Skip to main content

Security & Privacy · Teams and Freelancers

Winning the "Is Notion secure?" conversation

You're not reading this out of curiosity. You're reading it because you have to walk into a room — tomorrow or next week — and answer "is our data safe in this thing?" without stumbling.

That meeting always follows the same pattern. Someone senior asks a variation of the same question. You give a vague answer. They ask a follow-up you weren't expecting. Everything stalls.

This guide is built to prevent that. Read parts 1 to 6 to actually understand what you're talking about, not just repeat it. Then go straight to "Walking into the room" near the end: you'll find the script, stakeholder by stakeholder.

One note before we start: nothing here is a sales pitch. Where Notion has real limits, this guide says so.


TL;DR

  • Hosting. Notion rents server space from AWS. Your data is stored in the US by default. Data residency in Europe is Enterprise-only.
  • Ownership. You own your data. Notion only processes it. You can export or delete everything at any time.
  • AI. Notion does not train its models on your content by default. Enterprise adds a guarantee: no data retention by third-party AI providers.
  • Certifications. Encryption, backups, and independent audits (SOC 2, ISO 27001) are solid on all plans, including the free tier.
  • SSO. Single sign-on is available from the Business plan. No need for Enterprise.
  • Advanced controls. SCIM (automatic access removal), the full audit log, data residency, and advanced permission controls are Enterprise-only.
  • Real weakness. Below Enterprise, you can't choose where your data lives.
  • Real lesson. A secure vendor doesn't save you if your workspace permissions are a mess.

If you're a freelancer

This guide is written for both audiences, but as an independent freelancer or consultant, your questions are different. Here are the direct answers before going further.

Can I put client data in Notion?

Yes, with one caveat: avoid storing sensitive personal data (social security numbers, health records, banking details). For briefs, deliverables, quotes, meeting notes, ordinary client contact databases: there's no legal problem, as long as your clients are informed and you manage access properly.

If you share pages with clients, check that your permissions are correctly set. The most common risk isn't a Notion breach, it's a misconfigured page that anyone can view.

Is Notion GDPR-compliant for my business?

Notion provides standard contractual clauses (SCCs) for US data transfers, making it legally compatible with GDPR in the vast majority of cases. As a freelancer processing data on behalf of clients, you need a signed DPA with Notion. Notion offers this on request, or accessible from your dashboard on Business and Enterprise plans.

If you regularly work with large enterprises or regulated sectors (healthcare, finance, defence), check with your client before bringing them into your workspace.

What plan do I actually need?

For standard freelance use: Free or Plus is enough for most cases. Business becomes relevant if you want SSO (to authenticate via your professional or a client's account). Enterprise is rarely justified for a solo practice, unless a large client requires it contractually.


Part 1: three things to separate

Most of these conversations fail because everyone is using the word "security" to mean three different things. Start by separating them.

Data

Where your information physically lives, who is authorised to read it, and what happens to it when you leave.

Security

The locks on the building. Encryption, monitoring, audits, backups. Everything that stops someone from getting in uninvited.

Access

Who in your organisation can enter your Notion workspace, how those people prove their identity, and how quickly you can cut off access when someone leaves.

These three dimensions have different answers. Someone asking "is Notion secure?" may be asking all three at once without realising it. Your job is to separate them before answering.


Part 2: your data

Where your data lives

Notion hosts data on Amazon Web Services, region us-east-1 (Virginia, United States) by default. This isn't a proprietary solution: AWS is the most widely used infrastructure in the world for this type of service, and one of the most audited.

If your organisation has a data residency requirement in Europe (GDPR or internal policy), data residency is only available on the Enterprise plan. That's a clear limit.

Who owns your data

You do. Notion is a data processor under GDPR: it processes your data on your behalf, without owning it. You can export all your content as Markdown, CSV, or HTML at any time. If you cancel, your data is deleted after a defined period per their privacy policy.

Data and AI

Notion does not train on your content by default. If you use Notion AI (a paid feature), your prompts are processed by third-party AI providers. On Enterprise, Notion guarantees no data retention by those providers. On lower plans, check Notion AI's terms of service if this is a concern for your organisation.

GDPR in practice

Notion offers a Data Processing Agreement (DPA) formalising GDPR commitments, and standard contractual clauses for transfers to the US. These documents are accessible from your workspace settings or on request. They're mandatory under GDPR if your organisation processes personal data on behalf of third parties.

For heavily regulated sectors (healthcare, finance, defence), consult your DPO or legal team before deploying Notion for sensitive data.


Part 3: security

Encryption

Your data is encrypted in transit (TLS 1.2+) and at rest (AES-256). These are the reference standards for this type of service. Notion doesn't offer native end-to-end encryption (where only you and your team hold the keys), but Enterprise teams can request additional key management options.

Independent audits

Notion is certified SOC 2 Type II and ISO 27001. These certifications are not self-declared: they are issued after audit by accredited independent bodies. SOC 2 Type II is the reference for American SaaS companies. ISO 27001 is the international information security management standard.

Compliance reports are accessible via Notion's security centre at notion.com/security.

Backups

Notion performs regular automatic backups. Page version history is accessible from the interface (7 days on the free plan, unlimited on Business and Enterprise). This isn't a replacement for an external backup strategy if you have critical data: consider periodic exports.

Vulnerability disclosure programme

Notion maintains a public bug bounty programme that invites independent security researchers to report vulnerabilities. That's a positive signal: companies that hide their flaws don't have fewer of them. Companies that organise their disclosure handle incidents better.

Important caveat: certifications cover Notion's practices, not your own configurations. A workspace with publicly shared pages, unrestricted guests, or members added without oversight is not protected by SOC 2. The operational security of your workspace remains your responsibility.


Part 4: access

Authentication

By default, Notion authenticates via email and password, or via a Google, Apple, or Microsoft account. Two-factor authentication (2FA) is available for all accounts.

SSO (single sign-on via your corporate identity provider: Okta, Azure AD, etc.) is available from the Business plan. This is often the main condition set by IT teams.

Access management

Notion lets you control access at the page, database, or full workspace level. You can set different permissions for each member or group.

SCIM (automatic account provisioning via your HR or IT directory) is Enterprise-only. Without SCIM, when someone leaves your organisation you must remove their access manually. That's manageable, but it's a process you need to define.

The audit log

The full audit log (who viewed what, when, from which device) is available on Enterprise. On lower plans, you have access to page edit history, but not a centralised log of all actions.

Deactivating an account

On all plans, an admin can remove a member from the workspace in a few clicks. Without SCIM, that removal is manual. With SCIM, it's automatic as soon as the account is deactivated in your directory.


Part 5: honest limits

Notion does a lot of things well. But some limits are real and worth stating clearly.

No native end-to-end encryption

Notion can technically access your data. That's not a security flaw in the strict sense, and it's common among collaborative SaaS tools. But if your organisation handles highly confidential information (legal privilege, M&A, classified data), this point deserves discussion with your legal team.

Data residency is Enterprise-only

If a regulation or internal policy requires your data to stay in Europe, you need Enterprise. There's no workaround on lower plans.

Limited audit log below Enterprise

If your IT team needs to trace who accessed what for regulatory or internal security reasons, the full log is only available on Enterprise.

SCIM is Enterprise-only

Automatic provisioning via SCIM requires Enterprise. Below that, access management for joiners and leavers remains manual.

Operational security is your responsibility

This is the most important limit and the least often mentioned. A poorly configured workspace, with unintentional public pages, forgotten guests, or members with more access than necessary, cancels much of the protection Notion provides. Your internal governance matters as much as the vendor's certifications.


Part 6: Notion as a partner, not a vault

The best way to think about Notion's security isn't "is it secure?" but "how do I build something secure with these tools?"

Notion provides the infrastructure: encryption, certifications, access controls. Your organisation provides the governance: who has access to what, how access is removed, what data lives there and what shouldn't.

An audit of your current Notion workspace often reveals problems that vendor certifications can't solve: pages shared too broadly, databases accessible to members who no longer have an active role, third-party integrations connected and forgotten.

See Notion's official security practices documentation for the full technical details.

If you want to go further on workspace configuration, a Notion audit is the right starting point.


Walking into the room

Here's how to respond depending on who you're talking to. The goal isn't to convince through authority, but to open a productive conversation.

Facing senior management

Their question always takes some variant of the same form. Prepare two answers.

Them
"Are we taking a risk using this?"
You
"Notion is SOC 2 Type II and ISO 27001 certified, the same certifications as our other SaaS tools. The real risk isn't the vendor, it's how we configure our workspace. And that's something we control."
Them (follow-up)
"The data is in the US?"
You
"By default, yes. If we have a European residency requirement, we need the Enterprise plan. Otherwise, standard contractual clauses cover GDPR."

Facing IT or your CISO

They have specific questions. Have these answers ready:

  • SSO: available from Business (SAML 2.0, Okta, Azure AD, etc.).
  • SCIM: Enterprise-only.
  • Full audit log: Enterprise-only.
  • Encryption: TLS 1.2+ in transit, AES-256 at rest. No native end-to-end encryption.
  • Data residency: Enterprise-only (Europe available).
  • DPA and SCCs for GDPR: available on request or in Business/Enterprise settings.
  • Certifications: SOC 2 Type II, ISO 27001. Reports available at notion.com/security.

What they appreciate: that you bring this information upfront rather than discovering it together in the meeting. And that you're honest about limits (no end-to-end encryption, residency only on Enterprise).

Facing your DPO or legal team

Their main concern: GDPR and data transfers outside the EU.

Them
"Data hosted in the US, is that GDPR-compliant?"
You
"Notion offers a compliant DPA and standard contractual clauses for transfers to the US. For European data residency, you need Enterprise. We can request the documents directly from our dashboard."

For healthcare and finance in particular, check with them which data can live in Notion and which shouldn't.

Most common follow-up questions

Question
"What if Notion gets hacked?"
Answer
Notion has a public incident management programme. In the event of a breach, they must notify within 72 hours under GDPR. Encryption limits exposure. And your real lever: well-configured permissions reduce the exposed surface area.
Question
"Does our data train their AI?"
Answer
No, by default. Enterprise adds an extra guarantee on the AI provider side.
Question
"If we cancel, what happens to our data?"
Answer
You export everything in advance, Notion deletes the data per their policy. No risk of indefinite retention.

Glossary

Two-factor authentication (2FA)
A mechanism that requires a second proof of identity beyond a password (SMS code, authenticator app, hardware key). Significantly reduces the risk of account compromise even if the password is stolen.
AES-256
Symmetric encryption standard used for data stored at rest. AES-256 means a 256-bit key, considered unbreakable with current computing capabilities. Used by Notion to encrypt your data on their servers.
AWS / us-east-1
Amazon Web Services, Notion's cloud infrastructure provider. The us-east-1 region refers to data centres in Virginia, United States. This is the default storage region for all accounts below Enterprise with data residency.
DPA (Data Processing Agreement)
A contract governing the relationship between you (the data controller) and Notion (the data processor). Mandatory under GDPR whenever you entrust personal data to a service provider. Notion offers this on request or from Business/Enterprise dashboard settings.
End-to-end encryption (E2E)
An encryption mode where only the sender and recipient hold the keys. The provider cannot read the data. Notion does not offer native E2E encryption: data is encrypted on Notion's servers, but Notion can technically access it (as is true for virtually all collaborative SaaS tools).
Encryption
The process of encoding data so that only authorised parties can read it. Notion uses TLS 1.2+ for data in transit and AES-256 for data at rest. See also: End-to-end encryption, TLS.
Identity Provider (IdP)
A service that manages user identities in an organisation and enables single sign-on. Common examples: Okta, Microsoft Azure Active Directory, Google Workspace. Notion supports major IdPs via SAML 2.0 from the Business plan.
ISO 27001
The international standard for information security management. Awarded after audit by an accredited body, it certifies that an organisation has implemented a security management system aligned with global best practices. Notion is ISO 27001 certified.
Standard Contractual Clauses (SCCs)
A legal mechanism approved by the European Commission for governing personal data transfers to countries outside the EU (notably the US). Notion includes them in its DPA to ensure GDPR compliance despite US-based hosting.
SCIM
System for Cross-domain Identity Management. A protocol for automatically synchronising your user directory (HR system, Active Directory) with Notion. When an employee leaves, their Notion access is revoked automatically. Available only on the Enterprise plan.
SOC 2 Type II
An American security certification issued by independent auditors. "Type II" means controls were tested over an extended period (typically 6 to 12 months), not just observed at a single point in time. The reference standard for SaaS vendors. Notion is SOC 2 Type II certified.
SSO (Single Sign-On)
Single sign-on: your employees log into Notion using their corporate credentials (via your identity provider), without creating a separate password. Simplifies access management and improves security. Available from the Business plan on Notion (SAML 2.0).
TLS (Transport Layer Security)
A protocol for encrypting network communications. TLS 1.2+ ensures that data exchanged between your browser and Notion's servers cannot be intercepted in transit. It's the "S" in "HTTPS".
Diagnose