Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
This provision states that OneLogin implements commercially reasonable security measures but does not guarantee protection against unauthorized access, and requires users to acknowledge that they provide personal information at their own risk.
This analysis describes what OneLogin's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This clause establishes a self-risk acknowledgment for personal information submitted to the Service and limits OneLogin's security commitment to commercially reasonable measures, without defining the specific technical or organizational controls that satisfy that standard.
Interpretive note: The 'commercially reasonable measures' standard is undefined in the document, and the enforceability of the self-risk acknowledgment may vary by jurisdiction, particularly under GDPR and applicable state data protection laws.
Under this clause, the agreement requires users to acknowledge that personal information is provided at their own risk, and OneLogin does not guarantee that security measures will prevent unauthorized access or misuse of personal information or account content.
Cross-platform context
See how other platforms handle Security Disclaimer and Personal Information Risk Acknowledgment and similar clauses.
Compare across platforms →Monitoring
OneLogin has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"We have implemented commercially reasonable technical and organizational measures designed to secure your personal information and Content from accidental loss and from unauthorized access, use, alteration or disclosure. However, we cannot guarantee that unauthorized third parties will never be able to defeat those measures or use your personal information and Content for improper purposes. You acknowledge that you provide your personal information at your own risk.Excerpt from OneLogin's Terms of Service
(1) REGULATORY LANDSCAPE: This provision may require evaluation under GDPR where OneLogin processes personal data on behalf of EU-based controllers, as GDPR Article 32 requires data processors to implement appropriate technical and organizational measures and does not permit processors to disclaim responsibility for security failures through user acknowledgment clauses. The 'commercially reasonable measures' standard is not defined in the document and may not map directly to GDPR's risk-based security requirements. The FTC Act and applicable state data breach notification laws are also relevant. (2) GOVERNANCE EXPOSURE: High for organizations processing EU personal data through the Service. The self-risk acknowledgment clause may not satisfy GDPR processor accountability requirements, and the absence of defined security standards creates ambiguity in assessing OneLogin's obligations in the event of a breach. (3) JURISDICTION FLAGS: EU and EEA organizations face heightened exposure given GDPR's specific processor security obligations. California organizations should assess whether the self-risk acknowledgment is consistent with California's data breach notification requirements under the CCPA and California Civil Code Section 1798.82. (4) CONTRACT AND VENDOR IMPLICATIONS: Vendor risk assessments should document that this Terms of Service does not include specific security commitments, defined incident response timelines, or breach notification obligations. Enterprise customers in regulated industries should evaluate whether a separate data processing agreement or security addendum is required. (5) COMPLIANCE CONSIDERATIONS: Legal and compliance teams should assess whether reliance on this Terms of Service alone satisfies their organization's vendor security due diligence requirements, and whether OneLogin provides supplemental security documentation such as SOC 2 reports, ISO certifications, or a data processing addendum that includes defined security standards and breach notification obligations.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This clause establishes a self-risk acknowledgment for personal information submitted to the Service and limits OneLogin's security commitment to commercially reasonable measures, without defining the specific technical or organizational controls that satisfy that standard.
Under this clause, the agreement requires users to acknowledge that personal information is provided at their own risk, and OneLogin does not guarantee that security measures will prevent unauthorized access or misuse of personal information or account content.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OneLogin.