This provision states that OneLogin implements commercially reasonable security measures but does not guarantee protection against unauthorized access, and requires users to acknowledge that they provide personal information at their own risk.
This analysis describes what OneLogin's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This clause establishes a self-risk acknowledgment for personal information submitted to the Service and limits OneLogin's security commitment to commercially reasonable measures, without defining the specific technical or organizational controls that satisfy that standard.
Interpretive note: The 'commercially reasonable measures' standard is undefined in the document, and the enforceability of the self-risk acknowledgment may vary by jurisdiction, particularly under GDPR and applicable state data protection laws.
Under this clause, the agreement requires users to acknowledge that personal information is provided at their own risk, and OneLogin does not guarantee that security measures will prevent unauthorized access or misuse of personal information or account content.
Cross-platform context
See how other platforms handle Security Disclaimer and Personal Information Risk Acknowledgment and similar clauses.
Compare across platforms →"We have implemented commercially reasonable technical and organizational measures designed to secure your personal information and Content from accidental loss and from unauthorized access, use, alteration or disclosure. However, we cannot guarantee that unauthorized third parties will never be able to defeat those measures or use your personal information and Content for improper purposes. You acknowledge that you provide your personal information at your own risk.Excerpt from OneLogin's Terms of Service
(1) REGULATORY LANDSCAPE: This provision may require evaluation under GDPR where OneLogin processes personal data on behalf of EU-based controllers, as GDPR Article 32 requires data processors to implement appropriate technical and organizational measures and …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This clause establishes a self-risk acknowledgment for personal information submitted to the Service and limits OneLogin's security commitment to commercially reasonable measures, without defining the specific technical or organizational controls that satisfy that standard.
Under this clause, the agreement requires users to acknowledge that personal information is provided at their own risk, and OneLogin does not guarantee that security measures will prevent unauthorized access or misuse of personal information or account content.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OneLogin.