Track 3 platforms and get the weekly governance digest. No credit card required.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This is Zoom's public disclosure of the third-party companies and internal group entities authorized to process personal data on behalf of Zoom's enterprise customers. The document identifies specific data categories shared with each subprocessor, including real-time meeting traffic, cloud recordings, transcriptions, uploaded files, Customer Content for AI processing, payment card details, and identity and account metadata, along with the countries where that processing occurs and the legal mechanism governing international transfers. A notable provision states that several AI vendors including Anthropic, OpenAI, Perplexity, ElevenLabs, Suki AI, and Sumit-AI may process Customer Content and context when AI features are enabled, with all such processing occurring in the United States or European Union under SCCs.
This document is Zoom's Third-Party Subprocessor and Affiliate disclosure list, effective 29 April 2026, published under obligations arising from Zoom's Data Processing Agreement (DPA) and applicable data protection frameworks including the EU General Data Protection Regulation. The document states that Zoom requires all subprocessors to satisfy equivalent obligations as those imposed on Zoom as a Data Processor under its DPA, including processing personal data per controller instructions, maintaining personnel confidentiality obligations, reporting security breaches promptly, and cooperating with data subject and regulatory requests. The document identifies 25 third-party subprocessors, several of which are AI-focused vendors including Anthropic, OpenAI, Perplexity, ElevenLabs, Suki AI, and Sumit-AI, each authorized to process Customer Content and context when AI features are enabled, with transfers to the United States as the primary processing location and Standard Contractual Clauses (SCCs) as the stated transfer mechanism for most entries; Oracle relies on Binding Corporate Rules and includes Saudi Arabia as a processing location. The document engages GDPR and its Chapter V international transfer requirements, as well as jurisdiction-specific data protection regimes applicable to Zoom's affiliates in China, India, South Korea, Saudi Arabia, and other locations; the adequacy of SCCs as a transfer mechanism in these contexts may require evaluation under current regulatory guidance, particularly following Schrems II and evolving enforcement posture in the EU. Compliance teams reviewing vendor and affiliate exposure should note that Zoom's Chinese affiliates, including entities in Shanghai, Hangzhou, Wuhan, and Suzhou, are listed without an explicit international transfer mechanism, and that the affiliate-level data transfer agreement incorporating SCCs is referenced but not separately published in this document.
Institutional analysis available with Compliance
Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.
Get ComplianceEvery distinct legal provision identified in this document. Featured provisions appear above with analysis.
Monitoring
Zoom has updated this document before.
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
Compliance Governance Intelligence
Need provision-level monitoring and regulatory mapping?
Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.
Get ComplianceCross-platform context
See how other platforms handle All Zoom Group affiliates bound by intra-group data transfer agreement and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.