Insights · monday.com

Is monday.com GDPR compliant? How your data is stored in the EU

Where monday.com stores your data, how Enterprise differs from Standard and Pro, and what you are responsible for yourselves under GDPR.

Isak Blomkvist 8 min read

Where does our data end up, and are we GDPR compliant? It is one of the most common questions we get from IT and finance leaders before they choose monday.com. The platform has an EU data center, a data processing agreement and certifications such as ISO 27001 and SOC 2 Type II, and it can be used in compliance with GDPR. But whether your data stays in the EU depends on two things many people are not aware of: when and where the account was created, and which plan you are on. This guide covers where data is stored, what monday.com is responsible for, what you are responsible for yourselves and what you should check in your account.

AES-256encryption of data at rest
TLS 1.3encryption of data in transit, TLS 1.2 at minimum
3data regions: US, EU and APAC

According to monday.com's Trust Center and support article on data residency, October 2026.

Short answer

monday.com stores customer data in the EU for accounts created in the EU region. But only Enterprise accounts keep all customer data exclusively in the EU, including at monday.com's subprocessors. For Standard and Pro, data may also be processed in the US, protected by the EU Standard Contractual Clauses. The region is set when the account is created and cannot be changed afterwards. So check where your account is located, and remember that GDPR is also about how you use the system yourselves: who has access, what data you store and for how long.

Who is responsible for what under GDPR?

When you use monday.com, responsibility under GDPR is split between you and monday.com:

  • You are the data controller for what goes into your account: customers, contacts, employees, tickets and files. You decide what data is stored, why, who can see it and how long it is kept.
  • monday.com is the data processor for the same data. They are responsible for keeping the platform secure and for processing the data only according to your instructions.
  • monday.com is itself the data controller for a smaller part: account details, billing and technical usage data.

This means the platform can be as secure as it gets, but responsibility for what you store and who has access still lies with you.

Where is your data stored?

monday.com has three data regions, all in Amazon Web Services data centers: US, EU and APAC. Each account has a primary region where all customer data is stored, meaning everything you put in: items, files, images and updates.

How the region is set
  1. The account is created
  2. Router · Where is the first user?EUThe EU regionOtherUS or APAC
  3. The region cannot be changed afterwards

The region is set automatically based on where the first user is located when the account is opened. For users in the EU, Africa and the Middle East, it becomes the EU region.

Two things are important to know:

  1. Older accounts may be in the US. The EU region is available for Enterprise, and for Standard and Pro if the account was created on or after January 23, 2023. An older account may therefore be in the US, even if the company has always been based in Sweden.
  2. The region cannot be moved. If the account is in the wrong region, the only way forward is a new account in the right region and a migration of the data there. We describe how that works step by step in Moving monday.com from the US to the EU.

You can see which region your account is in under Administration → General → Profile, where it shows where your data is stored.

Enterprise or Standard and Pro: the difference for GDPR

For companies with strict requirements on where data may be processed, the plan is decisive.

AreaEnterpriseStandard and Pro
Customer data in the EU regionEnterpriseYesStandard and ProYes, for accounts created from January 23, 2023
Processing at subprocessorsEnterpriseEU onlyStandard and ProMay also take place in the US, with Standard Contractual Clauses
Login with SSOEnterpriseYes, for example via Microsoft Entra ID or OktaStandard and ProNo
Closed workspacesEnterpriseYesStandard and ProNo

How monday.com protects your data

monday.com publishes its security work openly in its Trust Center. In short:

  • Encryption: data at rest is encrypted with AES-256 or stronger, and data in transit with TLS 1.3, with TLS 1.2 as the minimum.
  • Certifications: ISO 27001 for information security, ISO 27018 for protection of personal data in the cloud and SOC 2 Type II, with annual external audits.
  • Security testing: annual penetration tests of both the application and the infrastructure, carried out by independent auditors.
  • Backups: continuous and encrypted, with a secondary site in another region for disaster recovery.
  • Agreements: a Data Processing Addendum (DPA) and the EU Standard Contractual Clauses for transfers outside the EU. monday.com's US company is also certified under the EU–US Data Privacy Framework.
  • Data protection officer: monday.com has an appointed data protection officer.

More on how monday.com handles GDPR can be found on their GDPR page and in the support article on where data is stored.

Your part: how to set up monday.com securely

The platform's security is only half the job. The other half is how you set up and use the system:

  1. Check the region. Look up where the account is located, and whether that is right for the data you store.
  2. Control login. With Enterprise, login can go through your existing account in, for example, Microsoft Entra ID or Okta. Access then follows along when someone joins or leaves.
  3. Grant the least access needed. Divide the work into workspaces and boards based on who needs to see what. Sensitive areas such as HR, finance and management should sit in closed workspaces where the plan allows it.
  4. Keep guests in order. External partners and customers should only have access to the boards they are invited to, not the rest of the account.
  5. Do not store more than you need. Avoid sensitive personal data such as national ID numbers and health information unless it is necessary, and decide how long data should be kept.
  6. Review apps and integrations. Apps and connections to other systems may process data outside your region. Check where they store data before you install them.
  7. Document the processing. monday.com's data processing agreement is part of their terms of service and applies automatically. What you need to do yourselves is add monday.com to your record of processing activities: what personal data is stored there, why and for how long.

This guide is an overview of how monday.com works, not legal advice. For questions about your own processing of personal data, check with your data protection officer or a lawyer.

Straviont helps you set up monday.com the right way

We are an official monday.com partner and certified CRM specialists with monday.com. We help companies set up monday.com with the right structure, permissions and guest management from the start, and we help when an account needs to be moved to the EU region.

Frequently asked questions

Is monday.com GDPR compliant?

Yes, monday.com can be used in compliance with GDPR. monday.com has a data processing agreement, uses the EU Standard Contractual Clauses, has a data region in the EU and is certified under ISO 27001, ISO 27018 and SOC 2 Type II, among others. As a customer, you are still the data controller for what data you store and who has access to it.

Where is data stored in monday.com?

Customer data is stored in the account's primary data region: US, EU or APAC, all in Amazon Web Services data centers. The region is determined by where the first user is located when the account is created.

Does all data stay in the EU if the account is in the EU region?

Only for Enterprise. Enterprise accounts in the EU region keep all customer data exclusively in the EU, including at subprocessors. For Standard and Pro in the EU region, customer data may also be processed in the US, protected by the EU Standard Contractual Clauses.

Can a monday.com account be moved from the US to the EU?

Not directly. The region cannot be changed once the account has started storing data. To switch region, a new account is created in the EU region and the data is moved there. That is something we at Straviont help with. The full migration is described in Moving monday.com from the US to the EU.

Does monday.com have a data processing agreement?

Yes. monday.com has a Data Processing Addendum that is part of the terms of service and applies automatically to all customers, with the EU Standard Contractual Clauses for transfers outside the EU.

Next steps

Start by checking where your account is located under Administration, and review who has access to what. If you want help reviewing the account, or moving it to the EU region, you are welcome to book a free review.

Ready to challenge
the way you work today?

Tell us briefly about your situation and a senior advisor will get back to you with a time to talk. Free of charge, no commitment.

We reply within one business day. Your details are only used for this. Prefer email? contact@straviont.com