← Compare

Is Chorus (ZoomInfo) GDPR Compliant? Where Your Call Data Goes, and the DPA Scope Gap

    Short answer

    Chorus can be used in a GDPR-compliant setup, but it is now a US product with a US data footprint. Chorus by ZoomInfo is operated by ZoomInfo Technologies LLC, a Delaware company in Vancouver, WA. ZoomInfo's paperwork is strong: Data Privacy Framework certified, current EU Standard Contractual Clauses in the DPA, and ISO 27001, ISO 27701, and SOC 2 Type II. But its own Security Overview states data centers are in the US, the entire AI stack is US-based, there is no published EU data region for Chorus, and the standard public DPA is scoped to business-contact data rather than call content. This piece quotes ZoomInfo's own current documents, retrieved 2026-07-26.

    Is Chorus (ZoomInfo) GDPR compliant?

    Chorus can be used in a GDPR-compliant setup, but it is now a US product with a US data footprint. Chorus was acquired by ZoomInfo and is marketed as "Chorus by ZoomInfo," operated by ZoomInfo Technologies LLC, a Delaware company based in Vancouver, Washington. ZoomInfo's compliance paperwork is strong: it is Data Privacy Framework certified, its DPA incorporates the current EU Standard Contractual Clauses, and it holds ISO 27001, ISO 27701, and SOC 2 Type II. An EU controller can transfer data to it lawfully with those mechanisms and a transfer assessment.

    The gaps are structural. ZoomInfo's own Security Overview states its data centers are in the US, the entire disclosed AI stack is US-based, and there is no published EU data region for Chorus. There is also a scope subtlety worth knowing: ZoomInfo's standard published DPA defines "Customer Personal Data" narrowly around business contact information for accessing the platform, not the call-recording and transcript content Chorus captures, which appears to be handled through negotiated enterprise agreements.

    Who owns Chorus and where it processes data

    ZoomInfo's Privacy Policy confirms the product and the operating entity. It contains a section headed "Using Chorus" describing tools that "collect, store, analyze, and share the contents of audio, video, image, and text-based communications such as phone calls, video calls, emails, chats, webinars, and meetings," and it names the entity as "ZoomInfo Technologies LLC," described as "a Delaware limited liability company" at "330 W Columbia Way, Floor 8, Vancouver, WA 98660." The publicly listed parent is ZoomInfo Technologies Inc. on Nasdaq. Both are US entities.

    On location, ZoomInfo's Security Overview is direct: "Our services are hosted on the three major cloud providers with hosting data centers in the U.S." The Privacy Policy and DPA both authorize US storage and processing. We found no first-party ZoomInfo document offering an EU data region for Chorus conversation intelligence.

    Sources, retrieved 2026-07-26: zoominfo.com/legal/privacy-policy, zoominfo.com/legal/security-overview.

    The DPA and its scope gap

    ZoomInfo publishes a Controller-to-Processor DPA (version dated 1 January 2023). It is a proper Article 28 agreement on its own terms, but read the scope carefully.

    What the DPA says

    The ZoomInfo DPA states "Customer is the Controller and Supplier is a Processor," and on transfers, "Customer authorizes Supplier to store or Process Customer Personal Data in the United States or any other country in which Supplier or its sub-processors maintain facilities." It incorporates the EU Standard Contractual Clauses (Decision 2021/914, Module 2) plus the UK Addendum and Swiss FADP modifications. But its defined "Customer Personal Data" is "business contact information (such as name, work email address, work phone number) relating to Customer's personnel provided by Customer to Supplier for purposes of accessing Supplier's software and/or database," not the call-recording and transcript content Chorus records.

    That scope gap matters for a conversation intelligence buyer. The publicly available, click-through DPA is written around platform-access contact data. Coverage for the actual call content Chorus captures appears to be handled in negotiated enterprise terms rather than the standard published DPA, so an EU controller should confirm in writing that its recording and transcript data is covered by an Article 28 agreement, not assume the public DPA does it. The transfer model throughout is US processing under SCCs, and the DPA does not name the Data Privacy Framework, though the Privacy Policy does.

    Sources, retrieved 2026-07-26: zoominfo.com DPA (C2P), zoominfo.com/legal/privacy-policy.

    ZoomInfo's sub-processors: an all-US AI stack

    ZoomInfo publishes a dated sub-processor list (last updated 17 July 2026). The AI and data layers relevant to Chorus are all US entities.

    • Amazon Web Services, Inc. (US) for cloud hosting and infrastructure, with no EU region disclosed on the page, and Google LLC (US) for "Cloud hosting, infrastructure, and generative AI."
    • OpenAI OpCo, LLC (US) and Anthropic, PBC (US) for "Generative AI services," with Groq, Inc. (US) and LangChain Inc. (US) also in the AI stack.
    • Databricks, Snowflake, Wasabi, and Box (all US) for data warehousing, storage, and document hosting.
    • The only non-US entries on the main list are Transloadit-II GmbH (Germany) for file processing and Pusher Limited (UK) for messaging, with affiliate sub-processors located in Canada, India, Ireland, Israel, and the UK.

    For an EU controller, this is a US-centered supply chain with an all-US AI layer. The sub-processor transparency is good, and the objection right is real, but the geography is not.

    Sources, retrieved 2026-07-26: zoominfo.com/legal/subprocessors.

    Residency, sovereignty, and the CLOUD Act

    ZoomInfo's documents describe US residency and a US legal home. Storage and processing are in the US, the AI stack is US, and the corporate parent is a US public company. That means the US CLOUD Act applies, and it can compel a US provider to produce data in its control regardless of where servers sit. Strong paperwork does not change the jurisdiction: DPF certification and SCCs govern the transfer, not the reach of US law over a US company. For the wider mechanics, see our explainer on the CLOUD Act and EU data sovereignty for AI.

    Where ZoomInfo and Chorus are genuinely solid

    ZoomInfo's compliance program is one of the more complete in this set, and that deserves acknowledgment.

    • Data Privacy Framework certified. The Privacy Policy states ZoomInfo "complies with the EU-US Data Privacy Framework (including the UK Extension) and Swiss-U.S. Data Privacy Framework," including its subsidiary Datanyze.
    • SCCs done properly. The DPA incorporates the current EU SCCs (Decision 2021/914, Module 2), the UK Addendum, and Swiss FADP modifications.
    • A broad certification set: ISO 27001, ISO 27701 (a privacy-specific management system), TRUSTe, and SOC 2 Type II, per the Security Overview.
    • A transparent, dated sub-processor list with a 30-day objection right in the DPA.

    The paperwork is not the problem. The problem for an EU sovereignty requirement is that all disclosed processing and the entire AI stack are US-based, there is no published EU region for Chorus, and the public DPA is not scoped to the call content itself. Certificates do not move the data into the EU.

    The EU-native alternative

    If the requirement is EU-resident call data, an EU-region AI layer, and an Article 28 agreement scoped to the recordings themselves, a US-hosted product does not meet it. The structural answer is a provider with no US hosting and no US AI provider in the analysis loop. Numi is a sovereign meeting assistant built on that principle: EU data residency, self-hosted open-source transcription, no US AI provider in the loop, and a GDPR Article 28 processor agreement (Auftragsverarbeitungsvertrag) behind it. For the full field of EU-native options, see our guide to Gong alternatives for the DACH region in 2026, and compare the data practices of the major tools on our compliance comparison hub.

    Frequently asked questions

    Is Chorus (ZoomInfo) GDPR compliant?

    Chorus can be used within a GDPR-compliant setup. It is now Chorus by ZoomInfo, operated by ZoomInfo Technologies LLC (a Delaware company in Vancouver, WA), which is Data Privacy Framework certified, incorporates the current EU Standard Contractual Clauses in its DPA, and holds ISO 27001, ISO 27701, and SOC 2 Type II. But its Security Overview states data centers are in the US, the AI stack is all US, and there is no published EU data region for Chorus, so EU data is processed in the United States under SCCs and the DPF.

    Where does Chorus by ZoomInfo store and process data?

    ZoomInfo's Security Overview states its services are hosted on the three major cloud providers with data centers in the US, and its DPA and Privacy Policy authorize storage and processing in the United States. No first-party ZoomInfo document offers an EU data region for Chorus conversation intelligence. Its sub-processor AI stack (AWS, Google, OpenAI, Anthropic, Groq) is all US-based.

    Does ZoomInfo's DPA cover Chorus call recordings?

    Read the scope carefully. ZoomInfo's standard published Controller-to-Processor DPA defines Customer Personal Data narrowly as business contact information provided to access the software, not the call-recording and transcript content Chorus captures. Coverage for that content appears to be handled through negotiated enterprise agreements. An EU controller should confirm in writing that its recording and transcript data is covered by an Article 28 agreement rather than assume the public DPA does it.

    What transfer mechanism does ZoomInfo rely on?

    Its DPA incorporates the EU Standard Contractual Clauses (Decision 2021/914, Module 2), the UK Addendum, and Swiss FADP modifications for transfers out of the EEA, and authorizes US processing. Its Privacy Policy adds that ZoomInfo is certified under the EU-US Data Privacy Framework and its UK and Swiss extensions. The DPF is under active legal challenge, so a posture relying on it carries standing risk.

    Can the CLOUD Act reach data held by ZoomInfo?

    Yes. ZoomInfo is a US public company hosting on US infrastructure with a US AI stack, so it falls under the US CLOUD Act, which can compel a US provider to produce data in its control regardless of where servers sit. DPF certification and SCCs govern the transfer, not the reach of US law over a US company.

    Numi keeps call audio, transcription, storage, and coaching under EU jurisdiction, with an Article 28 agreement scoped to the recordings themselves, so your DPA is backed by control, not just a contract.

    Get Early Access