Zoom · Zoom Privacy Statement · View original document ↗

Biometric Data Processing (Facial Geometry and Voiceprint)

High severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Zoom changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Zoom recorded 4 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Zoom Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

Zoom may collect and process biometric identifiers including facial geometry and voiceprint when users opt into certain enhanced features, subject to user consent. The data is subject to a deletion schedule tied to feature discontinuation or a two-year inactivity period, whichever comes first.

This analysis describes what Zoom's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision requires user opt-in consent and establishes a defined retention and deletion schedule for biometric identifiers. The collection of facial geometry and voiceprint data engages state biometric privacy laws, particularly Illinois BIPA, which imposes specific written consent, retention schedule publication, and destruction requirements that may impose obligations beyond what this provision alone establishes.

Clause Stability Stable

0
Changes
3
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

This provision establishes that Zoom processes biometric identifiers including facial geometry and voiceprint only when users affirmatively opt in and provide required consent, with deletion occurring upon feature discontinuation or after two years of inactivity. Users who do not opt into these enhanced features will not have biometric data collected under this clause.

Cross-platform context

See how other platforms handle Biometric Data Processing (Facial Geometry and Voiceprint) and similar clauses.

Compare across platforms →

Monitoring

Zoom has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
If you elect to enable certain features and you provide the requisite consent, Zoom may process data about your unique physical characteristics, including your facial geometry and/or voiceprint, for the purpose of offering the features. This data will be deleted when no longer necessary, adequate, or relevant to offering the features or when two years have passed since your last interaction with Zoom, whichever occurs first. Your account owner or administrator may need to enable these features before you can elect to enable them and/or may have the ability to disable the features on your behalf.

Excerpt from Zoom's Privacy Statement

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision directly engages Illinois BIPA (740 ILCS 14), which requires written informed consent before collecting biometric identifiers, a publicly available written retention schedule and destruction policy, and prohibition on sale or profit from biometric data. Texas CUBI (Tex. Bus. & Com. Code Ch. 503) and Washington's My Health MY Data Act also regulate biometric data collection. Under GDPR Article 9, biometric data constitutes special category data requiring explicit consent and additional safeguards. The UK GDPR imposes equivalent requirements. Enforcement authorities include the Illinois Attorney General and private plaintiffs under BIPA's private right of action, state attorneys general in Texas and Washington, and EU/UK data protection authorities. 2. GOVERNANCE EXPOSURE: High. Illinois BIPA's private right of action and per-violation statutory damages ($1,000 per negligent violation, $5,000 per intentional or reckless violation) create material litigation exposure for organizations deploying Zoom features that collect facial geometry or voiceprint data from Illinois residents. The statement discloses a two-year maximum retention period, but BIPA requires a publicly available written retention schedule and destruction policy, which organizations enabling these features should verify is in place. 3. JURISDICTION FLAGS: Illinois creates the highest exposure given BIPA's private right of action. Texas and Washington impose similar but administratively enforced requirements. GDPR and UK GDPR require explicit consent and data protection impact assessments for special category data processing. Organizations deploying these features to employees or users in these jurisdictions require jurisdiction-specific consent flows and retention schedule documentation. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers enabling biometric features should ensure their data processing agreement with Zoom addresses the specific handling, retention, and destruction of biometric data consistent with BIPA and applicable state law requirements. The statement notes account owners can enable or disable these features, which places configuration responsibility on the enterprise customer. Procurement teams should assess whether Zoom's BIPA compliance documentation is sufficient for enterprise indemnification purposes. 5. COMPLIANCE CONSIDERATIONS: Organizations should audit whether biometric-dependent Zoom features are enabled within their accounts and, if so, whether user consent flows satisfy BIPA and applicable state law requirements. A published biometric data retention and destruction policy, separate from this privacy statement, may be required under BIPA. GDPR Data Protection Impact Assessments should be conducted for EEA deployments involving biometric data processing.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • State AG
    State attorneys general in Illinois, Texas, and Washington have enforcement authority over biometric privacy laws (BIPA, CUBI, and My Health MY Data Act) applicable to biometric data collection described in this provision.
    File a complaint →
  • FTC
    The FTC has authority over unfair or deceptive practices related to biometric data collection and may evaluate whether consent mechanisms and data handling practices align with disclosed terms.
    File a complaint →

Provision details

Document information
Document
Zoom Privacy Statement
Entity
Zoom
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014448
Document ID
CA-D-00190
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
2cdaf89746b4ead6eb84dcc77d42c153ed2873fbea3fa5dae94f8a50d9833ee5
Analysis generated
July 9, 2026 05:36 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Zoom
Document: Zoom Privacy Statement
Record ID: CA-P-014448
Captured: 2026-07-09 05:36:51 UTC
SHA-256: 2cdaf89746b4ead6…
URL: https://conductatlas.com/platform/zoom/zoom-privacy-statement/provision/CA-P-014448/biometric-data-processing-facial-geometry-and-voiceprint/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Zoom's Biometric Data Processing (Facial Geometry and Voiceprint) clause do?

This provision requires user opt-in consent and establishes a defined retention and deletion schedule for biometric identifiers. The collection of facial geometry and voiceprint data engages state biometric privacy laws, particularly Illinois BIPA, which imposes specific written consent, retention schedule publication, and destruction requirements that may impose obligations beyond what this provision alone establishes.

How does this clause affect you?

This provision establishes that Zoom processes biometric identifiers including facial geometry and voiceprint only when users affirmatively opt in and provide required consent, with deletion occurring upon feature discontinuation or after two years of inactivity. Users who do not opt into these enhanced features will not have biometric data collected under this clause.

Is ConductAtlas affiliated with Zoom?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Zoom.