If you use Okta because your employer set it up, your company — not Okta — is responsible for your personal data rights. You must contact your employer, not Okta, to ask about your data.
This analysis describes what Okta's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This distinction allocates responsibility for data handling between Okta and its organizational customers under data protection frameworks. By designating customers as controllers, the provision clarifies that primary obligations for personal information management rest with the organizations that deploy Okta's services, while Okta's role is defined as a processor acting pursuant to those organizations' instructions.
The provision now explicitly limits the scope of the policy to Okta's controller role only and directs processor customers' end users to customer privacy policies rather than Okta's own, representing a significant structural clarification and shift in responsibility.
View full change record →This clause means that if your company uses Okta for logins, your authentication data — including when, where, and how frequently you log in — is controlled by your employer, and Okta will redirect any privacy requests back to them rather than acting on them directly.
How other platforms handle this
In certain instances, our clients hire ZipRecruiter to provide services on behalf of the client. In such case, we process Personal Data under the direction of that client (the data controller) and have no direct relationship with the individuals...
We do not use what you say in email, chat, video calls or voice mail, or your documents, photos or other personal files, to target advertising to you.
We use your personal information to send you newsletters and other promotional communications, including information about MyFitnessPal's new offerings, features, offers, events, webinars, and other information.
"When Okta provides its products and services to its customers (organizations and their designated administrators), Okta acts as a data processor or service provider on behalf of those customers. In that context, those customers are the data controllers or businesses and are responsible for the personal information they choose to submit to Okta's products and services. If you are an individual whose employer or another organization controls your access to Okta products and services, please direct your privacy questions to that organization.Excerpt from Okta's Privacy Policy
(1) REGULATORY FRAMEWORK: This provision implicates GDPR Arts.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
We read the privacy policies and terms of service of 38 AI platforms. Here is what they say about training, retention, arbitration, and liability.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This distinction allocates responsibility for data handling between Okta and its organizational customers under data protection frameworks. By designating customers as controllers, the provision clarifies that primary obligations for personal information management rest with the organizations that deploy Okta's services, while Okta's role is defined as a processor acting pursuant to those organizations' instructions.
This clause means that if your company uses Okta for logins, your authentication data — including when, where, and how frequently you log in — is controlled by your employer, and Okta will redirect any privacy requests back to them rather than acting on them directly.
ConductAtlas has identified this type of provision across 278 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Okta.