Zoom · Zoom Privacy Statement · View original document ↗

Meeting Content Collection

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Zoom recorded 5 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for Zoom Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

The statement discloses that Zoom collects audio recordings, video, chat messages, transcripts, whiteboard content, and other material generated during meetings, calls, and webinars. This collection applies regardless of whether recording or transcription features are explicitly activated by the user.

This analysis describes what Zoom's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that Zoom's data collection scope includes the substantive content of communications, not only metadata or usage signals. For enterprise accounts processing confidential business discussions, legal communications, or healthcare-related conversations, this collection scope is relevant to data classification and retention assessments.

Change history

modified May 23, 2026

Expanded scope to explicitly include Team Chat, Zoom Phone calls, and additional features (translation, whiteboard, closed captions) beyond the original list.

View full change record →

Consumer impact (what this means for users)

The agreement establishes that audio, video, chat, and transcript data generated during Zoom sessions may be collected and processed by Zoom. Users who enable features such as AI Companion summaries or transcription authorize additional processing of this content as described in the AI provisions.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Navigate to Zoom's privacy rights portal, select the data deletion request option, and specify the categories of data you wish to have deleted. Zoom will process the request subject to applicable legal retention requirements.

How other platforms handle this

Ledger Medium

At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.

Strava Medium

If we collect health information from these integrations (such as heart rate), we will not sell or use it for advertising or other similar purposes; we do not disclose it to third parties without your prior consent; and we will only use it for the specific purposes described in this Policy.

eBay Medium

We collect your personal data when you use our Services, create a new eBay account, provide us with information via a web form, add or update information in your eBay account, participate in online community discussions or otherwise interact with us.

See all platforms with this clause type →

Monitoring

Zoom has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We collect information associated with your use of our Products, including: Audio, video, and other content you share or generate during meetings, webinars, messaging, Team Chat, Zoom Phone calls, and other Zoom services, including when you use features like transcription, translation, whiteboard, or closed captions.

— Excerpt from Zoom's Zoom Privacy Statement

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

1. REGULATORY LANDSCAPE: Collection of meeting content including audio and video recordings engages GDPR Article 5 data minimization and purpose limitation principles for EEA users, as well as UK GDPR equivalents. In healthcare contexts where meeting content includes protected health information, HIPAA applies and a Business Associate Agreement is required. The FTC Act's prohibition on unfair or deceptive practices is relevant to the adequacy of disclosure regarding what content is collected. 2. GOVERNANCE EXPOSURE: High. The collection of substantive communication content, including audio, video, and transcripts, creates material compliance exposure for enterprises in regulated industries such as legal, healthcare, financial services, and government. The scope of this collection may require organizations to update data inventories and assess whether existing retention and deletion policies account for Zoom-held communication records. 3. JURISDICTION FLAGS: EU and EEA users have GDPR rights to access and deletion of collected content. California residents have CCPA rights to know what categories of personal information are collected. In healthcare deployments in the US, the absence of a signed BAA before deploying Zoom for PHI-containing meetings creates HIPAA exposure. Illinois BIPA may be engaged if biometric data is derived from video content. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement teams should verify that data processing agreements with Zoom address meeting content retention periods, deletion procedures, and restrictions on secondary use. Organizations should assess whether their own internal data retention policies are consistent with data Zoom may retain about meeting content. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should map Zoom meeting content collection against their data classification frameworks and determine whether confidential or privileged communications processed through Zoom require additional contractual protections or platform configuration changes, such as disabling AI features for sensitive meeting categories.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has jurisdiction over consumer data collection practices under the FTC Act's prohibition on unfair or deceptive practices, relevant to the scope and disclosure of meeting content collection.
    File a complaint →
  • Hhs Ocr
    Where meeting content includes protected health information, HIPAA applies and HHS OCR has enforcement authority over covered entities and their business associates.
    File a complaint →

Applicable regulations

EU AI Act
European Union
BIPA
Illinois, USA
CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
UK GDPR
United Kingdom
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Zoom Privacy Statement
Entity
Zoom
Document last updated
May 5, 2026
Tracking information
First tracked
May 20, 2026
Last verified
May 20, 2026
Record ID
CA-P-012532
Document ID
CA-D-00190
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
a287334eb71574e4fff5a2fb1521cc15c5d1a96621caa1ebefdb06dc715c9b47
Analysis generated
May 20, 2026 22:29 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Zoom
Document: Zoom Privacy Statement
Record ID: CA-P-012532
Captured: 2026-05-20 22:29:53 UTC
SHA-256: a287334eb71574e4…
URL: https://conductatlas.com/platform/zoom/zoom-privacy-statement/meeting-content-collection/
Accessed: June 8, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Zoom's Meeting Content Collection clause do?

This provision establishes that Zoom's data collection scope includes the substantive content of communications, not only metadata or usage signals. For enterprise accounts processing confidential business discussions, legal communications, or healthcare-related conversations, this collection scope is relevant to data classification and retention assessments.

How does this clause affect you?

The agreement establishes that audio, video, chat, and transcript data generated during Zoom sessions may be collected and processed by Zoom. Users who enable features such as AI Companion summaries or transcription authorize additional processing of this content as described in the AI provisions.

Is ConductAtlas affiliated with Zoom?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Zoom.