10 Total
0 High severity
7 Medium severity
3 Low severity
Summary

This document establishes ZipRecruiter's global privacy policy governing the collection, use, and disclosure of personal information on its job search and recruiting platform. The policy authorizes collection of resumes, job application history, browsing behavior, device identifiers, and data from connected third-party accounts, with authorized uses including AI-driven job matching and sharing with employers, advertising networks, and analytics providers. The document establishes data subject rights including access, correction, and deletion requests, with California residents granted additional rights under the California Consumer Privacy Act.

Technical / Legal Breakdown

This document is ZipRecruiter's Global Privacy Policy (effective August 12, 2025), governing data collection, use, storage, and disclosure across its employment marketplace websites in the U.S., Canada, Australia, New Zealand, India, EEA, UK, and Switzerland, with stated legal bases varying by jurisdiction including consent, contractual necessity, and legitimate interests. The policy states that ZipRecruiter collects Identity Data, Contact Data, Financial Data, Technical Data, Profile Data, Usage Data, and Sensitive Personal Data categories; the terms authorize sharing with third-party employers, analytics providers, advertising networks, affiliated entities within the ZipRecruiter Group, and service providers, and explicitly permit the use of AI and machine learning to match job seekers and employers. The policy operates as a dual-framework document with materially different provisions for EEA/UK/Switzerland users versus U.S./Canada/Australia/New Zealand/India users, reflecting GDPR obligations for the former and a more permissive data use posture for the latter; the terms also authorize collecting data about non-users from third-party sources, which is operationally distinct and may warrant scrutiny under applicable consumer protection frameworks. The policy expressly engages GDPR, the UK GDPR, CCPA/CPRA (with a dedicated California Privacy Notice), the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, with FTC jurisdiction confirmed over DPF compliance; Indian users are covered under the non-EEA section despite the Digital Personal Data Protection Act 2023 coming into force, which may require separate evaluation. Data transfers from EU/UK/Switzerland rely on DPF certification, but given the legal history of EU-U.S. transfer mechanisms, organizations relying on this policy for compliance should monitor DPF stability as a material risk.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial
Medium — 7 provisions
Low — 3 provisions

Monitoring

ZipRecruiter has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle AI and Machine Learning Job Matching and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured April 22, 2026 06:23 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000292
Version ID CA-V-000903
SHA-256 db452bbcc7a2c0c0dc549872d57bf13cccfa5f39c8cfa648506350e158e2fb95
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans