Chorus can be used in a GDPR-compliant setup, but it is now a US product with a US data footprint. Chorus by ZoomInfo is operated by ZoomInfo Technologies LLC, a Delaware company in Vancouver, WA. ZoomInfo's paperwork is strong: Data Privacy Framework certified, current EU Standard Contractual Clauses in the DPA, and ISO 27001, ISO 27701, and SOC 2 Type II. But its own Security Overview states data centers are in the US, the entire AI stack is US-based, there is no published EU data region for Chorus, and the standard public DPA is scoped to business-contact data rather than call content. This piece quotes ZoomInfo's own current documents, retrieved 2026-07-26.
Is Chorus (ZoomInfo) GDPR compliant?
Chorus can be used in a GDPR-compliant setup, but it is now a US product with a US data footprint. Chorus was acquired by ZoomInfo and is marketed as "Chorus by ZoomInfo," operated by ZoomInfo Technologies LLC, a Delaware company based in Vancouver, Washington. ZoomInfo's compliance paperwork is strong: it is Data Privacy Framework certified, its DPA incorporates the current EU Standard Contractual Clauses, and it holds ISO 27001, ISO 27701, and SOC 2 Type II. An EU controller can transfer data to it lawfully with those mechanisms and a transfer assessment.
The gaps are structural. ZoomInfo's own Security Overview states its data centers are in the US, the entire disclosed AI stack is US-based, and there is no published EU data region for Chorus. There is also a scope subtlety worth knowing: ZoomInfo's standard published DPA defines "Customer Personal Data" narrowly around business contact information for accessing the platform, not the call-recording and transcript content Chorus captures, which appears to be handled through negotiated enterprise agreements.
Who owns Chorus and where it processes data
ZoomInfo's Privacy Policy confirms the product and the operating entity. It contains a section headed "Using Chorus" describing tools that "collect, store, analyze, and share the contents of audio, video, image, and text-based communications such as phone calls, video calls, emails, chats, webinars, and meetings," and it names the entity as "ZoomInfo Technologies LLC," described as "a Delaware limited liability company" at "330 W Columbia Way, Floor 8, Vancouver, WA 98660." The publicly listed parent is ZoomInfo Technologies Inc. on Nasdaq. Both are US entities.
On location, ZoomInfo's Security Overview is direct: "Our services are hosted on the three major cloud providers with hosting data centers in the U.S." The Privacy Policy and DPA both authorize US storage and processing. We found no first-party ZoomInfo document offering an EU data region for Chorus conversation intelligence.
Sources, retrieved 2026-07-26: zoominfo.com/legal/privacy-policy, zoominfo.com/legal/security-overview.
The DPA and its scope gap
ZoomInfo publishes a Controller-to-Processor DPA (version dated 1 January 2023). It is a proper Article 28 agreement on its own terms, but read the scope carefully.
The ZoomInfo DPA states "Customer is the Controller and Supplier is a Processor," and on transfers, "Customer authorizes Supplier to store or Process Customer Personal Data in the United States or any other country in which Supplier or its sub-processors maintain facilities." It incorporates the EU Standard Contractual Clauses (Decision 2021/914, Module 2) plus the UK Addendum and Swiss FADP modifications. But its defined "Customer Personal Data" is "business contact information (such as name, work email address, work phone number) relating to Customer's personnel provided by Customer to Supplier for purposes of accessing Supplier's software and/or database," not the call-recording and transcript content Chorus records.
That scope gap matters for a conversation intelligence buyer. The publicly available, click-through DPA is written around platform-access contact data. Coverage for the actual call content Chorus captures appears to be handled in negotiated enterprise terms rather than the standard published DPA, so an EU controller should confirm in writing that its recording and transcript data is covered by an Article 28 agreement, not assume the public DPA does it. The transfer model throughout is US processing under SCCs, and the DPA does not name the Data Privacy Framework, though the Privacy Policy does.
Sources, retrieved 2026-07-26: zoominfo.com DPA (C2P), zoominfo.com/legal/privacy-policy.
ZoomInfo's sub-processors: an all-US AI stack
ZoomInfo publishes a dated sub-processor list (last updated 17 July 2026). The AI and data layers relevant to Chorus are all US entities.
- Amazon Web Services, Inc. (US) for cloud hosting and infrastructure, with no EU region disclosed on the page, and Google LLC (US) for "Cloud hosting, infrastructure, and generative AI."
- OpenAI OpCo, LLC (US) and Anthropic, PBC (US) for "Generative AI services," with Groq, Inc. (US) and LangChain Inc. (US) also in the AI stack.
- Databricks, Snowflake, Wasabi, and Box (all US) for data warehousing, storage, and document hosting.
- The only non-US entries on the main list are Transloadit-II GmbH (Germany) for file processing and Pusher Limited (UK) for messaging, with affiliate sub-processors located in Canada, India, Ireland, Israel, and the UK.
For an EU controller, this is a US-centered supply chain with an all-US AI layer. The sub-processor transparency is good, and the objection right is real, but the geography is not.
Sources, retrieved 2026-07-26: zoominfo.com/legal/subprocessors.
Residency, sovereignty, and the CLOUD Act
ZoomInfo's documents describe US residency and a US legal home. Storage and processing are in the US, the AI stack is US, and the corporate parent is a US public company. That means the US CLOUD Act applies, and it can compel a US provider to produce data in its control regardless of where servers sit. Strong paperwork does not change the jurisdiction: DPF certification and SCCs govern the transfer, not the reach of US law over a US company. For the wider mechanics, see our explainer on the CLOUD Act and EU data sovereignty for AI.
Where ZoomInfo and Chorus are genuinely solid
ZoomInfo's compliance program is one of the more complete in this set, and that deserves acknowledgment.
- Data Privacy Framework certified. The Privacy Policy states ZoomInfo "complies with the EU-US Data Privacy Framework (including the UK Extension) and Swiss-U.S. Data Privacy Framework," including its subsidiary Datanyze.
- SCCs done properly. The DPA incorporates the current EU SCCs (Decision 2021/914, Module 2), the UK Addendum, and Swiss FADP modifications.
- A broad certification set: ISO 27001, ISO 27701 (a privacy-specific management system), TRUSTe, and SOC 2 Type II, per the Security Overview.
- A transparent, dated sub-processor list with a 30-day objection right in the DPA.
The paperwork is not the problem. The problem for an EU sovereignty requirement is that all disclosed processing and the entire AI stack are US-based, there is no published EU region for Chorus, and the public DPA is not scoped to the call content itself. Certificates do not move the data into the EU.
The EU-native alternative
If the requirement is EU-resident call data, an EU-region AI layer, and an Article 28 agreement scoped to the recordings themselves, a US-hosted product does not meet it. The structural answer is a provider with no US hosting and no US AI provider in the analysis loop. Numi is a sovereign meeting assistant built on that principle: EU data residency, self-hosted open-source transcription, no US AI provider in the loop, and a GDPR Article 28 processor agreement (Auftragsverarbeitungsvertrag) behind it. For the full field of EU-native options, see our guide to Gong alternatives for the DACH region in 2026, and compare the data practices of the major tools on our compliance comparison hub.