Chavid
Back to blog
Compliance

GDPR and video calling: what UK businesses need to know

5 June 20267 min readCompliance

Using a US-based video platform? You may be breaking UK GDPR. We break down the rules, the risks, and what a compliant alternative looks like.

The problem most businesses don't know they have

If your business uses Zoom, Google Meet, or Microsoft Teams, your video call data is likely being processed on US servers. Under UK GDPR, this is a data transfer to a third country — and it requires specific legal safeguards.

Most businesses using these platforms haven't thought about this. Many are technically non-compliant.

What UK GDPR says about data transfers

The UK GDPR (retained from EU GDPR post-Brexit) restricts transfers of personal data to countries outside the UK unless adequate protections are in place. The US is not on the UK's adequacy list.

This means that if your video platform stores or processes data in the US, you need either: - Standard Contractual Clauses (SCCs) in place with your provider - Binding Corporate Rules - An explicit derogation

Most SMEs haven't done this. Most don't even know they need to.

The risk

The ICO can fine organisations up to £17.5 million or 4% of global annual turnover for serious GDPR breaches. While enforcement against SMEs for video platform use has been limited, the risk is real — especially as awareness grows.

More practically: if you handle sensitive data (healthcare, legal, financial), the reputational risk of a data breach involving a US-hosted platform is significant.

What a compliant solution looks like

A UK GDPR-compliant video platform should: - Store data on UK or EEA servers - Have a clear Data Processing Agreement - Not transfer data to the US without adequate safeguards - Be transparent about data retention and deletion

Chavid is built in the UK, hosted in the UK, and governed by UK law. All data stays on British servers. No US transfers, no compliance headaches.

What to do now

  1. Check where your current video platform stores data
  2. Review their DPA and data transfer mechanisms
  3. Consider switching to a UK-hosted alternative
  4. Document your decision for your records

If you're unsure, speak to a data protection officer or legal adviser. The ICO also has guidance on international data transfers on their website.

Share this article

Try Chavid free

No download. No credit card. No time limits. Just click a link and start your first call.

Start free trial