Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
When a customer enables Third-Party Products through the Zendesk platform, the agreement authorizes Zendesk to share Customer Account information and Service Data with those third-party providers, and the customer waives claims against Zendesk related to those products.
This analysis describes what Zendesk's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision authorizes Service Data sharing with third-party providers as a consequence of enabling integrations, without requiring a separate disclosure or consent step at the time of each integration. The scope of data shared is defined broadly as Customer Account information and Service Data, which encompasses all data submitted by customers, agents, and end users.
Under this clause, enabling any Third-Party Product integration on the Zendesk platform authorizes Zendesk to share Service Data, including all data submitted by agents and end users, with the relevant third-party provider. The agreement states that customers waive claims against Zendesk arising from Third-Party Products.
Cross-platform context
See how other platforms handle Third-Party Product Data Sharing and similar clauses.
Compare across platforms →Monitoring
Zendesk has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Customer's use of Third-Party Products will be subject to the applicable terms with the Third-Party Product providers. Zendesk is not responsible for any Third-Party Products and Customer waives any claims against Zendesk relating to Third-Party Products. By using Third-Party Products, Customer permits Zendesk to share Customer's Account information and Service Data with applicable Third-Party Product providers.Excerpt from Zendesk's Terms of Service
(1) REGULATORY LANDSCAPE: This provision engages GDPR requirements for lawful basis and adequate safeguards when transferring personal data to third parties, as well as CCPA disclosure requirements for sharing personal information with third parties. Where third-party providers are located outside the EU/EEA, data transfer mechanisms such as Standard Contractual Clauses may be required. Enforcement authorities include EU/EEA national data protection authorities, the California Privacy Protection Agency, and the FTC. (2) GOVERNANCE EXPOSURE: High. The authorization to share Service Data with third-party providers upon integration enablement may operate as a blanket data sharing permission rather than a granular, integration-specific disclosure. Organizations processing personal data of EU/EEA data subjects must assess whether this mechanism satisfies GDPR requirements for disclosure of sub-processors or third-party recipients. (3) JURISDICTION FLAGS: EU/EEA customers face heightened exposure under GDPR Articles governing data sharing with third parties and requirements to disclose recipients of personal data to data subjects. California customers should assess whether this sharing triggers CCPA disclosure or opt-out obligations. Customers in regulated industries such as financial services or healthcare should evaluate whether Service Data shared with third-party providers includes regulated information. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement and legal teams should maintain an inventory of all enabled Third-Party Products and confirm that each provider has appropriate data processing agreements in place. The waiver of claims against Zendesk for Third-Party Product issues shifts liability for third-party data handling to the customer, which may affect vendor risk assessments and cyber insurance coverage determinations. (5) COMPLIANCE CONSIDERATIONS: Organizations should audit their Zendesk integrations to identify all enabled Third-Party Products and assess the data sharing implications for each. Privacy notices provided to end users and agents should disclose that their data may be shared with third-party integration providers. Where Third-Party Product providers are outside the EU/EEA, data transfer impact assessments may be required under GDPR.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision authorizes Service Data sharing with third-party providers as a consequence of enabling integrations, without requiring a separate disclosure or consent step at the time of each integration. The scope of data shared is defined broadly as Customer Account information and Service Data, which encompasses all data submitted by customers, agents, and end users.
Under this clause, enabling any Third-Party Product integration on the Zendesk platform authorizes Zendesk to share Service Data, including all data submitted by agents and end users, with the relevant third-party provider. The agreement states that customers waive claims against Zendesk arising from Third-Party Products.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Zendesk.