Skip to main content
Zoom logo

Zoom

GDPR evidence

zoom.comVideo conferencingLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

Zoom and GDPR

CertReports found no public GDPR evidence for Zoom as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

Vendor-statedVendor states ISO/IEC 27701 on its trust centre
as of 17 Sep 2026 · confidence 90%
SourceCapturedQuoteLinks
Zoom trust centre (Drata)
Vendor trust centre · HTTP 200
17 Sep 2026ISO/IEC 27701
Live page Snapshotsha256 24b1483848
VerifiedActive: UK Extension Certification, SW-US Certification, EU-US Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
18 Nov 2016
Expires or valid through
19 Dec 2026
Scope
Please see Zoom's global DPA https://explore.zoom.us/docs/doc/Zoom_GLOBAL_DPA.pdf Categories of personal data processed by Zoom: Customer Content Data: Zoom Account Profile Info: Data associated with the end user's Zoom account, profile picture, password, company name, and Customer's preferences. This will include: • Zoom unique user ID, • profile picture (optional) Diagnostic Data: Meeting metadata: Metrics about Service usage, including when and how meetings were conducted). This category includes: • event logs (including action taken, event type and subtype, in-app event location, timestamp, client UUID, user ID, and meeting ID) • meeting session information, including frequency, average and actual duration, quantity, quality, network activity, and network connectivity • number of meetings • number of screen-sharing and non-screen-sharing sessions • number of participants • meeting host information • host name • meeting site URL • meeting start/end Time • join method • performance, troubleshooting and diagnostics information Telemetry data: Data collected from locally installed software (applications and browser information about the deployment of Zoom Services and related systems environment / technical information. This includes: • PC name • microphone • speaker • camera • domain • hard disc ID • network type • operating system type and version • client version • MAC address • event logs (including action taken, event type and subtype, in-app event location, timestamp, client UUID, • user ID and meeting ID) • service logs (information on systems events and states) Other Service Generated Data: • spam identification • push notifications • Zoom persistent unique identifiers such as UUID or user ids that are combined with other data elements including: • IP address • Data center • PC name • Microphone • Speaker • Camera • Domain • Hard disc ID • Network type • Operating System Type and Version • Client Version • IP Addresses along the Network Path Support Data: • problem description, post-meeting feedback
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Zoom: Active: UK Extension Certification, SW-US Certification, EU-US Certification
Live pagesha256 1c52639813
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is Zoom GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the Video conferencing category) whose GDPR row is verified or vendor-stated, ranked by similarity.