{"schema":"https://policywatcher.online/schemas/evidence-packet/v1","schemaVersion":"1.0.0","mappingVersion":"2026-07-29.1","changeId":"66fcf7ee-a113-43fa-bd57-4cb533e1fe0c","screeningDate":"2026-07-28T22:39:45.952Z","publicationGate":"published","company":{"id":"59438443-572b-47a4-a4ac-f0091158e154","name":"Zoom","slug":"zoom","industry":"Cloud/SaaS"},"policy":{"id":"0ec3d4b4-79d4-4e2e-8a66-60dde69a5c10","name":"Privacy Statement","type":"privacy","jurisdiction":"Global","sourceUrl":"https://www.zoom.com/en/trust/privacy/privacy-statement/"},"sourceConfidence":{"state":"review-required","lastCheckedAt":"2026-07-06T09:39:08.874Z","retrievalChannel":"other","dataStatus":"Available","publicSnapshotEvidence":true,"limitation":"Source confidence describes recorded retrieval and publication state. It does not rate the provider policy or certify source authenticity."},"snapshots":{"old":{"version":1,"sha256":"4b64ac62179f82d9cea0bf1ffd8b19e0f483686afcecabeafb335dbd3203c7f6","capturedAt":"2026-07-06T09:42:03.116Z"},"current":{"version":2,"sha256":"ae8f30d854f985a13f13d7e11a5efa5bf4d6f06927e5cefe9b60979ea986ba57","capturedAt":"2026-07-28T22:39:45.945Z"}},"assessment":{"summary":"Zoom now explicitly states it will not share mobile opt-in data from text campaigns with third parties, enhancing user privacy for mobile communications.","overallRisk":"Medium","overallScore":4,"previousPublicChange":null,"scoreDelta":null,"direction":"baseline","reasons":[{"icon":"info","textEn":"New clause protects mobile opt-in data from third-party sharing, enhancing user trust.","textIt":"Nuova clausola protegge i dati di opt-in mobile dalla condivisione, aumentando la fiducia degli utenti.","deltaScore":1,"evidenceQuote":null,"evidenceSide":null,"relatedKpi":null,"anchorStatus":"not-recorded"},{"icon":"warning","textEn":"Expanded tracking definition to \"similar technologies\" may increase data collection scope.","textIt":"Definizione di tracciamento estesa a \"tecnologie simili\" potrebbe ampliare la raccolta dati.","deltaScore":-1,"evidenceQuote":null,"evidenceSide":null,"relatedKpi":null,"anchorStatus":"not-recorded"},{"icon":"info","textEn":"Clarified AI training policy: customer content is not used for model training.","textIt":"Chiarita politica di training AI: i contenuti dei clienti non sono usati per l'addestramento dei modelli.","deltaScore":1,"evidenceQuote":null,"evidenceSide":null,"relatedKpi":null,"anchorStatus":"not-recorded"}],"keyPoints":[{"textEn":"Mobile opt-in data from text campaigns will not be shared with third parties, except for service or legal needs.","textIt":"I dati di opt-in mobile da campagne SMS non saranno condivisi con terze parti, salvo per esigenze di servizio o legali.","sentiment":"positive"},{"textEn":"Tracking technologies now include \"similar technologies\" alongside cookies, potentially broadening data collection methods.","textIt":"Le tecnologie di tracciamento ora includono \"tecnologie simili\" oltre ai cookie, ampliando potenzialmente i metodi di raccolta dati.","sentiment":"negative"},{"textEn":"Minor product name updates, like \"Zoom Team Chat,\" reflect internal branding changes without privacy impact.","textIt":"Aggiornamenti minori ai nomi dei prodotti, come \"Zoom Team Chat\", riflettono cambiamenti di branding interni senza impatto sulla privacy.","sentiment":"neutral"}],"regionImpacts":[{"region":"EU","perspective":"Enterprise","riskLevel":"Medium","impactAnalysisEn":"Enterprises must ensure their use of Zoom aligns with GDPR, especially regarding account owner controls and data processing agreements for \"similar technologies.\" AI Act implications for intelligent features are emerging.","complianceNoteEn":"GDPR, AI Act"},{"region":"EU","perspective":"Individual","riskLevel":"Medium","impactAnalysisEn":"The explicit mobile data protection is a positive step for GDPR compliance, but the expanded tracking definition requires careful review under ePrivacy and GDPR consent rules.","complianceNoteEn":"GDPR, ePrivacy Directive"},{"region":"Global","perspective":"Enterprise","riskLevel":"Medium","impactAnalysisEn":"Global enterprises must consider the updated policy in their data governance frameworks, particularly for mobile marketing and the use of diverse tracking technologies across jurisdictions.","complianceNoteEn":"International Data Transfer"},{"region":"Global","perspective":"Individual","riskLevel":"Medium","impactAnalysisEn":"Users worldwide benefit from the clearer stance on mobile data sharing, improving trust, while the broader tracking definition warrants attention to personal data collection.","complianceNoteEn":"Global Privacy Norms"},{"region":"US","perspective":"Enterprise","riskLevel":"Medium","impactAnalysisEn":"Businesses using Zoom should update their internal policies to reflect the new mobile data clause and assess the impact of \"similar technologies\" on their compliance with state privacy laws.","complianceNoteEn":"State Privacy Laws"},{"region":"US","perspective":"Individual","riskLevel":"Low","impactAnalysisEn":"The mobile data protection is a win for consumer privacy under state laws like CCPA/CPRA, offering more clarity on how text campaign data is handled.","complianceNoteEn":"CCPA/CPRA"}],"explanationBoundary":"Score reasons and deltaScore values are stored AI-assisted screening outputs. Verified anchors confirm only that the quoted passage occurs in the named snapshot; they do not prove the interpretation."},"governance":{"boundary":"Mappings identify review relevance between recorded PolicyWatcher KPI fields and framework topics. They are not legal interpretations, conformity assessments, certifications or compliance verdicts.","mappings":[{"framework":{"id":"eu-ai-act","name":"Regulation (EU) 2024/1689 (EU AI Act)","shortName":"EU AI Act","referenceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","referenceVersion":"Official Journal text, 2024","reviewQuestion":"Which recorded policy statements may be relevant to transparency, automated decisions, data use and human oversight review?","kpiFields":["kpiAiTrainingOptOut","kpiAlgoTransparency","kpiAutomatedDecision","kpiAiBiasFairness"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiAiTrainingOptOut","label":"AI training opt-out","value":"Not Available"},{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Opaque"},{"field":"kpiAutomatedDecision","label":"Automated decisions","value":"Opaque"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Absent"}]},{"framework":{"id":"iso-42001","name":"ISO/IEC 42001:2023","shortName":"ISO/IEC 42001","referenceUrl":"https://www.iso.org/standard/42001","referenceVersion":"ISO/IEC 42001:2023 overview","reviewQuestion":"Which recorded policy statements may inform an AI management-system review of transparency, risk oversight and independent assurance?","kpiFields":["kpiAlgoTransparency","kpiAiBiasFairness","kpiIndependentAudit","kpiRegulatoryCompliance"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Opaque"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Absent"},{"field":"kpiIndependentAudit","label":"Independent audit","value":"Absent"},{"field":"kpiRegulatoryCompliance","label":"Regulatory compliance","value":"Partial"}]},{"framework":{"id":"nist-ai-rmf","name":"NIST AI Risk Management Framework 1.0","shortName":"NIST AI RMF","referenceUrl":"https://www.nist.gov/itl/ai-risk-management-framework","referenceVersion":"AI RMF 1.0; NIST revision in progress, checked 2026-07-29","reviewQuestion":"Which recorded policy statements may support Govern, Map, Measure or Manage review questions?","kpiFields":["kpiAlgoTransparency","kpiAutomatedDecision","kpiAiBiasFairness","kpiContentModeration"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Opaque"},{"field":"kpiAutomatedDecision","label":"Automated decisions","value":"Opaque"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Absent"},{"field":"kpiContentModeration","label":"Content moderation","value":"Opaque"}]},{"framework":{"id":"oecd-ai-principles","name":"OECD AI Principles","shortName":"OECD AI Principles","referenceUrl":"https://oecd.ai/en/ai-principles","referenceVersion":"OECD AI Principles, updated 2024","reviewQuestion":"Which recorded policy statements may be relevant to transparency, fairness, accountability and user agency review?","kpiFields":["kpiConsentMechanism","kpiAlgoTransparency","kpiAiBiasFairness","kpiIndependentAudit"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiConsentMechanism","label":"Consent mechanism","value":"Opt-Out"},{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Opaque"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Absent"},{"field":"kpiIndependentAudit","label":"Independent audit","value":"Absent"}]}]},"humanReviewQuestions":["Does the original Privacy Statement source still match the recorded public snapshot version 2?","Do the cited source passages support each displayed reason, KPI value and regional note?","Which advisory framework topics require specialist legal, risk or governance review for this use case?","Has a later public change superseded this packet before it is reused in a decision or publication?"],"methodologyUrl":"https://policywatcher.online/methodology/confidence","changeUrl":"https://policywatcher.online/change/66fcf7ee-a113-43fa-bd57-4cb533e1fe0c","boundary":"This packet records PolicyWatcher evidence and AI-assisted screening for one public change. It is not legal advice, a compliance verdict, a certification, or proof that the external source remains unchanged.","contentDigest":"34ba54e9c49f3269e4826e0b64e01955ba73a3e399faa2e1db4eb9ad0f0943d0"}