Smartsheet · Smartsheet Privacy Policy · View original document ↗

GDPR Rights for EEA and UK Users

Medium severity High confidence Explicitdocumentlanguage Rare · 3 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Smartsheet Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

If you are in the EU or UK, you have the right to see, correct, delete, and move your personal data, and to object to certain uses of it. You can also complain to your national data protection authority if you believe your rights have been violated.

This analysis describes what Smartsheet's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

These rights are enforceable under GDPR and UK GDPR, and Smartsheet's acknowledgment of them means EEA and UK users have formal legal mechanisms to challenge or limit data processing, including the right to file complaints with national regulators.

Consumer impact (what this means for users)

EU and UK users can formally request access to, deletion of, or a copy of their personal data, and can object to Smartsheet processing their data based on legitimate interests, including for marketing purposes; these rights are exercisable through Smartsheet's privacy request form.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Submit a GDPR erasure or access request through Smartsheet's privacy request form. Smartsheet is required to respond within one month under GDPR.

How other platforms handle this

Grammarly Medium

If you are located in the EEA, UK, or Switzerland, you have certain rights with respect to your personal information, including the right to access your personal data, to correct or delete your personal data, to restrict processing of your personal data, to data portability, and to object to process...

Waze Medium

If you are located in the European Economic Area or the United Kingdom, you have certain rights under applicable data protection laws, including the right to access, correct, or delete your personal data, the right to object to or restrict processing, and the right to data portability. You may also ...

ADP Medium

If you are a California resident, you may have certain rights under the California Consumer Privacy Act (CCPA). These rights may include: the right to know about personal information collected, disclosed, or sold; the right to delete personal information collected from you; the right to opt-out of t...

See all platforms with this clause type →

Monitoring

Smartsheet has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
If you are located in the EEA or UK, you may have the following rights under applicable data protection law: the right to access your personal data; the right to rectify inaccurate personal data; the right to erasure of your personal data; the right to restrict processing of your personal data; the right to data portability; the right to object to processing based on legitimate interests; and the right to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your relevant supervisory authority.

— Excerpt from Smartsheet's Smartsheet Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision is governed by GDPR (Regulation 2016/679) and UK GDPR. Enforcement authorities are EU national data protection authorities and the UK Information Commissioner's Office. The rights enumerated correspond to GDPR Articles 15 through 21. Smartsheet's role as data controller for website and marketing data means it bears direct GDPR obligations for those processing activities; its role as processor for service data means enterprise customers bear controller obligations for that data. (2) GOVERNANCE EXPOSURE: Medium. The enumeration of GDPR rights is standard for a GDPR-covered controller. Compliance exposure arises from the operational adequacy of Smartsheet's rights response processes, including response timelines (one month under GDPR), identity verification procedures, and the handling of complex requests such as portability for service data where Smartsheet acts as processor. (3) JURISDICTION FLAGS: Applies to EEA member state residents and UK residents. Organizations headquartered in the EU or UK that use Smartsheet must ensure their DPA with Smartsheet addresses the controller's obligation to facilitate data subject rights requests that relate to processor-held data. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers in the EU and UK should ensure their Smartsheet DPA includes provisions requiring Smartsheet to assist with data subject rights requests as required by GDPR Article 28(3)(e). Without this, customers may face difficulty fulfilling their own GDPR obligations when employees submit rights requests. (5) COMPLIANCE CONSIDERATIONS: EU and UK users should exercise their right to object to processing based on legitimate interests if they wish to limit marketing or analytics data use. Legal teams should confirm Smartsheet's DPA obligations for assisting with data subject rights and document their own procedures for handling requests redirected from Smartsheet for service data.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable regulations

CCPA/CPRA
California, USA
Colorado AI Act
US-CO
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US
VPPA
United States Federal

Provision details

Document information
Document
Smartsheet Privacy Policy
Entity
Smartsheet
Document last updated
May 5, 2026
Tracking information
First tracked
May 7, 2026
Last verified
May 10, 2026
Record ID
CA-P-008062
Document ID
CA-D-00712
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
aa3e2b37314e800adf6f92513bffd0a54c2369282b4a03c0788838ef681cf41e
Analysis generated
May 7, 2026 16:22 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Smartsheet
Document: Smartsheet Privacy Policy
Record ID: CA-P-008062
Captured: 2026-05-07 16:22:45 UTC
SHA-256: aa3e2b37314e800a…
URL: https://conductatlas.com/platform/smartsheet/smartsheet-privacy-policy/gdpr-rights-for-eea-and-uk-users/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Smartsheet's GDPR Rights for EEA and UK Users clause do?

These rights are enforceable under GDPR and UK GDPR, and Smartsheet's acknowledgment of them means EEA and UK users have formal legal mechanisms to challenge or limit data processing, including the right to file complaints with national regulators.

How does this clause affect you?

EU and UK users can formally request access to, deletion of, or a copy of their personal data, and can object to Smartsheet processing their data based on legitimate interests, including for marketing purposes; these rights are exercisable through Smartsheet's privacy request form.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 3 platforms. See the full comparison.

Is ConductAtlas affiliated with Smartsheet?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Smartsheet.