Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Zoom's terms permit resellers through whom account owners obtained Zoom licenses to access personal data and content belonging to users on those accounts, including meeting, webinar, and message content.
This analysis describes what Zoom's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision discloses that reseller partners in the Zoom channel ecosystem may have access to user personal data and content, including meeting and message content, for accounts they sold. This creates an additional data access layer beyond Zoom and the direct account owner that may not be apparent to individual users.
This new provision discloses that resellers may access all user personal data and meeting content, creating an additional third-party access pathway not previously disclosed.
View full change record →This provision establishes that if an organization purchased Zoom through a reseller, that reseller may access personal data and content for users on the account, including meetings, webinars, and messages. Individual users operating under reseller-sourced accounts may have their data accessible to an additional third party.
Cross-platform context
See how other platforms handle Reseller Access to User Personal Data and similar clauses.
Compare across platforms →Monitoring
Zoom has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"If an account owner licensed or purchased Zoom products and services from a third-party reseller of Zoom products and services, the reseller may be able to access personal data and content for users, including meetings, webinars, and messages hosted by the account owner.Excerpt from Zoom's Privacy Statement
1. REGULATORY LANDSCAPE: This provision engages GDPR requirements for disclosure of data recipients and data sharing with third parties, requiring that data subjects be informed of the categories of recipients of their personal data. CCPA requires disclosure of categories of third parties with whom personal information is shared. The reseller access disclosure may need to be reflected in employer-to-employee privacy notices where the account is employer-provided. 2. GOVERNANCE EXPOSURE: Medium. Enterprise customers who procured Zoom through channel partners or resellers should assess what data access those resellers have under their reseller agreements with Zoom, and whether such access is disclosed in their own employee or end-user privacy notices. The provision does not specify the conditions under which reseller access is exercised or limited. 3. JURISDICTION FLAGS: GDPR and UK GDPR require specific disclosure of data recipients, including resellers, in privacy notices provided to data subjects. California residents are entitled to know the categories of third parties with whom their personal information is shared. Organizations in regulated sectors may have contractual or regulatory restrictions on third-party access to customer data that interact with this provision. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should review reseller agreements to understand the scope of data access rights granted to resellers and whether those rights are consistent with the organization's own data protection obligations. Reseller access to meeting and message content may be relevant to legal hold and e-discovery workflows. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should determine whether their Zoom account was procured through a reseller and, if so, assess whether the reseller's data access is adequately disclosed in applicable employee or end-user privacy notices. Data processing agreements should address the reseller's role as a data recipient and the conditions governing their access.
This provision discloses that reseller partners in the Zoom channel ecosystem may have access to user personal data and content, including meeting and message content, for accounts they sold. This creates an additional data access layer beyond Zoom and the direct account owner that may not be apparent to individual users.
This provision establishes that if an organization purchased Zoom through a reseller, that reseller may access personal data and content for users on the account, including meetings, webinars, and messages. Individual users operating under reseller-sourced accounts may have their data accessible to an additional third party.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Zoom.