Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy requests that users avoid submitting sensitive personal data categories including health information, biometrics, racial or ethnic origin, and criminal background through the service, but states that submission of such data in user-generated content constitutes consent to its processing under the policy.
This analysis describes what ClickUp's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that consent to process sensitive personal data categories is obtained through the act of submission rather than through a distinct affirmative consent mechanism. This approach may require evaluation under GDPR Article 9, which requires explicit consent for processing special categories of personal data, and CCPA sensitive personal information provisions, which impose additional handling requirements.
Interpretive note: Whether consent obtained through the act of data submission satisfies GDPR Article 9 explicit consent requirements depends on regulatory interpretation and may vary across EEA jurisdictions.
The updated policy now explicitly recognizes eight distinct data subject rights, including rights to access, correct, delete, restrict processing, receive data in portable format, object to processing, withdraw consent, and lodge complaints with regulators. Previously, ClickUp described privacy controls through general opt-out options and data access procedures without formal legal framing. The revised language aligns with GDPR and similar data protection frameworks, providing clearer legal reference points for how users may exercise control over their personal data. You can exercise these rights by contacting ClickUp's support team.
View change record →Under this provision, if a user submits content containing sensitive personal data such as health information, biometric data, or racial or ethnic origin through the ClickUp platform, the agreement treats that submission as consent to processing of that data under the policy's terms. The policy does not establish a distinct opt-in mechanism for sensitive data processing separate from the act of submission.
Cross-platform context
See how other platforms handle Sensitive Personal Data User-Generated Content Consent and similar clauses.
Compare across platforms →Monitoring
ClickUp has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Subject to the next paragraph, we ask that you not send or disclose to us any sensitive personal data (e.g., social security numbers, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics or genetic characteristics, criminal background or trade union membership) on or through the ClickUp Services or otherwise. If you send or disclose any sensitive personal data to us when you submit user generated content to the ClickUp Services, you consent to our processing and use of such sensitive personal data in accordance with this policy. If you do not consent to our processing and use of such sensitive personal data, you must not submit such user generated content to our platform.Excerpt from ClickUp's Privacy Policy
REGULATORY LANDSCAPE: This provision engages GDPR Article 9 (processing of special categories of personal data), CCPA and CPRA sensitive personal information provisions, Illinois BIPA (to the extent biometric data is submitted), and potentially HIPAA if health information is submitted by covered entities or business associates. GDPR Article 9 generally requires explicit consent for processing special category data, and consent obtained through the act of submission in a general productivity platform context may not satisfy the explicitness requirement under regulatory guidance. GOVERNANCE EXPOSURE: High for enterprise customers in regulated industries. If employees or end users submit health, biometric, or other special category data through ClickUp workspaces, the organization controlling the workspace may bear data controller obligations under GDPR for that data, irrespective of ClickUp's consent mechanism. Illinois BIPA imposes strict consent and retention requirements for biometric identifiers that are not addressed in this provision. JURISDICTION FLAGS: EEA users are most directly affected by GDPR Article 9 explicit consent requirements. Illinois residents are affected by BIPA if biometric data is submitted. California residents are affected by CPRA sensitive personal information provisions. Regulated-industry customers in healthcare face HIPAA considerations if protected health information is submitted through the platform. CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement teams should assess whether their Data Protection Addendum addresses the processing of special category data and whether ClickUp's role as a processor for such data is appropriately documented. Organizations in regulated industries should implement internal policies restricting submission of sensitive data through ClickUp to the extent possible. COMPLIANCE CONSIDERATIONS: Compliance teams should assess whether the submission-based consent mechanism for sensitive data satisfies GDPR Article 9 explicit consent requirements and whether additional consent mechanisms or contractual terms are needed for enterprise deployments. Organizations should also evaluate whether their employees or end users are likely to submit sensitive data categories through the platform and implement appropriate controls.
This provision establishes that consent to process sensitive personal data categories is obtained through the act of submission rather than through a distinct affirmative consent mechanism. This approach may require evaluation under GDPR Article 9, which requires explicit consent for processing special categories of personal data, and CCPA sensitive personal information provisions, which impose additional handling requirements.
Under this provision, if a user submits content containing sensitive personal data such as health information, biometric data, or racial or ethnic origin through the ClickUp platform, the agreement treats that submission as consent to processing of that data under the policy's terms. The policy does not establish a distinct opt-in mechanism for sensitive data processing separate from the act …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by ClickUp.