41 Total
14 High severity
22 Medium severity
5 Low severity
Summary

This is Zoom's public disclosure of the third-party companies and internal group entities authorized to process personal data on behalf of Zoom's enterprise customers. The document identifies specific data categories shared with each subprocessor, including real-time meeting traffic, cloud recordings, transcriptions, uploaded files, Customer Content for AI processing, payment card details, and identity and account metadata, along with the countries where that processing occurs and the legal mechanism governing international transfers. A notable provision states that several AI vendors including Anthropic, OpenAI, Perplexity, ElevenLabs, Suki AI, and Sumit-AI may process Customer Content and context when AI features are enabled, with all such processing occurring in the United States or European Union under SCCs.

Technical / Legal Breakdown

This document is Zoom's Third-Party Subprocessor and Affiliate disclosure list, effective 29 April 2026, published under obligations arising from Zoom's Data Processing Agreement (DPA) and applicable data protection frameworks including the EU General Data Protection Regulation. The document states that Zoom requires all subprocessors to satisfy equivalent obligations as those imposed on Zoom as a Data Processor under its DPA, including processing personal data per controller instructions, maintaining personnel confidentiality obligations, reporting security breaches promptly, and cooperating with data subject and regulatory requests. The document identifies 25 third-party subprocessors, several of which are AI-focused vendors including Anthropic, OpenAI, Perplexity, ElevenLabs, Suki AI, and Sumit-AI, each authorized to process Customer Content and context when AI features are enabled, with transfers to the United States as the primary processing location and Standard Contractual Clauses (SCCs) as the stated transfer mechanism for most entries; Oracle relies on Binding Corporate Rules and includes Saudi Arabia as a processing location. The document engages GDPR and its Chapter V international transfer requirements, as well as jurisdiction-specific data protection regimes applicable to Zoom's affiliates in China, India, South Korea, Saudi Arabia, and other locations; the adequacy of SCCs as a transfer mechanism in these contexts may require evaluation under current regulatory guidance, particularly following Schrems II and evolving enforcement posture in the EU. Compliance teams reviewing vendor and affiliate exposure should note that Zoom's Chinese affiliates, including entities in Shanghai, Hangzhou, Wuhan, and Suzhou, are listed without an explicit international transfer mechanism, and that the affiliate-level data transfer agreement incorporating SCCs is referenced but not separately published in this document.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Get Compliance
Featured — High severity
Featured — Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

41 provisions
12 featured
9 clause types
14 high severity
data_sharing 28
legal_jurisdiction 4
data_usage 2
privacy_rights 2
data_collection 1
data_retention 1
other 1
payment_fees 1
policy_changes 1

Monitoring

Zoom has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Get Compliance

Cross-platform context

See how other platforms handle All Zoom Group affiliates bound by intra-group data transfer agreement and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

BIPA
Illinois, USA
View official text ↗
CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
UK GDPR
United Kingdom
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured July 6, 2026 22:44 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000930
Version ID CA-V-004528
SHA-256 144798ca3a98501441f47060f315ea5ef2278a02e7cf3920b5f7e32307047e01
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans