GDPR check

Is Adobe Connect GDPR compliant? What universities should check

Adobe Connect is a virtual classroom, webinar and meeting platform used for distance teaching, webinars and online examinations. This page sets out what Adobe publicly documents about Connect's data handling, its data processing addendum, subprocessors, transfers and AI features, and what that means for an institution.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

Adobe states that it acts as a data processor for hosted and managed Adobe Connect services, and that for European business customers personal data is processed by Adobe Systems Software Ireland Limited under a data processing addendum with standard contractual clauses. Adobe also states that it complies with the EU-US Data Privacy Framework. Connect can also be deployed on-premises. The gaps in public documentation are Connect-specific: we did not find a public statement of Connect's hosting locations or of the subprocessors behind its new AI features. A university should get both in writing.

What Adobe documents publicly

The table summarises what Adobe states in its own documentation, read on 7 October 2026. Adobe's Connect help pages block automated fetching, so we read them in a browser. Where a document covers Adobe's cloud services generally rather than Connect specifically, we say so.

TopicWhat the vendor statesSource
Company and roleDocumented For hosted and managed services, Adobe is the processor and the organisations using Connect are controllers. For licensed (on-premises) deployments, the organisation is the controller and responsible for compliance. Adobe's privacy policy says Adobe is a processor when educational institutions use its products.Adobe Connect and GDPR [1], Privacy Policy [2]
Where data is stored and processedNot found Not found in public documentation for Connect specifically (checked 7 October 2026). Adobe's transfer page names the US, Ireland and India as the primary locations where Adobe handles personal data generally.Cross-border data transfers [3]
Data processing agreementDocumented Adobe publishes a DPA (June 2024 version) for business customers. For European data, Adobe Ireland is the initial recipient and ensures a transfer mechanism for onward transfers. At the end of the term, Adobe deletes or returns personal data at the customer's choice.Adobe DPA (PDF) [4]
SubprocessorsNot product-specific Adobe's list (last updated 28 September 2026) covers its cloud services. The product lists we read name many Experience Cloud apps but not Connect. Subscribers get at least 14 days' notice of a new subprocessor and may object on reasonable grounds.Sub-processors [5], [4]
International transfers (DPF, SCCs)Documented Adobe states that it and some US subsidiaries comply with the EU-US DPF, the UK Extension and the Swiss-US DPF (DPF status read from the vendor's privacy policy; the official list API returned no results for any query on the check date). For business customers, Adobe Ireland transfers to Adobe entities using SCCs and adequacy decisions, and publishes a transfer impact assessment summary.[2], [3]
AI features and trainingNot found Adobe's Connect product page announces AI blog generation from recordings and an AI Help Assistant for hosts. Which models and subprocessors these use, and whether content is used for training: not found in public documentation (checked 7 October 2026).Adobe Connect product page [6]
Data held and retentionPartly documented Profiles hold name, email, login, a salted password hash and optional phone number. IP addresses are stored with session information. Chat, polls and Q&A are stored as session data. Hosts own recordings and can delete them. Local system logs are kept for up to seven days, with a three-month roll-up in Splunk. A retention period for recordings and session data: not found in public documentation (checked 7 October 2026).[1]
Security certificationsGroup-level Adobe's compliance list includes Adobe Connect within its Adobe Experience Cloud grouping. SOC 2 reports are shared under NDA through the account team. We could not read the certificate-to-product mapping on the public page.Compliance list [7]
Institution controlsDocumented Account administrators can access, delete and modify user data; hosts can delete rooms and recordings; an API supports access and deletion requests from Connect 9.8. Adobe handles requests from controllers, not directly from students.[1]

Adobe Connect's strongest privacy feature is choice of deployment. A university that wants full control over where recordings live can run it on its own infrastructure under a licensed deployment. Adobe's group-wide documentation is also detailed, with a public DPA, a long subprocessor FAQ and a published transfer impact assessment summary.

What this means for a university

Validemic's analysis

Recordings. Connect recordings capture students' images, voices, names in the attendee list and chat messages. Adobe's new interactive recordings and AI blog generation increase how far that material can travel: a transcript or blog post generated from a seminar can repeat what a student said, with their name attached. Under recital 51 GDPR, video is special category biometric data only when processed for unique identification [8], but recordings still need a lawful basis, a retention rule and a notice to students before they are made.

Product-specific gaps. Adobe's documentation is mostly written for its cloud services as a whole. For Connect, the open questions are concrete: the data centre for your hosted account, the subprocessors that apply to Connect, and the AI processing behind the new features. None of these is unusual to ask, and Adobe's DPA gives you a right to information.

Deployment model. Hosted, managed and on-premises set-ups carry different responsibilities. On-premises moves hosting, patching and incident response to the university's IT team, which is a real cost. Hosted makes Adobe the processor, which brings the DPA and subprocessor rules into play.

Transfers. The European Commission's adequacy decision for the EU-US Data Privacy Framework took effect on 10 July 2023 [9]. Adobe states that it participates, and relies on SCCs for intra-group transfers from Ireland. Keep Adobe's transfer impact assessment summary on file.

DPIA likelihood. Article 35 GDPR requires a DPIA where processing is likely to result in a high risk [10]. Recorded examinations, oral assessments and AI processing of recordings point towards one. Routine webinars with recording off are less likely to reach the threshold.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask Adobe before approving Connect

  1. In which data centre is our hosted Connect account, and where are recordings, backups and logs stored?
  2. Which subprocessors on Adobe's list apply to Adobe Connect specifically?
  3. Which models and subprocessors power AI blog generation and the AI Help Assistant, are they on by default, and can administrators disable them?
  4. Is any Connect content, including recordings and transcripts, used to train or improve AI models?
  5. What retention applies to recordings, chat and attendance data, and can we enforce automatic deletion?
  6. Is our account on Connect 9.8 or later, so that access and deletion requests can be handled through the documented mechanisms?
  7. Which certifications in Adobe's compliance list cover Adobe Connect, and can we obtain the SOC 2 report?

The EU AI Act angle

AI blog generation and a host help assistant are productivity features, not the education uses listed as high-risk in Annex III of the AI Act. For most universities, the relevant obligation is AI literacy: Article 4, as amended, requires deployers to take measures to support the AI literacy of staff using AI systems [11]. Staff should check generated posts before publishing them, both for accuracy and for personal data about students.

Article 5(1)(f) prohibits AI systems that infer emotions in education institutions, except for medical or safety reasons [12]. We found nothing in Adobe's public Connect documentation describing emotion inference. If Connect were used with AI to evaluate students in examinations, that use would need a separate check, as Annex III obligations apply from 2 December 2027 under the amended Article 113 [13].

Sources

  1. Adobe Connect and GDPR (last updated 7 August 2025), Adobe Help Center, retrieved 7 October 2026
  2. Adobe Privacy Policy (last updated 24 October 2025), retrieved 7 October 2026
  3. Adobe cross-border data transfers, retrieved 7 October 2026
  4. Adobe Data Processing Addendum, June 2024 (PDF), linked from Adobe's data protection terms page, retrieved 7 October 2026
  5. Adobe Sub-Processors (last updated 28 September 2026), retrieved 7 October 2026
  6. Adobe Connect product page, retrieved 7 October 2026
  7. Adobe compliance list, Adobe Trust Center, retrieved 7 October 2026
  8. Regulation (EU) 2016/679 (GDPR), recital 51, retrieved 7 October 2026
  9. EU-US data transfers, European Commission, retrieved 7 October 2026
  10. Regulation (EU) 2016/679 (GDPR), Article 35, retrieved 7 October 2026
  11. AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026
  12. AI Act Article 5: Prohibited AI practices, AI Act Service Desk, retrieved 7 October 2026
  13. AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026

About this page

We read Adobe's Connect GDPR page, privacy policy, cross-border transfer page, DPA, subprocessor list, compliance list and Connect product page, and the relevant EU texts, on 7 October 2026. Adobe's servers refused automated requests, so we read these pages through a browser and a text reader. The official Data Privacy Framework list API returned no results on that date, so DPF status comes from Adobe's own statements. Our own view is labelled as Validemic's analysis. This page is not legal advice and does not say whether any particular use of Adobe Connect complies with the GDPR. If you spot an error or Adobe has published Connect-specific hosting or AI documentation, please contact us and we will correct it.

Frequently asked questions

Is Adobe Connect GDPR compliant?

No tool is GDPR compliant on its own. Adobe says it acts as a processor for hosted and managed Adobe Connect services, offers a data processing addendum through Adobe Systems Software Ireland Limited and states that Adobe participates in the EU-US Data Privacy Framework. Whether a university's use complies depends on its deployment model, contract, settings and transparency to students and staff.

Where is Adobe Connect data hosted?

We did not find a public Adobe document stating the hosting locations for Adobe Connect specifically (checked 7 October 2026). Adobe's cross-border transfer page says its primary locations for handling personal data are the US, Ireland and India. Universities should ask for the data centre of their own account in writing.

Can Adobe Connect run on-premises?

Yes. Adobe's Connect GDPR page describes licensed deployments, where the institution runs the software and is responsible as controller, alongside hosted and managed services where Adobe acts as processor. An on-premises deployment keeps hosting under the university's control but also moves security and patching to the university.

Who can delete Adobe Connect recordings?

Adobe's GDPR page says session owners own their sessions, uploaded content and recordings, and hosts can access or delete meeting rooms and specific recordings. Account administrators can access, delete and modify user information. Access and deletion mechanisms for GDPR requests require Connect 9.8 or later.

Does Adobe Connect use AI?

Adobe's product page announces an AI-powered blog generator that turns recordings into posts and an AI Help Assistant for hosts. We did not find a public Connect-specific document on which AI models or subprocessors these features use (checked 7 October 2026), so universities should ask before enabling them.