9 Total
0 High severity
5 Medium severity
4 Low severity
Stay ahead of the changes
Track Monday.com and get the diff the day its terms change.
Summary

This is the privacy policy governing how monday.com Ltd. handles personal data for users of its work management platform, site visitors, prospective customers, and technology partners. The policy authorizes collection of identifiers, device data, approximate geolocation, usage activity logs, call and video conference recordings, screen recordings, and professional profile information, and permits disclosure to a broad range of third parties including session recording services, call transcription services, advertising networks, and named data enrichment providers such as ZoomInfo, Clearbit, Cognism, and Lusha. The policy also discloses that Account Admins may access content submitted to private boards and may monitor, process, and analyze user activity within the platform on behalf of the Customer organization.

Analysis

This Privacy Policy, published by monday.com Ltd. and last updated June 28, 2026, governs the collection, storage, use, and disclosure of four categories of personal data: Customer Data (processed as data processor on behalf of business customers), User Data (platform users and account contacts), Prospect Data (site visitors and marketing contacts), and Technology Partner Data (developer and partner ecosystem participants), with legal bases asserted as performance of contract, legitimate interests, legal obligation, and consent. The policy states that monday.com collects identifiers, device and connectivity data, approximate geolocation derived from IP addresses, professional and employment information, usage and activity logs, call and video conference recordings, screen recordings, and written correspondence, and authorizes disclosure to service providers spanning hosting, analytics, billing, fraud detection, session recording, call recording and transcription, advertising networks, data enrichment providers (naming LinkedIn, ZoomInfo, Clearbit, Cognism, and Lusha), business partners, resellers, application providers, event sponsors, and other platform users including Account Admins. The policy asserts that continued use of the services after policy amendments constitutes acceptance of changes, and separately clarifies that monday.com is a data processor for Customer Data submitted to the platform, placing compliance obligations for that data category on the Customer as data controller. The policy engages GDPR, UK GDPR, Swiss Federal Data Protection Act, Israel Protection of Privacy Law, CCPA, and the EU-US Data Privacy Framework, with monday.com Inc. certified under the EU-US DPF and its UK and Swiss extensions, and with Standard Contractual Clauses cited for transfers to non-adequate third countries. Material compliance considerations include the breadth of third-party data enrichment sourcing for Prospect Data, the scope of session and call recording practices, the policy's treatment of consent in non-GDPR jurisdictions where terms acceptance is deemed consent, and the allocation of data subject rights responsibilities to Customers for Customer Data processed as a processor.

What this means for you

The agreement authorizes monday.com to collect call and video conference recordings, screen recordings, written correspondence, and usage activity logs for analytics, quality control, training, and record-keeping purposes. Under these terms, Account Admins employed by the Customer organization may access content submitted to boards designated as private, monitor user activity within the platform, and receive user personal data including profile information. You can opt out of promotional communications by emailing privacy@monday.com, updating communications preferences in your User Profile settings, or following unsubscribe instructions in received messages.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

1 important change detected

2 versions captured · Last updated: June 2026

What changed Monday.com updated its Privacy Policy on June 29, 2026, clarifying complaint and appeal procedures for data subject rights violations. The revised language broadens the complaint submission process, allowing users to lodge complaints directly with Monday.com if they believe their personal data processing violates applicable data protection law, in addition to complaints to supervisory authorities. The updated terms also establish a specific acknowledgment and response timeline, stating that Monday.com will acknowledge receipt of complaints and respond within applicable regulatory timeframes.
Why this matters The updated policy establishes a direct complaint submission mechanism for users who believe Monday.com's personal data processing violates applicable data protection law. Previously, the policy stated that GDPR-protected individuals could lodge complaints with supervisory authorities; the revised language broadens this to acknowledge that users may have rights under various regulatory frameworks, including GDPR. The updated terms now explicitly authorize users to submit complaints directly to Monday.com regarding either data protection violations or how the company handled a data subject rights request, with a commitment to acknowledge receipt and respond within applicable regulatory timeframes. You can submit a complaint to support@monday.com or the Data Protection Officer at dpo@monday.com.
View full change record →
Featured, Medium severity
Featured, Low severity
Stay ahead of the changes

Monitoring

Monday.com has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Account Admin Access to Private Board Content and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
DMA
European Union
View official text ↗
ePrivacy Directive
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured June 29, 2026 00:55 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000554
Version ID CA-V-004313
SHA-256 122167c43bb41ce919a6faf3fed5c0707592bf8b6c3ef510b7c4a5652edd0d39
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans