Solicitar una demostración
Contacte con nosotros
Zscaler Cloud Portal
Zscaler Cloud Portal | Admin
Zscaler Cloud Portal Two
Zscaler Cloud Portal Three
Zscaler Cloud Portal Beta
admin.zscloud.net
Zscaler Private Access Cloud Portal One | Admin
Zscaler Private Access Cloud Portal Two
English
Français
Deutsch
Italiano
日本語
Castellano - Mexico
Castellano - España
Portugues - Brasil
Home

Plataforma unificada de Zscaler

La plataforma de ciberseguridad unificada de Zscaler construida sobre el Zero Trust Exchange. Una plataforma hace que su superficie de ataque desaparezca y escale con la IA.

Más información

SASE Zero Trust en todas partes

Proteja a los usuarios, dispositivos, cargas de trabajo y agentes con la exclusiva plataforma SASE diseñada para Zero Trust e IA.

Más información
Acceso seguro a Internet (ZIA)Proteja a los usuarios al navegar por Internet o al usar aplicaciones SaaS.Acceso privado seguro (ZPA)Conecte a los usuarios con las aplicaciones privadas sin una VPN.Zero Trust BranchZero Trust CloudDigital Experience (ZDX)Detecte y resuelva rápidamente problemas de aplicaciones, redes y dispositivos.Navegador Zero Trust Proteja la navegación y el acceso privado a aplicaciones en cualquier dispositivo.Cloud SandboxDefend against unknown file-based threats.Zero Trust FirewallExtienda la inspección del tráfico a todos los puertos y protocolos.Zero Trust Gateway Continuidad del negocioMantenga los servicios críticos y el tiempo de actividad durante fallas críticas.Acceso remoto privilegiadoHabilite el acceso remoto seguro, controlado y sin cliente.Zscaler CelularProteja los dispositivos de telefonía celular y la infraestructura de telecomunicaciones.

Soluciones

Desde casos de uso e industrias hasta socios tecnológicos, encuentre la combinación adecuada de soluciones para su organización.

Más información
Gestión de activos de IASeguridad de la IAGestión de la superficie de ataqueSeguridad de dispositivos propios (BYOD)Gestión continua de la exposición a amenazasSeguridad de los datosMicrosegmentaciónSegmentación IoT/OTReemplace la VPNAcceso seguro a la IASecure B2BProteja el tráfico este-oesteSecure Ingress and Egress TrafficIoT/OT seguroProteja a la fuerza de trabajoGráfico de contexto de seguridadZero Trust + IAZero Trust SD-WAN

Biblioteca de recursos

Manténgase al día de las últimas novedades, informes, guías, seminarios web sobre ciberseguridad e historias de clientes.

Más información
Contacte con el soporteContacte al equipo de soporte técnico de Zscaler las 24 horas del día, los 7 días de la semana, por ticket o por teléfono.Centro de éxito del clienteCapacitación, buenas prácticas y recursos para aprovechar al máximo su implementación de Zscaler.Release NotesThe latest product updates, new features, and bug fixes across all Zscaler services.Portal de confianzaNotificaciones en tiempo real sobre el estado del servicio, estado de la actividad y mantenimiento planeado.Comunidad ZenithConéctese con más de 374,000 usuarios, socios y expertos de Zscaler.Zscaler Portal de AyudaDocumentación técnica, guías de productos y consejos para la resolución de problemas.

Sobre Zscaler

Empleando la mayor nube de seguridad del mundo, Zscaler ayuda a las principales empresas a mantenerse al frente de las amenazas y a simplificar las operaciones comerciales.

Más información

Who We Are

The people, values, and vision behind Zscaler and everything you need to know about us as a company.

Reconocimiento de analistasVea por qué Gartner®, Forrester y otros consideran a Zscaler como un líder.EmpleoCumplimientoResponsabilidad corporativaCómo Zscaler genera un impacto positivo a través de una gestión responsable.CulturaAprenda cómo trabajamos, qué valoramos y qué nos motiva.Preguntas frecuentesRespuestas rápidas sobre quiénes somos, qué hacemos y cómo funciona la plataforma.Relaciones con los inversoresResultados financieros, presentaciones ante la SEC y gobernanza corporativa para NASDAQ: ZS.Equipo directivoEmpresas ZenithInversión en la nueva generación de startups dedicadas a Zero Trust e inteligencia artificial.
Home
Solicitar una demostraciónContacte con nosotros
Last updated: August, 2026

Zscaler Data Processing Agreement

Contents

  1. DEFINITIONS
  2. DATA PROCESSING
  3. INTERNATIONAL TRANSFERS
  4. SUB-PROCESSORS
  5. SECURITY MEASURES AND DATA ACCESS
  6. SECURITY INCIDENTS
  7. RIGHTS OF DATA SUBJECTS
  8. DOCUMENTATION AND AUDIT RIGHT
  9. GENERAL
  10. Exhibit A

This Data Processing Agreement (“DPA”) forms part of any agreement between Zscaler, Inc. (“Zscaler”) and the customer that is identified on, and is a party to, such agreement (“Customer”) under which Zscaler’s products are provided (“Agreement”). Capitalized terms not defined herein shall have the meanings assigned to such terms in the Agreement.

1. DEFINITIONS

  1. “Controller” means the entity which determines the purposes and means of the processing of Personal Data.
  2. “Data Protection Legislation” means any and all applicable federal, state, provincial, and foreign data protection, privacy, and data security laws, regulations, and directives applicable to the processing of Personal Data under the Agreement, as amended from time to time.
  3. “Data Subject” means an identified or identifiable natural person to whom Personal Data relates.
  4. “Personal Data” means any information relating to an identified or identifiable natural person that is submitted to the Products by Customer and processed for the purposes of providing the Products to Customer. The types of Personal Data, specific uses, and retention periods are detailed in Exhibit A.
  5. “Processing”, “process”, or “processes” means any operation or set of operations which is performed upon Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
  6. “Processor” means the entity that processes Personal Data on behalf of the Controller.
  7. “Sub-processor” means the entity engaged by Zscaler for carrying out specific processing activities of Personal Data.
  8. “Supervisory Authority” means any local, national, supranational, state, governmental or quasi-governmental agency, body, department, board, official or entity exercising regulatory or supervisory authority pursuant to any Data Protection Legislation in accordance with this DPA.

2. DATA PROCESSING

  1. Roles of the Parties.  The parties acknowledge and agree that with regard to the processing of Personal Data for the provision of the Products, Customer is the Controller and Zscaler is the Processor. The parties agree to comply with Data Protection Legislation.
  2. Instructions. Zscaler will process the Personal Data only in accordance with this DPA and any documented Customer instructions. Zscaler will process Personal Data from its global data centers depending on where Customer’s users are located, for the following purposes: (a) processing necessary for the provision of the Products in accordance with this DPA and the Agreement; (b) any processing initiated by Customer’s end users in their use of the Products; and (c) any processing to comply with the other reasonable documented instructions provided by Customer to Zscaler (e.g., via email or via support requests) where such instructions are consistent with the terms of the Agreement, as required to comply with Data Protection Legislation, or as otherwise mutually agreed by the parties in writing. Zscaler will promptly inform Customer if in its opinion compliance with any Customer instruction would infringe Data Protection Legislation.
  3. Customer Responsibilities. Customer will, in its use of the Products, comply with the requirements of Data Protection Legislation which includes instructions to Zscaler in regard to the processing of Personal Data.  Customer will have sole responsibility for the accuracy, quality, and legality of Personal Data and for ensuring that the Personal Data was lawfully acquired by Customer (including any authorizations or consents if required).  Customer shall ensure that Customer is entitled to transfer the relevant Personal Data to Zscaler so that Zscaler may lawfully use, process, and transfer the Personal Data in accordance with Customer’s instructions.
  4. Cooperation. Taking into account the nature of processing and the information available to Zscaler, Zscaler will assist Customer with any necessary data protection impact assessments or similar assessments required of Customer by Data Protection Legislation, and will assist Customer in the cooperation or prior consultations with a Supervisory Authority.
  5. Deletion and Return of Personal Data. Zscaler will, at Customer’s option, and subject to the terms of this DPA (a) delete or return all Personal Data to Customer after the end of the provision of the Products, and (b) delete existing copies of Personal Data unless legally required to retain the Personal Data. Notwithstanding the foregoing, Zscaler will not store Personal Data beyond the retention period set forth in Exhibit A.

3. INTERNATIONAL TRANSFERS

  1. International Transfers. Customer consents to Zscaler processing or transferring any Personal Data in or to a territory other than the territory in which the Personal Data was first collected. Zscaler will take such measures as are necessary to ensure such processing or transfer is in compliance with Data Protection Legislation and in accordance with any applicable transfer mechanism provisions set forth in Section 3.2 (Transfer Mechanism) below.
  2. Transfer Mechanism. If Data Protection Legislation places restrictions on the transfer of Personal Data across international borders, then Zscaler will work with Customer to ensure that any international transfer is performed in accordance with Data Protection Legislation and, if required, the parties will execute such applicable legal mechanism (“Transfer Mechanism”). This includes, where applicable, relying on the following Transfer Mechanisms as part of this DPA:
    1. EU Standard Contractual Clauses and UK Addendum. To the extent that Personal Data is transferred outside of the EEA, Switzerland, or the United Kingdom those transfers will be governed by the pre-configured applicable approved standard contractual clauses and addenda (as may be amended or replaced by the respective regulatory authorities from time to time), which are incorporated herein by reference with all implementation details completed. The implementation details, including applicable modules, completed clauses, and full text of these transfer mechanisms can be found at: https://www.zscaler.com/resources/legal/eu-scc-contractual-clauses.pdf.
    2. Data Privacy Framework (“DPF”). Zscaler is certified to the EU-US DPF, the UK Extension to the EU-US DPF, and the Swiss-US DPF and the commitments they entail. These frameworks enable the transfer of personal information to the US from the EU, UK, and Switzerland on the basis of an adequacy decision from the European Commission. Zscaler’s status under the DPF frameworks can be found at https://www.dataprivacyframework.gov/.
  3. Alternative Transfer Mechanism. Zscaler will notify Customer if it determines that a change in Data Protection Legislation will adversely affect or invalidate the warranties and obligations provided under an executed Transfer Mechanism or if an alternative Transfer Mechanism becomes available to use by the parties.  In such an event, Zscaler will work with the Customer to find a mutually agreeable solution to ensure that Personal Data is transferred in compliance with Data Protection Legislation.

4. SUB-PROCESSORS

  1. Sub-processing. Customer provides a general authorization to Zscaler to engage sub-processors that are listed at the following URL: https://www.zscaler.com/privacy-compliance/subprocessors (the “Sub-Processor List”) to enable Zscaler to fulfill its contractual obligations under the Agreement and to provide support services on Zscaler’s behalf, subject to compliance with the requirements in this Section. The Sub-processor List includes information on Sub-processors’ location and services provided. The Sub-processor List may be updated by Zscaler from time to time in accordance with Subsection 4.3 (Changes to Sub-Processor List).
  2. Sub-processor Agreements. Zscaler will: (a) enter into a written agreement with any Sub-processor that will process Personal Data; (b) ensure that each such written agreement contains terms that are no less protective of Personal Data than those contained in this DPA; and (c) be liable for the acts and omissions of its Sub-processors to the same extent that Zscaler would be liable if it were performing the services of each of those Sub-processors directly under the terms of this DPA. Upon written request by Customer, copies of Sub-processor agreements may be provided to Customer. The parties agree that copies of any Sub-processor agreements that are provided by Zscaler to Customer may have all commercial information, business secrets, or other confidential information redacted by Zscaler beforehand.
  3. Changes to Sub-processor List. Zscaler will provide Customer with at least thirty (30) days advance notice before a new Sub-processor processes any Personal Data (which may be provided via email to the address shared by Customer when registering at the Zscaler Trust portal located at the following link: https://trust.zscaler.com, or such other reasonable means). Zscaler will not permit any new Sub-processor to process Personal Data until the earlier of the: (i) expiration of the thirty (30) day objection period, or (ii) resolution of any timely objection as described below.
    Customer may object to a new Sub-processor within thirty (30) days of such notice on reasonable grounds relating to data protection. If Customer objects, Zscaler will either: (a) not engage the Sub-processor for Personal Data processing, (b) take corrective steps to address Customer’s concerns, or (c) cease providing the specific Product feature requiring such Sub–processor. 
    If no mutually acceptable resolution is reached within thirty (30) days after Zscaler receives Customer’s objection, either party may terminate the affected Product(s), and Customer will receive a pro-rated refund of prepaid fees for the unused Subscription Term. This termination right is Customer’s sole remedy for Sub-processor objections.

5. SECURITY MEASURES AND DATA ACCESS

  1. Security Measures. Zscaler will implement appropriate technical, administrative, physical, and organizational measures set forth here: https://www.zscaler.com/legal/security-measures (“Security Measures”) to adequately safeguard and protect the security and confidentiality of Personal Data against accidental, unauthorized, or unlawful destruction, alteration, modification, processing, disclosure, loss, or access. Zscaler will not materially decrease the overall security of the Products during the term of the Agreement.  Zscaler will take appropriate steps to ensure compliance with the Security Measures by its employees, contractors, and Sub-processors to the extent applicable to their scope of performance.
  2. Confidentiality and Limitation of Access. Zscaler will ensure that persons authorized to process Personal Data on behalf of Zscaler have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Only Zscaler persons authorized to process Personal Data will have access to Personal Data to the extent it is necessary. 

6. SECURITY INCIDENTS

Zscaler shall notify Customer without undue delay (which may be provided via email to the address shared by Customer when registering at the Zscaler Trust portal located at the following link: https://trust.zscaler.com, or such other reasonable means) if it becomes aware of any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data (“Security Incident”). In the event of a Security Incident Zscaler will (a) take reasonable steps to identify and remediate the cause of the Security Incident; and (b) reasonably cooperate with Customer regarding any investigations and required notices.

7. RIGHTS OF DATA SUBJECTS

Taking into account the nature of the processing, Zscaler will reasonably assist Customer to enable their ability to respond to data subject rights requests provided under Data Protection Legislation relating to the processing of Personal Data, including providing reasonable assistance in implementing technical and organizational measures. Zscaler shall, to the extent legally permitted, promptly notify Customer if Zscaler receives such request. To the extent legally permitted, Customer shall be responsible for any reasonable costs that Zscaler may incur in providing such assistance.

8. DOCUMENTATION AND AUDIT RIGHT

  1. Records of Processing. Zscaler will maintain a record of all categories of processing activities carried out on behalf of Customer. Zscaler will make available to Customer or relevant supervisory authority, if requested, all information necessary to demonstrate Zscaler’s compliance with its obligations under Data Protection Legislation.
  2. Audits. The parties agree that the audits required under Data Protection Legislation (the “Audit”), will be carried out in accordance with the following conditions:
    1. An Audit of its data processing facilities may be performed no more than once per year during Zscaler’s normal business hours, unless (a) otherwise agreed to in writing by Customer and Zscaler, (b) required by a regulator or under applicable Data Protection Legislation, or (c) there is a Security Incident concerning Personal Data;
    2. Customer will provide Zscaler with at least thirty (30) days’ prior written notice of an Audit, which may be conducted by Customer, or an independent auditor appointed by Customer that is not a competitor of Zscaler (an “Auditor”);
    3. The Auditors will conduct Audits subject to any appropriate and reasonable confidentiality restrictions requested by Zscaler;
    4. The scope of an Audit will be limited to Zscaler systems, processes, and documentation relevant to the processing and protection of Personal Data;
    5. Prior to the start of an Audit, the parties will agree to reasonable scope, time, duration, place, and conditions for the Audit, and a reasonable reimbursement rate payable by Customer to Zscaler for Zscaler’s Audit expenses
    6. If available, Zscaler will provide an Auditor, upon request, with any third-party certifications pertinent to Zscaler’s compliance with its obligations under this DPA (for example, ISO 27001 and/or SOC 2, Type II); and
    7. Customer will promptly notify and provide Zscaler with full details regarding any perceived non-compliance or security concerns discovered during the course of an Audit.

9. GENERAL

  1. Term and Termination. This DPA will remain in effect for as long as Zscaler processes Personal Data on behalf of Customer under the Agreement.
  2. Governing Law. This DPA shall be governed by and construed in accordance with the governing law and jurisdiction provisions in the Agreement, unless otherwise required by Data Protection Legislation.
  3. Changes in Data Protection Legislation. If a change in Data Protection Legislation requires an amendment to this DPA or to any applicable Transfer Mechanism, the parties agree to negotiate such amendment in good faith, which shall be in writing and signed by both parties.
  4. Order of precedence.  In the event of a conflict, the order of precedence will be: (a) the applicable Transfer Mechanism, (b) this DPA, and (c) the Agreement. This DPA and the Agreement constitute the entire agreement between the parties on this subject matter.
  5. Supplemental Term. If Customer is established in an EU member state then, the supplemental terms available at https://www.zscaler.com/legal/data-act-addendum (as updated by Zscaler from time to time in accordance with applicable law) will apply and are incorporated into this DPA by reference. If this DPA conflicts with those supplemental terms, the supplemental terms prevail solely regarding the subject matter they address.
  6. Severability.  If any provision of this DPA is held to be unenforceable, the remaining provisions will remain in full force and effect.

Exhibit A

Details of Personal Data Processing

Subject Matter of Processing

The subject matter of processing is the provision of the Products pursuant to the Agreement.

Duration of Processing

The processing will continue until the expiration or termination of the Agreement, subject to the applicable Retention Period.

Categories of Data Subjects

Employees and other authorized users of Customer.

Nature and Purpose of Processing

Nature:  processing as part of the provision of the Products ordered by Customer in the Agreement.

Purpose:  The purpose of the processing of Personal Data by Zscaler is to provide the Products pursuant to the Agreement.

I. Types of Personal Data Processed

The following table lists the Personal Data that is processed by all Products.

Type of Personal Data

Description

Directory Information

Information fetched from Customer’s corporate directory such as name, employee number, group, and department.

User Identifier

Name, username, email address, phone number, or other identifier that identifies a specific user.

Device Details

Information from the device being used by an end user that can identify a specific user, which may include device owner name, machine host name, and MAC address.

IP Addresses

To map an organization’s physical office location to a logical location name in the Product based on the source IP of the traffic being sent to Zscaler. IP address of the user’s device.

Location

The general location of the device being used by a user derived from an IP address

AI Prompts and Responses

User inputs submitted to and responses   generated by AI tools, including any Personal Data contained therein.

The tables below list the additional Personal Data that is processed by a particular Product. Each table below should be read to be inclusive of the table above.

Zscaler Internet Access (ZIA)

Type of Personal Data

Description

Cookies and other similar technologies

By enabling the “Cookies Persistence” option for Zscaler Remote Browser Isolation, Customer authorizes Zscaler and its permitted third-party hosting service providers the right to store user-level cookies and other similar technologies.

URL

URL address of an internet destination if such address either is or contains identifying or identifiable information of a natural person.

Zscaler Digital Experience (ZDX)

Type of Personal Data

Description

Geolocation Data

Geolocation coordinates (longitude and latitude) of a user’s device.

Home Wifi SSID

Home Wi-Fi SSID would be captured if the user is working from home.

Device Serial Number

The unique serial number of the device being used by an authorized user.

Zero Trust Browser

The Personal Data that is processed by this product are subject to the Customer’s discretion when enabling policies and may include the following:

Type of Personal Data

Description

Browser Data

Browser configuration data, including browser name, browser version, and browser profile.

Browsing Activities

Web navigation metadata (navigation type, browser tab identifiers), site content accessed by the end user, user input into web forms and fields, and session recordings (RRWeb JSON replay files and screenshot images), clipboard data, AI prompts or outputs, and uploaded or downloaded files.

User Authentication Data

Credential or authentication tokens entered by end users.

MDR

The Personal Data that is processed by this product are subject to the Customer’s discretion when uploading data to make  use of the services and may include the following:

Type of Personal Data

Description

Phone Number

End user telephone numbers processed to deliver configurable automated notifications and alerts, including voice calls, email, and SMS messages.

II. Data Storage and Retention Periods

During the Subscription Term, the Personal Data shall be retained by Zscaler in accordance with the applicable data storage and retention policy for each Product. Depending on the Product, the applicable policy can be found at either https://help.zscaler.com/customer-logs-fair-use or https://docs.redcanary.com/docs/data-retention-policy.

 

III. Zscaler’s Privacy Team Contact Details

Email: [email protected]

Plataforma Zero Trust
Seguridad de la IA
Seguridad de los datos
SecOps
Productos y soluciones
Conozca el producto
Sectores
Socios
Carbon
Sobre Zscaler
Preguntas frecuentes sobre Zscaler
Liderazgo
Empleo
Inversores
Prensa
Responsabilidad
Contacto
Pricing
Red Canary
Comunidad
Analistas
Noticias
Zenith Live
Events
Aplicación Executive Insights
ThreatLabz Research
Biblioteca de recursos
Blog
Seminarios web
Zpedia
Cyber Academy
Historias de éxito de clientes
Centro de éxito del cliente
Contacte con el soporte
Portal de Ayuda
Asesorías de seguridad
Revele una vulnerabilidad
Evaluaciones de riesgos de seguridad
Cumplimiento
Portal de socios
Home

Zscaler es reconocido universalmente como el líder en Zero Trust. Aprovechando la nube de seguridad más grande del planeta, Zscaler anticipa, protege y simplifica la experiencia comercial para las empresas más establecidas del mundo. 

Visítenos en Facebook(opens in a new tab)Síganos en LinkedIn(opens in a new tab)Síganos en X(opens in a new tab)Suscríbase a nuestro canal de YouTube(opens in a new tab)Síganos en Instagram(opens in a new tab)
Mapa do sitePrivacyInformación legalSeguridadPreferencias de cookies
© 2026 Zscaler, Inc.

All rights reserved. Zscaler™ and other trademarks listed at zscaler.com/legal/trademarks are either (i) registered trademarks or service marks or (ii) trademarks or service marks of Zscaler, Inc. in the United States and/or other countries. Any other trademarks are the properties of their respective owners.