When you use Asana at work, your employer is the one legally responsible for your workspace data, not Asana. Asana only processes that data on your employer's behalf.
This analysis describes what Asana's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This distinction determines where you direct privacy requests. If your employer deployed Asana, you may need to go to your employer first to exercise rights like access or deletion of your workspace content.
Interpretive note: The document functions as a high-level hub page and does not reproduce the full controller-processor framework in verbatim contractual language; the precise scope is established in Asana's separate Data Processing Agreement.
Removal of explicit controller-processor distinction may indicate refocusing of privacy statement or consolidation of this concept elsewhere, potentially affecting clarity of data handling roles.
View full change record →This clarifies Asana's dual role as both processor and controller, establishing distinct legal responsibilities depending on the data category, which is essential for enterprise compliance.
View full change record →Individual employees using Asana through their organization may find that Asana cannot directly fulfill their data access or deletion requests for workspace content, because the employer is the controller of that data. Requests for workspace data typically must be routed through the employing organization.
How other platforms handle this
If you are an end user in a Workspace not owned by you and wish to update, delete, or receive any information we have about you, you may do so by contacting the organization who owns your ClickUp Workspace.
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
"Asana acts as a data processor for customer workspace data and as a data controller for data collected through its marketing and website activities.Excerpt from Asana's Privacy Statement
(1) REGULATORY LANDSCAPE: The controller-processor distinction is foundational to GDPR compliance, particularly Articles 4, 24, and 28, which define the obligations of controllers and processors and require a binding data processing agreement between them.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This distinction determines where you direct privacy requests. If your employer deployed Asana, you may need to go to your employer first to exercise rights like access or deletion of your workspace content.
Individual employees using Asana through their organization may find that Asana cannot directly fulfill their data access or deletion requests for workspace content, because the employer is the controller of that data. Requests for workspace data typically must be routed through the employing organization.
ConductAtlas has identified this type of provision across 289 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Asana.