Zendesk keeps your personal data for as long as it needs to for business or legal reasons, and says it will securely delete or anonymize it when it is no longer needed, including data stored in backups.
This analysis describes what Zendesk's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The notice does not specify concrete retention periods for most data categories, which means the duration Zendesk holds your data is determined by Zendesk's internal policies and legal obligations rather than fixed timelines disclosed to users.
Interpretive note: The adequacy of disclosure under GDPR Article 13/14 depends on whether Zendesk's separate or internal retention schedules provide sufficient specificity; this notice does not provide concrete retention periods for most data categories.
Your personal data may be retained by Zendesk for an unspecified period tied to business and legal necessity rather than a fixed timeframe, which limits your ability to predict when data will be deleted unless you submit a formal erasure request.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
Further, you may take legal actions in relation to any potential breach of your rights regarding the processing of your Personal Information, as well as to lodge complaints before the competent data prot...
"We retain personal data for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. When we no longer need personal data, we securely delete or anonymize it. If we cannot delete your information (for example, because it has been stored in backup archives), then we will securely store your information and isolate it from any further processing until deletion is possible.Excerpt from Zendesk's Privacy Policy
(1) REGULATORY LANDSCAPE: This provision engages GDPR Article 5(1)(e) (storage limitation principle), which requires personal data to be kept no longer than necessary for the specified purpose.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The notice does not specify concrete retention periods for most data categories, which means the duration Zendesk holds your data is determined by Zendesk's internal policies and legal obligations rather than fixed timelines disclosed to users.
Your personal data may be retained by Zendesk for an unspecified period tied to business and legal necessity rather than a fixed timeframe, which limits your ability to predict when data will be deleted unless you submit a formal erasure request.
ConductAtlas has identified this type of provision across 289 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Zendesk.