
Tools and providers
Part of GDPR compliant project management tools UK: which ones pass?
GDPR compliant project management tools UK: which ones pass?
How to judge project management tools against UK GDPR, the Data Protection Act 2018 and ICO guidance on transfers, residency and processor terms.
What to take away
- No project management tool is compliant on the label alone. Asana, monday.com, ClickUp, Trello, Wrike and Notion each publish a data processing agreement and a sub-processor list, but you still need the signed version and a named region.
- A tool passes when you hold an Article 28 contract, a current sub-processor list, a stated UK or EU region, and a UK IDTA or UK Addendum for transfers.
- Residency covers the primary database. Backups, analytics and support sessions need separate answers.
- ISO 27001 describes controls inside a stated scope. It never settles lawful basis, retention or transfer rules.
- Date every check. A trust page read in March may not match the contract signed in September.
Six checks before you shortlist
Work through these in order and stop at the first unanswered question.
- Confirm your lawful basis and your controller role. Record why you hold staff and client data in the tool.
- Request the signed Article 28 processor terms, not a link to a website privacy policy.
- Pull the current sub-processor list and the change notice period.
- Pin the primary and backup regions in the contract, not on a marketing page.
- Name the transfer mechanismthe UK IDTA or the UK Addendum to the EU SCCs.
- Agree the export format, the deletion timetable and the cost of leaving.
Six checks before shortlisting
- Name regions for storage, backups, support
- Request DPAbreach, audit, deletion
- Get sub-processor list and change notice
- Ask for third-country transfer mechanism
- Test export and deletion before buying
- Record decision with owner and review date
The same checks sit inside the wider productivity software selection checklist, which also covers workflow fit, cost and exit terms. The ICO's guide to the UK GDPR sets out the accountability principle, which expects you to demonstrate compliance rather than assert it. The Data Protection Act 2018 carries the enforcement detail that sits behind it.
Named tools checked against the six tests
Region to confirm
- Asana
- EU region listed on the Enterprise tier
- monday.com
- EU region listed on the Enterprise plan
- ClickUp
- EU region listed on the Enterprise plan
- Trello (Atlassian)
- Regions offered on higher plans
- Wrike
- EU region to confirm in writing
- Notion
- EU region listed on the Enterprise plan
DPA
- Asana
- Published, signable
- monday.com
- Published, signable
- ClickUp
- Published, signable
- Trello (Atlassian)
- Published, signable
- Wrike
- Published, signable
- Notion
- Published, signable
Sub-processor list
- Asana
- Public page, change notice
- monday.com
- Public page, change notice
- ClickUp
- Public page, change notice
- Trello (Atlassian)
- Public page, change notice
- Wrike
- Public page, change notice
- Notion
- Public page, change notice
Transfer route
- Asana
- UK IDTA or UK Addendum
- monday.com
- UK IDTA or UK Addendum
- ClickUp
- UK IDTA or UK Addendum
- Trello (Atlassian)
- UK IDTA or UK Addendum
- Wrike
- UK IDTA or UK Addendum
- Notion
- UK IDTA or UK Addendum
Verdict
- Asana
- Pass once the signed DPA names your region
- monday.com
- Pass once support staff regions are confirmed
- ClickUp
- Pass once the backup region is confirmed
- Trello (Atlassian)
- Pass once you know which region your plan buys
- Wrike
- Check first: get the region into the contract
- Notion
- Pass once the backup region is confirmed
Tier names, regions and plan inclusions change, so treat this as a starting point. Confirm each line in writing and record the date you checked it. For a side-by-side price and residency view of two of these, see Asana vs ClickUp for UK remote teams.
Residency, backups and support access
UK residency usually means the primary database sits in a UK region. It says nothing about backups, analytics, support sessions or the vendor's own CRM.
Regions move without the product page changing. Put the region in the contract and ask how you will be told if it shifts.
Support access is the gap most buyers miss. An engineer abroad viewing your workspace is processing data, even when nothing is stored there. Ask for the remote access policy and the regions support staff work from.
Certification, liability and breach duties
ISO 27001 certifies a management system for information security within a stated scope and audit cycle. It says nothing about your lawful basis, retention periods or transfer rules.
The NCSC's cloud security guidance is a better frame for reading a supplier's security page, because it separates what the provider secures from what you still own.
Your business stays accountable to the ICO as controller. The processor carries its own duties, and the contract should set out indemnities and audit rights.
Keep a record of processing for each tool, with retention limits on old project data and a named owner inside your firm.
A breach travels in two steps. The processor alerts you, then you have 72 hours to notify the ICO where the risk is high.
Self-hosting puts the processing on infrastructure you control, which is the strongest residency position available. A self-hosted open source guide sets out the patching and maintenance cost that comes with it. This article is general guidance, not legal advice, so take a qualified adviser's view on your own processing.
Common questions
Do we need a processor contract with every tool?
Yes, where the vendor handles personal data on your instructions. Article 28 of the UK GDPR requires written terms.
Is ISO 27001 enough on its own?
No. It covers security management, not lawful basis, retention or transfer rules.
Can we use a tool hosted in the United States?
Yes, with a transfer mechanism such as the UK IDTA or the UK Addendum, plus a transfer risk assessment.
Who is liable if a supplier mishandles our data?
Your business remains accountable to the ICO as controller. The processor has separate duties, and the contract should set out indemnities.



