OneLogin · OneLogin Terms of Service · View original document ↗

Limitation of Liability and Security Breach Disclaimer

High severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time OneLogin changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for OneLogin Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

This provision limits OneLogin's total financial liability to fees paid by the user in the preceding 12 months and excludes liability for indirect, consequential, or data-loss damages. It also expressly disclaims responsibility for losses resulting from hacking, unauthorized access, or tampering with the Service or user accounts.

This analysis describes what OneLogin's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This clause establishes a financial ceiling on OneLogin's contractual exposure that is directly tied to subscription fees paid, which may be substantially lower than the value of data or operational continuity at risk for organizations using OneLogin as identity infrastructure. The express exclusion of liability for hacking and unauthorized access is particularly material given the nature of the Service as an SSO and identity management platform.

Interpretive note: Enforceability of the liability cap and security breach disclaimer may vary by jurisdiction, particularly in the EU under GDPR processor obligations and in California under applicable consumer protection statutes.

Consumer impact (what this means for users)

Under this clause, the agreement limits any financial recovery against OneLogin to the amount paid in the 12 months preceding a claim, and specifically excludes recovery for losses resulting from unauthorized access to or breach of personal information and account content stored in the Service.

Cross-platform context

See how other platforms handle Limitation of Liability and Security Breach Disclaimer and similar clauses.

Compare across platforms →

Monitoring

OneLogin has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL ONELOGIN, ITS AFFILIATES, DIRECTORS, EMPLOYEES OR ITS LICENSORS BE LIABLE FOR (A) ANY INDIRECT, PUNITIVE, INCIDENTAL, SPECIAL, CONSEQUENTIAL OR EXEMPLARY DAMAGES, INCLUDING WITHOUT LIMITATION DAMAGES FOR LOSS OF PROFITS, GOODWILL, USE, DATA OR BUSINESS OR OTHER INTANGIBLE LOSSES, OR THE COST OF PROCUREMENT OF SUBSTITUTE GOODS, SERVICE OR TECHNOLOGY, (B) ANY MATTER BEYOND ITS REASONABLE CONTROL OR (C) ANY AMOUNTS THAT EXCEED THE FEES PAID BY YOU FOR THE SERVICE IN THE PRECEDING 12 MONTHS. WITHOUT LIMITING THE FOREGOING, UNDER NO CIRCUMSTANCES WILL ONELOGIN BE RESPONSIBLE FOR ANY DAMAGE, LOSS OR INJURY RESULTING FROM HACKING, TAMPERING OR OTHER UNAUTHORIZED ACCESS OR USE OF THE SERVICE OR YOUR ACCOUNT OR THE INFORMATION OR CONTENT CONTAINED THEREIN.

Excerpt from OneLogin's Terms of Service

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision may require evaluation under GDPR where OneLogin processes personal data on behalf of EU-based controllers, as processor liability frameworks under GDPR may constrain the extent to which contractual caps can insulate a data processor from liability for security failures. The FTC Act's unfair or deceptive practices framework is potentially relevant where security assurances interact with broad disclaimer language. California's consumer protection statutes may also apply to California-based business customers. (2) GOVERNANCE EXPOSURE: High. The combination of a fee-based liability cap and an express exclusion for hacking and unauthorized access creates material exposure for enterprise customers in regulated industries, particularly where identity platform breaches could trigger regulatory notification obligations, litigation, or customer harm exceeding 12 months of subscription fees. (3) JURISDICTION FLAGS: EU and EEA customers face heightened exposure because GDPR processor obligations may not be fully satisfied through a Terms of Service disclaimer alone. California-based organizations should assess whether California Civil Code provisions on limitation of liability apply. Organizations in financial services or healthcare face additional sector-specific concerns where data breach liability cannot be fully contractually disclaimed. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should evaluate whether this liability cap is acceptable relative to the organization's risk profile for an identity platform. The clause does not include carve-outs for gross negligence or willful misconduct, which are commonly negotiated in enterprise SaaS agreements. Vendor risk assessments should document this gap. (5) COMPLIANCE CONSIDERATIONS: Legal teams should assess whether a separate data processing agreement or data processing addendum is required to satisfy GDPR Article 28 obligations, as this Terms of Service does not contain processor-level commitments. Organizations should also review whether their cyber insurance policies address residual liability not recoverable under these contractual terms.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has jurisdiction over unfair or deceptive practices related to data security representations and disclaimer language in consumer and business service agreements.
    File a complaint →
  • State AG
    State attorneys general in California and other jurisdictions may have authority over liability disclaimer provisions in consumer and business service contracts under applicable state consumer protection laws.
    File a complaint →

Provision details

Document information
Document
OneLogin Terms of Service
Entity
OneLogin
Document last updated
May 5, 2026
Tracking information
First tracked
July 12, 2026
Last verified
July 12, 2026
Record ID
CA-P-074356
Document ID
CA-D-00693
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
7fec8f5039b9547d3ee03e85420719b8d7abdb572670a9cc49c418788ea277cf
Analysis generated
July 12, 2026 15:54 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: OneLogin
Document: OneLogin Terms of Service
Record ID: CA-P-074356
Captured: 2026-07-12 15:54:33 UTC
SHA-256: 7fec8f5039b9547d…
URL: https://conductatlas.com/platform/onelogin/onelogin-terms-of-service/provision/CA-P-074356/limitation-of-liability-and-security-breach-disclaimer/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does OneLogin's Limitation of Liability and Security Breach Disclaimer clause do?

This clause establishes a financial ceiling on OneLogin's contractual exposure that is directly tied to subscription fees paid, which may be substantially lower than the value of data or operational continuity at risk for organizations using OneLogin as identity infrastructure. The express exclusion of liability for hacking and unauthorized access is particularly material given the nature of the Service as …

How does this clause affect you?

Under this clause, the agreement limits any financial recovery against OneLogin to the amount paid in the 12 months preceding a claim, and specifically excludes recovery for losses resulting from unauthorized access to or breach of personal information and account content stored in the Service.

Is ConductAtlas affiliated with OneLogin?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OneLogin.