{"id":281,"date":"2026-05-11T00:00:22","date_gmt":"2026-05-11T00:00:22","guid":{"rendered":"https:\/\/l.monday.com\/l\/l\/?p=281"},"modified":"2026-05-11T07:42:36","modified_gmt":"2026-05-11T07:42:36","slug":"monday-com-is-gdpr-ready","status":"publish","type":"post","link":"https:\/\/monday.com\/l\/privacy\/monday-com-is-gdpr-ready\/","title":{"rendered":"monday.com &#038; the GDPR and UK GDPR"},"content":{"rendered":"\r\n<p>At monday.com, our Customers\u2019 success and the protection of their data is very important to us. With customers all over the world, we are committed to supporting our Customers\u2019 compliance with local privacy and data protection laws.<\/p>\r\n<p>As an organization offering services to, and processing the personal data of, individuals in the European Economic Area (EEA), Switzerland and the United Kingdom (UK), monday.com has developed a robust privacy program designed to support compliance with the requirements of European data protection laws, including the General Data Protection Regulation (GDPR).<\/p>\r\n<p>Following Brexit, the GDPR was incorporated into local UK law, creating what is known as the \u201cUK GDPR\u201d. Currently, the UK GDPR contains similar requirements to the EU GDPR. When we refer to \u201cthe GDPR\u201d we are referring both to the EU GDPR and to the UK GDPR.<\/p>\r\n<p><strong>Roles and Responsibilities<\/strong><\/p>\r\n<p>The GDPR defines two central roles for the processing of personal data: the \u201cData Controller\u201d and \u201cData Processor\u201d.<\/p>\r\n<ul>\r\n<li><strong>Data Controller<\/strong><strong>:<\/strong> the entity that determines the purposes and means for the processing of personal data. <br \/>monday.com\u2019s Customers are generally the Controllers of personal data submitted to the platform (e.g., via boards, workdocs, or CRM items). <br \/>monday.com acts as a Controller in some contexts, for example, over Customer account and billing information, technical usage data, and website visitor and lead information, as further described in our <a href=\"https:\/\/monday.com\/l\/privacy\/privacy-policy\/\">Privacy Policy<\/a>.<br \/><br \/><\/li>\r\n<li><strong>Data Processor:<\/strong> the entity that processes personal data on behalf of the Controller. monday.com serves as the Processor over personal data submitted onto the platform (e.g., via boards, workdocs, or CRM items), and processes the data under the instruction of the Controller (i.e. the Customer). Where monday.com engages third parties to process such personal data on its behalf, these third parties are considered monday.com\u2019s subprocessors.<\/li>\r\n<\/ul>\r\n<p>For a more detailed breakdown of these roles and our obligations, please refer to our\u00a0<a href=\"https:\/\/monday.com\/l\/legal\/tos\/\">Terms of Service<\/a>,\u00a0<a href=\"https:\/\/monday.com\/l\/privacy\/privacy-policy\/\">Privacy Policy<\/a>\u00a0and\u00a0<a href=\"https:\/\/monday.com\/l\/privacy\/dpa\/\">Data Processing Addendum.<\/a><\/p>\r\n<p><strong>What steps has<\/strong><strong> monday.com <\/strong><strong>taken to support compliance <\/strong><strong>with GDPR<\/strong><strong> requirements?<\/strong><\/p>\r\n<p>At monday.com, we regularly monitor and review our practices to support compliance with GDPR requirements, including:<\/p>\r\n<ul>\r\n<li><strong>EU data residency<\/strong>: We operate a dedicated data region in the EU. Customer accounts hosted in the EU region benefit from EU residency, ensuring alignment with data sovereignty preferences.<\/li>\r\n<\/ul>\r\n<ul>\r\n<li><strong>Global certifications<\/strong>: We undergo annual external audits for <a href=\"https:\/\/monday.com\/terms\/soc2\">SOC 2 Type II<\/a>\u00a0security certification from the American Institute of Certified Public Accountants (AICPA),\u00a0<a href=\"https:\/\/monday.com\/terms\/iso\">ISO 27001<\/a>\u00a0ISMS (information security management system) and\u00a0<a href=\"https:\/\/monday.com\/terms\/iso\">ISO 27018<\/a>\u00a0(for protecting personal data in the cloud).<\/li>\r\n<\/ul>\r\n<ul>\r\n<li><strong>Transparency<\/strong>: We ensure transparency around the collection, use and disclosure of personal data through easily accessible notices, including via our Privacy Policy and Job Candidate Privacy Notice.<\/li>\r\n<li><strong>Legal and contractual controls<\/strong>: We have a robust\u00a0<a href=\"https:\/\/monday.com\/l\/privacy\/dpa\/\">Data Processing Addendum<\/a>(DPA) for Customers in place to ensure the protection of personal data. Such DPAs allow us to perform our role as a data Processor for our Customers, and similar DPAs allow the same when we engage with sub-processors.<\/li>\r\n<li><strong>Data Subject Rights<\/strong>: We provide tools and functionality designed to support Customers in responding to data subject requests to exercise their privacy rights (e.g., correction, deletion, portability), and have a process in place to respond to data subject requests where we act as the Controller of such data.<\/li>\r\n<li><strong>DPO &amp; representative<\/strong>: We have designated a\u00a0<a href=\"https:\/\/monday.com\/l\/privacy\/privacy-policy\/#additional-notices\">representative<\/a>in the EU, and appointed a Data Protection Officer (DPO) for monitoring and advising on monday.com\u2019s ongoing privacy and data protection compliance and serving as a point of contact in relation to data protection and privacy matters for individuals and supervisory authorities.<\/li>\r\n<\/ul>\r\n<p><strong>Data transfers subject to the GDPR<\/strong><\/p>\r\n<p>Various monday.com subsidiaries are located in jurisdictions considered as affording an \u201cadequate\u201d level of protection for personal data by the relevant decision-makers in the EEA, UK and Switzerland, respectively. Accordingly, transfers of personal data between these regions and to subsidiaries in Israel, Japan and Brazil (from EEA only), are done in reliance on this \u201cadequacy\u201d status as a lawful transfer mechanism, without the need for additional safeguards.<\/p>\r\n<p>monday.com\u2019s US subsidiary, monday.com, Inc., has been certified under the US Department of Commerce\u2019s Data Privacy Framework (DPF) to receive data transfers from the EEA, UK or Switzerland to the US. Transfers from the EEA, UK and Switzerland to our US subsidiary, monday.com, Inc., are made primarily in reliance on such certification under this Framework.<\/p>\r\n<p>To the extent we transfer personal data originating from the EEA, the UK, Switzerland to countries that have not been recognized as offering an adequate level of data protection by the relevant competent authority, we rely on, and build into our relevant agreements, appropriate trans-border data transfer mechanisms as established under applicable law, such as the standard contractual clauses (which can be found\u00a0<a href=\"https:\/\/monday.com\/l\/privacy\/https-monday-com-l-scc-controller-to-processor\/\">here<\/a>\u00a0and\u00a0<a href=\"https:\/\/monday.com\/l\/privacy\/https-monday-com-l-scc-processor-to-processor\/\">here<\/a>). In addition to the protections provided by the SCCs, we supplement our contractual obligations with additional safeguards aimed at strengthening the rights and freedoms of data subjects beyond those granted by the SCCs, and have additional clauses in our contracts with Customers and vendors that aim to protect Customer personal data from being transferred in the event of governmental requests to surveil or otherwise gain access to such data.<\/p>\r\n<p>We also conduct Transfer Impact Assessments (TIAs) to supplement our reliance on SCCs and the Data Privacy Framework, ensuring that the legal protections of the EEA\/UK follow the data regardless of its physical location.<\/p>\r\n<p>If you have any questions concerning monday.com\u2019s privacy program, please feel free to contact our Data Protection Officer at <a href=\"mailto:dpo@monday.com\">dpo@monday.com<\/a>.<\/p>\r\n","protected":false},"excerpt":{"rendered":"<p>At monday.com, our Customers\u2019 success and the protection of their data is very important to us. With customers all over the world, we are committed to supporting our Customers\u2019 compliance with local privacy and data protection laws. As an organization offering services to, and processing the personal data of, individuals in the European Economic Area&#8230;<\/p>\n","protected":false},"author":9,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[15],"tags":[],"class_list":["post-281","post","type-post","status-publish","format-standard","hentry","category-privacy"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.2 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>monday.com &amp; the GDPR and UK GDPR - monday.com Legal Portal<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/monday.com\/l\/privacy\/monday-com-is-gdpr-ready\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"monday.com &amp; the GDPR and UK GDPR - monday.com Legal Portal\" \/>\n<meta property=\"og:description\" content=\"At monday.com, our Customers\u2019 success and the protection of their data is very important to us. With customers all over the world, we are committed to supporting our Customers\u2019 compliance with local privacy and data protection laws. As an organization offering services to, and processing the personal data of, individuals in the European Economic Area...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/monday.com\/l\/privacy\/monday-com-is-gdpr-ready\/\" \/>\n<meta property=\"og:site_name\" content=\"monday.com Legal Portal\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-11T00:00:22+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-05-11T07:42:36+00:00\" \/>\n<meta name=\"author\" content=\"Rona Richman\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Rona Richman\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/monday.com\/l\/privacy\/monday-com-is-gdpr-ready\/\",\"url\":\"https:\/\/monday.com\/l\/privacy\/monday-com-is-gdpr-ready\/\",\"name\":\"monday.com & the GDPR and UK GDPR - monday.com Legal Portal\",\"isPartOf\":{\"@id\":\"https:\/\/monday.com\/l\/ja\/#website\"},\"datePublished\":\"2026-05-11T00:00:22+00:00\",\"dateModified\":\"2026-05-11T07:42:36+00:00\",\"author\":{\"@id\":\"https:\/\/monday.com\/l\/ja\/#\/schema\/person\/111a8ce6696b6892655dd97da29c83e7\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/monday.com\/l\/privacy\/monday-com-is-gdpr-ready\/\"]}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/monday.com\/l\/ja\/#website\",\"url\":\"https:\/\/monday.com\/l\/ja\/\",\"name\":\"monday.com Legal Portal\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/monday.com\/l\/ja\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/monday.com\/l\/ja\/#\/schema\/person\/111a8ce6696b6892655dd97da29c83e7\",\"name\":\"Rona Richman\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/monday.com\/l\/ja\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/c78eed0c1578b2732e1c24dfab98fe2d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/c78eed0c1578b2732e1c24dfab98fe2d?s=96&d=mm&r=g\",\"caption\":\"Rona Richman\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"monday.com & the GDPR and UK GDPR - monday.com Legal Portal","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/monday.com\/l\/privacy\/monday-com-is-gdpr-ready\/","og_locale":"en_US","og_type":"article","og_title":"monday.com & the GDPR and UK GDPR - monday.com Legal Portal","og_description":"At monday.com, our Customers\u2019 success and the protection of their data is very important to us. With customers all over the world, we are committed to supporting our Customers\u2019 compliance with local privacy and data protection laws. As an organization offering services to, and processing the personal data of, individuals in the European Economic Area...","og_url":"https:\/\/monday.com\/l\/privacy\/monday-com-is-gdpr-ready\/","og_site_name":"monday.com Legal Portal","article_published_time":"2026-05-11T00:00:22+00:00","article_modified_time":"2026-05-11T07:42:36+00:00","author":"Rona Richman","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Rona Richman","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/monday.com\/l\/privacy\/monday-com-is-gdpr-ready\/","url":"https:\/\/monday.com\/l\/privacy\/monday-com-is-gdpr-ready\/","name":"monday.com & the GDPR and UK GDPR - monday.com Legal Portal","isPartOf":{"@id":"https:\/\/monday.com\/l\/ja\/#website"},"datePublished":"2026-05-11T00:00:22+00:00","dateModified":"2026-05-11T07:42:36+00:00","author":{"@id":"https:\/\/monday.com\/l\/ja\/#\/schema\/person\/111a8ce6696b6892655dd97da29c83e7"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/monday.com\/l\/privacy\/monday-com-is-gdpr-ready\/"]}]},{"@type":"WebSite","@id":"https:\/\/monday.com\/l\/ja\/#website","url":"https:\/\/monday.com\/l\/ja\/","name":"monday.com Legal Portal","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/monday.com\/l\/ja\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/monday.com\/l\/ja\/#\/schema\/person\/111a8ce6696b6892655dd97da29c83e7","name":"Rona Richman","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/monday.com\/l\/ja\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/c78eed0c1578b2732e1c24dfab98fe2d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/c78eed0c1578b2732e1c24dfab98fe2d?s=96&d=mm&r=g","caption":"Rona Richman"}}]}},"_links":{"self":[{"href":"https:\/\/monday.com\/l\/wp-json\/wp\/v2\/posts\/281","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/monday.com\/l\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/monday.com\/l\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/monday.com\/l\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/monday.com\/l\/wp-json\/wp\/v2\/comments?post=281"}],"version-history":[{"count":25,"href":"https:\/\/monday.com\/l\/wp-json\/wp\/v2\/posts\/281\/revisions"}],"predecessor-version":[{"id":8160,"href":"https:\/\/monday.com\/l\/wp-json\/wp\/v2\/posts\/281\/revisions\/8160"}],"wp:attachment":[{"href":"https:\/\/monday.com\/l\/wp-json\/wp\/v2\/media?parent=281"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/monday.com\/l\/wp-json\/wp\/v2\/categories?post=281"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/monday.com\/l\/wp-json\/wp\/v2\/tags?post=281"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}