Using a US-based video platform? You may be breaking UK GDPR. We break down the rules, the risks, and what a compliant alternative looks like.
If your business uses Zoom, Google Meet, or Microsoft Teams, your video call data is likely being processed on US servers. Under UK GDPR, this is a data transfer to a third country — and it requires specific legal safeguards.
Most businesses using these platforms haven't thought about this. Many are technically non-compliant.
The UK GDPR (retained from EU GDPR post-Brexit) restricts transfers of personal data to countries outside the UK unless adequate protections are in place. The US is not on the UK's adequacy list.
This means that if your video platform stores or processes data in the US, you need either: - Standard Contractual Clauses (SCCs) in place with your provider - Binding Corporate Rules - An explicit derogation
Most SMEs haven't done this. Most don't even know they need to.
The ICO can fine organisations up to £17.5 million or 4% of global annual turnover for serious GDPR breaches. While enforcement against SMEs for video platform use has been limited, the risk is real — especially as awareness grows.
More practically: if you handle sensitive data (healthcare, legal, financial), the reputational risk of a data breach involving a US-hosted platform is significant.
A UK GDPR-compliant video platform should: - Store data on UK or EEA servers - Have a clear Data Processing Agreement - Not transfer data to the US without adequate safeguards - Be transparent about data retention and deletion
Chavid is built in the UK, hosted in the UK, and governed by UK law. All data stays on British servers. No US transfers, no compliance headaches.
If you're unsure, speak to a data protection officer or legal adviser. The ICO also has guidance on international data transfers on their website.
No download. No credit card. No time limits. Just click a link and start your first call.
Start free trial