Zendesk Data Security and Privacy Technology

A map of the Zendesk data security and privacy technology you can configure, and the parts you have to ask about. Technical orientation, not legal advice.

Zendesk data security and privacy technology starts at the trust centre

Certifications, attestations, encryption standards, subprocessor lists and regional availability all change, and any article that states them as fact is out of date by the time you read it. This one included.

Zendesk maintains a trust and security centre where the current certifications, reports and policy documents live, along with the data processing agreement. That's the authoritative source, and it's what your security review should cite. If a specific control matters to your procurement, get it in writing from Zendesk rather than from anybody else.

What follows is the shape of the surface: which controls exist, where they sit, and which parts are yours rather than the vendor.

Zendesk data security access controls you own

Most real incidents in a helpdesk are access problems, not cryptography problems. Somebody had a role they shouldn't have had, or an account nobody deactivated.

Single sign-on. Route agent authentication through your identity provider so joiners and leavers are handled once, centrally. This is the highest-value control on the list, by a distance.
Roles. Agents can see far more than people assume by default. Custom roles let you restrict who can view all tickets, export data, or change business rules. Review them, because they drift.
API credentials. Tokens carry the permissions of the user behind them. A token on a full admin account, sitting in a config file, is an admin account sitting in a config file.
Deactivation. Ex-agents, ex-contractors and abandoned integration users. Tie it to your leaver process or it won't happen.

The security and compliance guide covers the settings side in more depth.

Zendesk data security at rest, in transit, and where it lives

Zendesk encrypts data in transit and at rest, and publishes the specifics in its security documentation. Read them there rather than trusting a summary, since the details are exactly the sort of thing a security questionnaire asks you to quote precisely.

The question that matters more operationally is where the data physically sits. Zendesk offers data residency options for hosting account data in specific regions, and the availability and scope of that varies by product and plan. If your regulator or your customers care about location, this needs confirming before you sign, not after. The data residency guide covers what the option does and does not extend to.

Subprocessors matter too. Voice, messaging, AI features and analytics may involve third parties, and the current subprocessor list is published. If you're answering a due diligence questionnaire, that list is part of your answer.

Zendesk privacy technology inside the product

Three mechanisms do most of the practical work.

Redaction removes sensitive content from a ticket after the fact. Customers paste card numbers and passwords into tickets constantly, and once it's in a comment it's in your data, your exports and your backups. Redaction is how you get it out. The redaction guide covers the options and their limits.

Deletion and export for individuals is how you serve a data subject request. Zendesk provides mechanisms for finding and deleting a user with their tickets, and for exporting what you hold about them. Test the process before you need it, because the first one always takes longer than the deadline suggests. The GDPR guide walks through it.

Retention. Data you no longer hold can't leak. Deciding how long tickets stay is a policy decision with a technical implementation, and most accounts have never made it. Ask the question, at least.

The Zendesk data security and privacy work that stays yours

The shared responsibility line sits in a predictable place, and it's worth being explicit about it.

Zendesk is responsible for the platform: infrastructure, encryption, availability, its own certifications and its own subprocessors. You are responsible for who has an account, what those accounts can reach, what your agents paste into tickets, which apps you install and what those apps send outward, and whether anyone reads the audit log when something odd happens.

Marketplace apps deserve specific mention. An installed app can generally read ticket data and send it somewhere else, and the security review of that destination is yours, not Zendesk. Treat installing an app as a data-sharing decision, because it is one.

None of this is legal advice. Your DPA, your regulator and your own counsel decide what is adequate. For the contractual side, the DPA guide is the right starting point.

FAQ

Frequently asked questions

Which Zendesk security features come with every plan?

Encryption in transit and at rest, role-based access and two-factor authentication. Zendesk data protection beyond that, meaning retention policies, access logs and encryption key control, sits behind the higher tiers and the add-on.

Is Zendesk data security and privacy technology enough for regulated data?

That depends on your regulator, your data and your configuration, and it is not a question an article can answer. Start from the Zendesk trust centre and your own legal review.

Which certifications does Zendesk hold?

Check the Zendesk trust and security centre for the current list and the underlying reports. Certification status changes, so cite the source rather than a summary.

Can I choose where Zendesk stores my data?

Data residency options exist for hosting account data in specific regions, with scope and availability varying by product and plan. Confirm the specifics for your account before relying on it.

How do I remove a credit card number from a ticket?

Use redaction. It removes the content from the comment rather than editing around it, which is what you need for anything that should never have been sent.

Are marketplace apps a security risk?

They can be. An installed app can typically read ticket data and transmit it elsewhere, so reviewing the vendor and the destination is your responsibility, not Zendesk.

Less data, fewer problems

Duplicate tickets are copies of the same customer data in two places. Merging them is a small privacy win as well as a queue one.

Start free trial

14-day free trial. No credit card required.