ClickUp · ClickUp Privacy Policy · View original document ↗

Sensitive Personal Data User-Generated Content Consent

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time ClickUp changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for ClickUp Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy requests that users avoid submitting sensitive personal data categories including health information, biometrics, racial or ethnic origin, and criminal background through the service, but states that submission of such data in user-generated content constitutes consent to its processing under the policy.

This analysis describes what ClickUp's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that consent to process sensitive personal data categories is obtained through the act of submission rather than through a distinct affirmative consent mechanism. This approach may require evaluation under GDPR Article 9, which requires explicit consent for processing special categories of personal data, and CCPA sensitive personal information provisions, which impose additional handling requirements.

Interpretive note: Whether consent obtained through the act of data submission satisfies GDPR Article 9 explicit consent requirements depends on regulatory interpretation and may vary across EEA jurisdictions.

Recent Activity

This document changed recently

Medium Jun 2, 2026

The updated policy now explicitly recognizes eight distinct data subject rights, including rights to access, correct, delete, restrict processing, receive data in portable format, object to processing, withdraw consent, and lodge complaints with regulators. Previously, ClickUp described privacy controls through general opt-out options and data access procedures without formal legal framing. The revised language aligns with GDPR and similar data protection frameworks, providing clearer legal reference points for how users may exercise control over their personal data. You can exercise these rights by contacting ClickUp's support team.

View change record →

Consumer impact (what this means for users)

Under this provision, if a user submits content containing sensitive personal data such as health information, biometric data, or racial or ethnic origin through the ClickUp platform, the agreement treats that submission as consent to processing of that data under the policy's terms. The policy does not establish a distinct opt-in mechanism for sensitive data processing separate from the act of submission.

Cross-platform context

See how other platforms handle Sensitive Personal Data User-Generated Content Consent and similar clauses.

Compare across platforms →

Monitoring

ClickUp has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Subject to the next paragraph, we ask that you not send or disclose to us any sensitive personal data (e.g., social security numbers, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics or genetic characteristics, criminal background or trade union membership) on or through the ClickUp Services or otherwise. If you send or disclose any sensitive personal data to us when you submit user generated content to the ClickUp Services, you consent to our processing and use of such sensitive personal data in accordance with this policy. If you do not consent to our processing and use of such sensitive personal data, you must not submit such user generated content to our platform.

Excerpt from ClickUp's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

REGULATORY LANDSCAPE: This provision engages GDPR Article 9 (processing of special categories of personal data), CCPA and CPRA sensitive personal information provisions, Illinois BIPA (to the extent biometric data is submitted), and potentially HIPAA if health information is submitted by covered entities or business associates. GDPR Article 9 generally requires explicit consent for processing special category data, and consent obtained through the act of submission in a general productivity platform context may not satisfy the explicitness requirement under regulatory guidance. GOVERNANCE EXPOSURE: High for enterprise customers in regulated industries. If employees or end users submit health, biometric, or other special category data through ClickUp workspaces, the organization controlling the workspace may bear data controller obligations under GDPR for that data, irrespective of ClickUp's consent mechanism. Illinois BIPA imposes strict consent and retention requirements for biometric identifiers that are not addressed in this provision. JURISDICTION FLAGS: EEA users are most directly affected by GDPR Article 9 explicit consent requirements. Illinois residents are affected by BIPA if biometric data is submitted. California residents are affected by CPRA sensitive personal information provisions. Regulated-industry customers in healthcare face HIPAA considerations if protected health information is submitted through the platform. CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement teams should assess whether their Data Protection Addendum addresses the processing of special category data and whether ClickUp's role as a processor for such data is appropriately documented. Organizations in regulated industries should implement internal policies restricting submission of sensitive data through ClickUp to the extent possible. COMPLIANCE CONSIDERATIONS: Compliance teams should assess whether the submission-based consent mechanism for sensitive data satisfies GDPR Article 9 explicit consent requirements and whether additional consent mechanisms or contractual terms are needed for enterprise deployments. Organizations should also evaluate whether their employees or end users are likely to submit sensitive data categories through the platform and implement appropriate controls.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • FTC
    The FTC holds enforcement authority over sensitive data processing representations and practices.
    File a complaint →
  • State AG
    California residents may file complaints regarding sensitive personal information handling under CPRA with the California Attorney General.
    File a complaint →

Provision details

Document information
Document
ClickUp Privacy Policy
Entity
ClickUp
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-016216
Document ID
CA-D-00710
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
d0a3316c1395c5cd27442a27c2b913ec53535cfe305f3467569da1615d276702
Analysis generated
July 9, 2026 09:51 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: ClickUp
Document: ClickUp Privacy Policy
Record ID: CA-P-016216
Captured: 2026-07-09 09:51:27 UTC
SHA-256: d0a3316c1395c5cd…
URL: https://conductatlas.com/platform/clickup/clickup-privacy-policy/provision/CA-P-016216/sensitive-personal-data-user-generated-content-consent/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does ClickUp's Sensitive Personal Data User-Generated Content Consent clause do?

This provision establishes that consent to process sensitive personal data categories is obtained through the act of submission rather than through a distinct affirmative consent mechanism. This approach may require evaluation under GDPR Article 9, which requires explicit consent for processing special categories of personal data, and CCPA sensitive personal information provisions, which impose additional handling requirements.

How does this clause affect you?

Under this provision, if a user submits content containing sensitive personal data such as health information, biometric data, or racial or ethnic origin through the ClickUp platform, the agreement treats that submission as consent to processing of that data under the policy's terms. The policy does not establish a distinct opt-in mechanism for sensitive data processing separate from the act …

Is ConductAtlas affiliated with ClickUp?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by ClickUp.