Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Content submitted by Managed Users (workplace or organization users) is classified as Customer Data owned and controlled by the subscribing Customer, which may manage, share, modify, or delete that content under the Customer Agreement.
This analysis describes what Asana's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that Managed Users' task data, messages, files, and related content are under the operational control of the subscribing Customer rather than the individual user, including the ability to expand access, share content, or delete it entirely.
Under this clause, employees or other Managed Users who submit content to Asana have no direct data control rights against Asana; their content is governed by the Customer Agreement between Asana and their employer or subscribing organization. The Customer may access, modify, share, or delete Managed User content as permitted under that agreement.
Cross-platform context
See how other platforms handle Managed User Data Controlled by Customer and similar clauses.
Compare across platforms →Monitoring
Asana has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"When you or another Managed User submit content or information to the Service, such as messages or files ("Customer Data"), you acknowledge and agree that, as between Asana and Customer, the Customer Data is controlled by Customer and the Customer Agreement provides Customer with choices and control over that Customer Data. For example, Customer may manage permissions, enable or disable third party integrations, or take steps to expand, consolidate or share the contents of Asana portfolios, projects, tasks and subtasks, and these choices and instructions may result in the access, use, disclosure, modification or deletion of certain or all Customer Data.Excerpt from Asana's Terms of Service
1) REGULATORY LANDSCAPE: This provision engages GDPR Articles 4 and 28 regarding the controller-processor relationship and employee data rights. Under GDPR, employees retain certain data subject rights regardless of employer control, and the Customer's designation as data controller creates obligations around lawful basis, data subject access requests, and retention policies. The document expressly places responsibility for lawful processing on the Customer. 2) GOVERNANCE EXPOSURE: High. The explicit delegation of data control to the Customer, combined with the clause placing sole responsibility for consent, lawfulness, and user notification on the Customer, creates direct and material compliance obligations for enterprise subscribers. Failure to meet these obligations could expose the Customer organization to regulatory action under GDPR, CCPA, or applicable employment law. 3) JURISDICTION FLAGS: EU/EEA organizations must ensure their Customer Agreement with Asana satisfies GDPR Article 28 processor requirements, including data processing agreements. California organizations should assess CCPA applicability to employee data. The document's acknowledgment that Customer bears sole responsibility for lawfulness does not insulate the Customer from regulatory enforcement. 4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement and HR legal teams should review whether existing employee data policies adequately disclose Asana's role and the Customer's control over submitted content. The Customer Agreement's specific data handling provisions are the operative document for Managed User data and should be reviewed in conjunction with these User Terms. 5) COMPLIANCE CONSIDERATIONS: Organizations should conduct a data mapping exercise to identify what categories of employee data are submitted to Asana as Customer Data, assess the legal basis for processing under applicable law, update employee-facing privacy notices to reflect Customer's role as data controller, and confirm that the Asana Data Processing Addendum is executed.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that Managed Users' task data, messages, files, and related content are under the operational control of the subscribing Customer rather than the individual user, including the ability to expand access, share content, or delete it entirely.
Under this clause, employees or other Managed Users who submit content to Asana have no direct data control rights against Asana; their content is governed by the Customer Agreement between Asana and their employer or subscribing organization. The Customer may access, modify, share, or delete Managed User content as permitted under that agreement.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Asana.