2026-05-12 · 5 min read

Zoom AI GDPR and SOC 2 compliance: what the rules actually require

Zoom AI Companion is now included in most paid Zoom plans at no additional cost. It summarizes meetings, suggests chat responses, and can answer questions about what was discussed. Because it processes the content of your meetings, audio, transcripts, video, it creates compliance obligations that many organizations have not yet addressed.

Zoom AI retains meeting summaries for 30 days: treat transcripts as data

What Zoom AI Companion processes

AI Companion features include:

Meeting summary: Processes audio and generates a written summary with action items after the meeting ends. The transcript is processed by Zoom's AI infrastructure.

In-meeting questions: Allows participants to ask AI questions about the meeting content so far, without interrupting. Processes the meeting transcript in real time.

AI Companion for chat: Generates draft responses to chat messages and summarizes unread threads. Processes chat message content.

Smart recordings: Automatically categorizes and chapters recorded meetings. Processes recording content.

If your company uses Zoom for customer calls, sales demos, support calls, or internal meetings that include personal data, customer names, health information, financial data, that content flows through Zoom's AI features if AI Companion is enabled.

GDPR requirements

DPA coverage

Zoom provides a Data Processing Agreement for paid accounts. For Business, Business Plus, Enterprise, and Education plans, the DPA covers Zoom AI Companion as a core product feature. The DPA should be available in your Zoom account settings or via Zoom's legal portal.

For free Zoom accounts: no DPA is available. Free accounts should not be used for meetings involving personal data if your organization is subject to GDPR.

Training commitment

Zoom states that for paid accounts, meeting audio, video, transcripts, and chat content are not used to train Zoom AI models or third-party models. This applies to AI Companion features. Review Zoom's current AI privacy statement (zoom.us) to confirm the current status, this commitment has been updated several times and the authoritative version is the current published statement, not third-party summaries.

Data residency

Zoom offers data residency options for Enterprise customers, meeting data can be stored in specific geographic regions (US, EU, Australia, Canada, India, Japan). The available regions for AI feature processing may differ from storage residency. If EU data residency is a requirement, verify that AI Companion processing falls within your configured region.

Consent and notification

GDPR's transparency requirements are relevant when AI features are recording or transcribing meetings with customers or external participants. When meeting recording or AI summary is active, Zoom requires that participants be notified. This is typically handled by Zoom's built-in notification, but you should verify your admin settings ensure notifications are displayed.

If you are recording sales calls or customer support calls, your privacy notice to customers should disclose that meetings may be summarized using AI tools.

SOC 2 requirements

Vendor inventory (CC9.1)

Update your Zoom vendor entry to include AI features:

  • Service scope: Video conferencing, meeting transcription, AI meeting summaries, chat
  • Data processed: Meeting audio, transcripts, video, chat messages, may include customer personal data, confidential business information, or sensitive discussions
  • Risk tier: High if customer calls are included; Medium if internal use only
  • DPA status: Zoom paid plan DPA in effect
  • Security documentation: Zoom's SOC 2 Type 2 report (available via Zoom's trust portal), ISO 27001, HIPAA BAA (available for qualifying plans)
  • AI features documented: Yes, AI Companion enabled/disabled status and configuration

Access controls (CC6)

Admin settings to review and document:

  • Is AI Companion enabled at the account level, or must each host enable it per meeting?
  • Can external participants access AI Companion features?
  • Are meeting summaries shared only within the organization or can they be sent externally?
  • Is recording + AI summary enabled by default or opt-in per meeting?

Acceptable use policy (CC1)

Your policy should address:

  • Whether customer-facing meetings may use AI Companion (and consent requirements)
  • What categories of meetings should not use AI features (e.g., board discussions, HR conversations, M&A discussions)
  • How meeting summaries containing sensitive information should be stored and shared
  • Employee responsibilities when hosting external meetings with AI features active

Configuring Zoom AI for compliance

Key admin settings in Zoom Admin Portal → Account Management → Account Settings → AI Companion:

01AI Companion toggle

Enable or disable at account, group, or user level.

02Meeting summary sharing

Configure who can share AI summaries (internal only vs. external).

03Participant consent notifications

Verify notifications are displayed when AI features are active.

04Smart recording

Configure whether this is on by default or requires host action.

05Data retention

Configure how long AI-generated summaries and transcripts are retained.

Getting Zoom AI audit-ready comes down to mapping its data flows to your SOC 2 and GDPR controls, confirming the DPA and sub-processors, and keeping that evidence current as the service changes. If you would rather a security leader owned that work than track it in a spreadsheet, book a call.

Related reading

Want a security leader to run this?

Xorabyte is a fractional CISO for startups who can review your cloud for the gaps found first, so a blocked deal or an audit stops being your problem to carry alone. Book a call and you will leave with a clear path, not a sales pitch.

Frequently asked questions

Is Zoom AI GDPR compliant?
Zoom AI Companion is GDPR compliant for paid Zoom customers who have executed a Data Processing Agreement with Zoom. Zoom's DPA covers Zoom AI Companion as a core product feature. Zoom states that for paid accounts, AI Companion data is not used to train Zoom's or third-party AI models. Free Zoom accounts do not receive GDPR-compliant data processing terms.
Does Zoom AI train on your meetings?
Zoom states that for paid accounts, audio, video, chat, screen sharing, and other data from meetings is not used to train Zoom AI models or third-party models. This commitment applies to AI Companion features. Free accounts are subject to different terms. Zoom's privacy statement for AI features is published at zoom.us and should be reviewed against your current plan.
What data does Zoom AI Companion collect?
Zoom AI Companion accesses meeting audio (for transcription), the transcript text, and meeting metadata to generate summaries, action items, and other AI outputs. If you use AI Companion for chat, it also processes chat message content. The data used to generate summaries is processed by Zoom and, in some cases, by third-party AI providers that Zoom uses as subprocessors.
Can you disable Zoom AI for your organization?
Yes. Account administrators can disable Zoom AI Companion features at the account, group, or user level in the Zoom admin portal. You can also configure whether hosts must enable AI features per meeting, whether participants are notified when AI features are active, and whether meeting summaries can be shared externally. Review your current admin settings to confirm AI features are configured as your policy requires.
What SOC 2 controls apply to Zoom AI?
Zoom AI usage affects SOC 2 requirements under CC9.1 (Zoom as a vendor processing meeting data, including AI features), CC6 (access controls for who can enable and use AI Companion features), and CC1 (acceptable use policy covering AI meeting summaries and data handling). If customer calls are recorded and summarized by Zoom AI, that data flow requires vendor risk assessment and documentation.

Xorabyte

Get a security leader in your corner.

Xorabyte is a fractional CISO for startups facing SOC 2, security questionnaires, and enterprise security reviews. Tell us what triggered the need and we will map the path.