Zoom states that all entities within the Zoom Group, including affiliates in China, India, South Korea, Saudi Arabia, Ireland, and other jurisdictions, have executed an intra-group data transfer agreement incorporating EU Standard Contractual Clauses.
This analysis describes what Zoom's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The document asserts SCCs as the transfer mechanism for intra-group transfers involving affiliates in China, Saudi Arabia, and other jurisdictions that lack EU adequacy status; the adequacy of SCCs for transfers to China in particular engages ongoing regulatory uncertainty given China's PIPL cross-border data transfer requirements and EU DPA scrutiny of transfers to jurisdictions with state surveillance concerns.
Interpretive note: The document does not specify which Chinese or Saudi Arabian affiliates access customer data, what categories of data are involved, or whether Chinese PIPL cross-border transfer requirements have been separately satisfied alongside the EU SCC mechanism.
Under this provision, personal data may flow among Zoom Group entities globally, including entities registered in China, Saudi Arabia, South Korea, and India, under an intra-group agreement incorporating EU SCCs. The document does not specify which categories of personal data are shared among affiliates or which affiliate entities act as processors versus independent controllers.
Cross-platform context
See how other platforms handle Zoom Affiliate Intra-Group Data Transfer Agreement and similar clauses.
Compare across platforms →"All parties of the Zoom Group have entered a data transfer agreement that sets out the data protection requirements and incorporates the appropriate EU Standard Contractual Clauses ("SCCs").Excerpt from Zoom's Sub-Processors
1) REGULATORY LANDSCAPE: This provision engages GDPR Chapter V for transfers involving EU-originating data flowing to Zoom affiliates in China, Saudi Arabia, South Korea, and other non-adequacy jurisdictions.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The document asserts SCCs as the transfer mechanism for intra-group transfers involving affiliates in China, Saudi Arabia, and other jurisdictions that lack EU adequacy status; the adequacy of SCCs for transfers to China in particular engages ongoing regulatory uncertainty given China's PIPL cross-border data transfer requirements and EU DPA scrutiny of transfers to jurisdictions with state surveillance concerns.
Under this provision, personal data may flow among Zoom Group entities globally, including entities registered in China, Saudi Arabia, South Korea, and India, under an intra-group agreement incorporating EU SCCs. The document does not specify which categories of personal data are shared among affiliates or which affiliate entities act as processors versus independent controllers.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Zoom.