Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Zoom transfers personal data globally, including to the United States and countries outside the EEA, Switzerland, and UK, which may have less protective data protection rules. The statement states Zoom takes appropriate contractual or other steps to protect personal data under applicable laws during such transfers.
This analysis describes what Zoom's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision discloses that personal data may be transferred to jurisdictions with different or less protective data protection frameworks, and references use of appropriate transfer mechanisms. For EEA, Swiss, and UK users, the adequacy of transfer mechanisms such as standard contractual clauses is a material compliance consideration following Schrems II and related regulatory guidance.
Interpretive note: The statement does not specify which transfer mechanisms (standard contractual clauses, DPF certification, adequacy decisions) apply to specific transfer scenarios, which creates some ambiguity regarding the applicable legal basis for particular data flows.
This new provision explicitly discloses cross-border data transfers without geographic limitations, which affects users' data protection rights depending on their jurisdiction.
View full change record →Removal of explicit mention of Standard Contractual Clauses and specific safeguards for international data transfers reduces transparency about GDPR/UK-GDPR compliance mechanisms for cross-border data flows.
View full change record →This provision discloses that personal data of users in the EEA, Switzerland, UK, and other regions may be transferred to the United States and other countries, and that those countries may have different or less protective data protection rules. The statement indicates Zoom uses contractual or other protective steps for such transfers under applicable law.
Cross-platform context
See how other platforms handle International Data Transfers and similar clauses.
Compare across platforms →Monitoring
Zoom has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Zoom operates globally, which means personal data may be transferred, stored (for example, in a data center), and processed outside of the country or region where it was initially collected where Zoom or its service providers have customers or facilities – including in countries where meeting participants or account owners hosting meetings or webinars that you participate in or receiving messages that you send are based. Therefore, by using Zoom products and services or providing personal data for any of the purposes stated above, you acknowledge that your personal data may be transferred to or stored in the United States where we are established, as well as in other countries outside of the EEA, Switzerland, and the UK. Such countries may have data protection rules that are different and less protective than those of your country.Excerpt from Zoom's Privacy Statement
1. REGULATORY LANDSCAPE: International data transfer provisions engage GDPR Chapter V (transfers to third countries), the UK GDPR international transfer framework (including UK SCCs and the UK Adequacy Regulations), and the Swiss Federal Act on Data Protection (revFADP). The EU-U.S. Data Privacy Framework (DPF) established in 2023 provides an adequacy mechanism for transfers to certified U.S. organizations, though its continued validity is subject to legal and political developments. The CJEU's Schrems II decision (C-311/18) invalidated Privacy Shield and imposed additional due diligence requirements for standard contractual clauses, including transfer impact assessments. Primary enforcement authorities are EU national data protection authorities, the UK ICO, and the Swiss Federal Data Protection and Information Commissioner. 2. GOVERNANCE EXPOSURE: Medium. The statement references use of appropriate contractual or other protective steps but does not specify which transfer mechanisms (standard contractual clauses, adequacy decisions, DPF certification, binding corporate rules) are employed in specific transfer scenarios. Enterprise customers subject to GDPR must ensure their data processing agreements with Zoom address transfer mechanisms and may need to conduct transfer impact assessments for transfers to the U.S. and other third countries. 3. JURISDICTION FLAGS: EEA users have the highest exposure given GDPR Chapter V requirements and the potential for supervisory authority enforcement actions. UK users are subject to UK GDPR transfer requirements. Swiss users are subject to revFADP. Organizations in sectors subject to data localization requirements (such as financial services in certain EU member states) may face additional restrictions on cross-border transfers. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers should confirm which transfer mechanisms Zoom relies upon for data flows from the EEA, UK, and Switzerland to the U.S. and other third countries, and whether transfer impact assessments have been conducted. Data processing agreements should explicitly identify applicable transfer mechanisms. For customers in financial services or healthcare, sector-specific data localization or transfer restrictions may require additional contractual or technical controls. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should map personal data flows from their Zoom deployments to identify which transfer mechanisms apply. Transfer impact assessments should be conducted or updated in light of current regulatory guidance. Where Zoom relies on DPF certification, organizations should monitor for any legal challenges or regulatory developments that could affect DPF validity.
This provision discloses that personal data may be transferred to jurisdictions with different or less protective data protection frameworks, and references use of appropriate transfer mechanisms. For EEA, Swiss, and UK users, the adequacy of transfer mechanisms such as standard contractual clauses is a material compliance consideration following Schrems II and related regulatory guidance.
This provision discloses that personal data of users in the EEA, Switzerland, UK, and other regions may be transferred to the United States and other countries, and that those countries may have different or less protective data protection rules. The statement indicates Zoom uses contractual or other protective steps for such transfers under applicable law.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Zoom.