Skip to main content
WAIMAKERS
About UsCareersContact
|
Start a conversation
Back to overview

Notion AI

Notion

ConditionalEU: LimitedNo training¹Variable retentionUS / EU storage

Assessment labels are editorial guidance, not GDPR certifications. Validate the exact plan, lawful basis, DPA, subprocessors, retention, residency and feature settings. EU storage and no-training terms alone do not establish GDPR compliance. ¹ No training applies under the reviewed plan’s terms.

Rolling out Notion AI safely?

We assess the actual plan, settings, data flows and governance controls, then turn the findings into a practical rollout decision.

Request an assessment

Pricing / Contract Route

Official pricing varies by plan, market, billing cadence and contract

Enterprise Features

DPA, Enterprise EU at-rest residency, zero-retention LLM providers by default, SSO/admin controls and subprocessor notices

Last Updated

September 10, 2026

Version: 10 September 2026 - prepared by WAIMAKERS B.V.

Executive summary

Notion AI can support a GDPR-compliant deployment under Notion's commercial terms, but this depends on the plan, enabled AI features, subprocessors, permissions, retention and residency configuration. The service is not itself a GDPR certification.

Is Notion AI GDPR compliant?

Not automatically. Notion's DPA, no-training default and security controls can support the customer's compliance programme. Lawful basis, minimisation, transparency, permissions, retention, transfers and any DPIA remain customer responsibilities.

What is supported

  • ✅ Notion says it and its AI subprocessors do not use Customer Data to train models by default.
  • ✅ Enterprise LLM providers use zero data retention by default.
  • ✅ Notion AI is in scope for Notion's SOC 2 Type 2 report and ISO 27001 certification.
  • ✅ Notion AI respects existing workspace permissions.
  • ✅ Customer Data sent to AI subprocessors uses TLS 1.2 or later in transit.

What still needs review

  • ⚠️ Zero retention applies to the LLM provider, not to all Notion data.
  • ⚠️ Existing oversharing can make content discoverable through AI.
  • ⚠️ Some data-retaining features and External Agents have separate practices.
  • ⚠️ EU residency requires a completed migration and only covers listed data at rest.
  • ⚠️ Web search, connectors, Custom Agents and External Agents create separate data flows.

Tiers at a glance (EU focus)

Route Training and AI providers LLM-provider retention EU data residency Practical assessment
Non-Enterprise workspace ✅ No training on Customer Data by default. Notion uses hosted models and organisations such as OpenAI and Anthropic; verify the current subprocessor list. ⚠️ By default, 30 days or fewer. Some data-retaining features are off by default and admins receive a setting. External Agents differ. ❌ No regional-at-rest commitment is documented; default hosting is the US. Assess the exact plan and enabled features before processing sensitive data.
Enterprise without completed migration ✅ Same no-training default ✅ Enterprise LLM providers use zero retention by default ❌ Workspace data remains in the US until Notion confirms the requested migration is complete. Do not infer EU residency from the Enterprise plan alone.
Enterprise with confirmed EU residency ✅ Zero-retention LLM providers by default; DPA and live subprocessor list still apply ⚠️ Workspace content, embeddings and deleted pages have separate lifecycles ✅ Listed Customer Data at rest is in Frankfurt, with Ireland backup. Processing and excluded products can remain international. Stronger at-rest control, with documented product and processing limits.

Public prices and AI packaging change by market, billing cadence and contract. Verify Notion's live pricing and order form before purchase.

How Notion AI processes data

  1. A user's permissions determine which workspace content Notion AI can access.
  2. Notion can route a request to Notion-hosted models or AI providers such as Anthropic and OpenAI.
  3. The LLM-provider retention rule depends on the plan and enabled feature.
  4. Notion separately stores workspace content and embeddings.
  5. Connectors, web search and agents can add other processors and locations.

Retention and deletion

  • ✅ Enterprise LLM providers use zero data retention by default.
  • ⚠️ Non-Enterprise LLM providers retain Customer Data for no more than 30 days by default.
  • ⚠️ Some features require a data-retaining LLM and have separate admin settings.
  • ✅ The OpenAI embeddings API used by Notion is zero-retention.
  • ⚠️ Notion stores the resulting embeddings in a vector database and deletes them within 60 days after the page or workspace is deleted.
  • ⚠️ Deleted pages and workspaces remain recoverable for 30 days before becoming unrecoverable, subject to applicable contract or legal exceptions.

EU data residency

EU residency is not automatic with Enterprise. Migration must be requested and completed. Until Notion confirms completion, workspace data remains hosted in the US.

For a completed EU migration, listed Customer Data at rest is stored in AWS Frankfurt with backup in Ireland. This includes page content, uploaded files, the Customer Data search index and stored third-party or bot messages. Notion says US copies of covered data are deleted about 30 days after migration.

The commitment does not cover account information, usage data, subprocessor processing, Notion Calendar, Notion Mail, beta services, integrations or non-Notion services. Processing can still occur in the US and other countries.

EU rollout checklist

  1. Confirm the plan, current DPA, Master Subscription Agreement and live subprocessor list.
  2. Record which AI functions, web search, connectors and agents are enabled.
  3. If EU residency is required, obtain confirmation that migration is complete and record the covered data categories.
  4. Document LLM-provider retention separately from workspace, deletion and embedding retention.
  5. Remediate permissions and apply least privilege before enabling workspace-wide search.
  6. Test deletion, restore and export workflows, including embeddings and integrated services.
  7. Set an approved-data policy and complete the lawful-basis, transparency, DPIA and transfer assessment required by the use case.

Notes and caveats

  • ⚠️ OpenAI and Anthropic are examples of providers, not a complete fixed list.
  • ⚠️ A certification supports a controls assessment but does not certify the customer's GDPR compliance.
  • ⚠️ HIPAA statements have their own contract and configuration conditions.
  • ⚠️ Connectors and third-party data do not automatically remain within Notion's EU at-rest region.

Sources

  • Notion AI security and privacy practices
  • Notion data residency
  • Notion GDPR information
  • Notion subprocessors
  • Notion pricing

Disclaimer

This overview is an informational procurement aid, not legal advice or certification of a workspace. Verify the live plan, contract, settings and data flows before production use. The customer remains responsible for its GDPR obligations.

Prepared and issued by WAIMAKERS B.V. - 10 September 2026.

Compare related tools

Gemini Notebookn8n

Need help navigating AI?

Start a conversation
WAIMAKERS

Learn. Lead. Make.

AI Transformation Boutique · Amsterdam

Make work exciting, make businesses unstoppable.

Who We Help

View all roles & industriesCEOs & Board MembersPE & Investment ManagersCFOs & Finance LeadersInnovation DirectorsCTOs & IT LeadersCommercial Directors

What We Do

View all servicesOur ApproachLearnTailored Training ProgrammesAI Champions ProgrammeAI Champions — Executive (London)Agentic Way of WorkingE-learningLeadMake

Company

About UsResourcesContactCareersPodcast ↗

© 2026 WAIMAKERS. All rights reserved.

Privacy PolicyCookie Policy