
Zoom and GDPR
CertReports found no public GDPR evidence for Zoom as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 18 Nov 2016
- Expires or valid through
- 19 Dec 2026
- Scope
- Please see Zoom's global DPA https://explore.zoom.us/docs/doc/Zoom_GLOBAL_DPA.pdf Categories of personal data processed by Zoom: Customer Content Data: Zoom Account Profile Info: Data associated with the end user's Zoom account, profile picture, password, company name, and Customer's preferences. This will include: • Zoom unique user ID, • profile picture (optional) Diagnostic Data: Meeting metadata: Metrics about Service usage, including when and how meetings were conducted). This category includes: • event logs (including action taken, event type and subtype, in-app event location, timestamp, client UUID, user ID, and meeting ID) • meeting session information, including frequency, average and actual duration, quantity, quality, network activity, and network connectivity • number of meetings • number of screen-sharing and non-screen-sharing sessions • number of participants • meeting host information • host name • meeting site URL • meeting start/end Time • join method • performance, troubleshooting and diagnostics information Telemetry data: Data collected from locally installed software (applications and browser information about the deployment of Zoom Services and related systems environment / technical information. This includes: • PC name • microphone • speaker • camera • domain • hard disc ID • network type • operating system type and version • client version • MAC address • event logs (including action taken, event type and subtype, in-app event location, timestamp, client UUID, • user ID and meeting ID) • service logs (information on systems events and states) Other Service Generated Data: • spam identification • push notifications • Zoom persistent unique identifiers such as UUID or user ids that are combined with other data elements including: • IP address • Data center • PC name • Microphone • Speaker • Camera • Domain • Hard disc ID • Network type • Operating System Type and Version • Client Version • IP Addresses along the Network Path Support Data: • problem description, post-meeting feedback
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Zoom: Active: UK Extension Certification, SW-US Certification, EU-US Certification | Live pagesha256 1c52639813 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Zoom GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Video conferencing category) whose GDPR row is verified or vendor-stated, ranked by similarity.