Notion provides a Data Processing Addendum (DPA) and publishes a list of third-party sub-processors for enterprise customers who need GDPR-compliant data processing arrangements.
This analysis describes what Notion's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The provision operationalizes Notion's role as a data processor under GDPR, establishing the infrastructure by which personal data is handled and transmitted across the service infrastructure. This framework determines how data flows through the service and which third-party entities are authorized to process data on Notion's behalf.
Interpretive note: The specific terms of the DPA including audit rights, breach notification timelines, and cross-border transfer mechanisms cannot be assessed from this index page and require review of the full DPA document.
Removal of explicit DPA and sub-processor documentation may indicate integration into Privacy Policy or other master terms, risking reduced GDPR compliance clarity for EU users.
View full change record →Enterprise customers in the EU or those processing EU personal data can execute Notion's DPA to establish a GDPR-compliant processing relationship; individual consumers benefit indirectly from the sub-processor transparency this framework provides.
How other platforms handle this
Each payment processor uses and processes your complete payment information in accordance with its applicable privacy policy (Stripe and PayPal).
we may share data between our affiliates for the safety and security of our users and may take necessary actions if we believe you have violated these Terms, including banning you from our Services and/or our affiliates' services...
Protect us, our business, our users, and others, for example to enforce our terms of service, prevent spam or other unwanted communications, and investigate or protect against fraud
"Data Processing Addendum | Sub-processorsExcerpt from Notion's Terms of Service
REGULATORY LANDSCAPE: The DPA directly implicates GDPR Article 28, which mandates written contracts between data controllers and processors.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
ConductAtlas detected a major restructuring of Meta’s privacy policy that removed detailed consumer rights disclosures and relocated them to separate documents.
Your genetic data may be transferred to a new owner as a business asset. Here is what the Terms of Service actually say and what you can do right now.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The provision operationalizes Notion's role as a data processor under GDPR, establishing the infrastructure by which personal data is handled and transmitted across the service infrastructure. This framework determines how data flows through the service and which third-party entities are authorized to process data on Notion's behalf.
Enterprise customers in the EU or those processing EU personal data can execute Notion's DPA to establish a GDPR-compliant processing relationship; individual consumers benefit indirectly from the sub-processor transparency this framework provides.
ConductAtlas has identified this type of provision across 288 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Notion.