6 Total
1 High severity
4 Medium severity
1 Low severity
Summary

This is Smartsheet's Privacy Notice, covering how the company collects and uses personal data from visitors to www.smartsheet.com and users of its work management platform. The notice authorizes collection of identifiers, device information, usage activity, location-inferred data, and payment information, and permits sharing with advertising, analytics, and third-party service providers. For enterprise customers, the notice acknowledges Smartsheet may act as a data processor handling content uploaded by business users, with the terms of that processing governed separately by customer agreements.

Technical / Legal Breakdown

The Smartsheet Privacy Notice governs how Smartsheet Inc. collects, uses, shares, and retains personal data across its website (www.smartsheet.com) and associated services, with stated legal bases including consent, contractual necessity, legitimate interests, and legal obligations depending on jurisdiction. The notice states that Smartsheet collects identifiers, contact details, account credentials, device and usage data, location-inferred data, payment information, and content data submitted through the platform, and authorizes sharing with service providers, advertising and analytics partners, corporate affiliates, and business transaction parties. The notice discloses a layered structure composed of a main page and additional product-specific or region-specific sub-notices, which means the full scope of data practices may require review across multiple linked documents rather than a single instrument. The notice engages GDPR and UK GDPR for EU and UK residents, CCPA and CPRA for California residents, and references additional regional frameworks, with Smartsheet acting as a data controller for site and marketing data and as a data processor for customer-uploaded content processed on behalf of enterprise clients. Compliance teams should note that the processor-controller distinction has material implications for data subject rights fulfilment, contractual obligations with enterprise customers, and the scope of Smartsheet's direct regulatory obligations under applicable data protection law.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Start Compliance free trial

2 important changes detected

3 versions captured · Last updated: June 2026

June 5, 2026

medium
What changed Smartsheet modified a single sentence in its Privacy Policy on June 5, 2026 describing which entities participate in the EU-U.S. Data Privacy Framework. The updated language specifies that 'Smartsheet and its U.S. affiliates' participate in the framework, whereas the previous version stated 'Smartsheet and its affiliates' without the geographic qualifier. This change narrows the scope of framework participation to U.S.-based affiliates only, which may affect how personal data transfers are handled for non-U.S. affiliated entities.
Why this matters The updated privacy policy states that only Smartsheet's U.S.-based affiliates participate in the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Framework. Previously, the policy referenced participation by Smartsheet and its affiliates without geographic qualification. This narrowed scope may affect the data transfer mechanisms available for processing personal data from EU, UK, and Swiss users if non-U.S. affiliates are involved in data handling. The policy does not explicitly describe alternative transfer mechanisms for non-U.S. affiliates.
View full change record →
What changed Smartsheet updated its privacy policy to replace the term 'Offerings' with 'Services' throughout the document, and added a single sentence directing readers to a Glossary for definitions of capitalized terms. The term 'Online Services' was also capitalized in one instance. These changes are primarily terminological and organizational, with no material shifts in the substantive privacy practices, data collection authority, or user rights described in the policy.
Why this matters The updated privacy policy replaces the term 'Offerings' with 'Services' throughout and adds a reference to a Glossary for capitalized term definitions. These are terminological and organizational changes that do not alter the substantive privacy practices, data collection methods, or user rights previously described in the policy. No new obligations or restrictions are introduced by this change.
View full change record →

Recent Provision Changes Jun 5, 2026

6 provisions unchanged.

View full change record →
High — 1 provision
Medium — 4 provisions
Low — 1 provision

Monitoring

Smartsheet has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Compliance free trial

Cross-platform context

See how other platforms handle Controller-Processor Distinction for Enterprise Data and similar clauses.

Compare across platforms →
Archival ProvenanceSource & Archival Record
Last Captured June 5, 2026 19:13 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000712
Version ID CA-V-003480
SHA-256 ac4a824dd36efe3e6b9e4e135180dc2c22109c966a07a5364957825aa2222193
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans