Provision record
ClickUp · ClickUp Privacy Policy · View original document ↗

Sensitive Personal Data User-Generated Content Consent

Medium severity Medium confidence Explicit document language Unique · 0 of 352 platforms
Stay ahead of the changes
Track ClickUp and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

The policy requests that users avoid submitting sensitive personal data categories including health information, biometrics, racial or ethnic origin, and criminal background through the service, but states that submission of such data in user-generated content constitutes consent to its processing under the policy.

ⓘ

This analysis describes what ClickUp's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that consent to process sensitive personal data categories is obtained through the act of submission rather than through a distinct affirmative consent mechanism. This approach may require evaluation under GDPR Article 9, which requires explicit consent for processing special categories of personal data, and CCPA sensitive personal information provisions, which impose additional handling requirements.

⚠

Interpretive note: Whether consent obtained through the act of data submission satisfies GDPR Article 9 explicit consent requirements depends on regulatory interpretation and may vary across EEA jurisdictions.

Recent Activity

This document changed recently

Medium Jun 2, 2026

The updated policy now explicitly recognizes eight distinct data subject rights, including rights to access, correct, delete, restrict processing, receive data in portable format, object to processing, withdraw consent, and lodge complaints with regulators. Previously, ClickUp described privacy controls through general opt-out options and data access procedures without formal legal framing. The revised language aligns with GDPR and similar data protection frameworks, providing clearer legal reference points for how users may exercise control over their personal data. You can exercise these rights by contacting ClickUp's support team.

View change record →

Consumer impact (what this means for users)

Under this provision, if a user submits content containing sensitive personal data such as health information, biometric data, or racial or ethnic origin through the ClickUp platform, the agreement treats that submission as consent to processing of that data under the policy's terms. The policy does not establish a distinct opt-in mechanism for sensitive data processing separate from the act of submission.

Cross-platform context

See how other platforms handle Sensitive Personal Data User-Generated Content Consent and similar clauses.

Compare across platforms →
▸ View Original Clause Language DOCUMENT RECORD
"
Subject to the next paragraph, we ask that you not send or disclose to us any sensitive personal data (e.g., social security numbers, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics or genetic characteristics, criminal background or trade union membership) on or through the ClickUp Services or otherwise. If you send or disclose any sensitive personal data to us when you submit user generated content to the ClickUp Services, you consent to our processing and use of such sensitive personal data in accordance with this policy. If you do not consent to our processing and use of such sensitive personal data, you must not submit such user generated content to our platform.

Excerpt from ClickUp's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

REGULATORY LANDSCAPE: This provision engages GDPR Article 9 (processing of special categories of personal data), CCPA and CPRA sensitive personal information provisions, Illinois BIPA (to the extent biometric data is submitted), and potentially HIPAA if …

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →
  • State Attorney General
    State AGs in California, New York, Texas, and other states can investigate violations of state consumer protection and privacy laws, including CCPA (California), SHIELD Act (New York), and equivalents.
    Who can file: Residents of states with comprehensive privacy laws — primarily California, Virginia, Colorado, Connecticut, and Utah
    What you need: Evidence of the violation, explanation of how your state rights were affected, and your account or contact information with the company
    What to expect: Outcomes vary by state. May result in investigation, enforcement action, or requirement for the company to change practices. No direct individual compensation in most cases.

    Search "[your state] attorney general consumer complaint" to find your state's direct complaint form

Provision details

Document information
Document
ClickUp Privacy Policy
Entity
ClickUp
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-016216
Document ID
CA-D-00710
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
d0a3316c1395c5cd27442a27c2b913ec53535cfe305f3467569da1615d276702
Analysis generated
July 9, 2026 09:51 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: ClickUp
Document: ClickUp Privacy Policy
Record ID: CA-P-016216
Captured: 2026-07-09 09:51:27 UTC
SHA-256: d0a3316c1395c5cd…
URL: https://conductatlas.com/platform/clickup/clickup-privacy-policy/provision/CA-P-016216/sensitive-personal-data-user-generated-content-consent/
Accessed: Sept. 26, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does ClickUp's Sensitive Personal Data User-Generated Content Consent clause do?

This provision establishes that consent to process sensitive personal data categories is obtained through the act of submission rather than through a distinct affirmative consent mechanism. This approach may require evaluation under GDPR Article 9, which requires explicit consent for processing special categories of personal data, and CCPA sensitive personal information provisions, which impose additional handling requirements.

How does this clause affect you?

Under this provision, if a user submits content containing sensitive personal data such as health information, biometric data, or racial or ethnic origin through the ClickUp platform, the agreement treats that submission as consent to processing of that data under the policy's terms. The policy does not establish a distinct opt-in mechanism for sensitive data processing separate from the act …

Is ConductAtlas affiliated with ClickUp?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by ClickUp.