Zoom · Zoom Privacy Statement · View original document ↗

Account Owner Access to Participant Messages and Content

High severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Zoom changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Zoom recorded 4 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Zoom Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

Account owners and their designated administrators may access participant message content, direct messages, recordings, transcripts, and collaborative feature content generated by users on their accounts, subject to their configured settings. The scope of access includes in-meeting chat, Zoom Chat, direct messages under archiving, email and calendar content on Zoom Email accounts, and content from collaborative features such as whiteboards and polls.

This analysis describes what Zoom's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that organizations operating as Zoom account owners have broad visibility into communications and content generated by users on their accounts, including direct messages when archiving is enabled. The scope of access depends on account settings but includes categories of content that employees or participants may not expect to be accessible to their employer or hosting organization.

Clause Stability Stable

0
Changes
3
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

This provision establishes that account owners such as employers or educational institutions may access participant messages, direct messages under archiving configurations, recordings, transcripts, and collaborative feature content. Under this clause, individuals using Zoom through an organizational account should be aware that their account owner's settings determine the extent of visibility into their communications.

Cross-platform context

See how other platforms handle Account Owner Access to Participant Messages and Content and similar clauses.

Compare across platforms →

Monitoring

Zoom has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Depending on their settings, account owners and the users they designate can access personal data for participants who join meetings and webinars on their account or send messages to users on their account. Depending on their settings, account owners also can see sender and receiver information, and other messaging data, along with the content of messages sent to and from users on their account (including from in-meeting chat where dedicated meeting group chats are enabled), unless the account owner has enabled Advanced Chat Encryption. If a participant in a meeting is subject to archiving, their account owner will have access to messages sent to Everyone in the meeting, as well as direct messages sent to that participant.

Excerpt from Zoom's Privacy Statement

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision engages GDPR Article 6 (lawful basis for processing) and Article 88 (processing in the context of employment), which in several EU member states requires explicit employee monitoring disclosures and in some jurisdictions works council consultation before implementing monitoring measures. In the UK, the ICO Employment Practices Code addresses monitoring of electronic communications. In the U.S., the Electronic Communications Privacy Act and state wiretapping laws may interact with employer monitoring of employee communications depending on jurisdiction and consent configurations. CCPA and applicable U.S. state privacy laws may require employer notice to employees as consumers where personal data is accessed. 2. GOVERNANCE EXPOSURE: High. Enterprise customers acting as account owners bear independent compliance obligations for the monitoring and archiving of employee or participant communications. The provision authorizes access to direct messages when archiving is enabled, which represents a category of content that participants may reasonably expect to be private. Compliance with applicable employee monitoring laws requires affirmative disclosure and, in some EU jurisdictions, consent or works council approval before enabling archiving. 3. JURISDICTION FLAGS: EU member states (particularly Germany, France, and the Netherlands) impose the most stringent employee monitoring requirements, including works council consultation obligations. The UK ICO Employment Practices Code requires proportionality assessments. In the U.S., states including Connecticut, Delaware, and New York have enacted employee monitoring disclosure statutes. Illinois and other states with electronic surveillance laws may also interact with this provision. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement teams should confirm that their data processing agreement with Zoom accurately reflects the controller-processor relationship for Customer Content accessed by account owners. Organizations enabling archiving should assess whether their employment contracts, acceptable use policies, and onboarding disclosures adequately notify users of monitoring. The provision that access depends on settings creates a shared responsibility model that may require internal controls documentation. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should audit current archiving and recording configurations against applicable employee monitoring disclosure requirements by jurisdiction. Where Zoom is deployed across multiple jurisdictions, a jurisdiction-by-jurisdiction assessment of monitoring consent and disclosure obligations is warranted. Internal policy updates may be required to align with the scope of access disclosed in this provision.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has authority over unfair or deceptive practices related to consumer privacy disclosures, including employer monitoring practices that may not be adequately disclosed to users.
    File a complaint →
  • State AG
    State attorneys general in jurisdictions with employee monitoring statutes (e.g., Connecticut, Delaware, New York) may have enforcement authority over monitoring disclosure requirements applicable to organizational Zoom account owners.
    File a complaint →

Provision details

Document information
Document
Zoom Privacy Statement
Entity
Zoom
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014447
Document ID
CA-D-00190
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
2cdaf89746b4ead6eb84dcc77d42c153ed2873fbea3fa5dae94f8a50d9833ee5
Analysis generated
July 9, 2026 05:36 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Zoom
Document: Zoom Privacy Statement
Record ID: CA-P-014447
Captured: 2026-07-09 05:36:51 UTC
SHA-256: 2cdaf89746b4ead6…
URL: https://conductatlas.com/platform/zoom/zoom-privacy-statement/provision/CA-P-014447/account-owner-access-to-participant-messages-and-content/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Zoom's Account Owner Access to Participant Messages and Content clause do?

This provision establishes that organizations operating as Zoom account owners have broad visibility into communications and content generated by users on their accounts, including direct messages when archiving is enabled. The scope of access depends on account settings but includes categories of content that employees or participants may not expect to be accessible to their employer or hosting organization.

How does this clause affect you?

This provision establishes that account owners such as employers or educational institutions may access participant messages, direct messages under archiving configurations, recordings, transcripts, and collaborative feature content. Under this clause, individuals using Zoom through an organizational account should be aware that their account owner's settings determine the extent of visibility into their communications.

Is ConductAtlas affiliated with Zoom?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Zoom.