GDPR check

Is EndNote GDPR compliant? What universities should check

EndNote is one of the most widely licensed reference managers in European universities. This page sets out what Clarivate publicly documents about the desktop library, online sync, its data processing addendum, transfers, certifications and the AI Research Assistant, and what that means for an institution.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

EndNote is made by Clarivate. The desktop application keeps the library on the user's computer, and Sync copies references and attachments to EndNote online. Clarivate's EndNote product terms bring its data processing addendum into play for desktop use and for sync, and that addendum incorporates the EU Standard Contractual Clauses. Clarivate lists ISO 27001 for EndNote and says its AI features do not use customer data to train language models. The same terms forbid uploading special category data. We did not find where EndNote online is hosted, and Clarivate does not appear on the Data Privacy Framework list. For a university, the main questions are the hosting location, the AI subprocessors and keeping sensitive files out of synced libraries.

Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers reference management and a research library with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data

What Clarivate documents publicly

Everything in this table comes from Clarivate's and EndNote's own pages or the official Data Privacy Framework list, read on 7 October 2026. Numbers in brackets refer to the sources at the end of the page.

TopicWhat the vendor statesSource
Company and establishmentEndNote is a Clarivate product. The privacy notice gives Clarivate Analytics (UK) Limited in London and Clarivate Analytics (US) LLC in Ann Arbor as contact entities. The data processing addendum is signed by "the Clarivate entity that is a party to the Agreement".[1] [2]
Desktop versus cloudConfiguration-dependent EndNote desktop holds the library locally. Sync is "always initiated from EndNote" and copies references, groups and file attachments to EndNote Web/online. A sync library can be shared with up to 1,000 other EndNote 2025 users.[4]
Where synced data is storedNot found publicly The hosting location of EndNote online. The privacy notice says data "may be transferred" to countries including the United States.[1]
Data processing agreementDocumented The EndNote product terms say the Clarivate DPA applies "when syncing data with EndNote Online or EndNote Web, and when inputting data into EndNote Desktop". DPA version 3.1 (September 2026): client is controller, Clarivate is processor, except for billing, account management and internal reporting, where Clarivate acts as an independent controller. Breach notice within 48 hours. Deletion or return of client personal data if the client asks within 30 days of termination, with backups isolated until deleted under Clarivate's policies.[2] [3]
SubprocessorsPartly documented Clients have general authorisation; the list is offered through Clarivate's privacy centre (via a sign-up form) or on request to data.privacy@clarivate.com. Clients who subscribe to change notices can object on reasonable grounds within 10 days. We could not view the list's contents publicly.[2] [5]
International transfersDocumented The DPA incorporates the 2021 SCCs (Modules One and Two) and the UK Addendum. The privacy notice also names an intra-group agreement with SCCs. Searches of the official DPF list for "Clarivate" returned no participant.[1] [2] [9]
Sensitive dataDocumented The product terms say users "must not upload any sensitive or special category data" to EndNote. The DPA also excludes special category data unless listed in its appendix.[2] [3]
AI features and trainingEndNote 2025 adds Research Assistant: Key Takeaways, chat with a PDF, translation and summaries. Clarivate's AI policy says it "does not use your data to directly or indirectly train LLMs", and that inputs are not stored by the model beyond the session. The LLM providers are not named in the pages we read.[6] [7]
Security certificationsDocumented Clarivate's product compliance list shows ISO 27001 for EndNote, plus PCI-DSS SAQ-A for EndNote online purchases and TX-RAMP Level 1. Clarivate notes that not all products are individually certified.[8]

Clarivate deserves credit for several things. The product terms state plainly that the DPA covers both desktop and synced use, which removes a common ambiguity. The DPA itself is public, current and uses the 2021 SCCs, with a 48-hour breach notification commitment that is shorter than many vendors offer. The ban on special category data is explicit rather than buried. And the product-level certification list makes it easy to see what applies to EndNote rather than to Clarivate in general.

What this means for research and teaching

Validemic's analysis

Desktop-only use keeps most data at home. A library that is never synced stays on the user's machine, subject to the university's own endpoint and backup rules. The DPA's EndNote entry still covers implementation and technical support as well as hosting [2], so support sessions are worth a policy line.

Sync makes EndNote a cloud service. Once a user syncs or shares a library, references, notes and PDFs leave the institution. The DPA gives a clear processor framework, but the hosting region is not public. Ask Clarivate where EndNote online data is stored, because that decides whether the SCCs are actually used and whether a transfer impact assessment is needed under Chapter V GDPR [10].

The special category ban is a practical rule, not a formality. Researchers often attach working files to references. If those include interview extracts, health information or other Article 9 data [10], they breach the product terms as well as the university's likely rules. Training material for researchers should say this directly.

Licence type matters. The product terms distinguish site licences from individual purchases [3]. With a site licence, the university is the contracting party and can rely on the DPA as controller. With personally bought copies, the researcher is the customer and the university has no contract with Clarivate.

DPIA likelihood. Reference management alone rarely meets the Article 35 threshold [10]. Turning on AI chat over full-text PDFs for a whole institution, with unnamed model providers, is a reason to run at least a screening. Try our DPIA screening tool.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask Clarivate before approving it

  1. Where is EndNote online and EndNote Web data hosted, and can our institution's data be kept in the EU?
  2. Which subprocessors process EndNote data, including for Research Assistant, and in which countries?
  3. Which LLM providers power Research Assistant, and what do your contracts with them say about retention and training?
  4. Can our administrators switch Research Assistant off for all users on our site licence?
  5. Does the DPA version 3.1 apply automatically to our existing site licence, or do we need to sign it?
  6. What data does Clarivate process as an independent controller about our users, and for how long?
  7. How are shared sync libraries handled when a member leaves the university or deletes their account?
  8. Can we receive the ISO 27001 certificate and statement of applicability that covers EndNote?

The EU AI Act angle

EndNote's AI features summarise, translate and answer questions about documents the user chooses. These are productivity features, not one of the education uses listed as high-risk in Annex III, which covers admission, evaluating learning outcomes, assessing the level of education and monitoring students during tests [11]. Those Annex III obligations now apply from 2 December 2027 under the amended Article 113 [12]. The duty that applies today is AI literacy: Article 4, as amended, asks deployers to take measures to support the AI literacy of staff using AI systems [13]. For EndNote, that means explaining that AI summaries can be wrong and should be checked against the paper, which Clarivate's own AI policy also says [7].

Sources

  1. Clarivate Privacy Notice (as published on endnote.com), last updated 7 April 2024, retrieved 7 October 2026
  2. Clarivate Data Processing Addendum, EU SCCs and UK Addendum, version 3.1, September 2026, retrieved 7 October 2026
  3. EndNote Product Terms (Clarivate Product/Service Terms), retrieved 7 October 2026
  4. Overview of the Sync Process, EndNote 2025 documentation, retrieved 7 October 2026
  5. Clarivate Privacy Center: your rights and choices (subprocessor list sign-up), retrieved 7 October 2026
  6. Introducing EndNote Research Assistant, EndNote blog, 23 September 2025, retrieved 7 October 2026
  7. Clarivate Academia & Government: Use of Generative AI, retrieved 7 October 2026
  8. Clarivate Security Compliance, product compliance list, retrieved 7 October 2026
  9. Data Privacy Framework List, search for "Clarivate", retrieved 7 October 2026
  10. Regulation (EU) 2016/679 (GDPR), Articles 9 and 35 and Chapter V, text read from the Publications Office copy, retrieved 7 October 2026
  11. AI Act Annex III: High-risk AI systems, AI Act Service Desk, retrieved 7 October 2026
  12. AI Act Article 113: Entry into force and application, AI Act Service Desk (as amended by Regulation (EU) 2026/1744), retrieved 7 October 2026
  13. AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026

About this page

We read Clarivate's privacy notice, data processing addendum, EndNote product terms, EndNote sync documentation, AI policy, privacy centre and security compliance page on 7 October 2026, and searched the official Data Privacy Framework list through its public search interface on the same day. Some endnote.com pages block automated requests, so we read them through a text-rendering proxy and checked them against Clarivate's own documents. "Not found" means we could not find the information in public documentation; it does not mean Clarivate lacks it. A negotiated site licence may say more than the public pages.

This page is not legal advice and does not say whether any particular use of EndNote complies with the GDPR. If you work for Clarivate and see an error, please contact us and we will correct it.

Frequently asked questions

Is EndNote GDPR compliant?

No tool is GDPR compliant on its own. Clarivate's EndNote product terms say EndNote processes personal information under Clarivate's data processing addendum, including when users sync with EndNote online, and the addendum incorporates the EU Standard Contractual Clauses. Whether a university's use complies depends on its licence, configuration and what users put into their libraries.

Does EndNote store my library in the cloud?

EndNote desktop keeps a library on the user's computer. If the user runs Sync, references, groups and file attachments are copied to EndNote online and kept in step with the desktop library. The hosting location for EndNote online was not found in Clarivate's public documentation (checked 7 October 2026).

Does EndNote have a DPA?

Yes. The EndNote product terms state that Clarivate's Data Processing Addendum applies, including when syncing with EndNote online or EndNote Web. The current addendum (version 3.1, September 2026) names the client as controller and Clarivate as processor, incorporates the 2021 SCCs and the UK Addendum, and commits to breach notification within 48 hours.

Does EndNote's AI use my documents for training?

Clarivate's Academic AI policy states that Clarivate does not use your data to directly or indirectly train large language models, and that inputs are not stored by the LLM beyond the immediate session. Clarivate does not name the LLM providers in the pages we read.

Can researchers store interview data in EndNote?

The EndNote product terms say users must not upload sensitive or special category data to EndNote, and that anyone who does so is responsible for complying with the GDPR. Keep participant data and confidential attachments in approved university storage instead.