Zoom · Zoom Privacy Statement · View original document ↗

International Data Transfers

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Zoom changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Zoom recorded 4 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Zoom Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

Zoom transfers personal data globally, including to the United States and countries outside the EEA, Switzerland, and UK, which may have less protective data protection rules. The statement states Zoom takes appropriate contractual or other steps to protect personal data under applicable laws during such transfers.

This analysis describes what Zoom's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision discloses that personal data may be transferred to jurisdictions with different or less protective data protection frameworks, and references use of appropriate transfer mechanisms. For EEA, Swiss, and UK users, the adequacy of transfer mechanisms such as standard contractual clauses is a material compliance consideration following Schrems II and related regulatory guidance.

Interpretive note: The statement does not specify which transfer mechanisms (standard contractual clauses, DPF certification, adequacy decisions) apply to specific transfer scenarios, which creates some ambiguity regarding the applicable legal basis for particular data flows.

Clause Stability Stable

0
Changes
3
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Change history

added Jul 18, 2026

This new provision explicitly discloses cross-border data transfers without geographic limitations, which affects users' data protection rights depending on their jurisdiction.

View full change record →
removed May 23, 2026

Removal of explicit mention of Standard Contractual Clauses and specific safeguards for international data transfers reduces transparency about GDPR/UK-GDPR compliance mechanisms for cross-border data flows.

View full change record →

Consumer impact (what this means for users)

This provision discloses that personal data of users in the EEA, Switzerland, UK, and other regions may be transferred to the United States and other countries, and that those countries may have different or less protective data protection rules. The statement indicates Zoom uses contractual or other protective steps for such transfers under applicable law.

Cross-platform context

See how other platforms handle International Data Transfers and similar clauses.

Compare across platforms →

Monitoring

Zoom has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Zoom operates globally, which means personal data may be transferred, stored (for example, in a data center), and processed outside of the country or region where it was initially collected where Zoom or its service providers have customers or facilities – including in countries where meeting participants or account owners hosting meetings or webinars that you participate in or receiving messages that you send are based. Therefore, by using Zoom products and services or providing personal data for any of the purposes stated above, you acknowledge that your personal data may be transferred to or stored in the United States where we are established, as well as in other countries outside of the EEA, Switzerland, and the UK. Such countries may have data protection rules that are different and less protective than those of your country.

Excerpt from Zoom's Privacy Statement

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: International data transfer provisions engage GDPR Chapter V (transfers to third countries), the UK GDPR international transfer framework (including UK SCCs and the UK Adequacy Regulations), and the Swiss Federal Act on Data Protection (revFADP). The EU-U.S. Data Privacy Framework (DPF) established in 2023 provides an adequacy mechanism for transfers to certified U.S. organizations, though its continued validity is subject to legal and political developments. The CJEU's Schrems II decision (C-311/18) invalidated Privacy Shield and imposed additional due diligence requirements for standard contractual clauses, including transfer impact assessments. Primary enforcement authorities are EU national data protection authorities, the UK ICO, and the Swiss Federal Data Protection and Information Commissioner. 2. GOVERNANCE EXPOSURE: Medium. The statement references use of appropriate contractual or other protective steps but does not specify which transfer mechanisms (standard contractual clauses, adequacy decisions, DPF certification, binding corporate rules) are employed in specific transfer scenarios. Enterprise customers subject to GDPR must ensure their data processing agreements with Zoom address transfer mechanisms and may need to conduct transfer impact assessments for transfers to the U.S. and other third countries. 3. JURISDICTION FLAGS: EEA users have the highest exposure given GDPR Chapter V requirements and the potential for supervisory authority enforcement actions. UK users are subject to UK GDPR transfer requirements. Swiss users are subject to revFADP. Organizations in sectors subject to data localization requirements (such as financial services in certain EU member states) may face additional restrictions on cross-border transfers. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers should confirm which transfer mechanisms Zoom relies upon for data flows from the EEA, UK, and Switzerland to the U.S. and other third countries, and whether transfer impact assessments have been conducted. Data processing agreements should explicitly identify applicable transfer mechanisms. For customers in financial services or healthcare, sector-specific data localization or transfer restrictions may require additional contractual or technical controls. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should map personal data flows from their Zoom deployments to identify which transfer mechanisms apply. Transfer impact assessments should be conducted or updated in light of current regulatory guidance. Where Zoom relies on DPF certification, organizations should monitor for any legal challenges or regulatory developments that could affect DPF validity.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Applicable agencies

  • State AG
    State attorneys general may have jurisdiction over data transfer practices affecting residents of their states, particularly in jurisdictions with applicable data protection or consumer privacy laws.
    File a complaint →

Provision details

Document information
Document
Zoom Privacy Statement
Entity
Zoom
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014451
Document ID
CA-D-00190
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
2cdaf89746b4ead6eb84dcc77d42c153ed2873fbea3fa5dae94f8a50d9833ee5
Analysis generated
July 9, 2026 05:36 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Zoom
Document: Zoom Privacy Statement
Record ID: CA-P-014451
Captured: 2026-07-09 05:36:51 UTC
SHA-256: 2cdaf89746b4ead6…
URL: https://conductatlas.com/platform/zoom/zoom-privacy-statement/provision/CA-P-014451/international-data-transfers/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Frequently Asked Questions

What does Zoom's International Data Transfers clause do?

This provision discloses that personal data may be transferred to jurisdictions with different or less protective data protection frameworks, and references use of appropriate transfer mechanisms. For EEA, Swiss, and UK users, the adequacy of transfer mechanisms such as standard contractual clauses is a material compliance consideration following Schrems II and related regulatory guidance.

How does this clause affect you?

This provision discloses that personal data of users in the EEA, Switzerland, UK, and other regions may be transferred to the United States and other countries, and that those countries may have different or less protective data protection rules. The statement indicates Zoom uses contractual or other protective steps for such transfers under applicable law.

Is ConductAtlas affiliated with Zoom?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Zoom.