ThreatLabz
Customer Success Stories
Careers
Partners
Support
Get in touch
1-408-533-0288
Zscaler Cloud Portal | Admin
Zscaler Cloud Portal One | Admin
Zscaler Cloud Portal Two | Admin
Zscaler Cloud Portal Three | Admin
Zscaler Cloud Portal Beta | Admin
admin.zscloud.net
Zscaler Private Access Cloud Portal One | Admin
Zscaler Private Access Cloud Portal Two | Admin
Home
Take a product tourRequest a demo
Secure the Workforce

Provide users with seamless, secure, reliable access to applications and data.

Secure the Cloud

Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.

Secure IoT/OT

Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.

Secure B2B

Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.

Zscaler Platform
Why Zscaler
Leadership in AI
Zscaler SASE
Zscaler SSE
Analyst Recognition
Zero Trust Automation
Customer Stories
Partner Ecosystem
Reduce Your Carbon Footprint

Industry Report

Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)

nvaigation-gartner-report-2025-desktop
Zero Trust SASE
Secure Internet Access (ZIA)
Secure Private Access (ZPA)
Digital Experience (ZDX)
Zero Trust Firewall
Cloud Sandbox
Zero Trust Browser
Zero Trust Branch
Zero Trust SD-WAN
IoT/OT Segmentation
Privileged Remote Access
Zscaler Cellular
AI Security
AI Asset Management
AI Access Security
AI Red Teaming
AI Guardrails
Zero Trust Cloud
Secure Ingress and Egress Traffic
Secure East-West Traffic
Microsegmentation
Zero Trust Gateway
Data Security
Web and Email DLP
Endpoint DLP
BYOD Security
Multi-Mode CASB
Unified SaaS Security
DSPM
Microsoft Copilot Data Protection
Agentic Security Operations
Agentic SecOps Core
Deception
Asset Exposure Management
Unified Vulnerability Management
Threat Hunting
Managed Detection & Response
Data Fabric for Security
Use Cases
Zero Trust + AI
Business Insights
Replace VPN
Cyberthreat Protection
Stop Ransomware
VDI Alternative
Secure Your Data
Optimize Digital Experiences
Deploy BYOD Securely
Reduce Cyber Risk
Security Operations
Continuous Threat Exposure Management
Accelerate M&A and Divestitures
Industry & Market Solutions
Healthcare
Banking & Financial Services
Manufacturing
Education
Retail
Australia Government
China Government
US Public Sector
US Federal Government
US State & Local Government
APJ Mid-Market / Commercial
Partners
Explore Our Partners
Become a Partner
Partner Portal
Technology Partners
Explore Technology Partners
Microsoft
CrowdStrike
AWS
Okta
Rubrik
SAP
Zero Trust + AI
Business Insights
Replace VPN
Cyberthreat Protection
Stop Ransomware
VDI Alternative
Secure Your Data
Optimize Digital Experiences
Deploy BYOD Securely
Reduce Cyber Risk
Security Operations
Continuous Threat Exposure Management
Accelerate M&A and Divestitures
Healthcare
Banking & Financial Services
Manufacturing
Education
Retail
Australia Government
China Government
US Public Sector
US Federal Government
US State & Local Government
APJ Mid-Market / Commercial
Explore Our Partners
Become a Partner
Partner Portal
Explore Technology Partners
Microsoft
CrowdStrike
AWS
Okta
Rubrik
SAP
Resource Center
Resource Library
Blog
Customer Success Stories
Webinars
Zpedia
Events & Trainings
Upcoming Events
Zenith Live
Zscaler Cyber Academy
Security Research & Services
ThreatLabz Analytics
Security Advisory Updates
Tools
Security Preview
Security and Risk Assessment
Disclose a Vulnerability
Executive Insights App
Ransomware Protection ROI Calculator
Community & Support
Customer Success Center
Zenith Community
Zscaler Help Portal
Resource Library
Blog
Customer Success Stories
Webinars
Zpedia
Upcoming Events
Zenith Live
Zscaler Cyber Academy
ThreatLabz Analytics
Security Advisory Updates
Security Preview
Security and Risk Assessment
Disclose a Vulnerability
Executive Insights App
Ransomware Protection ROI Calculator
Customer Success Center
Zenith Community
Zscaler Help Portal
About Zscaler

Discover how it began and where it’s going

Partners

Meet our partners and explore system integrators and technology alliances

News & Announcements

Stay up to date with the latest news

Leadership Team

Meet our management team

Partner Integrations

Explore our technology partner integrations

Investor Relations

See news, stock information, and quarterly reports

Careers

Join our mission

Compliance

Understand our adherence to rigorous standards

Press Center

Find everything you need to cover Zscaler

Culture

Our values, leadership principles, and ways of working

Zenith Ventures

Learn about our strategic startup investments

Corporate Responsibility

Learn about our approach

Home
Take a product tourRequest a demo
Last updated: June, 2026

Zscaler Data Processing Agreement

Contents

  1. DEFINITIONS
  2. DATA PROCESSING
  3. INTERNATIONAL TRANSFERS
  4. SUB-PROCESSORS
  5. SECURITY MEASURES AND DATA ACCESS
  6. SECURITY INCIDENTS
  7. RIGHTS OF DATA SUBJECTS
  8. DOCUMENTATION AND AUDIT RIGHT
  9. GENERAL
  10. Exhibit A

This Data Processing Agreement (“DPA”) forms part of any agreement between Zscaler, Inc. (“Zscaler”) and the customer that is identified on, and is a party to, such agreement (“Customer”) under which Zscaler’s products are provided (“Agreement”). Capitalized terms not defined herein shall have the meanings assigned to such terms in the Agreement.

1. DEFINITIONS

  1. “Controller” means the entity which determines the purposes and means of the processing of Personal Data.
  2. “Data Protection Legislation” means any and all applicable federal, state, provincial, and foreign data protection, privacy, and data security laws, regulations, and directives applicable to the processing of Personal Data under the Agreement, as amended from time to time.
  3. “Data Subject” means an identified or identifiable natural person to whom Personal Data relates.
  4. “Personal Data” means any information relating to an identified or identifiable natural person that is submitted to the Products by Customer and processed for the purposes of providing the Products to Customer. The types of Personal Data, specific uses, and retention periods are detailed in Exhibit A.
  5. “Processing”, “process”, or “processes” means any operation or set of operations which is performed upon Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
  6. “Processor” means the entity that processes Personal Data on behalf of the Controller.
  7. “Sub-processor” means the entity engaged by Zscaler for carrying out specific processing activities of Personal Data.
  8. “Supervisory Authority” means any local, national, supranational, state, governmental or quasi-governmental agency, body, department, board, official or entity exercising regulatory or supervisory authority pursuant to any Data Protection Legislation in accordance with this DPA.

2. DATA PROCESSING

  1. Roles of the Parties.  The parties acknowledge and agree that with regard to the processing of Personal Data for the provision of the Products, Customer is the Controller and Zscaler is the Processor. The parties agree to comply with the Data Protection Legislation.
  2. Instructions. Zscaler will process the Personal Data only in accordance with this DPA and any documented Customer instructions. Zscaler will process Personal Data from its global data centers depending on where Customer’s users are located, for the following purposes: (a) processing necessary for the provision of the Products in accordance with this DPA and the Agreement; (b) any processing initiated by Customer’s end users in their use of the Products; and (c) any processing to comply with the other reasonable documented instructions provided by Customer to Zscaler (e.g., via email or via support requests) where such instructions are consistent with the terms of the Agreement, as required to comply with Data Protection Legislation, or as otherwise mutually agreed by the parties in writing. Zscaler will promptly inform Customer if in its opinion compliance with any Customer instruction would infringe Data Protection Legislation.
  3. Customer Responsibilities. Customer will, in its use of the Products, comply with the requirements of Data Protection Legislation which includes instructions to Zscaler in regard to the processing of Personal Data.  Customer will have sole responsibility for the accuracy, quality, and legality of Personal Data and for ensuring that the Personal Data was lawfully acquired by Customer (including any authorizations or consents if required).  Customer shall ensure that Customer is entitled to transfer the relevant Personal Data to Zscaler so that Zscaler may lawfully use, process, and transfer the Personal Data in accordance with Customer’s instructions.
  4. Cooperation. Taking into account the nature of processing and the information available to Zscaler, Zscaler will assist Customer with any necessary data protection impact assessments or similar assessments required of Customer by Data Protection Legislation, and will assist Customer in the cooperation or prior consultations with a Supervisory Authority.
  5. Deletion and Return of Personal Data. Zscaler will, at Customer’s option, and subject to the terms of this DPA (a) delete or return all Personal Data to Customer after the end of the provision of the Products, and (b) delete existing copies of Personal Data unless legally required to retain the Personal Data. Notwithstanding the foregoing, Zscaler will not store Personal Data beyond the retention period set forth in Exhibit A.

3. INTERNATIONAL TRANSFERS

  1. International Transfers. Customer consents to Zscaler processing or transferring any Personal Data in or to a territory other than the territory in which the Personal Data was first collected. Zscaler will take such measures as are necessary to ensure such processing or transfer is in compliance with Data Protection Legislation and in accordance with any applicable transfer mechanism provisions set forth in Section 3.2 (Transfer Mechanism) below.
  2. Transfer Mechanism. If Data Protection Legislation places restrictions on the transfer of Personal Data across international borders, then Zscaler will work with Customer to ensure that any international transfer is performed in accordance with Data Protection Legislation and, if required, the parties will execute such applicable legal mechanism (“Transfer Mechanism”). This includes, where applicable, relying on the following Transfer Mechanisms as part of this DPA:
    1. EU Standard Contractual Clauses and UK Addendum. To the extent that Personal Data is transferred outside of the EEA, Switzerland, or the United Kingdom those transfers will be governed by the pre-configured applicable approved standard contractual clauses and addenda (as may be amended or replaced by the respective regulatory authorities from time to time), which are incorporated herein by reference with all implementation details completed. The implementation details, including applicable modules, completed clauses, and full text of these transfer mechanisms can be found at: https://www.zscaler.com/resources/legal/eu-scc-contractual-clauses.pdf.
    2. Data Privacy Framework (“DPF”). Zscaler is certified to the EU-US DPF, the UK Extension to the EU-US DPF, and the Swiss-US DPF and the commitments they entail. These frameworks enable the transfer of personal information to the US from the EU, UK, and Switzerland on the basis of an adequacy decision from the European Commission. Zscaler’s status under the DPF frameworks can be found at https://www.dataprivacyframework.gov/.
  3. Alternative Transfer Mechanism. Zscaler will notify Customer if it determines that a change in Data Protection Legislation will adversely affect or invalidate the warranties and obligations provided under an executed Transfer Mechanism or if an alternative Transfer Mechanism becomes available to use by the parties.  In such an event, Zscaler will work with the Customer to find a mutually agreeable solution to ensure that Personal Data is transferred in compliance with Data Protection Legislation.

4. SUB-PROCESSORS

  1. Sub-processing. Customer provides a general authorization to Zscaler to engage sub-processors that are listed at the following URL: https://www.zscaler.com/privacy-compliance/subprocessors (the “Sub-Processor List”) to enable Zscaler to fulfill its contractual obligations under the Agreement and to provide support services on Zscaler’s behalf, subject to compliance with the requirements in this Section. The Sub-processor List includes information on Sub-processors’ location and services provided. The Sub-processor List may be updated by Zscaler from time to time in accordance with Subsection 4.3 (Changes to Sub-Processor List).
  2. Sub-processor Agreements. Zscaler will: (a) enter into a written agreement with any Sub-processor that will process Personal Data; (b) ensure that each such written agreement contains terms that are no less protective of Personal Data than those contained in this DPA; and (c) be liable for the acts and omissions of its Sub-processors to the same extent that Zscaler would be liable if it were performing the services of each of those Sub-processors directly under the terms of this DPA. Upon written request by Customer, copies of Sub-processor agreements may be provided to Customer. The parties agree that copies of any Sub-processor agreements that are provided by Zscaler to Customer may have all commercial information, business secrets, or other confidential information redacted by Zscaler beforehand.
  3. Changes to Sub-processor List. Zscaler will provide Customer with at least thirty (30) days advance notice before a new Sub-processor processes any Personal Data (which may be provided via email to the address shared by Customer when registering at the Zscaler Trust portal located at the following link: https://trust.zscaler.com, or such other reasonable means). Zscaler will not permit any new Sub-processor to process Personal Data until the earlier of the: (i) expiration of the thirty (30) day objection period, or (ii) resolution of any timely objection as described below.
    Customer may object to a new Sub-processor within thirty (30) days of such notice on reasonable grounds relating to data protection. If Customer objects, Zscaler will either: (a) not engage the Sub-processor for Personal Data processing, (b) take corrective steps to address Customer’s concerns, or (c) cease providing the specific Product feature requiring such Sub–processor. 
    If no mutually acceptable resolution is reached within thirty (30) days after Zscaler receives Customer’s objection, either party may terminate the affected Product(s), and Customer will receive a pro-rated refund of prepaid fees for the unused Subscription Term. This termination right is Customer’s sole remedy for Sub-processor objections.

5. SECURITY MEASURES AND DATA ACCESS

  1. Security Measures. Zscaler will implement appropriate technical, administrative, physical, and organizational measures set forth here: https://www.zscaler.com/legal/security-measures (“Security Measures”) to adequately safeguard and protect the security and confidentiality of Personal Data against accidental, unauthorized, or unlawful destruction, alteration, modification, processing, disclosure, loss, or access. Zscaler will not materially decrease the overall security of the Products during the term of the Agreement.  Zscaler will take appropriate steps to ensure compliance with the Security Measures by its employees, contractors, and Sub-processors to the extent applicable to their scope of performance.
  2. Confidentiality and Limitation of Access. Zscaler will ensure that persons authorized to process Personal Data on behalf of Zscaler have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Only Zscaler persons authorized to process Personal Data will have access to Personal Data to the extent it is necessary. 

6. SECURITY INCIDENTS

Zscaler shall notify Customer without undue delay (which may be provided via email to the address shared by Customer when registering at the Zscaler Trust portal located at the following link: https://trust.zscaler.com, or such other reasonable means) if it becomes aware of any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data (“Security Incident”). In the event of a Security Incident Zscaler will (a) take reasonable steps to identify and remediate the cause of the Security Incident; and (b) reasonably cooperate with Customer regarding any investigations and required notices.

7. RIGHTS OF DATA SUBJECTS

Taking into account the nature of the processing, Zscaler will reasonably assist Customer to enable their ability to respond to data subject rights requests provided under Data Protection Legislation relating to the processing of Personal Data, including providing reasonable assistance in implementing technical and organizational measures. Zscaler shall, to the extent legally permitted, promptly notify Customer if Zscaler receives such request. To the extent legally permitted, Customer shall be responsible for any reasonable costs that Zscaler may incur in providing such assistance.

8. DOCUMENTATION AND AUDIT RIGHT

  1. Records of Processing. Zscaler will maintain a record of all categories of processing activities carried out on behalf of Customer. Zscaler will make available to Customer or relevant supervisory authority, if requested, all information necessary to demonstrate Zscaler’s compliance with its obligations under Data Protection Legislation.
  2. Audits. The parties agree that the audits required under Data Protection Legislation (the “Audit”), will be carried out in accordance with the following conditions:
    1. An Audit of its data processing facilities may be performed no more than once per year during Zscaler’s normal business hours, unless (a) otherwise agreed to in writing by Customer and Zscaler, (b) required by a regulator or under applicable Data Protection Legislation, or (c) there is a Security Incident concerning Personal Data;
    2. Customer will provide Zscaler with at least thirty (30) days’ prior written notice of an Audit, which may be conducted by Customer, or an independent auditor appointed by Customer that is not a competitor of Zscaler (an “Auditor”);
    3. The Auditors will conduct Audits subject to any appropriate and reasonable confidentiality restrictions requested by Zscaler;
    4. The scope of an Audit will be limited to Zscaler systems, processes, and documentation relevant to the processing and protection of Personal Data;
    5. Prior to the start of an Audit, the parties will agree to reasonable scope, time, duration, place, and conditions for the Audit, and a reasonable reimbursement rate payable by Customer to Zscaler for Zscaler’s Audit expenses
    6. If available, Zscaler will provide an Auditor, upon request, with any third-party certifications pertinent to Zscaler’s compliance with its obligations under this DPA (for example, ISO 27001 and/or SOC 2, Type II); and
    7. Customer will promptly notify and provide Zscaler with full details regarding any perceived non-compliance or security concerns discovered during the course of an Audit.

9. GENERAL

  1. Term and Termination. This DPA will remain in effect for as long as Zscaler processes Personal Data on behalf of Customer under the Agreement.
  2. Governing Law. This DPA shall be governed by and construed in accordance with the governing law and jurisdiction provisions in the Agreement, unless otherwise required by Data Protection Legislation.
  3. Changes in Data Protection Legislation. If a change in Data Protection Legislation requires an amendment to this DPA or to any applicable Transfer Mechanism, the parties agree to negotiate such amendment in good faith, which shall be in writing and signed by both parties.
  4. Order of precedence.  In the event of a conflict, the order of precedence will be: (a) the applicable Transfer Mechanism, (b) this DPA, and (c) the Agreement. This DPA and the Agreement constitute the entire agreement between the parties on this subject matter.
  5. Severability.  If any provision of this DPA is held to be unenforceable, the remaining provisions will remain in full force and effect.

Exhibit A

Details of Personal Data Processing

Subject Matter of Processing

The subject matter of processing is the provision of the Products pursuant to the Agreement.

Duration of Processing

The processing will continue until the expiration or termination of the Agreement, subject to the applicable Retention Period.

Categories of Data Subjects

Employees and other authorized users of Customer.

Nature and Purpose of Processing

Nature:  processing as part of the provision of the Products ordered by Customer in the Agreement.

Purpose:  The purpose of the processing of Personal Data by Zscaler is to provide the Products pursuant to the Agreement.

I. Types of Personal Data Processed

The following table lists the Personal Data that is processed by all Products.

Type of Personal Data

Description

Directory Information

Information fetched from Customer’s corporate directory such as name, employee number, group, and department.

User Identifier

Name, username, email address, phone number, or other identifier that identifies a specific user.

Device Details

Information from the device being used by an end user that can identify a specific user, which may include device owner name, machine host name, and MAC address.

IP Addresses

To map an organization’s physical office location to a logical location name in the Product based on the source IP of the traffic being sent to Zscaler. IP address of the user’s device.

Location

The general location of the device being used by a user derived from an IP address

AI Prompts and Responses

User inputs submitted to and responses   generated by AI tools, including any Personal Data contained therein.

The tables below list the additional Personal Data that is processed by a particular Product. Each table below should be read to be inclusive of the table above.

Zscaler Internet Access (ZIA)

Type of Personal Data

Description

Cookies and other similar technologies

By enabling the “Cookies Persistence” option for Zscaler Remote Browser Isolation, Customer authorizes Zscaler and its permitted third-party hosting service providers the right to store user-level cookies and other similar technologies.

URL

URL address of an internet destination if such address either is or contains identifying or identifiable information of a natural person.

Zscaler Digital Experience (ZDX)

Type of Personal Data

Description

Geolocation Data

Geolocation coordinates (longitude and latitude) of a user’s device.

Home Wifi SSID

Home Wi-Fi SSID would be captured if the user is working from home.

Device Serial Number

The unique serial number of the device being used by an authorized user.

Zscaler AI Scanning Platform

Type of Personal Data

Description

Probe Test Interactions

User prompts and outputs exchanged with chatbots during pen-testing and scanning activities.

Zero Trust Browser

The Personal Data that is processed by this product are subject to the Customer’s discretion when enabling policies and may include the following:

Type of Personal Data

Description

Browser Data

Browser configuration data, including browser name, browser version, and browser profile.

Browsing Activities

Web navigation metadata (navigation type, browser tab identifiers), site content accessed by the end user, user input into web forms and fields, and session recordings (RRWeb JSON replay files and screenshot images), clipboard data, AI prompts or outputs, and uploaded or downloaded files.

User Authentication Data

Credential or authentication tokens entered by end users.

II. Data Storage and Retention Periods

During the Subscription Term, the Personal Data shall be retained by Zscaler depending on the Product. The applicable data storage and retention for each Product can be found at https://help.zscaler.com/customer-logs-fair-use.

 

III. Zscaler’s Privacy Team Contact Details

Email: [email protected]

Zscaler Platform
AI Security
Data Security
SecOps
Product & Solutions
Product Tours
Industries
Partners
Carbon
About Zscaler
Zscaler FAQ
Leadership
Careers
Investors
Press
Responsibility
Contact
Pricing
Red Canary
Community
Analysts
News
Zenith Live
Events
Executive Insights App
ThreatLabz Research
Resource Library
Blog
Webinars
Zpedia Articles
Cyber Academy
Customer Stories
Customer Success Center
Contact Support
Help Portal
Security Advisories
Disclose a Vulnerability
Security Risk Assessments
Compliance
Partner Portal
Home

Zscaler is universally recognized as the leader in zero trust. Leveraging the largest security cloud on the planet, Zscaler anticipates, secures, and simplifies the experience of doing business for the world's most established companies.

Visit us on Facebook(opens in a new tab)Find us on LinkedIn(opens in a new tab)Follow us on X(opens in a new tab)Subscribe our Youtube Channel(opens in a new tab)Follow us on Instagram(opens in a new tab)
SitemapPrivacyLegalSecurityCookie preferences
© 2026 Zscaler, Inc.

All rights reserved. Zscaler™ and other trademarks listed at zscaler.com/legal/trademarks are either (i) registered trademarks or service marks or (ii) trademarks or service marks of Zscaler, Inc. in the United States and/or other countries. Any other trademarks are the properties of their respective owners.