Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Personal data shared with third-party apps and integrations installed through the Zoom App Marketplace is governed by those developers' own terms and privacy policies, not by Zoom's Privacy Statement. The range of data that may be shared with approved apps includes account information, contact information, participant lists, meeting content, device information, and third-party emails.
This analysis describes what Zoom's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that once personal data is shared with third-party apps authorized on a Zoom account, Zoom's Privacy Statement no longer governs that data. The breadth of data categories that may be shared (including meeting content, participant lists, and third-party emails) means that app authorization decisions by account owners have significant downstream privacy implications for all users on those accounts.
This provision establishes that personal data shared with third-party apps approved by account owners is governed by the developer's own terms and privacy policies rather than Zoom's. Users on accounts where third-party apps are enabled should be aware that their data, potentially including meeting content, contact information, and device information, may be processed under different privacy terms once shared with those apps.
Cross-platform context
See how other platforms handle Third-Party App Data Governed by Developer Terms and similar clauses.
Compare across platforms →Monitoring
Zoom has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Personal information shared by account owners and users with third-party apps and integrations is collected and processed in accordance with the app developers' terms and privacy policies, not Zoom's. Depending on their settings, account owners', users' and guests' personal data and content may be shared with apps and integrations, including Zoom-developed apps, approved by account owners, which may include all of the personal data categories listed above, such as account information, profile and contact information, registration information, participants list, settings, content, product usage, device information, or third-party emails that have been shared with the app.Excerpt from Zoom's Privacy Statement
1. REGULATORY LANDSCAPE: This provision engages GDPR requirements for data controller accountability and the obligation to ensure downstream processors and controllers provide adequate protections. Where a third-party app acts as an independent data controller upon receiving user data, the Zoom account owner and individual users may have limited recourse under Zoom's privacy framework. CCPA similarly requires disclosure of third parties with whom personal information is shared and the purposes of sharing. The FTC has addressed platform accountability for third-party app data practices. 2. GOVERNANCE EXPOSURE: High. Enterprise account owners who authorize third-party apps assume de facto responsibility for assessing those apps' data practices, since Zoom's Privacy Statement explicitly states its protections do not extend to data shared with those apps. The breadth of data categories that may be shared, including meeting content and third-party email content, represents a material data governance gap if app authorization decisions are not subject to rigorous vendor assessment. 3. JURISDICTION FLAGS: EU and UK GDPR impose data controller accountability obligations that may require enterprise account owners to conduct due diligence on third-party apps as independent data controllers or processors. California CCPA may require disclosure of the specific apps with whom personal information is shared. Sector-specific regulations in financial services (GLBA) and healthcare (HIPAA) may restrict sharing of regulated data with third-party apps that have not entered into appropriate agreements. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement and compliance teams should establish an app authorization governance process for any third-party apps enabled on organizational Zoom accounts. Each authorized app should be assessed as an independent data controller or processor, with appropriate data processing agreements in place where required by GDPR or sector-specific regulation. The provision's statement that Zoom's protections do not extend to third-party apps effectively transfers data governance responsibility to the account owner for authorized apps. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should audit which third-party apps are currently authorized on their Zoom accounts and assess whether those apps' privacy policies and terms are consistent with the organization's data protection obligations. HIPAA-covered entities and financial services organizations should confirm that no regulated data categories are shared with third-party apps lacking appropriate agreements. A periodic review process for app authorizations should be established.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that once personal data is shared with third-party apps authorized on a Zoom account, Zoom's Privacy Statement no longer governs that data. The breadth of data categories that may be shared (including meeting content, participant lists, and third-party emails) means that app authorization decisions by account owners have significant downstream privacy implications for all users on those …
This provision establishes that personal data shared with third-party apps approved by account owners is governed by the developer's own terms and privacy policies rather than Zoom's. Users on accounts where third-party apps are enabled should be aware that their data, potentially including meeting content, contact information, and device information, may be processed under different privacy terms once shared with …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Zoom.