Checklist card for UK GDPR project management tool compliance evidence
Image: Work Stack Lab

Tools and providers

Part of GDPR compliant project management tools UK: which ones pass?

GDPR compliant project management tools UK: which ones pass?

How to judge project management tools against UK GDPR, the Data Protection Act 2018 and ICO guidance on transfers, residency and processor terms.

What to take away

  • No project management tool is compliant on the label alone. Asana, monday.com, ClickUp, Trello, Wrike and Notion each publish a data processing agreement and a sub-processor list, but you still need the signed version and a named region.
  • A tool passes when you hold an Article 28 contract, a current sub-processor list, a stated UK or EU region, and a UK IDTA or UK Addendum for transfers.
  • Residency covers the primary database. Backups, analytics and support sessions need separate answers.
  • ISO 27001 describes controls inside a stated scope. It never settles lawful basis, retention or transfer rules.
  • Date every check. A trust page read in March may not match the contract signed in September.

Six checks before you shortlist

Work through these in order and stop at the first unanswered question.

  1. Confirm your lawful basis and your controller role. Record why you hold staff and client data in the tool.
  2. Request the signed Article 28 processor terms, not a link to a website privacy policy.
  3. Pull the current sub-processor list and the change notice period.
  4. Pin the primary and backup regions in the contract, not on a marketing page.
  5. Name the transfer mechanismthe UK IDTA or the UK Addendum to the EU SCCs.
  6. Agree the export format, the deletion timetable and the cost of leaving.

Six checks before shortlisting

  • Name regions for storage, backups, support
  • Request DPAbreach, audit, deletion
  • Get sub-processor list and change notice
  • Ask for third-country transfer mechanism
  • Test export and deletion before buying
  • Record decision with owner and review date

The same checks sit inside the wider productivity software selection checklist, which also covers workflow fit, cost and exit terms. The ICO's guide to the UK GDPR sets out the accountability principle, which expects you to demonstrate compliance rather than assert it. The Data Protection Act 2018 carries the enforcement detail that sits behind it.

Named tools checked against the six tests

Region to confirm

Asana
EU region listed on the Enterprise tier
monday.com
EU region listed on the Enterprise plan
ClickUp
EU region listed on the Enterprise plan
Trello (Atlassian)
Regions offered on higher plans
Wrike
EU region to confirm in writing
Notion
EU region listed on the Enterprise plan

DPA

Asana
Published, signable
monday.com
Published, signable
ClickUp
Published, signable
Trello (Atlassian)
Published, signable
Wrike
Published, signable
Notion
Published, signable

Sub-processor list

Asana
Public page, change notice
monday.com
Public page, change notice
ClickUp
Public page, change notice
Trello (Atlassian)
Public page, change notice
Wrike
Public page, change notice
Notion
Public page, change notice

Transfer route

Asana
UK IDTA or UK Addendum
monday.com
UK IDTA or UK Addendum
ClickUp
UK IDTA or UK Addendum
Trello (Atlassian)
UK IDTA or UK Addendum
Wrike
UK IDTA or UK Addendum
Notion
UK IDTA or UK Addendum

Verdict

Asana
Pass once the signed DPA names your region
monday.com
Pass once support staff regions are confirmed
ClickUp
Pass once the backup region is confirmed
Trello (Atlassian)
Pass once you know which region your plan buys
Wrike
Check first: get the region into the contract
Notion
Pass once the backup region is confirmed

Tier names, regions and plan inclusions change, so treat this as a starting point. Confirm each line in writing and record the date you checked it. For a side-by-side price and residency view of two of these, see Asana vs ClickUp for UK remote teams.

Residency, backups and support access

UK residency usually means the primary database sits in a UK region. It says nothing about backups, analytics, support sessions or the vendor's own CRM.

Regions move without the product page changing. Put the region in the contract and ask how you will be told if it shifts.

Support access is the gap most buyers miss. An engineer abroad viewing your workspace is processing data, even when nothing is stored there. Ask for the remote access policy and the regions support staff work from.

Certification, liability and breach duties

ISO 27001 certifies a management system for information security within a stated scope and audit cycle. It says nothing about your lawful basis, retention periods or transfer rules.

The NCSC's cloud security guidance is a better frame for reading a supplier's security page, because it separates what the provider secures from what you still own.

Your business stays accountable to the ICO as controller. The processor carries its own duties, and the contract should set out indemnities and audit rights.

Keep a record of processing for each tool, with retention limits on old project data and a named owner inside your firm.

A breach travels in two steps. The processor alerts you, then you have 72 hours to notify the ICO where the risk is high.

Flow of breach notification duties from processor to controller to ICO (GDPR compliant project management tools UK: which ones pass?)
Breach duties split in two: the processor alerts you, then you have 72 hours to notify the ICO. Image: Work Stack Lab

Self-hosting puts the processing on infrastructure you control, which is the strongest residency position available. A self-hosted open source guide sets out the patching and maintenance cost that comes with it. This article is general guidance, not legal advice, so take a qualified adviser's view on your own processing.

Common questions

Do we need a processor contract with every tool?

Yes, where the vendor handles personal data on your instructions. Article 28 of the UK GDPR requires written terms.

Is ISO 27001 enough on its own?

No. It covers security management, not lawful basis, retention or transfer rules.

Can we use a tool hosted in the United States?

Yes, with a transfer mechanism such as the UK IDTA or the UK Addendum, plus a transfer risk assessment.

Who is liable if a supplier mishandles our data?

Your business remains accountable to the ICO as controller. The processor has separate duties, and the contract should set out indemnities.

More in Tools and providers