This episode is recorded in person in Denver, where the hosts are about to run a privacy workshop. The primary topic is Zoom's controversial update to its terms of service, which asserted the right to use content captured through the platform to train AI models. The update itself may not have been nefarious — companies routinely try to keep their terms elastic as technology evolves — but the absence of any accompanying communication transformed a routine legal exercise into a media storm. The deeper issue is structural: Zoom operates as a B2B service provider processing customer data under enterprise contracts and data processing agreements that strictly constrain what processors can do with that data. When a processor tries to expand its rights to use customer data for its own AI purposes without proactive disclosure, it violates both the letter of those agreements and the trust at the core of the business relationship. The takeaway for in-house counsel is clear — any material change to data use requires upfront dialogue, not just a terms revision, and the bar is especially high when the change involves AI and public understanding of the technology remains limited. The second story is NatWest and the emergence of what might be called privacy cancel culture. UK politician Nigel Farage had his bank account closed; when he filed a data subject request, he discovered the closure was politically motivated. He publicized the finding, built a Facebook group of ten thousand followers, and the group began coordinating mass data subject requests against the bank. The episode surfaces a structural vulnerability: most companies size their DSR operations based on steady historical volume, making them unprepared for a viral event that floods them with simultaneous requests under binding legal deadlines. DSRs have become a tool of collective consumer protest — a weaponized mechanism that activates when public attention turns negative on a company. Transparency in data practices is a partial defense, but insufficient on its own — companies also need the operational infrastructure to handle surge volumes before the crisis arrives, not while it is happening. The episode closes with a preview of the Denver workshop agenda: data deletion operationalization, sensitive personal information handling, and data protection impact assessments. These topics were chosen because clients are asking about them frequently and because industry consensus has not yet formed around how to approach them practically.
Zoom AI terms backlash and weaponized data subject requests
- AI PrivacyPrivacy RegulationsGDPR
- Episode 22
- August 10, 2023
Stream this episode on
Summary
Transcript
**Jonathan:** Person. We're in person for once. **Alysa:** I love it. A Practical Privacy, here in Denver. Right? **Jonathan:** It's August. I thought nothing was supposed to be happening. **Alysa:** Yeah. Before taking vacations. **Jonathan:** I think every privacy lawyer was feeling that too. Like, it's August. Does it ever stop? **Alysa:** And it doesn't. It just doesn't. And then Zoom does the thing. People are still talking about AI. I thought we'd be done with that. **Jonathan:** No. But we're — a, we're not done. And b, I think it raises a whole new risk consideration to think about for the in-house lawyer as, you know, we're juggling lots of things — but what kind of — the smallest thing, what you would think would be the smallest thing, like, we just gotta update and account for certain developments, and have it turn into, like, a massive media existential issue for the business. Let's talk about that. So let's talk about Zoom and AI and then updating their policies there. And — big backtrack. And then NatWest, which I think is somewhat related. **Alysa:** So Zoom, what's happening? They came up with an update to their policies. They said, hey. All your conversations, everything we're picking up on Zoom, we can use that to train the algorithm. So that was certainly the media — that was the national takeaway. I'm gonna zoom out a little bit, and you have this issue where companies — a, anytime they update their terms and conditions in or privacy policy, they need to make it a little bit elastic for, like, some developments. And could not know there's this development of AI, right, and how companies can use data to update their practices. Now the — I think the real pain point is when you have B2B companies — the data that they have is customer data. And if you're a service provider, if you're a processor service provider, customer data is sacrosanct. So many data processing addendums about processors only using the data on behalf of the controller, and there's just a really narrow element about where the service provider can use the data for its own purposes. And I think you get into this hot zone when the service provider does things like video recording, audio recording, confidential communications, sensitive communications, and particularly, you know, you have these enterprise contracts with Zoom, but it's beyond Zoom because it really goes to that B2B issue — on your ability to use data or not and how upfront you are about that or how you try to slide that under the radar. And I think the problem here was they did update the terms and conditions, and everybody's now taking a more critical look. It's not just the lawyers reading these terms and conditions. And so you have plain language takes on, wait a second — what are they trying to do with the data? And nothing nefarious. It was just let's try to keep this language open in case we need to do something with this. So — I don't represent Zoom. I don't know what the intent was, but I know the issue of what clients face when they update the terms and conditions, and they are trying to account for — improving this question of how do you address AI in your terms and or your privacy policy is not typical language. And so they did it in a way there was no accompanying communication around what it means. And that's always the judgment call on what kind of additional notice you provide. But it created somewhat of a storm because, look, there was a public take on what it meant, and that goes to trust. And suddenly, you're on your back feet, you're on your heels, and you're in a defensive posture trying to explain what you meant, what you intended, and now all your customers are questioning, like, your loyalty and how you're using their data. And that's a position that no company wants to be in. **Jonathan:** Gotcha. And so we're back there. Right? We talk about responsible data practices. Transparency is a big one. Whatever your reasons, your motivations, you gotta be front and center now when you're talking data. Right. Maybe especially in AI, given it's not well understood. **Alysa:** Right. And I think the take that I would — if I was in-house counsel — anytime, a, you're always talking to business, always wants to use data for more reasons, and so you're constantly guiding around, well, here's what our contracts say, here's what our terms say, and those are the lines that we have to play in. If you want to do something new with data that your terms do not allow, there's a different process to make that happen. And if it's material or it's gonna cause questions for your clients, then you have the judgment call on how much of an upfront dialogue and opt-in are we gonna have to make sure that folks are fully informed and there's no misunderstandings — because it goes to our brand, it goes to the relationship. And so I think in-house counsel, that's it. I mean, they're already doing that, but this point just put a sharper — yeah — dot right on the top. **Jonathan:** And the connection to NatWest, which might be a thin one, but — I mean, there's a DSR bomb that comes with that. Right? People are weaponizing data subject requests when they don't like what they see. **Alysa:** And so we saw at NatWest, Nigel Farage, politician over there, had his loan denied by the bank. Does a DSR, finds out that actually, well, here's why we did it. It was nothing to do with his financial situation. It was all political. And then he starts this ten-thousand-person Facebook page, and they're all — a lot of them are now executing DSRs. And I always thought DSRs would come — would rise maybe with the awareness of some of these privacy laws. I never would have thought it would be a situation like this. The point is a DSR bomb can come from anywhere. **Jonathan:** It's a tool. **Alysa:** It's a tool. It's weaponized. Yes. And we talk about risk, and risk — we often will say media risk. Right? That's one of the risks to think about separate from legal risk. It can always involve legal risk. I think now an additional risk is if there's negative public attention to you as a company, to your data practices, this is a tool that can, as you mentioned, weaponize data subject access requests — because that's a pain point. And we've seen cancel culture. I think this is privacy cancel culture in some ways, and really bringing a lot of attention to that. And I think that's a fair point to consider as you're evaluating an overall business practice and what kinds of potential consequences could occur. Transparency helps you with that. Yes. But then you also need the mechanisms to deal with these DSRs in a way that — it will come. So most companies look at the volume of their DSRs to figure out how they need to staff, what kind of resources they need — right, technology. What kind of technology? But they're watching this kind of trendline, and it's fairly steady. Something you have a viral moment like that, and that's not a steady. That's overwhelming resources. You still have the legal obligation to respond within a certain amount of time, but now you're on the clock, and you have to come up with a very directed way to solve that. And nobody wants to be figuring out the solution at that moment on the clock. Right? You want the time to do it beforehand, leverage to do it beforehand. So, yeah, it's a new tool for consumers, and I think it's a new tool for in-house counsel as they're planning their budgets and getting resources and figuring out what tools they need. It's not necessarily what's happened to date. It's really thinking what's around the corner and being prepared for it. **Jonathan:** Yeah. No. I got you. And transparency — just updating that. Always. Programmatic tools for it. So we're here. We're about to do a workshop with a group of folks here in Denver. We're talking data deletion. We're talking sensitive and personal information. We're talking data protection impact assessments. So looking forward to that. Thanks for joining us. **Alysa:** Yeah. No. My pleasure. And, you know, it's always interesting what topics we wanna talk through and really get into and get some benchmarking. We chose these topics because these are questions clients ask a lot and largely because there's not consensus yet. There's not consensus on — with the new requirements — the personal information. What do you do with the data that you have? How do you advertise on certain areas that trigger those considerations? Just even doing data protection impact assessments on tough topics and wanting to get a little bit of a sense on, like, how are others doing it. You know, you might know how you're doing it, but to get outside your bubble. And then deletion. Yes. Every state privacy law has a deletion requirement. Now what do you do in terms of how do you operationalize that, and a bit of sharing feedback around the room — I thought would be really, really useful. And we'll update everybody next week.
Next step
See permissioning infrastructure in action
Walk through the platform with a Ketch architect, or launch the free CMP today.
Get started in less than 5 min