2026-04-17 · 5 min read

Notion AI GDPR and SOC 2 compliance: what your team needs to know

Notion has become the default wiki, project tracker, and documentation tool at thousands of SaaS companies. When Notion added AI features, AI-generated summaries, Q&A over your workspace, writing assistance, those features created new compliance obligations that many teams have not yet addressed.

No DPA with Notion means no compliant AI usage

This guide covers what you need to do about Notion AI for GDPR and SOC 2.

What Notion AI actually does with your data

Notion AI processes the content in your prompts, including whatever text exists in the Notion pages you share with it. If your Notion workspace contains customer information, employee records, product roadmaps, or any other sensitive data, and your employees use Notion AI features on those pages, that content flows to Notion's AI infrastructure and third-party AI providers.

Notion uses third-party AI providers (which have included Anthropic and others) to power Notion AI features. Your prompts are processed by these providers as subprocessors under Notion's agreements with them. Notion's DPA should cover these flows for Business and Enterprise customers.

GDPR requirements

DPA status by plan

PlanDPA availableNotion AI coveredTraining opt-out
FreeNoNoN/A
PlusLimitedCheck current termsN/A
BusinessYesYesYes (by default)
EnterpriseYesYesYes (by default)

The critical threshold is Business plan. Free and Plus users accessing Notion AI are not processing data under a GDPR-compliant DPA. If your employees are on personal or company-paid Plus plans and using Notion AI with work data, that is a GDPR gap.

Signing the DPA

Notion's Data Processing Addendum is incorporated into the Business and Enterprise terms of service. For most Business customers, it applies automatically. For Enterprise, it is negotiated as part of the contract. Verify that your organization's Notion contract includes the DPA and that it is effective.

Subprocessors and data transfers

Notion's DPA should cover transfers of personal data to Notion's subprocessors (including AI providers) via Standard Contractual Clauses. Review Notion's current subprocessor list to confirm which AI providers process your data and under what mechanisms.

Data residency

Notion offers a US data residency option for Enterprise customers. Business customers process data in Notion's default infrastructure (primarily US-based). If EU data residency is a requirement for your organization, this is an Enterprise feature and may require negotiation.

SOC 2 requirements

Vendor inventory (CC9.1)

Add Notion to your vendor inventory. The entry should document:

  • Service scope: Wiki, project management, documentation, AI writing assistant
  • Data processed: Internal documents, which may include confidential business information, product data, or personal data depending on what your team stores in Notion
  • Risk tier: Medium to High depending on whether customer personal data is in your Notion workspace
  • DPA status: Notion Business/Enterprise DPA on file
  • Security documentation: Notion's SOC 2 Type 2 report (available via NDA from Notion's trust page), ISO 27001 certificate
  • Review cadence: Annual

Access controls (CC6)

Key access decisions for Notion:

  • Who has Notion accounts (employees, contractors, temporary staff)?
  • Are guest users able to access pages with sensitive data?
  • Is Notion AI enabled workspace-wide or for specific members?
  • Do departing employee accounts get deprovisioned promptly?

Notion's Business and Enterprise plans support SCIM provisioning through Okta, Azure AD, and other identity providers, which makes provisioning and deprovisioning automatable.

Acceptable use policy (CC1)

Your policy should address:

  • Which data classifications are appropriate for Notion pages (and therefore Notion AI prompts)
  • Whether restricted or confidential data should be stored in Notion at all
  • Whether employees may use personal Notion accounts for work purposes
  • Specific guidance on Notion AI, what types of prompts are acceptable

What to do right now

01Check your Notion plan

Confirm you are on Business or Enterprise if employees use Notion for work data.

02Verify the DPA is in effect

Check your Notion billing settings or contract.

03Review AI feature settings

In Notion's Settings & Members → Workspace Settings, review whether Notion AI is enabled and for whom.

04Update your vendor inventory

Add Notion as a vendor with AI features noted.

05Update your acceptable use policy

Add explicit guidance on Notion AI.

06Add Notion to your AI tools inventory

Part of your CC9.1 vendor management for AI specifically.

Getting Notion AI audit-ready comes down to mapping its data flows to your SOC 2 and GDPR controls, confirming the DPA and sub-processors, and keeping that evidence current as the service changes. If you would rather a security leader owned that work than track it in a spreadsheet, book a call.

Related reading

Want a security leader to run this?

Xorabyte is a fractional CISO for startups who can review your cloud for the gaps found first, so a blocked deal or an audit stops being your problem to carry alone. Book a call and you will leave with a clear path, not a sales pitch.

Frequently asked questions

Is Notion AI GDPR compliant?
Notion AI can be GDPR compliant when used on a paid Business or Enterprise plan with a signed Data Processing Addendum (DPA). Notion's DPA covers Notion AI features as part of the core service. Free and Plus plan users do not receive GDPR-compliant data processing terms. If your employees use Notion with a free or Plus account and paste personal data into Notion AI, that processing is not covered by a DPA.
Does Notion train on your data?
Notion states that for Business and Enterprise customers, content submitted to Notion AI is not used to train Notion's AI models. For free and Plus plans, check Notion's current terms, training behavior for consumer tiers has varied. Notion uses third-party AI providers (including Anthropic and others) to power Notion AI; those providers process your prompts under their own terms as Notion's subprocessors.
What subprocessors does Notion AI use?
Notion uses third-party AI providers to power Notion AI features. Notion's subprocessor list (available at notion.so/subprocessors) includes AI infrastructure providers. These subprocessors receive the content of your Notion AI prompts. For GDPR compliance, Notion's DPA should cover data transfers to these subprocessors via Standard Contractual Clauses. Review Notion's current subprocessor list for the specific AI providers in use.
What SOC 2 controls apply to Notion AI?
Notion AI usage triggers SOC 2 requirements under CC9.1 (Notion must be in your vendor inventory as a data processor), CC6 (access controls determining who can use Notion and with what data), and CC1 (acceptable use policy covering AI features). If employees paste customer data or confidential information into Notion AI, that data flow must be inventoried and risk-assessed.
Should I enable Notion AI for my whole company?
Before enabling Notion AI broadly, ensure you are on a Business or Enterprise plan with a signed DPA, review your data classification policy to determine what data types are appropriate for Notion AI prompts, and update your acceptable use policy to cover Notion AI specifically. Consider whether all employees need AI features or whether a subset with specific data access restrictions is more appropriate.

Xorabyte

Get a security leader in your corner.

Xorabyte is a fractional CISO for startups facing SOC 2, security questionnaires, and enterprise security reviews. Tell us what triggered the need and we will map the path.