Is Notion GDPR Compliant?
Verdict: Yes — with the right plan and DPA in place
Notion offers GDPR compliance on paid plans with a Data Processing Agreement available. EU data hosting is available for Enterprise customers. Notion AI has additional considerations worth understanding.
Notion's Core GDPR Compliance
Notion offers a Data Processing Agreement (DPA) for customers on Plus, Business, and Enterprise plans. The DPA covers Notion's standard data processing activities and includes Standard Contractual Clauses for data transfers outside the EU.
Key Compliance Facts
- DPA available: Plus plan and above
- Data deletion and export: Users can export and delete all their data
- Standard Contractual Clauses: In place for EU-US data transfers
- EU data residency: Available on Enterprise plans
- Free plan: No DPA available — not for business personal data
What About Notion AI?
Notion AI uses third-party AI model providers to power its features. When you use Notion AI, your content is sent to these providers for processing. Notion has published an AI-specific DPA addendum that covers this. Notion states that AI providers do not use customer content to train their models — verify this in current terms before relying on it for sensitive data.
Practical Guidance
Free plan: Suitable for personal use or non-sensitive team notes. Do not store personal data about clients, customers, or employees.
Plus or Business plan: Request and sign the DPA. Suitable for most business use cases involving personal data.
Enterprise plan: Request EU data hosting in addition to the DPA. Suitable for regulated industries.
To request Notion's DPA, go to notion.so/privacy and use the DPA request form.
[Browse GDPR-compliant productivity tools on stckfndr →](/?category=productivity&compliance=gdpr)