Provision record
OneLogin · OneLogin Privacy Policy · View original document ↗

Cross-Border Data Transfer Mechanisms

Medium severity High confidence Explicit document language Unique · 0 of 352 platforms
Stay ahead of the changes
Track OneLogin and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

The policy states that Personal Data may be stored and processed in the United States or other countries where affiliates or Business Partners operate, and that transfers outside the EU/EEA are protected by Standard Contractual Clauses and the EU-U.S. Data Privacy Framework.

This analysis describes what OneLogin's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes the transfer mechanisms Quest asserts for cross-border Personal Data flows, including the EU-U.S. DPF, UK Extension, Swiss-U.S. DPF, and EU SCCs. DPF certification is subject to ongoing U.S. Department of Commerce and European Commission oversight, and the continued validity of these mechanisms depends on factors outside Quest's direct control.

Recent Activity

This document changed recently

Medium May 6, 2026

The updated policy discloses that OneLogin may record calls with consent and use AI to analyze call transcripts, chat conversations, and sales emails for multiple purposes including follow-up task identification, call summarization, sales analytics, communication effectiveness analysis, and forecast modeling. Under the revised terms, recorded call audio and video may be reviewed for employee training, monitoring, and coaching purposes. The policy also states that OneLogin will save chat and call conversation data to inform future interactions. These practices apply when you communicate with OneLogin via phone calls, chat, email, text, or other teleconference solutions. You should review the updated disclosure to understand how your communication data will be processed and retained.

View change record →
High May 5, 2026

The updated policy removes explicit language describing how OneLogin uses AI to analyze customer communications. Previously, the policy stated that call audio and video would be recorded with consent and analyzed using AI to identify follow-up tasks, summarize calls, and conduct sales analytics; that chatbot conversations would be analyzed and saved; and that sales emails would be analyzed to determine communication efficacy and forecast next steps. These specific AI analysis practices are no longer described in the updated policy. The revised language also narrows one stated data use purpose, changing 'answers or services you have asked or licensed' to 'services you have purchased.' No consumer opt-out mechanisms or alternative disclosures are provided in the change text.

View change record →

Clause Stability Stable

0
Changes
3
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under these terms, Personal Data of EU, UK, and Swiss users may be transferred to the United States and processed there under the EU-U.S. Data Privacy Framework and Standard Contractual Clauses. The policy states Quest has certified to the U.S. Department of Commerce under all three DPF components.

Cross-platform context

See how other platforms handle Cross-Border Data Transfer Mechanisms and similar clauses.

Compare across platforms →
▸ View Original Clause Language DOCUMENT RECORD
"
Personal Data we collect may be stored and processed in the United States or any other country in which the entities represented by our affiliates, subsidiary companies or Business Partners maintain facilities. We provide appropriate levels of protection to safeguard your Personal Data including providing adequate protection for any transfer of Personal Data to a country outside the EU/EEA. These safeguards include data protection agreements, incorporating the new EU standard contractual clauses, and the Data Privacy Framework.

Excerpt from OneLogin's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →

Provision details

Document information
Document
OneLogin Privacy Policy
Entity
OneLogin
Document last updated
May 5, 2026
Tracking information
First tracked
May 10, 2026
Last verified
July 9, 2026
Record ID
CA-P-016305
Document ID
CA-D-00694
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
632189e2a9ad8217101dfa942396127b2a6421e5aa908b71324036c3925e9a3a
Analysis generated
May 10, 2026 01:37 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: OneLogin
Document: OneLogin Privacy Policy
Record ID: CA-P-016305
Captured: 2026-05-10 01:37:12 UTC
SHA-256: 632189e2a9ad8217…
URL: https://conductatlas.com/platform/onelogin/onelogin-privacy-policy/provision/CA-P-016305/cross-border-data-transfer-mechanisms/
Accessed: Aug. 11, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does OneLogin's Cross-Border Data Transfer Mechanisms clause do?

This provision establishes the transfer mechanisms Quest asserts for cross-border Personal Data flows, including the EU-U.S. DPF, UK Extension, Swiss-U.S. DPF, and EU SCCs. DPF certification is subject to ongoing U.S. Department of Commerce and European Commission oversight, and the continued validity of these mechanisms depends on factors outside Quest's direct control.

How does this clause affect you?

Under these terms, Personal Data of EU, UK, and Swiss users may be transferred to the United States and processed there under the EU-U.S. Data Privacy Framework and Standard Contractual Clauses. The policy states Quest has certified to the U.S. Department of Commerce under all three DPF components.

Is ConductAtlas affiliated with OneLogin?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OneLogin.