Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
This provision limits OneLogin's total financial liability to fees paid by the user in the preceding 12 months and excludes liability for indirect, consequential, or data-loss damages. It also expressly disclaims responsibility for losses resulting from hacking, unauthorized access, or tampering with the Service or user accounts.
This analysis describes what OneLogin's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This clause establishes a financial ceiling on OneLogin's contractual exposure that is directly tied to subscription fees paid, which may be substantially lower than the value of data or operational continuity at risk for organizations using OneLogin as identity infrastructure. The express exclusion of liability for hacking and unauthorized access is particularly material given the nature of the Service as an SSO and identity management platform.
Interpretive note: Enforceability of the liability cap and security breach disclaimer may vary by jurisdiction, particularly in the EU under GDPR processor obligations and in California under applicable consumer protection statutes.
Under this clause, the agreement limits any financial recovery against OneLogin to the amount paid in the 12 months preceding a claim, and specifically excludes recovery for losses resulting from unauthorized access to or breach of personal information and account content stored in the Service.
Cross-platform context
See how other platforms handle Limitation of Liability and Security Breach Disclaimer and similar clauses.
Compare across platforms →Monitoring
OneLogin has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL ONELOGIN, ITS AFFILIATES, DIRECTORS, EMPLOYEES OR ITS LICENSORS BE LIABLE FOR (A) ANY INDIRECT, PUNITIVE, INCIDENTAL, SPECIAL, CONSEQUENTIAL OR EXEMPLARY DAMAGES, INCLUDING WITHOUT LIMITATION DAMAGES FOR LOSS OF PROFITS, GOODWILL, USE, DATA OR BUSINESS OR OTHER INTANGIBLE LOSSES, OR THE COST OF PROCUREMENT OF SUBSTITUTE GOODS, SERVICE OR TECHNOLOGY, (B) ANY MATTER BEYOND ITS REASONABLE CONTROL OR (C) ANY AMOUNTS THAT EXCEED THE FEES PAID BY YOU FOR THE SERVICE IN THE PRECEDING 12 MONTHS. WITHOUT LIMITING THE FOREGOING, UNDER NO CIRCUMSTANCES WILL ONELOGIN BE RESPONSIBLE FOR ANY DAMAGE, LOSS OR INJURY RESULTING FROM HACKING, TAMPERING OR OTHER UNAUTHORIZED ACCESS OR USE OF THE SERVICE OR YOUR ACCOUNT OR THE INFORMATION OR CONTENT CONTAINED THEREIN.Excerpt from OneLogin's Terms of Service
(1) REGULATORY LANDSCAPE: This provision may require evaluation under GDPR where OneLogin processes personal data on behalf of EU-based controllers, as processor liability frameworks under GDPR may constrain the extent to which contractual caps can insulate a data processor from liability for security failures. The FTC Act's unfair or deceptive practices framework is potentially relevant where security assurances interact with broad disclaimer language. California's consumer protection statutes may also apply to California-based business customers. (2) GOVERNANCE EXPOSURE: High. The combination of a fee-based liability cap and an express exclusion for hacking and unauthorized access creates material exposure for enterprise customers in regulated industries, particularly where identity platform breaches could trigger regulatory notification obligations, litigation, or customer harm exceeding 12 months of subscription fees. (3) JURISDICTION FLAGS: EU and EEA customers face heightened exposure because GDPR processor obligations may not be fully satisfied through a Terms of Service disclaimer alone. California-based organizations should assess whether California Civil Code provisions on limitation of liability apply. Organizations in financial services or healthcare face additional sector-specific concerns where data breach liability cannot be fully contractually disclaimed. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should evaluate whether this liability cap is acceptable relative to the organization's risk profile for an identity platform. The clause does not include carve-outs for gross negligence or willful misconduct, which are commonly negotiated in enterprise SaaS agreements. Vendor risk assessments should document this gap. (5) COMPLIANCE CONSIDERATIONS: Legal teams should assess whether a separate data processing agreement or data processing addendum is required to satisfy GDPR Article 28 obligations, as this Terms of Service does not contain processor-level commitments. Organizations should also review whether their cyber insurance policies address residual liability not recoverable under these contractual terms.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This clause establishes a financial ceiling on OneLogin's contractual exposure that is directly tied to subscription fees paid, which may be substantially lower than the value of data or operational continuity at risk for organizations using OneLogin as identity infrastructure. The express exclusion of liability for hacking and unauthorized access is particularly material given the nature of the Service as …
Under this clause, the agreement limits any financial recovery against OneLogin to the amount paid in the 12 months preceding a claim, and specifically excludes recovery for losses resulting from unauthorized access to or breach of personal information and account content stored in the Service.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OneLogin.