Guide
Is Notion HIPAA, SOC 2 and GDPR compliant? What it means for a law firm
Is Notion HIPAA, SOC 2 and GDPR compliant? What each label means, which plan matters, and what compliance requires of a law firm using it for client data.
By Raghav R Handa, practising lawyer17 min read
TL;DR
- Notion states it holds a SOC 2 Type 2 report and several ISO certifications, offers a HIPAA business associate agreement on its Enterprise plan, and supports GDPR through a data processing agreement.
- Compliance is shared: the vendor's controls do not make your own workspace, your own processes or your own legal duties compliant.
- HIPAA applies to a law firm only if it handles protected health information as a business associate; then the plan and the signed agreement matter. GDPR applies when you process personal data in scope, and you remain the controller.
- Collect an evidence pack (report, certificates, agreements, subprocessor list), read Notion's current Trust Center, and check your regulator's rules.
Notion states that it holds a SOC 2 Type 2 report and several ISO certifications, offers a HIPAA Business Associate Agreement on its Enterprise plan, and supports GDPR compliance. None of that makes a law firm's workspace compliant by itself: compliance is shared between the vendor and you. This is practical information, not legal advice. Facts below are as Notion publishes them, checked 2026-10-03; read Notion's security page and Trust Center for the current text. This guide explains what each label means, how to read the evidence behind it, when each regime reaches a law firm, and what to collect so you can show a reasoned decision.
Shared responsibility: who is responsible for what
Every cloud service divides responsibility. The vendor secures the platform; you configure your use of it, manage your users and answer to your regulator. Compliance labels describe the vendor's half.
| Area | The vendor | You (the firm) |
|---|---|---|
| Infrastructure and platform security | Secures data centres, encryption, platform controls | Chooses a plan and region options where offered |
| Access | Provides authentication and permission features | Requires MFA, designs permissions, removes leavers, reviews guests |
| Data handling | Processes data under its agreement; states retention and subprocessors | Decides what data goes in; classifies it; keeps tier-4 data out |
| AI features | States training and retention terms | Decides what AI may reach and do; verifies output |
| Incident response | Detects and responds to platform incidents; notifies customers | Detects and responds to firm-side incidents; notifies clients and regulators as required |
| Legal duties | Its own obligations as processor or business associate | Confidentiality, competence, supervision, privacy law as controller |
What each label means
| Label | What it is | What it is not |
|---|---|---|
| SOC 2 Type 2 | An independent audit of a vendor's controls over a period, against criteria such as security and confidentiality | A certificate that your use is compliant |
| ISO 27001 / 27017 / 27018 / 27701 | Standards for security management, cloud security, cloud privacy and privacy management | Approval by your bar or regulator |
| HIPAA (BAA) | A contract under which the vendor handles PHI as a business associate | Available on every plan, or applicable to every firm |
| GDPR | A data protection law; vendors provide a data processing agreement and safeguards | A guarantee that you, as controller, are compliant |
SOC 2: how to read a report
A SOC 2 report is long and rewards a half-hour of attention. If you can obtain Notion's through its Trust Center, check these things:
- Type 1 or Type 2. Type 2 tests controls over a period and carries more weight.
- The period covered and how recent it is. An old report says little about today.
- The scope. Which systems and services are in the audit. Confirm the product and features you use are covered.
- The Trust Services Criteria included. Security is always covered; availability, processing integrity, confidentiality and privacy are optional. For a law firm, confidentiality and security matter most.
- The auditor's opinion. Unqualified means no significant issue; read any qualification closely.
- Exceptions. Tests where controls did not operate as expected, and the vendor's response.
- Complementary user entity controls. What the report assumes you do. Check you actually do it.
- Subservice organisations. Who the vendor relies on, such as cloud infrastructure providers, and whether they are carved out of scope.
ISO certifications in brief
ISO/IEC 27001 certifies an information security management system. 27017 and 27018 add guidance for cloud security and for protecting personal data in public clouds, and 27701 extends 27001 to privacy management. Notion states it holds all four. For you, the questions are the certificate's scope and validity dates, and which services and sites it covers. A certificate shows a management system exists; it does not tell you how your workspace is configured.
HIPAA: when it reaches a law firm
HIPAA applies to covered entities (health plans, providers, clearinghouses) and their business associates: those who create, receive, maintain or transmit protected health information on their behalf. A law firm becomes a business associate when it provides services to a covered entity (or another business associate) that involve PHI: for example, a firm advising a hospital, a health insurer or a healthcare provider on matters that require access to patient information.
| Situation | Likely position (take advice) |
|---|---|
| A personal injury firm holds its own client's medical records for the client's claim | Typically not a business associate: the records come from the client, not on behalf of a covered entity. Confidentiality duties still apply |
| A firm advises a hospital system and receives patient records to do so | Likely a business associate: needs a BAA with the hospital and its own safeguards |
| A firm acts for a health insurer in coverage disputes involving member records | Likely a business associate |
| A firm uses a cloud tool to store PHI it holds as a business associate | The tool provider is a subcontractor business associate: you need a BAA with it |
If you are a business associate: you need a tool whose provider will sign a BAA on the plan you use, you must apply the Security Rule's administrative, physical and technical safeguards, follow the minimum-necessary principle, and have breach procedures. Notion states that its BAA is tied to its Enterprise-grade security features, so check that you are on the right plan and have the signed agreement before any PHI goes in. See HHS's guidance on business associates.
GDPR: when it reaches a law firm
GDPR (and the UK's equivalent) governs personal data of people in scope. A law firm is typically a controller of its clients' personal data and the vendor is a processor. Your duties as controller include:
- A lawful basis for processing, and transparency to the people concerned.
- Data minimisation and retention limits.
- A written data processing agreement with each processor.
- Safeguards for transfers of data outside the EU or UK (such as adequacy decisions or standard contractual clauses).
- Handling data subject requests (access, correction, erasure where applicable).
- Security appropriate to the risk, and breach notification where required, which generally means telling the supervisory authority without undue delay and where feasible within 72 hours of becoming aware.
- A data protection impact assessment where processing is high risk.
Check where Notion stores your workspace data and whether a regional option applies to your plan, which subprocessors it uses, and how the data processing agreement covers transfers. The regulation text is on EUR-Lex; the UK regulator is the Information Commissioner's Office.
Other privacy regimes you may meet
| Jurisdiction | Instrument to check |
|---|---|
| Canada | PIPEDA and provincial private-sector privacy laws |
| India | The Digital Personal Data Protection Act, 2023 |
| New Zealand | The Privacy Act 2020 |
| Singapore | The Personal Data Protection Act |
| Ireland | GDPR and the Data Protection Act 2018 |
| United States | A patchwork: sector laws such as HIPAA, state privacy and breach-notification laws |
The evidence pack to collect for any vendor
| Document | Why | Where from |
|---|---|---|
| SOC 2 Type 2 report | Independent evidence of controls | Vendor's trust centre, under confidentiality terms |
| ISO certificates | Scope and validity of management systems | Vendor's trust centre |
| Data processing agreement | Required for GDPR-type regimes; sets what the vendor may do with data | Vendor's legal pages |
| Business associate agreement | Required if you handle PHI as a business associate | Vendor, on the right plan |
| Subprocessor list | Who else touches your data | Vendor's legal or trust pages |
| Security overview or whitepaper | Architecture and practices | Vendor's security page |
| Status page and incident history | Reliability and transparency | Vendor's status page |
| Terms of service and privacy policy | What you have accepted | Vendor's legal pages |
Keep these in a vendor register with dates, and re-collect them yearly. The vendor due diligence checklist gives the questions to ask.
Mapping the regimes to your firm
| Question | If yes | Vendor evidence | Your duty |
|---|---|---|---|
| Do I handle PHI for a covered entity? | HIPAA business associate rules | BAA on the right plan; SOC 2 and ISO | Safeguards, minimum necessary, breach procedure |
| Do I process personal data of people in the EU or UK? | GDPR or UK GDPR | DPA; subprocessor list; transfer mechanism | Lawful basis, retention, subject requests, breach notice |
| Do I hold personal information of Canadians? | PIPEDA or provincial law | Privacy statement; data location | Accountability, consent, safeguards |
| Do I only hold ordinary client confidences? | Professional confidentiality duties | SOC 2 and ISO as supporting evidence | Reasonable efforts; documented decision |
Questions to ask Notion, or any vendor
- Which plan does each certification and agreement apply to?
- Which regions can my data be stored in, and is that a plan feature?
- Who are your subprocessors, and how will you notify me of changes?
- What is your breach notification commitment and timing?
- How are AI features scoped, what is retained and for how long, and by plan?
- How long are audit logs kept, and what do they record?
- What is the process and format for a full export, and for deletion at exit?
Common mistakes
- Treating "SOC 2 compliant" as "safe for our clients".
- Assuming a BAA exists on the plan you use without checking.
- Assuming GDPR is the vendor's problem; you are the controller.
- Never reading the report's scope or period.
- Collecting the evidence once and never refreshing it.
Also read can lawyers use Notion for client data?, is Notion AI safe for confidential legal work? and is Notion secure enough for privilege?
Frequently asked questions
Is Notion HIPAA compliant?
Notion states that businesses subject to HIPAA may process protected health information in Notion if they use its Enterprise-grade security features and sign Notion's Business Associate Agreement. So HIPAA suitability depends on the plan and the signed agreement, not on Notion in general. A law firm handling PHI as a business associate should confirm this directly with Notion before relying on it.
Is Notion SOC 2 compliant?
Notion states that it has a SOC 2 Type 2 report from an independent auditor. SOC 2 is an attestation about a vendor's controls over a period; it is not a certification that your use of the tool is compliant, and the report is available through Notion's Trust Center, usually under confidentiality terms.
Is Notion GDPR compliant?
Notion states that it supports GDPR compliance, including a data processing agreement. A law firm that is a data controller remains responsible for its own lawful basis, transfers, retention and subject-access handling, so check where data is stored, which subprocessors are used and whether the agreement covers your use.
Does a law firm need a BAA?
Only if the firm creates, receives, maintains or transmits protected health information on behalf of a HIPAA covered entity or another business associate, which makes it a business associate. A firm handling its own clients' medical records in a personal injury case is in a different position from a firm acting for a hospital or insurer, so take advice on which describes you.
What is the difference between SOC 2 Type 1 and Type 2?
A Type 1 report assesses whether controls are suitably designed at a point in time. A Type 2 report also tests whether they operated effectively over a period, which is why it is generally given more weight.
What are complementary user entity controls?
Controls that a SOC 2 report assumes you, the customer, will have in place for the vendor's controls to work, such as managing your own user access properly. Reading them tells you what the vendor expects of you.
Does GDPR apply to a law firm outside the EU?
It can, where the firm processes personal data of people in the EU or UK in the ways the regulation covers, for example offering services to them or monitoring their behaviour. Whether it applies to you is a legal question to check, and the UK has its own equivalent regime.
How long do I have to report a personal data breach under GDPR?
Where a breach must be notified to the supervisory authority, the regulation generally requires notice without undue delay and, where feasible, within 72 hours of becoming aware of it. Other regimes and contracts set their own timings, so build a response plan before you need it.
Where do I get Notion's SOC 2 report?
Notion states that compliance reports are available through its Trust Center. You may need to request access and agree to confidentiality terms. Keep the report in your vendor register and note the period it covers.
Related guides
- Can lawyers use Notion for client data? Confidentiality, ethics and a safe setup
- Is Notion secure enough for attorney-client privilege? How privilege is lost, and how to avoid it
- Do lawyers need bar-approved software? What regulators actually require
- The ABA Model Rules applied to cloud tools and AI: what each rule asks of a lawyer