Leexi on iOSLeexi on Android

Zoom and GDPR: What to Check Before Using It

  • U.S. storage by default, region choice for paid accounts, consent, certifications: what Zoom documents.
Try for free
Zoom stores cloud recordings in the U.S. by default, with a region choice for paid accounts. What Zoom does with meetings, its certifications, and consent. Facts checked September 2, 2026.

Zoom stores your cloud recordings, transcriptions, and meeting messages in the United States by default. A paid account can choose another storage region, including Germany or Switzerland, and select the data centers that process live meeting traffic. Account and operational data remain in the United States. In its privacy statement, Zoom commits not to train its AI models on your content, and lists a range of certifications including ISO 27001, ISO 27701, and SOC 2 Type 2. Zoom is a U.S.-law company. This page is published by Leexi, whose AI note-taking tool works with Zoom, and it states only what Zoom's official pages document.

Where Zoom hosts and processes your data

In the United States by default. In Europe through a setting, for some data, on a paid account.

Zoom's GDPR page states this plainly.

Zoom, “GDPR” page, dated August 8, 2024 “Customer Content, Account Data, and Diagnostic Data are still stored in the U.S.”

Zoom offers two separate settings, and this is the point that marketplace pages conflate.

The first concerns storage. According to the “Managing Data & Storage location” page, “all paid customers (including Pro)” can choose the storage location for certain data: cloud recordings, transcriptions, messages and files exchanged in meetings, whiteboards, and Zoom Phone and Zoom Contact Center data. The available regions are Australia, Brazil, Canada, Germany, Japan, Singapore, Mexico, Switzerland, and the United States. Data not covered by this setting remains in the region where the account was provisioned. Account and operational data remain in the United States.

The second concerns live-traffic processing. The “Selecting data center for meetings, webinars, whiteboards, notes and docs” page lets users choose the data centers that process “participants' real-time meeting and webinar video, audio, whiteboard, notes, docs.” The document adds a caveat.

Zoom, “Selecting data center for meetings, webinars, whiteboards, notes and docs” “Zoom may route through traffic between data centers using industry standard network routing protocols while traversing Zoom private network connections (i.e., edge-routing).”

What this means for you: two questions to ask your Zoom administrator. Which storage region is configured for cloud recordings? Which data centers are enabled for live processing? A free account has access to neither setting.

What Zoom does with your conversations

Zoom commits not to train its AI models, or those of third parties, on your content.

The commitment appears in the privacy statement, not just on a blog.

Zoom, privacy statement, updated July 27, 2026 “Zoom does not use any of your audio, video, chat, screen sharing, attachments or other communications-like Customer Content… to train Zoom's or its third-party artificial intelligence models.”

Regarding Zoom's role, the GDPR page states that Zoom acts as a processor for its customers and incorporates its data processing agreement into its general terms for all customers. This is the GDPR requirement.

GDPR, Article 28(3)(a) “processes personal data only on documented instructions from the controller”

Regarding transfers, the same page states that Zoom has implemented the 2021 Standard Contractual Clauses for transfers outside the European Economic Area, and that it is registered as an active participant in the EU-U.S. Data Privacy Framework. The privacy statement confirms this: Zoom processes personal data globally, including in the United States.

What this means for you: the no-training commitment is written into the contractual document. What it does not state is the default retention period for your cloud recordings, which depends on your settings and Zoom's retention policy, to be checked in your account.

Zoom's certifications

The portfolio is broad and public.

Zoom's Trust Center “Legal & compliance” page lists the following for its commercial offering: ISO 27001, ISO 27017 and 27018, ISO 27701, SOC 2 Type 2, SOC 2 + HITRUST, CSA STAR Level 2, BSI C5, ENS, UK Cyber Essentials Plus, and HDS, the French certification for hosting health data. U.S. government certifications are also included (FedRAMP Moderate, DoD IL4).

Credit where it is due: few videoconferencing providers display the German C5, Spanish ENS, and French HDS at the same time. What the page does not provide are the scopes and dates of each certificate, which should be requested along with the SOC 2 report.

The provider's legal jurisdiction

Zoom is a U.S.-law company, and its account data remain in the United States.

18 U.S. Code § 2713, added by Pub. L. 115-141 on March 23, 2018 “A provider of electronic communication service or remote computing service shall comply with the obligations of this chapter to preserve, backup, or disclose the contents of a wire or electronic communication and any record or other information pertaining to a customer or subscriber within such provider's possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States.”

What this means for you: choosing Germany as the storage region answers the question “where.” The question “which law” remains tied to the provider's headquarters, and Zoom itself states that account data remain in the United States. The point is made once.

What this changes for a European team

Your situation What Zoom provides What you verify
Everyday use A request for participants' consent when recording starts; a written no-training commitment in the privacy statement The account type: a free account stores data in the United States with no available setting
Regulated sector Germany or Switzerland as the storage region for recordings and transcriptions; European data centers for live traffic Both settings, and the data that remain outside the setting (account data, logs, polls)
RFP, security questionnaire ISO 27001, 27701, SOC 2 Type 2, C5, ENS, and HDS displayed; DPA in the general terms; Standard Contractual Clauses The scopes and dates of the certificates, the SOC 2 report, and the retention policy
Strict sovereignty requirement Nothing that enables it A provider governed by European law, or processing outside Zoom

With Zoom, Leexi is a separate scope from Zoom's: the bot joins the meeting, and the audio is transcribed and summarized on Leexi's infrastructure (AWS Paris region, language model run through Azure France in a closed circuit, no training on your meetings), with a public DPA and ten named subprocessors. The Zoom integration page explains how to connect Leexi to Zoom. The compliance file and glossary provide the definitions and supporting documents.

Frequently asked questions

Where are my Zoom cloud recordings stored?

In the United States by default. A paid account, including Pro, can choose another region for cloud recordings, transcriptions, and meeting messages: Australia, Brazil, Canada, Germany, Japan, Singapore, Mexico, Switzerland, or the United States. Account and operational data remain in the United States.

Is choosing a European data center enough to keep my meetings in Europe?

Not on its own. The data-center choice concerns live-traffic processing, and Zoom states that traffic may pass through other data centers on its private network. Recording storage is controlled by a separate setting. Both are needed, and account data remain in the United States in all cases.

Does Zoom use my meetings to train its AI?

No. The privacy statement dated July 27, 2026 excludes audio, video, chat, screen sharing, and attachments from training Zoom's models and those of its third parties. The commitment appears in the contractual document.

Must participants consent to recording?

Zoom asks them to. When recording starts, or when joining an already recorded meeting, each participant sees a consent request and chooses whether to continue or leave. The administrator can limit the request to external participants or customize its wording. This request does not replace the information that GDPR requires you to provide about the purpose and retention period.

Is Zoom HDS certified?

Zoom's “Legal & compliance” page lists HDS, the French certification for hosting health data, among its commercial certifications. The certificate's exact scope, including the services and regions covered, should be requested from Zoom before using it with health data.

Is Zoom enough for a strict sovereignty requirement?

No. Zoom is a U.S.-law company, subject to 18 U.S. Code § 2713 regardless of the storage location, and its account data remain in the United States. Regional settings localize some data; they do not change the provider's legal jurisdiction.

Sources

Data verified on September 2, 2026, on Zoom's official pages.

  • Zoom, “Managing Data & Storage location,” Help Center
  • Zoom, “Selecting data center for meetings, webinars, whiteboards, notes and docs,” Help Center
  • Zoom, “Providing consent to be recorded,” Help Center
  • Zoom, “GDPR” page, dated August 8, 2024
  • Zoom, privacy statement, updated July 27, 2026
  • Zoom, Trust Center, “Legal & compliance” page
  • GDPR, Articles 5 and 28, text published by the CNIL
  • 18 U.S. Code § 2713, Legal Information Institute, Cornell Law School

This page describes the applicable framework. It does not constitute legal advice.

Try Leexi for free

Recommended Articles

Ready to boost your productivity with Leexi?

Leexi AI Notetaker takes notes for you

Discover here