Guide

Is Notion HIPAA, SOC 2 and GDPR compliant? What it means for a law firm

Is Notion HIPAA, SOC 2 and GDPR compliant? What each label means, which plan matters, and what compliance requires of a law firm using it for client data.

By , practising lawyer17 min read

TL;DR

  • Notion states it holds a SOC 2 Type 2 report and several ISO certifications, offers a HIPAA business associate agreement on its Enterprise plan, and supports GDPR through a data processing agreement.
  • Compliance is shared: the vendor's controls do not make your own workspace, your own processes or your own legal duties compliant.
  • HIPAA applies to a law firm only if it handles protected health information as a business associate; then the plan and the signed agreement matter. GDPR applies when you process personal data in scope, and you remain the controller.
  • Collect an evidence pack (report, certificates, agreements, subprocessor list), read Notion's current Trust Center, and check your regulator's rules.
Free downloadLawyerOS — Matters, Clients, Billing & AIGet it

Notion states that it holds a SOC 2 Type 2 report and several ISO certifications, offers a HIPAA Business Associate Agreement on its Enterprise plan, and supports GDPR compliance. None of that makes a law firm's workspace compliant by itself: compliance is shared between the vendor and you. This is practical information, not legal advice. Facts below are as Notion publishes them, checked 2026-10-03; read Notion's security page and Trust Center for the current text. This guide explains what each label means, how to read the evidence behind it, when each regime reaches a law firm, and what to collect so you can show a reasoned decision.

Shared responsibility: who is responsible for what

Every cloud service divides responsibility. The vendor secures the platform; you configure your use of it, manage your users and answer to your regulator. Compliance labels describe the vendor's half.

AreaThe vendorYou (the firm)
Infrastructure and platform securitySecures data centres, encryption, platform controlsChooses a plan and region options where offered
AccessProvides authentication and permission featuresRequires MFA, designs permissions, removes leavers, reviews guests
Data handlingProcesses data under its agreement; states retention and subprocessorsDecides what data goes in; classifies it; keeps tier-4 data out
AI featuresStates training and retention termsDecides what AI may reach and do; verifies output
Incident responseDetects and responds to platform incidents; notifies customersDetects and responds to firm-side incidents; notifies clients and regulators as required
Legal dutiesIts own obligations as processor or business associateConfidentiality, competence, supervision, privacy law as controller

What each label means

LabelWhat it isWhat it is not
SOC 2 Type 2An independent audit of a vendor's controls over a period, against criteria such as security and confidentialityA certificate that your use is compliant
ISO 27001 / 27017 / 27018 / 27701Standards for security management, cloud security, cloud privacy and privacy managementApproval by your bar or regulator
HIPAA (BAA)A contract under which the vendor handles PHI as a business associateAvailable on every plan, or applicable to every firm
GDPRA data protection law; vendors provide a data processing agreement and safeguardsA guarantee that you, as controller, are compliant

SOC 2: how to read a report

A SOC 2 report is long and rewards a half-hour of attention. If you can obtain Notion's through its Trust Center, check these things:

  1. Type 1 or Type 2. Type 2 tests controls over a period and carries more weight.
  2. The period covered and how recent it is. An old report says little about today.
  3. The scope. Which systems and services are in the audit. Confirm the product and features you use are covered.
  4. The Trust Services Criteria included. Security is always covered; availability, processing integrity, confidentiality and privacy are optional. For a law firm, confidentiality and security matter most.
  5. The auditor's opinion. Unqualified means no significant issue; read any qualification closely.
  6. Exceptions. Tests where controls did not operate as expected, and the vendor's response.
  7. Complementary user entity controls. What the report assumes you do. Check you actually do it.
  8. Subservice organisations. Who the vendor relies on, such as cloud infrastructure providers, and whether they are carved out of scope.

ISO certifications in brief

ISO/IEC 27001 certifies an information security management system. 27017 and 27018 add guidance for cloud security and for protecting personal data in public clouds, and 27701 extends 27001 to privacy management. Notion states it holds all four. For you, the questions are the certificate's scope and validity dates, and which services and sites it covers. A certificate shows a management system exists; it does not tell you how your workspace is configured.

HIPAA: when it reaches a law firm

HIPAA applies to covered entities (health plans, providers, clearinghouses) and their business associates: those who create, receive, maintain or transmit protected health information on their behalf. A law firm becomes a business associate when it provides services to a covered entity (or another business associate) that involve PHI: for example, a firm advising a hospital, a health insurer or a healthcare provider on matters that require access to patient information.

SituationLikely position (take advice)
A personal injury firm holds its own client's medical records for the client's claimTypically not a business associate: the records come from the client, not on behalf of a covered entity. Confidentiality duties still apply
A firm advises a hospital system and receives patient records to do soLikely a business associate: needs a BAA with the hospital and its own safeguards
A firm acts for a health insurer in coverage disputes involving member recordsLikely a business associate
A firm uses a cloud tool to store PHI it holds as a business associateThe tool provider is a subcontractor business associate: you need a BAA with it

If you are a business associate: you need a tool whose provider will sign a BAA on the plan you use, you must apply the Security Rule's administrative, physical and technical safeguards, follow the minimum-necessary principle, and have breach procedures. Notion states that its BAA is tied to its Enterprise-grade security features, so check that you are on the right plan and have the signed agreement before any PHI goes in. See HHS's guidance on business associates.

GDPR: when it reaches a law firm

GDPR (and the UK's equivalent) governs personal data of people in scope. A law firm is typically a controller of its clients' personal data and the vendor is a processor. Your duties as controller include:

  • A lawful basis for processing, and transparency to the people concerned.
  • Data minimisation and retention limits.
  • A written data processing agreement with each processor.
  • Safeguards for transfers of data outside the EU or UK (such as adequacy decisions or standard contractual clauses).
  • Handling data subject requests (access, correction, erasure where applicable).
  • Security appropriate to the risk, and breach notification where required, which generally means telling the supervisory authority without undue delay and where feasible within 72 hours of becoming aware.
  • A data protection impact assessment where processing is high risk.

Check where Notion stores your workspace data and whether a regional option applies to your plan, which subprocessors it uses, and how the data processing agreement covers transfers. The regulation text is on EUR-Lex; the UK regulator is the Information Commissioner's Office.

Other privacy regimes you may meet

JurisdictionInstrument to check
CanadaPIPEDA and provincial private-sector privacy laws
IndiaThe Digital Personal Data Protection Act, 2023
New ZealandThe Privacy Act 2020
SingaporeThe Personal Data Protection Act
IrelandGDPR and the Data Protection Act 2018
United StatesA patchwork: sector laws such as HIPAA, state privacy and breach-notification laws

The evidence pack to collect for any vendor

DocumentWhyWhere from
SOC 2 Type 2 reportIndependent evidence of controlsVendor's trust centre, under confidentiality terms
ISO certificatesScope and validity of management systemsVendor's trust centre
Data processing agreementRequired for GDPR-type regimes; sets what the vendor may do with dataVendor's legal pages
Business associate agreementRequired if you handle PHI as a business associateVendor, on the right plan
Subprocessor listWho else touches your dataVendor's legal or trust pages
Security overview or whitepaperArchitecture and practicesVendor's security page
Status page and incident historyReliability and transparencyVendor's status page
Terms of service and privacy policyWhat you have acceptedVendor's legal pages

Keep these in a vendor register with dates, and re-collect them yearly. The vendor due diligence checklist gives the questions to ask.

Mapping the regimes to your firm

QuestionIf yesVendor evidenceYour duty
Do I handle PHI for a covered entity?HIPAA business associate rulesBAA on the right plan; SOC 2 and ISOSafeguards, minimum necessary, breach procedure
Do I process personal data of people in the EU or UK?GDPR or UK GDPRDPA; subprocessor list; transfer mechanismLawful basis, retention, subject requests, breach notice
Do I hold personal information of Canadians?PIPEDA or provincial lawPrivacy statement; data locationAccountability, consent, safeguards
Do I only hold ordinary client confidences?Professional confidentiality dutiesSOC 2 and ISO as supporting evidenceReasonable efforts; documented decision

Questions to ask Notion, or any vendor

  • Which plan does each certification and agreement apply to?
  • Which regions can my data be stored in, and is that a plan feature?
  • Who are your subprocessors, and how will you notify me of changes?
  • What is your breach notification commitment and timing?
  • How are AI features scoped, what is retained and for how long, and by plan?
  • How long are audit logs kept, and what do they record?
  • What is the process and format for a full export, and for deletion at exit?

Common mistakes

  • Treating "SOC 2 compliant" as "safe for our clients".
  • Assuming a BAA exists on the plan you use without checking.
  • Assuming GDPR is the vendor's problem; you are the controller.
  • Never reading the report's scope or period.
  • Collecting the evidence once and never refreshing it.

Also read can lawyers use Notion for client data?, is Notion AI safe for confidential legal work? and is Notion secure enough for privilege?

Frequently asked questions

Is Notion HIPAA compliant?

Notion states that businesses subject to HIPAA may process protected health information in Notion if they use its Enterprise-grade security features and sign Notion's Business Associate Agreement. So HIPAA suitability depends on the plan and the signed agreement, not on Notion in general. A law firm handling PHI as a business associate should confirm this directly with Notion before relying on it.

Is Notion SOC 2 compliant?

Notion states that it has a SOC 2 Type 2 report from an independent auditor. SOC 2 is an attestation about a vendor's controls over a period; it is not a certification that your use of the tool is compliant, and the report is available through Notion's Trust Center, usually under confidentiality terms.

Is Notion GDPR compliant?

Notion states that it supports GDPR compliance, including a data processing agreement. A law firm that is a data controller remains responsible for its own lawful basis, transfers, retention and subject-access handling, so check where data is stored, which subprocessors are used and whether the agreement covers your use.

Does a law firm need a BAA?

Only if the firm creates, receives, maintains or transmits protected health information on behalf of a HIPAA covered entity or another business associate, which makes it a business associate. A firm handling its own clients' medical records in a personal injury case is in a different position from a firm acting for a hospital or insurer, so take advice on which describes you.

What is the difference between SOC 2 Type 1 and Type 2?

A Type 1 report assesses whether controls are suitably designed at a point in time. A Type 2 report also tests whether they operated effectively over a period, which is why it is generally given more weight.

What are complementary user entity controls?

Controls that a SOC 2 report assumes you, the customer, will have in place for the vendor's controls to work, such as managing your own user access properly. Reading them tells you what the vendor expects of you.

Does GDPR apply to a law firm outside the EU?

It can, where the firm processes personal data of people in the EU or UK in the ways the regulation covers, for example offering services to them or monitoring their behaviour. Whether it applies to you is a legal question to check, and the UK has its own equivalent regime.

How long do I have to report a personal data breach under GDPR?

Where a breach must be notified to the supervisory authority, the regulation generally requires notice without undue delay and, where feasible, within 72 hours of becoming aware of it. Other regimes and contracts set their own timings, so build a response plan before you need it.

Where do I get Notion's SOC 2 report?

Notion states that compliance reports are available through its Trust Center. You may need to request access and agree to confidentiality terms. Keep the report in your vendor register and note the period it covers.