Shared responsibilities model
This shared responsibilities model ensures that Notion and you work together to create a safe and effective workspace experience 🤝
Notion is a single space where you can think, write and plan. As an all-in-one workspace that lets you build your own tools for doing your best work, you can trust Notion with both your professional and personal information.
A shared responsibilities model (SRM) is a framework that outlines how responsibilities are divided between a service provider (e.g., Notion) and you. It clearly sets out which security and operational tasks are handled by each party.
This document outlines the responsibilities that Notion and you share in protecting and maintaining the security of Notion, its systems, user accounts, and workspaces.
The Notion SRM provides clarity for both Notion and you about which party is responsible for each type of security. This clarity lets Notion focus on areas where we can best support the security of our systems, while showing that you are best placed to secure your account. Overall, this enhances security and efficiency in protecting Notion’s systems and accounts.
Additionally, the SRM promotes transparency in how Notion services are delivered and who is responsible for maintaining access to different Notion systems. This also ensures that both Notion and you comply with applicable local, regional, national and international regulations.
In short: Notion is responsible for maintaining, upgrading and protecting the systems that underpin Notion, while you are responsible for protecting your account access credentials, managing workspace access for members & guests, and adhering to the Content & Use policy and other relevant Terms.
Notion’s responsibilities:
Notion is responsible for maintaining and upgrading its systems – including its servers, software and corporate hardware. It is also tasked with protecting access to its core systems and ensuring the security of its data, as well as implementing and managing network security across its systems.
Your responsibilities:
You are responsible for protecting your login credentials and restricting access to Notion workspaces to known and trusted collaborators. You should also adhere to Notion’s policies regarding data storage and management – for example, only storing appropriate materials in Notion and keeping your data secure within the product. Additionally, you must comply with Notion’s Terms and other relevant policies at all times.
Access & authorisation management
You can set granular permissions for shared content as well as for general account access. You should regularly review and update access permissions across your workspaces. If you access Notion using a password, make sure you use strong, unique passwords to protect your account and avoid reusing credentials on other services. Also, update your login details in line with your internal policies and whenever external login credential breaches come to light.
Authentication controls
We expect that you don’t share your login information with others. Whenever possible, we strongly encourage you to set up two-factor authentication to further secure your account. You should maintain an individual account rather than a shared one. You can also manage team member access to give additional collaborators entry to relevant pages and workspaces, allowing you to fine-tune permissions to ensure each member has the right access.
Access monitoring and review
You should also keep an eye on member activity and act appropriately if you spot any suspicious behaviour – for example, by revoking unauthorised or outdated user sessions (available via Enterprise plan). When a team member leaves your team or workspace, you should revoke that member’s access and any associated accounts.
Responsible use:
You should use Notion's systems responsibly and within their intended capacity. This means avoiding actions that could overload or strain system resources. Do not try to circumvent or test system limitations or security measures. If you become aware of any security vulnerabilities or notice system misuse, report these incidents to Notion promptly.
Data management:
You are responsible for proper data management – this means regularly backing up important information, following established data retention policies and ensuring that sensitive information is deleted promptly and securely when no longer needed. You should submit complete and accurate Account Data to Notion, and if you find any errors in your data, correct them as soon as possible.
By following this shared responsibilities model, both Notion and you help create a secure, efficient and productive workspace.
