Zendesk · Zendesk Privacy Policy · View original document ↗

Cross-Border Data Transfers and Data Privacy Framework

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Zendesk changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Zendesk Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

Zendesk states that cross-border data transfers are conducted using EU Standard Contractual Clauses, UK Addendum, Binding Corporate Rules, and DPF certification; Zendesk asserts ongoing liability for onward transfers to third-party agents under DPF Principles.

This analysis describes what Zendesk's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes the legal mechanisms Zendesk relies upon for international data transfers and asserts accountability for onward transfers to agents under the DPF framework. Compliance teams should assess the continued adequacy of DPF certification as a transfer mechanism given the historical legal challenges to EU-U.S. data transfer frameworks.

Interpretive note: The legal stability of the EU-U.S. DPF as a valid transfer mechanism is subject to ongoing judicial and regulatory scrutiny, and the adequacy of this mechanism may depend on future determinations by EU supervisory authorities or courts.

Consumer impact (what this means for users)

Under this clause, personal data transferred from the EU, UK, and Switzerland to the United States is governed by DPF certification and Standard Contractual Clauses or Binding Corporate Rules, and individuals may invoke binding arbitration for unresolved DPF complaints at no cost through JAMS.

Cross-platform context

See how other platforms handle Cross-Border Data Transfers and Data Privacy Framework and similar clauses.

Compare across platforms →

Monitoring

Zendesk has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Zendesk, Inc., FutureSimple Inc., and Smooch Technologies US Inc. comply with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce (collectively, the 'Principles'). Transfers within the Zendesk Group or to third parties located in such third countries take place using a valid data transfer mechanism, such as the EU Standard Contractual Clauses and/or the U.K. Addendum to such clauses, approved Binding Corporate Rules, approved codes of conduct and certifications mechanisms, on the basis of permissible statutory derogations, or any other valid data transfer mechanism issued or approved by the EEA, Swiss, or U.K. authorities. Zendesk remains liable under the Principles if Zendesk's agent processes personal data in a manner inconsistent with the Principles, unless Zendesk proves that it is not responsible for the event giving rise to damage.

Excerpt from Zendesk's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision implicates GDPR Chapter V (international transfers), UK GDPR, and Swiss data protection law, enforced by EU data protection supervisory authorities, the UK ICO, and the Swiss Federal Data Protection and Information Commissioner. The DPF is administered by the U.S. Department of Commerce with FTC enforcement jurisdiction over certified entities. The legal stability of the DPF as a transfer mechanism has been subject to prior legal challenges (Schrems I and II), and compliance teams should monitor for future judicial or regulatory developments. 2. GOVERNANCE EXPOSURE: Medium. Reliance on DPF certification as a primary transfer mechanism for EU-U.S. data flows carries residual risk given the framework's history of legal challenge. The document's acknowledgment of Binding Corporate Rules and SCCs as parallel mechanisms provides additional transfer safeguards. Zendesk's assertion of liability for onward agent transfers under DPF Principles is a governance-positive disclosure but creates accountability obligations that should be documented in vendor agreements. 3. JURISDICTION FLAGS: Heightened exposure in the EU and EEA, where supervisory authorities have historically scrutinized EU-U.S. data transfers. UK and Swiss transfers are addressed separately through the UK Extension and Swiss-U.S. DPF. Organizations transferring data from these jurisdictions to Zendesk should confirm which transfer mechanism applies to their specific data flows. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should confirm whether Zendesk's DPA specifies which transfer mechanism applies to their contractual relationship (DPF, SCCs, or BCRs) and obtain copies of applicable SCCs or evidence of BCR approval as required by GDPR Article 46. The document provides a link to BCR approval evidence on the European Data Protection Board's website. 5. COMPLIANCE CONSIDERATIONS: Legal teams should assess the current legal status of the EU-U.S. DPF as a valid transfer mechanism and ensure that SCCs or BCRs are in place as backup mechanisms. The JAMS dispute resolution mechanism for unresolved DPF complaints should be disclosed to data subjects as part of the organization's privacy notice obligations. DPF certification scope should be verified to confirm it covers all relevant Zendesk entities.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • FTC
    The FTC has enforcement jurisdiction over Zendesk's compliance with the EU-U.S. DPF, UK Extension, and Swiss-U.S. DPF as identified in the notice.
    File a complaint →

Provision details

Document information
Document
Zendesk Privacy Policy
Entity
Zendesk
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-016071
Document ID
CA-D-00639
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
61bead77ffc0694e673595ad8660fbe7d6a546799b687496b3755d40d3acc968
Analysis generated
July 9, 2026 09:29 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Zendesk
Document: Zendesk Privacy Policy
Record ID: CA-P-016071
Captured: 2026-07-09 09:29:52 UTC
SHA-256: 61bead77ffc0694e…
URL: https://conductatlas.com/platform/zendesk/zendesk-privacy-policy/provision/CA-P-016071/cross-border-data-transfers-and-data-privacy-framework/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Zendesk's Cross-Border Data Transfers and Data Privacy Framework clause do?

This provision establishes the legal mechanisms Zendesk relies upon for international data transfers and asserts accountability for onward transfers to agents under the DPF framework. Compliance teams should assess the continued adequacy of DPF certification as a transfer mechanism given the historical legal challenges to EU-U.S. data transfer frameworks.

How does this clause affect you?

Under this clause, personal data transferred from the EU, UK, and Switzerland to the United States is governed by DPF certification and Standard Contractual Clauses or Binding Corporate Rules, and individuals may invoke binding arbitration for unresolved DPF complaints at no cost through JAMS.

Is ConductAtlas affiliated with Zendesk?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Zendesk.