ModelCharter

Is ClickUp Brain GDPR compliant?

Yes

ClickUp · Productivity

Yes. ClickUp offers a Data Processing Agreement (DPA) for ClickUp Brain, the baseline GDPR control when a vendor processes personal data on your behalf.

What we checked

This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.

Data Processing Agreement
Confirmed
ClickUp publishes a DPA. A DPA is necessary but does not replace your own lawful-basis, DPIA and transfer assessment.
EU data residency
Confirmed
ClickUp documents an EU data-residency option; confirm it is enabled for the account and workload in scope.
Default data training
No by default
ClickUp's AI partners are prohibited from using your data to train their models, and ClickUp gains no right to use Customer Data for training; zero third-party data retention.
Business-tier training
No by default
Enterprise (HIPAA BAA, EU and APAC residency and full compliance-report access are Enterprise-gated) is the business tier recorded for this profile.
Practical risk: ClickUp Brain does not train on customer data and enforces zero data retention with its LLM partners, backed by SOC 2 Type II and ISO 27001. HIPAA BAA and EU and APAC data residency are available but Enterprise-tier only.

How to make a decision

Check the precise account tier, written contract and intended data before approving ClickUp Brain. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.

More on ClickUp Brain

See the full ClickUp Brain risk profile, with every data-handling fact and its source, or browse all rated AI tools.