Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The agreement requires the Customer to provide required notices to and obtain required consents from Agents and End Users necessary for Zendesk to lawfully process Service Data, and to inform Agents about their rights under Zendesk's Privacy Notice.
This analysis describes what Zendesk's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision places the legal responsibility for obtaining all consents and providing all notices necessary for lawful processing of Service Data on the Customer rather than Zendesk. This allocation of responsibility is significant under GDPR and CCPA, where inadequate consent or notice mechanisms create direct regulatory exposure for the Customer as data controller.
Under this clause, the Customer is responsible for ensuring that agents and end users have received required notices and provided any required consents before their data is processed by Zendesk. The Customer must also inform agents about their rights as described in Zendesk's Privacy Notice.
Cross-platform context
See how other platforms handle Customer Consent Obligations for Agent and End User Data and similar clauses.
Compare across platforms →Monitoring
Zendesk has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Customer will: ... (iii) provide any notices to, and obtain any required consents from, Agents and End Users necessary for Zendesk to lawfully process Service Data; (iv) if Customer provides Agent information to Zendesk to create account logins, inform those Agents about applicable rights outlined in the Privacy NoticeExcerpt from Zendesk's Terms of Service
(1) REGULATORY LANDSCAPE: This provision directly engages GDPR requirements for lawful basis, transparency, and data subject rights, as well as CCPA requirements for notice at collection. Under GDPR, the Customer operating as a data controller is responsible for establishing and documenting lawful basis for processing, and for providing data subjects with required privacy information. CCPA requires businesses to provide notice at or before collection of personal information. (2) GOVERNANCE EXPOSURE: High. This clause allocates consent and notice compliance obligations entirely to the Customer, meaning that if Customer's consent mechanisms or privacy notices are inadequate, the Customer bears the regulatory exposure. The agreement does not specify minimum standards for what constitutes adequate notice or consent, leaving that determination to the Customer and applicable law. (3) JURISDICTION FLAGS: EU/EEA customers face heightened exposure under GDPR Articles on lawful basis and transparency, which require specific disclosures about data processors and processing purposes. California customers must ensure notice at collection requirements under CCPA are met for end user data. Customers operating in multiple jurisdictions must reconcile potentially divergent consent and notice requirements across their agent and end user populations. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement and compliance teams should audit existing privacy notices and consent mechanisms to confirm they disclose Zendesk as a data processor and describe the purposes for which Service Data will be processed, including Zendesk's product improvement use authorized under Section 3.1. The obligation to inform agents about rights in Zendesk's Privacy Notice requires that customers are familiar with the content of that document and that their internal HR or onboarding processes include the required disclosure. (5) COMPLIANCE CONSIDERATIONS: Data protection officers and privacy compliance teams should review customer-facing and employee-facing privacy notices to ensure they accurately describe Zendesk's processing of Service Data, including sharing with third-party product providers. Consent mechanisms for end users should be evaluated against applicable law in each jurisdiction where end users are located. Records of consent and notice delivery should be maintained to demonstrate compliance.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision places the legal responsibility for obtaining all consents and providing all notices necessary for lawful processing of Service Data on the Customer rather than Zendesk. This allocation of responsibility is significant under GDPR and CCPA, where inadequate consent or notice mechanisms create direct regulatory exposure for the Customer as data controller.
Under this clause, the Customer is responsible for ensuring that agents and end users have received required notices and provided any required consents before their data is processed by Zendesk. The Customer must also inform agents about their rights as described in Zendesk's Privacy Notice.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Zendesk.