Upwork collects a wide range of personal information when you sign up and use the platform, including your name, contact details, payment card information, and anything else you choose to share in your profile.
This analysis describes what Upwork's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The breadth of data collected, including financial and payment data alongside identity and communications information, means Upwork holds sensitive personal information that could cause harm if improperly disclosed or breached.
Interpretive note: The document provided was truncated and the exact verbatim text of the data collection clause could not be confirmed from the source HTML; the excerpt reflects standard Upwork privacy policy language based on publicly available versions of this document.
Upwork's privacy policy previously disclosed that it complied with the U.S. Data Privacy Framework and certified adherence to its Principles regarding how it processes personal data from EU, UK, and Swiss residents. The updated policy removes nearly all of this language, including the explicit commitment to Data Privacy Framework Principles and the statement that those Principles would govern in case of conflict with other policy terms. Users in the EU, UK, and Switzerland no longer have a clear, policy-level statement of the legal framework protecting their data when transferred to the U.S., which may reduce transparency about data protection safeguards. You may contact Upwork to request copies of the data transfer mechanism documents it uses.
View change record →The updated policy now explicitly states that Upwork complies with the U.S. Data Privacy Framework and has certified to the U.S. Department of Commerce that it adheres to DPF principles when processing personal data from EU, UK, and Swiss residents. The policy establishes that if any conflict exists between Upwork's privacy policy and DPF principles, the DPF principles will govern. This creates an explicit legal hierarchy for data protection standards applicable to residents of those jurisdictions. Users from affected regions can visit https://www.dataprivacyframework.gov/ to view Upwork's certification and learn more about the DPF program.
View change record →Every piece of information you enter on Upwork, from your name and address to your payment card details and profile content, is collected and retained by Upwork under these terms. Financial data in particular carries elevated sensitivity and is subject to additional legal protections in many jurisdictions.
How other platforms handle this
At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.
We use information to enhance the quality, reliability, and/or accuracy of our AI Features by creating, developing, training, testing, improving, and maintaining AI and ML models run by Strava or our service providers. We use aggregated, de-identified data for this purpose. We also use personal info...
We collect your personal data when you use our Services, create a new eBay account, provide us with information via a web form, add or update information in your eBay account, participate in online community discussions or otherwise interact with us.
Monitoring
Upwork has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"We collect information you provide directly to us, such as when you create or modify your account, request on-demand services, contact customer support or otherwise communicate with us. This information may include: name, email, phone number, postal address, profile picture, payment method, financial and credit card information, and other information you choose to provide.— Excerpt from Upwork's Upwork Privacy Policy
REGULATORY LANDSCAPE: Collection of financial and payment card data engages PCI DSS standards, though PCI DSS is a contractual security standard rather than a privacy regulation. GDPR Article 5 principles of data minimization and purpose limitation apply to EU/EEA users. CCPA Section 1798.100 gives California residents the right to know what categories of personal information are collected. The FTC Act Section 5 requires that data collection practices match disclosed representations. GOVERNANCE EXPOSURE: Medium. The policy lists broad categories of data collected but does not enumerate specific data minimization practices or retention periods for each category. This creates a compliance gap for GDPR Article 5(1)(e) storage limitation requirements and may require supplementary documentation for DPA purposes. JURISDICTION FLAGS: EU/EEA users benefit from GDPR data minimization and purpose limitation requirements that may constrain Upwork's ability to use collected data for secondary purposes. California residents under CPRA have the right to correct inaccurate personal information. Illinois users should note that if identity verification involves facial recognition or biometric identifiers, BIPA may apply. CONTRACT AND VENDOR IMPLICATIONS: Enterprise clients using Upwork for workforce procurement should ensure a Data Processing Agreement is in place that addresses the categories of personal data listed here, including financial data. The breadth of collection categories means vendor assessments should include a data mapping exercise. COMPLIANCE CONSIDERATIONS: Compliance teams should verify that Upwork's data retention schedules are documented and available upon request, and that the lawful basis for each category of data processing is identified. For EU deployments, a Records of Processing Activities entry should reflect the full scope of data categories disclosed in this provision.
Full compliance analysis
Regulatory citations, enforcement risk, and due diligence action items.
Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
The breadth of data collected, including financial and payment data alongside identity and communications information, means Upwork holds sensitive personal information that could cause harm if improperly disclosed or breached.
Every piece of information you enter on Upwork, from your name and address to your payment card details and profile content, is collected and retained by Upwork under these terms. Financial data in particular carries elevated sensitivity and is subject to additional legal protections in many jurisdictions.
ConductAtlas has identified this type of provision across 14 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Upwork.