that sub-processor lists are accessible and change notifications are contractually committed; and that the DPA's data categories accurately reflect the deployment. The policy's structure does not itself constitute a DPA, and reliance on this public policy alone would be insufficient for GDPR compliance. COMPLIANCE CONSIDERATIONS: Organizations should audit their Okta DPA against current GDPR Article 28 requirements, confirm SCCs are appended for cross-border transfers if applicable, and establish an internal process for receiving and responding to Okta's sub-processor change notifications. Legal teams should also determine whether their employees or customers have independent rights under their jurisdiction that require separate disclosure.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    FTC has jurisdiction over deceptive or unfair data practices; the accuracy of Okta's disclosure about the scope of this policy's coverage is a consumer protection matter
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Colorado AI Act
US-CO
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US
VPPA
United States Federal

Provision details

Document information
Document
Okta Privacy Policy
Entity
Okta
Document last updated
May 5, 2026
Tracking information
First tracked
May 10, 2026
Last verified
May 10, 2026
Record ID
CA-P-008601
Document ID
CA-D-00690
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
2c41898c161e33c56a4d696c23462f40793f348428c982d661e3c8a2a0ceec19
Analysis generated
May 10, 2026 08:45 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Okta
Document: Okta Privacy Policy
Record ID: CA-P-008601
Captured: 2026-05-10 08:45:28 UTC
SHA-256: 2c41898c161e33c5…
URL: https://conductatlas.com/platform/okta/okta-privacy-policy/controller-processor-bifurcation/
Accessed: June 27, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Okta's Controller-Processor Bifurcation clause do?

Most people encounter Okta through workplace login, but this policy explicitly does not cover that context, meaning employees have no direct privacy rights against Okta for their authentication data under this document.

How does this clause affect you?

Workers who use Okta-powered single sign-on at work cannot rely on this policy to exercise data rights against Okta; they must look to their employer's privacy policy and the enterprise agreement between their employer and Okta. This limits the privacy recourse available directly from Okta for the most common use of its platform.

Is ConductAtlas affiliated with Okta?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Okta.