The world has changed significantly in the past 18 months when it comes to how people interact. Video conferencing, once a niche for purposes of business meetings, has become ubiquitous. The timing of that change coincided with last year’s Schrems II decision, which struck down the Privacy Shield Framework that many companies relied on to transfer data between the European Union and United States. Companies have struggled to keep up with the evolving data privacy landscape and now, a data protection watchdog in Germany has warned the Senate Chancellery of Hamburg to avoid using Zoom as its video conferencing software is now incompatible with the EU’s GDPR.
A new press release from the Hamburg Commissioner for Data Protection and Freedom of Information warns members of the German government not to use the on-demand version of Zoom. The stated rationale is that Schrems II prevents businesses in the EU from carrying out data transfers to non-EU businesses, and that Zoom violates GDPR as the software transmits personal data to the US.
In response, Zoom has stated that it will sign Standard Contractual Clauses (“SCCs”) with customers in Europe as well as take additional safeguards to protect their data in such a way that it lives up to the standards laid out under GDPR. However, it should be noted that Zoom has a history of questionable practices related to GDPR compliance, and it remains to be seen whether their usage of SCCs can be scaled in a manner commensurate with their global footprint.
If you’re conducting video conferencing meetings with participants in the EU, and especially if you are recording such meetings, you should take a few steps to ensure that you’re in compliance with GDPR, including:
Ensure compliance with your obligation to process data lawfully and fairly.