41 Total
14 High severity
22 Medium severity
5 Low severity

Key Facts

Does AWS process Customer Content and context if AI features are enabled?
AWS processes Customer Content and context for AI processing if AI features are enabled.
Does AWS process real-time meeting and webinar traffic?
AWS processes real-time meeting and webinar traffic, meeting and call recordings saved to the cloud, and transcriptions of meeting or call recordings as a cloud service provider.
Does AWS process meeting and call recordings saved to the cloud?
AWS processes real-time meeting and webinar traffic, meeting and call recordings saved to the cloud, and transcriptions of meeting or call recordings as a cloud service provider.
Does AWS process transcriptions of meeting or call recordings?
AWS processes real-time meeting and webinar traffic, meeting and call recordings saved to the cloud, and transcriptions of meeting or call recordings as a cloud service provider.
Have all parties of the Zoom Group entered a data transfer agreement?
All parties of the Zoom Group have entered a data transfer agreement that sets out data protection requirements and incorporates the appropriate EU Standard Contractual Clauses (SCCs).
Does the data transfer agreement incorporate the appropriate EU Standard Contractual Clauses?
All parties of the Zoom Group have entered a data transfer agreement that sets out data protection requirements and incorporates the appropriate EU Standard Contractual Clauses (SCCs).
May Anthropic process Customer Content and context if AI features are enabled?
Anthropic may process Customer Content and context if AI features are enabled.
Does Google Cloud process Customer Content and context if AI features are enabled?
Google Cloud processes Customer Content and context for AI processing if AI features are enabled.
Does Google Cloud Platform process real-time meeting and webinar traffic?
Google Cloud Platform processes real-time meeting and webinar traffic as a Cloud Service Provider and Intelligent Features Service Provider.
May OpenAI process Customer Content and context if AI features are enabled?
OpenAI may process Customer Content and context if AI features are enabled.
Stay ahead of the changes
Track Zoom and get the diff the day its terms change.
Summary

This document lists the outside companies that handle your data when you use Zoom, and sets rules for how those companies must protect it. Your live meeting traffic, cloud recordings, and transcriptions flow through major cloud providers like AWS and Google, and if you use Zoom's AI features, companies like OpenAI, Anthropic, Google Cloud, and AWS may also process your meeting content. Zoom contractually requires all of these sub-processors to follow the same data protection standards Zoom itself must meet.

Analysis

This document establishes Zoom's sub-processor framework, identifying the third-party entities that process personal data on behalf of Zoom's customers and the contractual obligations governing those arrangements. Key cloud infrastructure providers—AWS, Google Cloud Platform, and Oracle—process real-time meeting and webinar traffic, cloud recordings, and transcriptions. When AI features are enabled, AI providers including AWS, Google Cloud, Anthropic, and OpenAI may process Customer Content and context. Zoom requires all sub-processors to satisfy obligations equivalent to those Zoom itself bears under its Data Processing Agreement, and to process personal data solely per Customer instructions as relayed by Zoom. Intra-group Zoom transfers are governed by a data transfer agreement incorporating EU Standard Contractual Clauses, and Stripe processes payment and transaction data for Zoom Events.

What this means for you

As an individual user, your real-time meeting traffic, cloud-saved recordings, and transcriptions are processed by third-party cloud providers including AWS, Google Cloud Platform, and Oracle. If AI features are enabled on your account, your Customer Content and context may additionally be processed by Anthropic, OpenAI, and Google Cloud. Payment and transaction data—including bank account and card details—is processed by Stripe for Zoom Events transactions. Zoom requires all sub-processors to handle personal data only according to Customer instructions and to meet equivalent data protection standards to those in Zoom's own Data Processing Agreement. Notice of new sub-processors is provided to the Customer's account owner to the extent required by contract, and updates are posted on Zoom's sub-processor page.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

Featured, High severity
Featured, Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

41 provisions
12 featured
9 clause types
14 high severity
Data Sharing 28 10 high
Show all 28 data sharing provisions
Stay ahead of the changes

Monitoring

Zoom has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle All Zoom Group affiliates bound by intra-group data transfer agreement and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

BIPA
Illinois, USA
View official text ↗
CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
UK GDPR
United Kingdom
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured August 7, 2026 00:32 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000930
Version ID CA-V-005565
SHA-256 968a222126b500f108cfdd4c33ca7254eab1ba4f74a6c4af3528375983964a76
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans