8 Total
0 High severity
5 Medium severity
3 Low severity
Summary

This is One Identity's privacy policy, which explains how the company collects and uses personal information from people who visit their website or use their identity and access management products. The most important thing to know is that One Identity shares your personal data, including contact details, usage behavior, and device information, with affiliates, business partners, and third-party vendors for purposes that include marketing and analytics, not just service delivery. If you are a California resident or an EU/EEA user, the policy describes specific rights you can exercise, including requesting deletion or correction of your data, by contacting privacy@oneidentity.com.

Technical / Legal Breakdown

This document is One Identity's (formerly OneLogin's) privacy policy governing the collection, use, storage, and sharing of personal information from customers, website visitors, and users of One Identity products and services, with GDPR and various international frameworks cited as its legal basis. The policy states that One Identity collects personal data including contact information, usage data, device identifiers, and in some cases sensitive categories, and the terms authorize sharing this data with subsidiaries, affiliates, business partners, and third-party service providers for purposes including marketing, analytics, product improvement, and legal compliance. The policy includes a broad retention clause permitting data to be held 'as long as necessary' for business or legal purposes without specifying fixed retention periods, and asserts data transfers from the EU/EEA to the US and other jurisdictions under mechanisms such as Standard Contractual Clauses; the breadth of these assertions may be subject to evaluation under applicable data protection law. The policy engages GDPR (as a primary framework for EU/EEA users), CCPA/CPRA (for California residents), and references compliance with various country-specific laws; One Identity's dual role as both a data controller for website visitors and a data processor for enterprise customers creates distinct compliance obligations that the document partially addresses but does not fully delineate in all operational contexts.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial

1 important change detected

2 versions captured · Last updated: May 2026

May 6, 2026

medium
What changed OneLogin updated its privacy policy on May 6, 2026 to disclose new data collection and processing practices around recorded communications. The policy now states that calls may be recorded with consent to optimize interactions and improve processes, and that OneLogin uses AI to analyze call transcripts, chat conversations, and sales emails to extract follow-up tasks, summarize interactions, perform sales analytics, and forecast next steps. The updated language also clarifies that recorded call data will be saved and used in future interactions, and it specifies new communication channels (email, text, telephone, chat) as points where personal data collection occurs.
Why this matters The updated policy discloses that OneLogin may record calls with consent and use AI to analyze call transcripts, chat conversations, and sales emails for multiple purposes including follow-up task identification, call summarization, sales analytics, communication effectiveness analysis, and forecast modeling. Under the revised terms, recorded call audio and video may be reviewed for employee training, monitoring, and coaching purposes. The policy also states that OneLogin will save chat and call conversation data to inform future interactions. These practices apply when you communicate with OneLogin via phone calls, chat, email, text, or other teleconference solutions. You should review the updated disclosure to understand how your communication data will be processed and retained.
View full change record →
Medium — 5 provisions
Low — 3 provisions

Monitoring

OneLogin has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle California Resident Rights (CCPA/CPRA) and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
DMA
European Union
View official text ↗
ePrivacy Directive
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 6, 2026 09:59 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000694
Version ID CA-V-002273
SHA-256 632189e2a9ad8217101dfa942396127b2a6421e5aa908b71324036c3925e9a3a
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans