Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Zoom collects behavioral usage data including mouse movements, clicks, and keystrokes (described as authorized by the account owner) to understand feature usage, improve product design, and suggest features. The statement notes that some usage data collection is optional and may be controlled via a Diagnostic Data Preferences Setting.
This analysis describes what Zoom's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision discloses collection of granular behavioral interaction data including keystroke-level inputs, which is a detailed category of behavioral monitoring. The statement conditions certain collection on account owner authorization and notes an optional Diagnostic Data Preferences Setting for some usage data, but does not fully delineate which specific data types are subject to that opt-out.
Interpretive note: The statement does not fully specify which behavioral data types (including keystroke collection) are subject to the Diagnostic Data Preferences Setting opt-out versus which are collected as a baseline operational requirement.
This new provision explicitly discloses collection of granular interaction data including keystrokes and mouse movements, which represents detailed behavioral tracking previously not transparently disclosed.
View full change record →This provision discloses that Zoom collects mouse movements, clicks, and keystrokes during use of its products, where authorized by the account owner, for purposes of feature usage analysis and product improvement. Under this clause, some usage data collection can be managed through the Diagnostic Data Preferences Setting in user account settings.
Cross-platform context
See how other platforms handle Usage Data Collection Including Keystrokes and Mouse Movements and similar clauses.
Compare across platforms →Monitoring
Zoom has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Information about how people and their devices interact with Zoom products and services, such as: when participants join and leave a meeting; whether participants sent messages and who they message with; performance data; mouse movements, clicks, keystrokes or actions (such as mute/unmute or video on/off), edits to transcript text, where authorized by the account owner and other inputs that help Zoom to understand feature usage, improve product design, and suggest features.Excerpt from Zoom's Privacy Statement
1. REGULATORY LANDSCAPE: Collection of keystroke and mouse movement data engages GDPR principles of data minimization and purpose limitation under Articles 5 and 25. In employment contexts, such behavioral monitoring may engage EU member state labor law monitoring requirements and works council consultation obligations. The UK ICO Employment Practices Code addresses proportionality of employee monitoring. In the U.S., state electronic surveillance laws in states including California (CIPA), Illinois, and others may interact with keystroke collection depending on consent configuration. 2. GOVERNANCE EXPOSURE: Medium. The collection of keystroke and mouse movement data is conditioned on account owner authorization, which means enterprise customers bear responsibility for ensuring that any such collection authorized on their accounts is disclosed to and, where required, consented to by their employees or users. The statement does not fully specify which behavioral data types are subject to the Diagnostic Data Preferences Setting opt-out. 3. JURISDICTION FLAGS: EU member states with co-determination requirements (Germany, Netherlands, France) may require works council consultation before enabling behavioral monitoring features. California's CIPA and Illinois Electronic Communications Privacy Act may interact with keystroke collection in certain contexts. Healthcare and financial services organizations may face sector-specific restrictions on behavioral monitoring tools. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers should review which behavioral data collection features are enabled in their Zoom accounts and ensure applicable employee monitoring disclosures are in place. The statement's reference to account owner authorization as a condition for some behavioral data collection should be documented in internal governance records. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should audit which usage data collection features are currently active on their Zoom accounts and assess disclosure adequacy for employees and users. The Diagnostic Data Preferences Setting should be reviewed to confirm which data types it controls. Organizations in EU jurisdictions should assess whether works council consultation is required before enabling behavioral monitoring features.
This provision discloses collection of granular behavioral interaction data including keystroke-level inputs, which is a detailed category of behavioral monitoring. The statement conditions certain collection on account owner authorization and notes an optional Diagnostic Data Preferences Setting for some usage data, but does not fully delineate which specific data types are subject to that opt-out.
This provision discloses that Zoom collects mouse movements, clicks, and keystrokes during use of its products, where authorized by the account owner, for purposes of feature usage analysis and product improvement. Under this clause, some usage data collection can be managed through the Diagnostic Data Preferences Setting in user account settings.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Zoom.