The policy states that Personal Data may be stored and processed in the United States or other countries where affiliates or Business Partners operate, and that transfers outside the EU/EEA are protected by Standard Contractual Clauses and the EU-U.S. Data Privacy Framework.
This analysis describes what OneLogin's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the transfer mechanisms Quest asserts for cross-border Personal Data flows, including the EU-U.S. DPF, UK Extension, Swiss-U.S. DPF, and EU SCCs. DPF certification is subject to ongoing U.S. Department of Commerce and European Commission oversight, and the continued validity of these mechanisms depends on factors outside Quest's direct control.
Under these terms, Personal Data of EU, UK, and Swiss users may be transferred to the United States and processed there under the EU-U.S. Data Privacy Framework and Standard Contractual Clauses. The policy states Quest has certified to the U.S. Department of Commerce under all three DPF components.
Cross-platform context
See how other platforms handle Cross-Border Data Transfer Mechanisms and similar clauses.
Compare across platforms →"Personal Data we collect may be stored and processed in the United States or any other country in which the entities represented by our affiliates, subsidiary companies or Business Partners maintain facilities. We provide appropriate levels of protection to safeguard your Personal Data including providing adequate protection for any transfer of Personal Data to a country outside the EU/EEA. These safeguards include data protection agreements, incorporating the new EU standard contractual clauses, and the Data Privacy Framework.Excerpt from OneLogin's Privacy Policy
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes the transfer mechanisms Quest asserts for cross-border Personal Data flows, including the EU-U.S. DPF, UK Extension, Swiss-U.S. DPF, and EU SCCs. DPF certification is subject to ongoing U.S. Department of Commerce and European Commission oversight, and the continued validity of these mechanisms depends on factors outside Quest's direct control.
Under these terms, Personal Data of EU, UK, and Swiss users may be transferred to the United States and processed there under the EU-U.S. Data Privacy Framework and Standard Contractual Clauses. The policy states Quest has certified to the U.S. Department of Commerce under all three DPF components.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OneLogin.