

Zoho CRM
Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 21 Feb 2026
AI Trust Summary
- •In AI: it does not document ethical AI principles, which may lead to discrimination risks in sales interactions.
- •In Core Privacy: it provides clear data retention criteria, ensuring that information is kept only for as long as necessary.
Safer Alternatives
Higher-rated software in the same category
Attention Points in AI (1)
AI criteria that require attention. Buy the Premium Analysis to see all 1 criteria.
- •Zoho CRM
- •Does not mention ethical AI principles, which may result in discrimination in sales interactions.
- •Does not document safeguards for international transfers, creating compliance risks.
- •It is necessary to demand contractual clauses that address these critical aspects.
Ethical AI principles and anti-bias measures not documented
There is no mention of ethical AI principles or anti-bias measures, which may lead to discrimination risks in sales interactions.
Source: vendor public documents
Compliances in AI (3)
AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.
- •Zoho CRM
- •Documents data processing purposes, connecting data categories with specific purposes.
- •Clarifies the data retention period, ensuring that information is kept only while the account is active.
- •These practices facilitate due diligence and demonstrate a commitment to privacy.
Use of artificial intelligence clearly disclosed in policies
The policy explicitly states the use of Artificial Intelligence, ensuring that customers are aware of how their contact data is used.
AI data retention policy clearly documented
The policy defines service data retention, ensuring that contact data is kept only while the account is active.
AI training opt-out control available
The policy offers generic controls for data management, but there is no specific opt-out for the use of contact data in AI training.
Source: vendor public documents
Highlights in Privacy (3)
Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.
Sensitive data processing without additional documented safeguards
No mention of sensitive data or special categories of data was found, which may lead to legal and compliance risks.
Data controller and processor roles clearly defined
The policy clearly identifies Zoho as the controller, ensuring that contact and sales interaction data is managed appropriately.
Processing purposes clearly listed by data category
The policy connects contact and sales interaction data categories with their specific purposes, ensuring transparency for users.
Source: vendor public documents
Critical Alerts
- •Tratamento de dados sensíveis sem salvaguardas adicionais documentadas: Importante para a proteção de dados sensíveis de clientes..
- •Salvaguardas para transferência internacional não são mencionadas: Crucial para garantir a proteção de dados em transferências internacionais.
Conformance analysis (20)
Roles of data controller and processor clearly defined
Reference: ISO/IEC 27701 (7.3)
Purposes of processing clearly listed by data category
Reference: ISO/IEC 27701 (7.3)
Data retention period clearly informed
Reference: ISO/IEC 27701 (7.4.6)
Source: vendor public documents
Follow this company and access all 20 criteria
Track score changes, get alerts on policy updates, and view the full conformance analysis
Don't miss any update
Sign up to follow this company and track changes in privacy and AI scores
Why trust the AITS Index: Open Community Audit
Public transparency, peer review and open evidence trails — all verifiable by the community
Trust guarantees
Peer review
users, professionals and experts confirm or contest items online.
Public history
vendor and index changes are versioned and accessible.
Participate
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Zoho CRM: A Comprehensive Review of Privacy and Security Features
Transparency in Data Processing
Zoho CRM excels in its transparency regarding data processing purposes. With a solid AITS Privacy Score of 78%, users can feel confident that their data is handled with clarity. The platform categorizes data processing purposes, allowing users to understand how their data is utilized. This clear categorization not only aligns with GDPR and LGPD regulations but also empowers users to make informed decisions about their data. For those considering Zoho CRM, this transparency is a significant strength, ensuring that users are aware of how their information is being processed and for what specific purposes.
Clear Data Retention Policies
Another notable strength of Zoho CRM is its clearly defined data retention period. Users can rest assured that their data will only be retained for as long as necessary, which is a critical aspect of compliance with privacy regulations like GDPR. This means that once the data is no longer needed for its intended purpose, it will be deleted, reducing the risk of unnecessary data exposure. Users should regularly review their data retention settings within Zoho CRM to ensure they align with their organizational policies and legal requirements, enhancing their overall data governance strategy.
Lack of Ethical AI Documentation
Despite its strengths, Zoho CRM has notable weaknesses, particularly concerning its AI practices. The platform currently lacks documentation on ethical AI principles and anti-bias measures, resulting in an AITS AI Score of only 38%. This absence raises concerns about potential discrimination in sales interactions, as users may unknowingly be subjected to biased algorithms. For users, this means that while the CRM may be effective, they should remain vigilant about how AI-driven features are impacting their customer interactions. It is advisable to monitor AI outputs closely and provide feedback to Zoho for improvements in this area.
Inadequate Safeguards for Sensitive Data
Another critical weakness is the handling of sensitive data without documented additional safeguards. Users should be cautious when inputting sensitive information into Zoho CRM, as the lack of robust protections could expose them to data breaches or misuse. To mitigate these risks, users are encouraged to limit the amount of sensitive information entered into the system and to utilize encryption tools where possible. Additionally, reviewing the platform's privacy settings and ensuring that only necessary data is collected can help minimize exposure.
International Data Transfer Concerns
The absence of safeguards for international data transfers is another area of concern for users of Zoho CRM. Without clear policies in place, there is a risk that data could be transferred to jurisdictions with less stringent privacy protections, potentially compromising user data. Users should take proactive steps to understand where their data is being stored and processed. It may be beneficial to consult with legal experts to ensure compliance with international data transfer regulations, especially if your organization operates across borders.
Practical Steps for Enhanced Privacy Management
To enhance privacy management while using Zoho CRM, users should regularly audit their data settings and privacy policies. This includes checking the data retention settings to ensure compliance with GDPR and LGPD, as well as reviewing user access permissions to limit data exposure. Additionally, consider implementing regular training for staff on data privacy best practices and the importance of ethical AI usage. By taking these steps, users can better protect their data and ensure that they are leveraging Zoho CRM's strengths while mitigating its weaknesses.
Other Sales CRM software
Dive into in-depth research and analysis of each player
Source: vendor public documents
Analyzed Sources
Public documents used in the audit of Zoho CRM:
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Scope & Limitations
TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).
The content is indicative in nature, intended for screening and comparison, not replacing internal audits.
TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.
Source: vendor public documents






