OneLogin · OneLogin Terms of Service · View original document ↗

Security Disclaimer and Personal Information Risk Acknowledgment

High severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time OneLogin changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for OneLogin Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

This provision states that OneLogin implements commercially reasonable security measures but does not guarantee protection against unauthorized access, and requires users to acknowledge that they provide personal information at their own risk.

This analysis describes what OneLogin's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This clause establishes a self-risk acknowledgment for personal information submitted to the Service and limits OneLogin's security commitment to commercially reasonable measures, without defining the specific technical or organizational controls that satisfy that standard.

Interpretive note: The 'commercially reasonable measures' standard is undefined in the document, and the enforceability of the self-risk acknowledgment may vary by jurisdiction, particularly under GDPR and applicable state data protection laws.

Consumer impact (what this means for users)

Under this clause, the agreement requires users to acknowledge that personal information is provided at their own risk, and OneLogin does not guarantee that security measures will prevent unauthorized access or misuse of personal information or account content.

Cross-platform context

See how other platforms handle Security Disclaimer and Personal Information Risk Acknowledgment and similar clauses.

Compare across platforms →

Monitoring

OneLogin has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We have implemented commercially reasonable technical and organizational measures designed to secure your personal information and Content from accidental loss and from unauthorized access, use, alteration or disclosure. However, we cannot guarantee that unauthorized third parties will never be able to defeat those measures or use your personal information and Content for improper purposes. You acknowledge that you provide your personal information at your own risk.

Excerpt from OneLogin's Terms of Service

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision may require evaluation under GDPR where OneLogin processes personal data on behalf of EU-based controllers, as GDPR Article 32 requires data processors to implement appropriate technical and organizational measures and does not permit processors to disclaim responsibility for security failures through user acknowledgment clauses. The 'commercially reasonable measures' standard is not defined in the document and may not map directly to GDPR's risk-based security requirements. The FTC Act and applicable state data breach notification laws are also relevant. (2) GOVERNANCE EXPOSURE: High for organizations processing EU personal data through the Service. The self-risk acknowledgment clause may not satisfy GDPR processor accountability requirements, and the absence of defined security standards creates ambiguity in assessing OneLogin's obligations in the event of a breach. (3) JURISDICTION FLAGS: EU and EEA organizations face heightened exposure given GDPR's specific processor security obligations. California organizations should assess whether the self-risk acknowledgment is consistent with California's data breach notification requirements under the CCPA and California Civil Code Section 1798.82. (4) CONTRACT AND VENDOR IMPLICATIONS: Vendor risk assessments should document that this Terms of Service does not include specific security commitments, defined incident response timelines, or breach notification obligations. Enterprise customers in regulated industries should evaluate whether a separate data processing agreement or security addendum is required. (5) COMPLIANCE CONSIDERATIONS: Legal and compliance teams should assess whether reliance on this Terms of Service alone satisfies their organization's vendor security due diligence requirements, and whether OneLogin provides supplemental security documentation such as SOC 2 reports, ISO certifications, or a data processing addendum that includes defined security standards and breach notification obligations.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has authority over the adequacy of data security practices and security representations in consumer and business service agreements under the FTC Act.
    File a complaint →
  • State AG
    State attorneys general have authority over data breach notification obligations and data security adequacy under state data protection and consumer protection laws.
    File a complaint →

Provision details

Document information
Document
OneLogin Terms of Service
Entity
OneLogin
Document last updated
May 5, 2026
Tracking information
First tracked
July 12, 2026
Last verified
July 12, 2026
Record ID
CA-P-074363
Document ID
CA-D-00693
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
7fec8f5039b9547d3ee03e85420719b8d7abdb572670a9cc49c418788ea277cf
Analysis generated
July 12, 2026 15:54 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: OneLogin
Document: OneLogin Terms of Service
Record ID: CA-P-074363
Captured: 2026-07-12 15:54:33 UTC
SHA-256: 7fec8f5039b9547d…
URL: https://conductatlas.com/platform/onelogin/onelogin-terms-of-service/provision/CA-P-074363/security-disclaimer-and-personal-information-risk-acknowledgment/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does OneLogin's Security Disclaimer and Personal Information Risk Acknowledgment clause do?

This clause establishes a self-risk acknowledgment for personal information submitted to the Service and limits OneLogin's security commitment to commercially reasonable measures, without defining the specific technical or organizational controls that satisfy that standard.

How does this clause affect you?

Under this clause, the agreement requires users to acknowledge that personal information is provided at their own risk, and OneLogin does not guarantee that security measures will prevent unauthorized access or misuse of personal information or account content.

Is ConductAtlas affiliated with OneLogin?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OneLogin.