Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Asana AI features that rely on AI Partners process metadata, personal information, and user-generated content such as task titles and task descriptions, in contrast to Asana's own AI features which are limited to metadata only.
This analysis describes what Asana's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision distinguishes two categories of AI processing with materially different data scope: features powered by AI Partners access user-generated content and personal information, which may implicate subprocessor obligations, data minimization requirements, and consent mechanisms under GDPR and CCPA.
This provision establishes that certain Asana AI features, specifically those powered by AI Partners, process task titles, task descriptions, and personal information. Under these terms, organizations using AI Partner-powered features should account for this data scope in their internal data mapping and subprocessor records.
Cross-platform context
See how other platforms handle AI Partners Use of User-Generated Content and similar clauses.
Compare across platforms →Monitoring
Asana has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Asana AI features powered by AI Partners use metadata, personal information, and user-generated content (e.g., task titles and task descriptions).Excerpt from Asana's Privacy Statement
(1) REGULATORY LANDSCAPE: This provision implicates GDPR Articles on data minimization and subprocessor management (Article 28), CCPA service provider restrictions on secondary use of personal information, and APPI restrictions on third-party provision of personal information. The relevant enforcement authorities are the European Data Protection Authorities, the California Privacy Protection Agency, and Japan's Personal Information Protection Commission. Where AI Partners are located outside the EEA or Japan, cross-border transfer obligations may also apply. (2) GOVERNANCE EXPOSURE: High. The distinction between metadata-only processing and processing that includes personal information and user-generated content is material for GDPR data mapping, CCPA service provider agreements, and internal privacy impact assessments. Organizations must confirm that AI Partner subprocessors are listed in Asana's published subprocessor list and that appropriate contractual protections are in place. (3) JURISDICTION FLAGS: EU/EEA organizations face heightened exposure under GDPR data minimization and subprocessor notification obligations. California organizations must confirm that AI Partner processing does not constitute a sale or sharing of personal information under CCPA. Japan-based data subjects may be affected by APPI third-party transfer restrictions. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should verify that Asana's subprocessor list identifies all AI Partners engaged for this processing, and that the DPA's subprocessor provisions require adequate notice of changes to AI Partner relationships. Vendor assessments should include review of AI Partner data retention and security practices. (5) COMPLIANCE CONSIDERATIONS: Organizations should update Records of Processing Activities to reflect AI Partner-driven processing of user-generated content, review consent mechanisms where personal information in tasks may relate to data subjects not party to the Asana agreement, and confirm that AI features using AI Partners can be selectively disabled via the admin console.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision distinguishes two categories of AI processing with materially different data scope: features powered by AI Partners access user-generated content and personal information, which may implicate subprocessor obligations, data minimization requirements, and consent mechanisms under GDPR and CCPA.
This provision establishes that certain Asana AI features, specifically those powered by AI Partners, process task titles, task descriptions, and personal information. Under these terms, organizations using AI Partner-powered features should account for this data scope in their internal data mapping and subprocessor records.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Asana.