StackLégal

Authentication

GDPR Auth0

In an indie stack, Auth0 is used for Authentication and identity management. Entity cited: Okta, Inc.. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.

Translation of the French sheet. The facts do not change. The date is the date the official pages were read.

DPA Auth0

Yes. Okta DPA (January 2025 PDF), also applicable to Auth0 Customer Identity Cloud according to the Auth0 help center.

Read the DPA

Stated role

The Okta DPA, which the Auth0 help center states is applicable to Auth0 Customer Identity Cloud, makes Okta a processor and the customer a controller or a processor.

Personal data

Identifiers (first name, last name, identity data, business and personal contact details), title, position, employer, security questions, internet or network activity, login data, location data, commercial information about products purchased.

Sub-processors of Auth0

The DPA points the list to Okta's Agreements page, Trust & Compliance section.

List published by the vendor

Transfers outside the EU

Hosting / location

Public-cloud tenants are created in a chosen region. Documented localities: Australia, Canada, Europe (EU and EU-2), Japan, United Kingdom, United States (US, US-3, US-4, US-5). The chosen region determines where the tenant's data is hosted. A Private Cloud on AWS can be deployed in other listed regions, including Germany and Ireland.

EU–United States Data Privacy Framework

Okta, Inc. is registered. EU-U.S. Data Privacy Framework status: Active. Auth0, LLC and Auth0 International LLC are listed as covered entities.

Data Privacy Framework sheet

Cookies

The Authentication API documentation indicates, among the cookies used: auth0 and auth0_compat (SSO session), auth0-mf and auth0-mf_compat (MFA), a0_users:sess and a0_users:sess.sig (Classic Login CSRF), did and did_compat (protection against attacks). With a custom domain, these cookies are sent to the customer's hostname. Exhaustive list: not disclosed.

Typical use, written by StackLégal and not by the vendor: Authentication and identity management.

History

Last update: October 4, 2026.

  1. Cookies: names taken from the Authentication API documentation, in place of "not disclosed".

  2. First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".

Clause to paste

Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.

Sub-processor clause

Add this vendor to your free sub-processors widget

Sources

Verified on October 4, 2026.

Frequently asked questions

Is Auth0 a processor within the meaning of the GDPR?

The Okta DPA, which the Auth0 help center states is applicable to Auth0 Customer Identity Cloud, makes Okta a processor and the customer a controller or a processor.

What DPA does Auth0 publish?

Yes. Okta DPA (January 2025 PDF), also applicable to Auth0 Customer Identity Cloud according to the Auth0 help center. https://www.okta.com/content/dam/okta---digital/en_us/legal/data-processing-addendum-2025-01.pdf

Which further sub-processors does Auth0 publish?

The DPA points the list to Okta's Agreements page, Trust & Compliance section. https://www.okta.com/agreements

Where does Auth0 state that it processes data, including outside the EU?

Public-cloud tenants are created in a chosen region. Documented localities: Australia, Canada, Europe (EU and EU-2), Japan, United Kingdom, United States (US, US-3, US-4, US-5). The chosen region determines where the tenant's data is hosted. A Private Cloud on AWS can be deployed in other listed regions, including Germany and Ireland.

Is Auth0 registered under the EU–United States Data Privacy Framework?

Okta, Inc. is registered. EU-U.S. Data Privacy Framework status: Active. Auth0, LLC and Auth0 International LLC are listed as covered entities. https://www.dataprivacyframework.gov/participant/9734

Which personal data does Auth0 mention?

Identifiers (first name, last name, identity data, business and personal contact details), title, position, employer, security questions, internet or network activity, login data, location data, commercial information about products purchased.

Often in the same stack

These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.

Related tools

All the sheets authentication

Full pack, from 39 € incl. VAT

The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.