Is Zoom GDPR compliant? What universities should check
Zoom is the default lecture and meeting tool at many European universities. This page sets out what Zoom publicly documents about hosting, its data processing addendum, subprocessors, transfers and AI features, and what that means for a university approving or renewing it.
Short answer
Zoom Communications, Inc. is a US company with an EU representative in Ireland. It incorporates a data processing addendum into its Terms of Service for all customers, publishes a subprocessor list and transfer impact assessments, and states that it participates in the EU-US Data Privacy Framework. Eligible paid accounts, including Education accounts, can route real-time meeting traffic through EU data centres, while free accounts cannot choose regions. Zoom says it does not use communications-like customer content to train AI models, but AI Companion features rely on US subprocessors when enabled. The detailed answer depends on your plan, your account settings and whether you switch on recording and AI features.
What Zoom documents publicly
The table below summarises what Zoom states in its own documentation, read on 7 October 2026. It covers Zoom Workplace (Meetings, Webinars, Team Chat and related features) as used by an institution.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and establishment | Documented Services are offered by Zoom Communications, Inc. of San Jose, California. Its EU representative is Workvivo Limited in Cork, Ireland, and its UK representative is ZVC UK Ltd. | Privacy Statement [1] |
| Where data is stored and processed | Plan-dependent Pro, Business, Enterprise and Education accounts can select data centre regions for real-time meeting, webinar, whiteboard, notes and docs content; free accounts cannot. Zoom notes data may still pass through network links in opted-out regions. European customers on eligible paid accounts can use EU data centres, store recordings locally or in their local data centre, and have support data processed exclusively in the EU. | Support article [5], GDPR page [2] |
| Data processing agreement | Documented Zoom says it provides its Data Processing Addendum to all customers by incorporating it into the Terms of Service. The global DPA covers deletion or return of personal data at the end of the services. | [2], Global DPA (PDF) [3] |
| Subprocessors | Documented Public list with purpose, data shared, location and transfer mechanism. Entries include Amazon Web Services, Microsoft, Google Cloud, Cloudflare, Anthropic and OpenAI. The DPA provides for notice at least 30 business days before a new subprocessor starts, with 15 business days to object. | Subprocessor list [4], [3] |
| International transfers (DPF, SCCs) | Documented Zoom's privacy statement says Zoom Communications, Inc. complies with the EU-US Data Privacy Framework (DPF status read from the vendor's privacy statement). Zoom also incorporates the 2021 SCCs into its DPA and publishes transfer impact assessments for Meetings, Webinar and Team Chat. | [1], [2] |
| AI features and training on customer content | Documented Zoom states it does not use audio, video, chat, screen sharing, attachments or other communications-like customer content to train Zoom's or third-party AI models. When AI features are enabled, Anthropic and OpenAI (United States, SCCs) may process customer content and context. | [1], [4] |
| Retention and deletion | Plan-dependent Personal data is kept "for as long as required" for the stated uses, based on listed criteria. Under the DPA, the customer can delete or have Zoom delete customer personal data at the end of the services. Files shared through in-meeting chat transfer are deleted within 31 days of the meeting. Recording retention largely follows account settings. | [1], [3] |
| Security certifications | Documented Zoom lists ISO 27001, ISO 27017/27018, ISO 27701, SOC 2 Type 2, CSA STAR Level 2, BSI C5 and Spain's ENS among its commercial certifications and attestations. | Compliance page [6] |
| Institution controls (SSO, admin, education licence) | Documented SAML single sign-on, authentication profiles restricting entry to specific email domains, waiting rooms, host controls and optional end-to-end encryption for meetings. Education accounts are among the plans that can select data centre regions. | [2], [5] |
Zoom also links, from its own GDPR page, to a public DPIA of Zoom Education commissioned by SURF, the Dutch IT cooperative for education and research [2]. The public update by Privacy Company, dated 3 April 2024, concluded that Zoom had taken most of the agreed measures and that, if Dutch education and research organisations apply the recommended measures, all known data protection risks are mitigated [7]. That is a meaningful piece of independent work, but it was written for the SURF agreement and the product as it stood in early 2024, before many of the current AI features.
What this means for a university
Validemic's analysis
Student and staff data. Lectures, seminars, supervision and oral examinations put student images, voices, names, chat messages and sometimes health or disability information (for example, when a student explains an absence) into Zoom. Recordings are the main multiplier: once a session is recorded and stored in the cloud, retention, access rights and deletion all become questions the university must answer, not Zoom.
Minors. Most university students are adults, so child-specific rules rarely apply. They become relevant for outreach programmes, summer schools or early-admission pupils, which some institutions run on the same Zoom account.
DPIA likelihood. Article 35 GDPR requires a DPIA where processing, particularly with new technologies, is likely to result in a high risk [9]. Routine video teaching on a well-configured education account may not reach that threshold on its own, but recorded examinations, AI meeting summaries, transcription of sensitive conversations and large-scale use across the institution are factors that push towards one. The SURF DPIA [7] is a useful starting point that a university can adapt rather than copy.
Transfers. The European Commission adopted its adequacy decision for the EU-US Data Privacy Framework on 10 July 2023, which allows transfers to participating US companies [8]. Zoom states it participates [1]. Even with EU data centres selected, the subprocessor list shows some processing in the US, notably for AI features [4]. Check the official DPF list yourself before relying on it, and keep the SCCs and Zoom's transfer impact assessments on file as a fallback.
Plan tier. The difference between a free or individual account and an institutional Education or Enterprise account is large: region selection, administrative control and a contract the university actually signs. Staff using personal accounts for teaching sit outside those controls, which is a common gap.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask Zoom before approving it
- Which Zoom entity signs our agreement and DPA, and is the DPA the global version incorporated into the Terms of Service or a negotiated one?
- Is our account provisioned in Zoom's EU data centre infrastructure, and which data categories (meeting content, recordings, chat, account data, telemetry, support data) stay in the EU?
- Which AI Companion features are enabled by default on an Education account, and can administrators disable them at account, group and user level?
- When AI features are on, which subprocessors process our content, in which countries, and with what retention at the subprocessor?
- How long are cloud recordings, transcripts and AI summaries kept by default, and can we enforce automatic deletion centrally?
- Which of the measures recommended in the SURF DPIA are available to us outside the SURF agreement?
- How will we be notified of new subprocessors, and to which address should notices go?
- Can we obtain the current SOC 2 Type 2 report and ISO certificates under NDA?
- How do we handle data subject access requests from students for recordings in which several people appear?
The EU AI Act angle
Zoom's AI features (meeting summaries, transcription, chat assistance) are general productivity functions, not the education uses listed as high-risk in Annex III of the AI Act. For most universities the relevant obligation today is AI literacy: Article 4, as amended, requires deployers to take measures to support the AI literacy of staff and others operating AI systems on their behalf [10]. In practice, that means telling teachers what the summaries can get wrong before they rely on them.
Article 5(1)(f) prohibits AI systems that infer the emotions of a natural person in education institutions, except for medical or safety reasons [11]. We found nothing in Zoom's public documentation describing emotion inference in its education offering. If a third-party app from the Zoom Marketplace offered engagement or sentiment scoring on students, that would need a separate and careful check. For the wider timeline, high-risk obligations for Annex III systems now apply from 2 December 2027 under the amended Article 113 [12][13].
Sources
- Zoom Privacy Statement (last updated 17 September 2026), retrieved 7 October 2026
- Zoom and the European Union's General Data Protection Regulation (GDPR), retrieved 7 October 2026
- Zoom Global Data Processing Addendum (PDF), retrieved 7 October 2026
- Zoom Third-Party Subprocessors and Zoom Affiliates, retrieved 7 October 2026
- Selecting data center for meetings, webinars, whiteboards, notes and docs, Zoom Support, retrieved 7 October 2026
- Zoom Compliance (certifications and attestations), retrieved 7 October 2026
- Update DPIA Zoom Education SURF, public version 3 April 2024 (Privacy Company), retrieved 7 October 2026
- EU-US data transfers, European Commission, retrieved 7 October 2026
- Regulation (EU) 2016/679 (GDPR), Article 35, text read from the Publications Office copy, retrieved 7 October 2026
- AI Act Article 4: AI literacy, AI Act Service Desk (consolidated text of Regulation (EU) 2024/1689 as at 27 July 2026), retrieved 7 October 2026
- AI Act Article 5: Prohibited AI practices, AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026
- AI Act, Shaping Europe's digital future (European Commission), retrieved 7 October 2026
About this page
We read Zoom's privacy statement, GDPR page, global DPA, subprocessor list, support documentation and compliance page, the SURF DPIA linked from Zoom's site, and the relevant EU legal texts on 7 October 2026. Every statement about Zoom above comes from those pages. Where we give our own view, it is labelled as Validemic's analysis. This page is not legal advice and does not say whether any particular use of Zoom complies with the GDPR: that depends on your contract, configuration and purposes. Zoom's documentation changes often, so check the linked sources before relying on a detail. If you spot an error or Zoom has updated a document, please contact us and we will correct it.
Frequently asked questions
Is Zoom GDPR compliant?
No tool is GDPR compliant on its own. Zoom offers a data processing addendum incorporated into its Terms of Service, states that it participates in the EU-US Data Privacy Framework and lets eligible paid accounts use EU data centres. Whether a university's use complies depends on its contract, account settings, lawful basis and transparency to students and staff.
Does Zoom store data in the EU?
Zoom says European customers on eligible paid accounts can use data centres in the EU for real-time meeting and webinar traffic, and can store recordings locally or in their local data centre. Free accounts cannot customise data centre regions. Some processing, such as certain subprocessors and AI features, can take place outside the EU.
Does Zoom use meeting content to train AI?
Zoom's privacy statement says it does not use audio, video, chat, screen sharing, attachments or other communications-like customer content to train Zoom's or third-party AI models. When AI features are enabled, Zoom lists Anthropic and OpenAI among the subprocessors that may process customer content and context.
Is there a Zoom DPIA for universities?
Yes, there is a public one. SURF, the Dutch IT cooperative for education and research, commissioned DPIAs of Zoom Education. The public update by Privacy Company, dated 3 April 2024, concluded that if institutions follow its recommended measures, all known data protection risks are mitigated. It reflects the SURF contract and the product at that time, so a university should still assess its own set-up.
Do universities need a DPIA for Zoom?
Often yes, or at least a documented screening. Recording lectures and exams, using AI summaries and transferring some data to the US are factors that point towards a DPIA under Article 35 GDPR. A university can draw on the SURF DPIA but must reflect its own contract and configuration.