Is Zotero GDPR compliant? What universities should check
Zotero is the reference manager many European libraries recommend first. This page sets out what Zotero publicly documents about local storage, optional syncing, groups, hosting, contracts and transfers, and what that means for a university deciding how staff and students may use it.
Short answer
Zotero is free, open-source software from the Corporation for Digital Scholarship, a US non-profit. Its desktop application saves research data on the user's own computer by default, and syncing is optional and switched off until the user sets it up. If a user syncs, library data and files are stored with Amazon Web Services in the United States. Zotero states that it does not sell data and funds itself through storage subscriptions. We found no public data processing agreement, no Data Privacy Framework certification and no described transfer mechanism. Used locally, Zotero keeps most personal data off third-party servers. Once synced, especially in groups, a university should treat it as a US cloud service.
Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers reference management and a research library with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data
What Zotero documents publicly
Everything in this table comes from Zotero's own pages or the official Data Privacy Framework list, read on 7 October 2026. Numbers in brackets refer to the sources at the end of the page.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and establishment | Zotero's services are operated by the Corporation for Digital Scholarship (CDS) "from its offices within the United States on a not-for-profit basis", with a notice address in Falls Church, Virginia. An EU representative under Article 27 GDPR was not found in public documentation (checked 7 October 2026). | [2] |
| Desktop versus cloud | Documented Zotero is "a local program that saves data to your own computer by default". An account is not required. Syncing "is entirely optional and is disabled by default". | [1] [3] |
| Where synced data is stored | "All Zotero server data is stored in the United States in Amazon Web Services", specifically the us-east-1 region. Data in newly created accounts is encrypted at rest with AES-256. Files in personal libraries can be synced to a WebDAV server instead, but library data and group files sync only with Zotero's servers. Not found publicly An EU hosting option. | [1] [3] |
| Data processing agreement | Not found publicly No DPA was found in public documentation (checked 7 October 2026). The terms of service do not mention the GDPR, and are governed by the laws of Virginia. | [2] |
| Third parties | No formal subprocessor list. The privacy policy names Stripe (payments), Intuit (institutional invoices), Anrok and VAT IT (tax), Google reCAPTCHA, hCaptcha or Cloudflare Turnstile (registration and login checks), and Inworld AI or Google for Read Aloud premium voices, which receive document text. Metadata lookups can reach public services such as Crossref and the Library of Congress. | [1] |
| International transfers | Not found publicly No transfer mechanism is described. Searches of the official DPF list for Corporation for Digital Scholarship and Zotero returned no participant. | [1] [6] |
| Use of data and AI | Zotero states it has "no financial interest in your private information" and does not sell data. Synced library data is anonymised and aggregated into readership statistics using only publicly available metadata. No generative AI features or AI training on library content were found in the documentation we read. | [1] |
| Retention and deletion | Website and API access logs up to 90 days; failed-save reports up to one week; backups up to six months. Users can delete their account and synced library data from the settings. Free accounts without file sync activity for 90 days may have their files deleted. | [1] [2] |
| Security certifications | Not found publicly No ISO 27001 or SOC 2 report was found. Zotero points instead to its open-source code, code-signed builds and encryption in transit. | [3] |
| Institution options | Zotero Lab and Zotero Institution plans give members unlimited personal and group cloud storage and can be paid by bank transfer. Single sign-on, admin controls or an education contract were not found publicly. | [5] |
Zotero deserves credit for several things a data protection officer looks for. Local storage is the default, not an add-on. The privacy policy lists exactly which automatic requests the software makes and how to switch each one off. Retention periods are stated in days and months rather than in general terms. The client and server code are open source and can be audited, and the security page openly says the server can be self-hosted, though without support.
Groups change the picture
Zotero groups are how research teams and classes share libraries. Groups can be private (hidden, invitation only), public with closed membership, or public with open membership. In public groups, administrators choose whether the library is visible to non-members, and private and closed groups can also share files [4]. Group file storage counts against the group owner's storage plan [4], and syncing is required to use groups at all [3].
For a university, that means group libraries always sit on Zotero's US servers. The owner of the group, often a single researcher's personal account, controls membership and deletion. Zotero itself suggests that a team set up a separate account to own the group so it is not lost when someone leaves [4].
What this means for research and teaching
Validemic's analysisA reference library is usually low-risk data, but not always. Bibliographic metadata about published papers is mostly public information. The personal data at stake is the user's account and what they add: notes, annotations, attached PDFs and, in some fields, documents that should never be in a reference manager. Interview transcripts, consent forms or draft papers containing participant quotes can easily end up attached to a library item. Health, political or other sensitive data in such files is special category data under Article 9 GDPR [7].
Local use and synced use are different decisions. Used locally without an account, Zotero processes very little personal data on its own servers, and the university's normal endpoint rules apply. Once a user syncs, Zotero becomes a cloud service in the United States. We found no DPA, no DPF certification and no stated transfer mechanism. For an institution that pays for Zotero Institution storage and directs staff to use it, the processor obligations in Article 28 GDPR [7] and the transfer rules in Chapter V become relevant. That is a question to raise with CDS directly before signing.
Individual accounts. Most researchers sign up for Zotero themselves. In that case the user, not the university, is the account holder, and the university has no contract with the vendor. That is a reasonable arrangement for public bibliographic data, and a poor one for confidential research material.
DPIA likelihood. Routine reference management will rarely need a data protection impact assessment under Article 35 GDPR [7]. A synced group library holding sensitive attachments for a large project could. Use our DPIA screening tool for a first view.
Practical guidance. Many institutions can support Zotero well with simple rules: local use is fine; sync only bibliographic data and published PDFs; keep confidential files in university storage and link to them rather than attaching them; and use WebDAV on a university server for personal file sync where available.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask the Corporation for Digital Scholarship
- Will you sign a data processing agreement with our university for Zotero Institution storage, and which entity signs it?
- What transfer mechanism do you rely on for personal data synced from the EU to AWS in the United States?
- Is there, or will there be, an option to store our institution's synced data in an EU region?
- Which service providers, beyond those named in the privacy policy, can access synced library data or files?
- Are accounts created before encryption at rest was introduced now encrypted, and can existing data be migrated?
- Can our institution see which accounts are covered by our Zotero Institution plan and remove leavers?
- When a user deletes their account, how long do copies remain in backups (the policy says up to six months)?
- Do you have any independent security assessment or questionnaire, such as a HECVAT, that you can share?
The EU AI Act angle
Zotero is not an AI tool in the sense of the EU AI Act, and the documentation we read describes no generative AI features. Premium Read Aloud voices use text-to-speech providers [1], which is speech synthesis rather than a decision about people. None of the education uses listed as high-risk in Annex III (admission, evaluating learning outcomes, assessing the level of education, or monitoring students during tests) applies to reference management [8]. Those Annex III obligations now apply from 2 December 2027 [9]. Article 4 on AI literacy, as amended, asks deployers to take measures to support the AI literacy of their staff [10]. That is relevant if a university pairs Zotero with plugins or other tools that do use AI.
Sources
- Zotero Privacy Policy, last updated 18 May 2026, retrieved 7 October 2026
- Zotero Terms of Service, last updated 13 June 2026, retrieved 7 October 2026
- Zotero Security, retrieved 7 October 2026
- Zotero Groups documentation, retrieved 7 October 2026
- Zotero Storage FAQ and Zotero Storage, retrieved 7 October 2026
- Data Privacy Framework List, searches for "Digital Scholarship" and "Zotero", retrieved 7 October 2026
- Regulation (EU) 2016/679 (GDPR), Articles 9, 28 and 35 and Chapter V, text read from the Publications Office copy, retrieved 7 October 2026
- AI Act Annex III: High-risk AI systems, AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 113: Entry into force and application, AI Act Service Desk (as amended by Regulation (EU) 2026/1744), retrieved 7 October 2026
- AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026
About this page
We read Zotero's privacy policy, terms of service, security page, groups documentation and storage pages on 7 October 2026, and searched the official Data Privacy Framework list through its public search interface on the same day. Every statement about Zotero above comes from those pages. Where we give our own view, it is labelled as Validemic's analysis. "Not found" means we could not find the information in public documentation; it does not mean the Corporation for Digital Scholarship lacks it, and a contract may say more than the public pages do.
This page is not legal advice and does not say whether any particular use of Zotero complies with the GDPR: that depends on your configuration, contract and what users store. If you work on Zotero and see an error, please contact us and we will correct it.
Frequently asked questions
Is Zotero GDPR compliant?
No tool is GDPR compliant on its own. Zotero's desktop application stores data locally by default and can be used without an account, which keeps most personal data on the user's computer. If users switch on syncing, library data and files are stored with Amazon Web Services in the United States. Whether a university's use complies depends on whether syncing is used, what goes into the library and what contract is in place.
Where does Zotero store my data?
By default, on your own computer. Zotero's privacy policy and security page say syncing is optional and disabled by default. If you sync, data is stored in the us-east-1 AWS region in the United States. Personal library files can instead be synced to a WebDAV server you control, but library data and group files can only be synced with Zotero's servers.
Does Zotero sign a data processing agreement?
A data processing agreement for institutions was not found in Zotero's public documentation (checked 7 October 2026). The terms of service are governed by Virginia law and do not mention the GDPR. Universities that buy Zotero Institution storage should ask the Corporation for Digital Scholarship directly.
Is Zotero on the EU-U.S. Data Privacy Framework list?
On 7 October 2026, searches of the official Data Privacy Framework list for Corporation for Digital Scholarship and for Zotero returned no participant. Zotero's privacy policy does not describe a transfer mechanism for data synced from the EU to the United States.
Can students use Zotero without any data leaving the university?
Yes, for personal libraries. Zotero's security page says it can always be used locally without syncing any data if institutional policies prevent uploads to third-party servers. Some automatic lookups, such as metadata retrieval, still contact Zotero or public services, and these can be disabled in the preferences. Group libraries require syncing.