Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Zendesk states that cross-border data transfers are conducted using EU Standard Contractual Clauses, UK Addendum, Binding Corporate Rules, and DPF certification; Zendesk asserts ongoing liability for onward transfers to third-party agents under DPF Principles.
This analysis describes what Zendesk's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the legal mechanisms Zendesk relies upon for international data transfers and asserts accountability for onward transfers to agents under the DPF framework. Compliance teams should assess the continued adequacy of DPF certification as a transfer mechanism given the historical legal challenges to EU-U.S. data transfer frameworks.
Interpretive note: The legal stability of the EU-U.S. DPF as a valid transfer mechanism is subject to ongoing judicial and regulatory scrutiny, and the adequacy of this mechanism may depend on future determinations by EU supervisory authorities or courts.
Under this clause, personal data transferred from the EU, UK, and Switzerland to the United States is governed by DPF certification and Standard Contractual Clauses or Binding Corporate Rules, and individuals may invoke binding arbitration for unresolved DPF complaints at no cost through JAMS.
Cross-platform context
See how other platforms handle Cross-Border Data Transfers and Data Privacy Framework and similar clauses.
Compare across platforms →Monitoring
Zendesk has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Zendesk, Inc., FutureSimple Inc., and Smooch Technologies US Inc. comply with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce (collectively, the 'Principles'). Transfers within the Zendesk Group or to third parties located in such third countries take place using a valid data transfer mechanism, such as the EU Standard Contractual Clauses and/or the U.K. Addendum to such clauses, approved Binding Corporate Rules, approved codes of conduct and certifications mechanisms, on the basis of permissible statutory derogations, or any other valid data transfer mechanism issued or approved by the EEA, Swiss, or U.K. authorities. Zendesk remains liable under the Principles if Zendesk's agent processes personal data in a manner inconsistent with the Principles, unless Zendesk proves that it is not responsible for the event giving rise to damage.Excerpt from Zendesk's Privacy Policy
1. REGULATORY LANDSCAPE: This provision implicates GDPR Chapter V (international transfers), UK GDPR, and Swiss data protection law, enforced by EU data protection supervisory authorities, the UK ICO, and the Swiss Federal Data Protection and Information Commissioner. The DPF is administered by the U.S. Department of Commerce with FTC enforcement jurisdiction over certified entities. The legal stability of the DPF as a transfer mechanism has been subject to prior legal challenges (Schrems I and II), and compliance teams should monitor for future judicial or regulatory developments. 2. GOVERNANCE EXPOSURE: Medium. Reliance on DPF certification as a primary transfer mechanism for EU-U.S. data flows carries residual risk given the framework's history of legal challenge. The document's acknowledgment of Binding Corporate Rules and SCCs as parallel mechanisms provides additional transfer safeguards. Zendesk's assertion of liability for onward agent transfers under DPF Principles is a governance-positive disclosure but creates accountability obligations that should be documented in vendor agreements. 3. JURISDICTION FLAGS: Heightened exposure in the EU and EEA, where supervisory authorities have historically scrutinized EU-U.S. data transfers. UK and Swiss transfers are addressed separately through the UK Extension and Swiss-U.S. DPF. Organizations transferring data from these jurisdictions to Zendesk should confirm which transfer mechanism applies to their specific data flows. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should confirm whether Zendesk's DPA specifies which transfer mechanism applies to their contractual relationship (DPF, SCCs, or BCRs) and obtain copies of applicable SCCs or evidence of BCR approval as required by GDPR Article 46. The document provides a link to BCR approval evidence on the European Data Protection Board's website. 5. COMPLIANCE CONSIDERATIONS: Legal teams should assess the current legal status of the EU-U.S. DPF as a valid transfer mechanism and ensure that SCCs or BCRs are in place as backup mechanisms. The JAMS dispute resolution mechanism for unresolved DPF complaints should be disclosed to data subjects as part of the organization's privacy notice obligations. DPF certification scope should be verified to confirm it covers all relevant Zendesk entities.
This provision establishes the legal mechanisms Zendesk relies upon for international data transfers and asserts accountability for onward transfers to agents under the DPF framework. Compliance teams should assess the continued adequacy of DPF certification as a transfer mechanism given the historical legal challenges to EU-U.S. data transfer frameworks.
Under this clause, personal data transferred from the EU, UK, and Switzerland to the United States is governed by DPF certification and Standard Contractual Clauses or Binding Corporate Rules, and individuals may invoke binding arbitration for unresolved DPF complaints at no cost through JAMS.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Zendesk.