Home Blog Is Notion GDPR Compliant? Where the DPA Lives

GDPR

Is Notion GDPR Compliant? Where the DPA Lives

Posted by Kevin Yun|August 18, 2026

Notion provides the processor-side contract GDPR asks for. Its data processing addendum is incorporated by reference into your agreement, it acts as your processor for content you and your users put into a workspace, and its addendum incorporates both the EU and UK Standard Contractual Clauses. Whether your use is lawful is a different question, and it turns almost entirely on what your team has typed into Notion over the past two years.

This article covers where the DPA actually lives, what role Notion occupies, how its subprocessor notifications work and why the AI providers on that list matter, the deletion timeline you inherit, and the obligations that stay with you.

Where Notion's DPA Is, And Why There Is Nothing To Sign

Notion publishes its GDPR position at notion.com/help/gdpr-at-notion, and links the addendum from there. Both the addendum and the subprocessor list are hosted as Notion pages on notion.so rather than as PDFs, which is charming and slightly awkward when a procurement team asks you for a document.

The mechanism is incorporation by reference. Notion's own wording is that the terms of the addendum are incorporated and apply to the extent Notion processes personal data subject to GDPR on the customer's behalf. There is no separate signature step in the self-serve flow. That satisfies Article 28(9), which permits a processing contract in electronic form, but it leaves you with the same evidence problem as every click-through arrangement: what you are bound by is the version that was live when you agreed.

The same page carries an explicit caveat from Notion that it is for informational purposes only and may be changed at any time. Take that at face value. Capture the addendum as it stands, note the date, and file it with your processor records. We checked these pages on 7 August 2026; if you are reading this later, assume the detail has moved and go and look.

If you are unsure what a processing contract is supposed to contain before you assess Notion's, start with our guide to data processing agreements.

What Notion Is In Your Data Chain

Notion's privacy documentation states the position plainly: where the customer is a controller or a processor, Notion is the processor of personal data that the customer and their users upload, processing it at the customer's direction and on the customer's behalf.

The clause worth pausing on is "and their users." A Notion workspace is not a database with a schema somebody designed. It is whatever your team has put in it. Interview notes on candidates. A spreadsheet of churned customers with reasons. A support escalation thread quoting a user's email. A performance review. None of that arrived through a form with a lawful basis attached to it, and all of it is personal data you are the controller of.

That is the practical difference between Notion and a purpose-built system. With a CRM you can describe the categories of data it holds. With Notion, the honest answer to "what personal data is in there" is usually "we would have to go and look," and that answer is not sufficient for an Article 30 record. Keeping your record of processing activities accurate means knowing what workspaces exist and roughly what lives in them.

Subprocessors, And The AI Providers On That List

Notion maintains a subprocessor list and links it from the same GDPR page. Notification is opt-in and the mechanism is manual: Notion's documentation describes customers signing up by emailing with the subject line "Subscribe to New Subprocessors," after which Notion provides notice of new subprocessors before authorising them to process customer data.

Notice before authorisation is better than most vendors offer, and an email-based subscription is easier to forget than most. Do it once and route it somewhere shared.

The list itself is the part that has changed character. Notion's trust centre discloses infrastructure providers alongside providers of large language model and embedding hosting. If your workspace has AI features in use, workspace content is reaching model-hosting infrastructure as part of normal operation, and those providers are subprocessors in your chain like any other.

This is not an accusation of anything. It is a description of an architecture, and it has two consequences you own. First, your own customers are entitled to know who is in your processing chain, which means these names may need to appear on your published list too — our guide to subprocessor management covers how far down the chain that disclosure runs. Second, "we do not use AI" is not a control. Availability of a feature and a documented decision about it are different things.

Deletion, Export And The Thirty-Day Window

Notion documents three mechanisms that matter for data subject rights.

Export works at two levels: an entire workspace can be exported from workspace settings, producing a folder of markdown, or individual pages can be exported from the page menu. That covers a portability request adequately at workspace scale and poorly at person scale, because nothing in an export is organised around an individual.

Workspace deletion is the sharper instrument. Notion documents that on requesting deletion, content immediately becomes inaccessible, and after 30 days it is deleted from Notion's servers and can no longer be recovered. Thirty days is a real window and it cuts both ways — it is your grace period if someone deletes the wrong workspace, and it is a period in which data you intended to erase still exists.

Neither mechanism gives you what an erasure request usually needs, which is the removal of one named person from the middle of hundreds of pages. That is manual work, and it is yours.

What Notion Does Not Decide For You

Notion does not set your lawful basis, your retention periods, or your access model. Workspace and page permissions are yours to configure, and the most common real-world failure is not a vendor failure at all: a page shared to the web, or a workspace where everyone can see everything because that was convenient at eight people and never revisited at forty.

It also does not tell you what is in there. No vendor can. The only way to answer a regulator's question about what personal data you hold in Notion is to have decided in advance what belongs in it.

Common Mistakes With Notion And GDPR

Looking for a DPA to sign. It is incorporated by reference and there is no signature step. Record the version and date instead of chasing a document.

Never subscribing to subprocessor notices. Notion gives notice before authorising a new subprocessor, but only to customers who opted in by email. Unsubscribed, you find out by re-reading the list.

Treating a workspace as infrastructure rather than a data store. Notion holds whatever your team put in it, including personal data nobody recorded a basis for. It belongs in your Article 30 record with an honest description.

Assuming public page sharing is internal. A page shared to the web is published. Audit what is shared externally before you audit anything else.

Confusing workspace deletion with erasure. Deleting a workspace clears everything after thirty days. Removing one person from across many pages is a manual job that no export or deletion feature performs for you.

FAQ

Do I need to sign a DPA with Notion?

No separate signature is required in the standard flow. Notion states that its data processing addendum is incorporated by reference and applies to the extent it processes personal data subject to GDPR on your behalf. Because nothing is countersigned, record which version you accepted and when, and confirm the position for your specific plan and contract if procurement needs a document.

Is Notion a controller or a processor?

A processor for the content you and your users upload. Notion's documentation states that where its customer is a controller or processor, Notion is the processor of that uploaded personal data and processes it at the customer's direction. Notion will separately be a controller of its own account and billing data about you.

Does Notion use Standard Contractual Clauses?

Yes. Notion's privacy documentation states that its data processing addendum incorporates both the EU and UK Standard Contractual Clauses, and its GDPR page describes relying on standard contractual clauses for transfers from the EU to countries outside it.

How long does Notion keep data after I delete a workspace?

Notion documents that content becomes inaccessible immediately on requesting deletion, and is deleted from its servers after 30 days, after which it cannot be recovered. That is a workspace-level operation and is not a substitute for handling an individual erasure request.

Closing Thought

The awkward thing about Notion is that it is good at the exact behaviour privacy programmes are built to prevent. It rewards putting things somewhere quickly, in whatever shape they arrive, so they are not lost. That is why teams love it, and it is why nobody can tell you what is in it.

There is no vendor setting that fixes that, and switching tools does not either — the same content would accumulate somewhere else. What helps is having a place where the answer lives: what you process, why, for how long, and who else touches it. ComplyDog gives you a compliance portal on your own domain covering your DPA, your subprocessor list, your data subject request intake and your security page. It will not index your workspace. It will mean the question of what you process has a documented answer rather than an archaeological one.