Zoom · Zoom Privacy Statement · View original document ↗

GDPR Legal Bases for Processing

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Zoom changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Zoom recorded 4 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Zoom Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

For EEA, Swiss, and UK users, Zoom identifies five legal bases for processing personal data as a controller: contractual necessity, consent (specifically for advertising cookies), legal obligation, vital interests, and legitimate interests. The legitimate interests basis covers product development, security, marketing, and compliance with non-EEA legal obligations.

This analysis describes what Zoom's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes the GDPR legal bases Zoom asserts for its processing activities as a controller, which is a core compliance disclosure under GDPR Article 13 and 14. The use of legitimate interests as a basis for marketing communications, product development, and compliance with non-EEA laws may be subject to balancing test requirements and data subject objection rights under GDPR Article 21.

Clause Stability Stable

0
Changes
3
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Change history

added Jul 18, 2026

This new provision provides transparency regarding GDPR legal bases for processing, which is legally required but was not previously disclosed in the privacy statement.

View full change record →

Consumer impact (what this means for users)

This provision establishes that EEA, Swiss, and UK users have data subject rights corresponding to the legal basis under which their data is processed, including the right to object to processing based on legitimate interests and the right to withdraw consent for advertising cookies. Under this clause, users in these jurisdictions can exercise rights including access, erasure, rectification, restriction, and portability by submitting requests through the designated privacy rights portal.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Access the Zoom privacy rights request portal linked in the Privacy Statement. Submit a request to exercise your rights under GDPR, including access, erasure, rectification, restriction, portability, or objection. Zoom may request identity verification before processing the request.

Cross-platform context

See how other platforms handle GDPR Legal Bases for Processing and similar clauses.

Compare across platforms →

Monitoring

Zoom has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We only use your information in a lawful, transparent, and fair manner. Depending on the specific personal data concerned and the factual context, when Zoom processes personal data as a controller for individuals in regions such as the EEA, Switzerland, and the UK, we rely on the following legal bases as applicable in your jurisdiction: As necessary for our contract... Consistent with specific revocable consents... As necessary to comply with our legal obligations... To protect your vital interests or those of others... As necessary for our (or others') legitimate interests, unless those interests are overridden by your interests or fundamental rights and freedoms.

Excerpt from Zoom's Privacy Statement

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision directly engages GDPR Articles 6, 7, 9, 13, 14, and 21, as well as the UK GDPR and Swiss revFADP equivalents. The assertion of legitimate interests as a legal basis for marketing communications may interact with GDPR Article 21's right to object, which requires that processing cease upon objection unless Zoom can demonstrate compelling legitimate grounds. The EU's ePrivacy Directive imposes a prior consent requirement for electronic direct marketing that may constrain the legitimate interests basis for certain marketing activities. Enforcement authority lies with EU national data protection authorities, the UK ICO, and the Swiss Federal Data Protection and Information Commissioner. 2. GOVERNANCE EXPOSURE: Medium. The legitimate interests basis is the broadest of the five identified legal bases and covers a range of processing activities including marketing, product development, security, and non-EEA legal compliance. Enterprise customers should confirm that their data processing agreements with Zoom accurately reflect the legal bases applicable to their specific processing contexts, and that Zoom's legitimate interests assessments are documented and available for regulatory review. 3. JURISDICTION FLAGS: Germany's data protection authorities (DSK) have historically taken a restrictive view of legitimate interests for online advertising and profiling. France's CNIL and Ireland's DPC (where Zoom's EU operations are likely anchored) may be the lead supervisory authority for cross-border processing. Switzerland's revFADP, which came into full effect in September 2023, introduced requirements substantially aligned with GDPR. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers should ensure their data processing agreements with Zoom identify the applicable legal bases for processing in each customer's deployment context. Where Zoom processes personal data as a processor on behalf of an enterprise customer, the customer as controller is responsible for identifying the applicable legal basis. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should map Zoom processing activities to the legal bases disclosed in this provision and assess whether any activities rely on legitimate interests in ways that may require data subject impact balancing documentation. The right to object to legitimate interests processing should be reflected in employee and user privacy notices. Where consent is the stated legal basis (advertising cookies), consent withdrawal mechanisms should be tested for functionality.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Applicable agencies

  • State AG
    For U.S. users, state attorneys general in jurisdictions with comprehensive privacy laws (California, Colorado, Connecticut, Virginia) have enforcement authority over analogous data rights provisions.
    File a complaint →

Provision details

Document information
Document
Zoom Privacy Statement
Entity
Zoom
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014455
Document ID
CA-D-00190
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
2cdaf89746b4ead6eb84dcc77d42c153ed2873fbea3fa5dae94f8a50d9833ee5
Analysis generated
July 9, 2026 05:36 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Zoom
Document: Zoom Privacy Statement
Record ID: CA-P-014455
Captured: 2026-07-09 05:36:51 UTC
SHA-256: 2cdaf89746b4ead6…
URL: https://conductatlas.com/platform/zoom/zoom-privacy-statement/provision/CA-P-014455/gdpr-legal-bases-for-processing/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Frequently Asked Questions

What does Zoom's GDPR Legal Bases for Processing clause do?

This provision establishes the GDPR legal bases Zoom asserts for its processing activities as a controller, which is a core compliance disclosure under GDPR Article 13 and 14. The use of legitimate interests as a basis for marketing communications, product development, and compliance with non-EEA laws may be subject to balancing test requirements and data subject objection rights under GDPR …

How does this clause affect you?

This provision establishes that EEA, Swiss, and UK users have data subject rights corresponding to the legal basis under which their data is processed, including the right to object to processing based on legitimate interests and the right to withdraw consent for advertising cookies. Under this clause, users in these jurisdictions can exercise rights including access, erasure, rectification, restriction, and …

Is ConductAtlas affiliated with Zoom?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Zoom.