Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Account owners and their designated administrators may access participant message content, direct messages, recordings, transcripts, and collaborative feature content generated by users on their accounts, subject to their configured settings. The scope of access includes in-meeting chat, Zoom Chat, direct messages under archiving, email and calendar content on Zoom Email accounts, and content from collaborative features such as whiteboards and polls.
This analysis describes what Zoom's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that organizations operating as Zoom account owners have broad visibility into communications and content generated by users on their accounts, including direct messages when archiving is enabled. The scope of access depends on account settings but includes categories of content that employees or participants may not expect to be accessible to their employer or hosting organization.
This provision establishes that account owners such as employers or educational institutions may access participant messages, direct messages under archiving configurations, recordings, transcripts, and collaborative feature content. Under this clause, individuals using Zoom through an organizational account should be aware that their account owner's settings determine the extent of visibility into their communications.
Cross-platform context
See how other platforms handle Account Owner Access to Participant Messages and Content and similar clauses.
Compare across platforms →Monitoring
Zoom has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Depending on their settings, account owners and the users they designate can access personal data for participants who join meetings and webinars on their account or send messages to users on their account. Depending on their settings, account owners also can see sender and receiver information, and other messaging data, along with the content of messages sent to and from users on their account (including from in-meeting chat where dedicated meeting group chats are enabled), unless the account owner has enabled Advanced Chat Encryption. If a participant in a meeting is subject to archiving, their account owner will have access to messages sent to Everyone in the meeting, as well as direct messages sent to that participant.Excerpt from Zoom's Privacy Statement
1. REGULATORY LANDSCAPE: This provision engages GDPR Article 6 (lawful basis for processing) and Article 88 (processing in the context of employment), which in several EU member states requires explicit employee monitoring disclosures and in some jurisdictions works council consultation before implementing monitoring measures. In the UK, the ICO Employment Practices Code addresses monitoring of electronic communications. In the U.S., the Electronic Communications Privacy Act and state wiretapping laws may interact with employer monitoring of employee communications depending on jurisdiction and consent configurations. CCPA and applicable U.S. state privacy laws may require employer notice to employees as consumers where personal data is accessed. 2. GOVERNANCE EXPOSURE: High. Enterprise customers acting as account owners bear independent compliance obligations for the monitoring and archiving of employee or participant communications. The provision authorizes access to direct messages when archiving is enabled, which represents a category of content that participants may reasonably expect to be private. Compliance with applicable employee monitoring laws requires affirmative disclosure and, in some EU jurisdictions, consent or works council approval before enabling archiving. 3. JURISDICTION FLAGS: EU member states (particularly Germany, France, and the Netherlands) impose the most stringent employee monitoring requirements, including works council consultation obligations. The UK ICO Employment Practices Code requires proportionality assessments. In the U.S., states including Connecticut, Delaware, and New York have enacted employee monitoring disclosure statutes. Illinois and other states with electronic surveillance laws may also interact with this provision. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement teams should confirm that their data processing agreement with Zoom accurately reflects the controller-processor relationship for Customer Content accessed by account owners. Organizations enabling archiving should assess whether their employment contracts, acceptable use policies, and onboarding disclosures adequately notify users of monitoring. The provision that access depends on settings creates a shared responsibility model that may require internal controls documentation. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should audit current archiving and recording configurations against applicable employee monitoring disclosure requirements by jurisdiction. Where Zoom is deployed across multiple jurisdictions, a jurisdiction-by-jurisdiction assessment of monitoring consent and disclosure obligations is warranted. Internal policy updates may be required to align with the scope of access disclosed in this provision.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that organizations operating as Zoom account owners have broad visibility into communications and content generated by users on their accounts, including direct messages when archiving is enabled. The scope of access depends on account settings but includes categories of content that employees or participants may not expect to be accessible to their employer or hosting organization.
This provision establishes that account owners such as employers or educational institutions may access participant messages, direct messages under archiving configurations, recordings, transcripts, and collaborative feature content. Under this clause, individuals using Zoom through an organizational account should be aware that their account owner's settings determine the extent of visibility into their communications.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Zoom.