Compliance frameworks, security audits, and quality certifications this company maintains.
Notion holds SOC 2 Type II certification covering security, availability, and confidentiality of team workspace data across its cloud platform used by 100M+ users.
Notion is ISO 27001 certified for its information security management system, covering risk management, access controls, and incident response for enterprise workspace deployments.
Notion provides GDPR-compliant data handling with EU data residency options, data subject access request workflows, and signed Data Processing Agreements for European customers.
Notion supports CCPA compliance for California-based users with data deletion requests, privacy controls, and clear opt-out mechanisms in its consumer privacy portal.
Notion offers HIPAA-eligible workspace configurations for healthcare customers with Business Associate Agreements to support compliant storage of protected health information.
Notion maintains PCI DSS Level 1 compliance for payment card data handling in its subscription billing and enterprise payment processing workflows, ensuring customer payment information is protected to the highest card industry security standards.
Notion holds ISO 27017 certification for cloud service security controls, providing enterprise customers with third-party assurance that Notion cloud workspace infrastructure follows internationally recognized security standards for cloud environments.
Notion maintains ISO 27018 certification for protection of personally identifiable information in public cloud, ensuring that customer workspace data including notes, databases, and documents is handled in accordance with international cloud privacy standards.
Notion designs its workspace platform to meet WCAG 2.1 AA accessibility standards, ensuring users with visual, motor, and cognitive disabilities can effectively use Notion for personal and team knowledge management.
Notion supports FERPA compliance for educational institutions using Notion for student work, collaboration, and campus knowledge management, with appropriate data handling agreements for institutions managing student education records.