GDPR check

Is Mendeley GDPR compliant? What universities should check

Mendeley Reference Manager is free and widely used by students and researchers. This page sets out what Elsevier publicly documents about Mendeley accounts, syncing, sharing across Elsevier services, storage locations, transfers and contracts, and what that means for a university.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

Mendeley is part of Elsevier, which belongs to RELX. Accounts are covered by Elsevier's group privacy policy, which provides a Data Protection Officer, an EU representative in Amsterdam and a list of storage countries both inside and outside the EU. That policy also says Elsevier shares usage and preference information across Mendeley, ScienceDirect and Scopus to personalise recommendations. For transfers, Elsevier Inc. is covered by RELX's active Data Privacy Framework certification. The data processing addendum we found is aimed at institutional subscriptions, and Mendeley is not among the services Elsevier names as processing data on an institution's behalf. In practice, Mendeley is a free individual service where Elsevier is the controller. A university should decide on that basis what staff and students may put into it.

Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers reference management and a research library with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data

What Elsevier documents publicly

Everything in this table comes from Elsevier's, Mendeley's and RELX's own pages or the official Data Privacy Framework list, read on 7 October 2026. Numbers in brackets refer to the sources at the end of the page.

TopicWhat the vendor statesSource
Company and establishmentThe Mendeley terms say the services are provided by Mendeley Limited, under English law. Mendeley links to Elsevier's privacy policy, under which the Elsevier company that runs a service is its controller. Elsevier's Data Protection Officer sits at Elsevier Limited in London, and Elsevier B.V. in Amsterdam is the EU data protection representative for group businesses established outside the EEA.[1] [2]
Desktop versus cloudCloud-synced Mendeley Reference Manager is a "free web and desktop" application. The terms say the desktop software collects certain data, "even while you are offline", and uploads it to Elsevier's servers when it syncs. Free accounts include 2 GB of storage.[2] [3] [4]
Where data is storedPersonal information "may be stored and processed in your region or another country", including Australia, France, Germany, India, Ireland, the Netherlands, the Philippines, Singapore, the United Kingdom and the United States. Not found publicly A Mendeley-specific hosting location.[1]
Use of library dataUnder the terms, Mendeley processes metadata of papers in your library (such as authors, titles and keywords) for cataloguing, indexing, document recognition, personal recommendations and "anonymous aggregate statistical information" about reading patterns, including for sub-groups such as all users at your institution.[2]
Sharing across ElsevierElsevier "will share your usage activity, preferences and other information" across ScienceDirect, Scopus, Mendeley and related services. Its example: ScienceDirect may recommend content based on your Mendeley library. The policy also lists targeted advertising among the purposes of processing.[1]
Data processing agreementNot found publicly A Mendeley-specific DPA. Elsevier's DPA (last updated 28 January 2025) applies to subscription agreements that reference it. The privacy policy names Digital Commons, Interfolio, Pure, Researchfish and SciBite as services where Elsevier processes data for the institution; Mendeley is not listed.[1] [5]
SubprocessorsNot found publicly Elsevier's subprocessor pages cover twelve products or services; none is for Mendeley.[6]
International transfersDocumented The official list shows RELX as an active participant in the EU-U.S. DPF, the UK Extension and the Swiss-U.S. DPF (non-HR data), with Elsevier Inc. a covered entity. Elsevier says Elsevier Inc. has certified "certain of its services". RELX's DPF notice (14 August 2026) covers "Elsevier services provided or supported by Elsevier Inc.".[1] [7] [8]
Groups and sharingUsers can create private groups to share references, annotations and comments. Membership and contributions are visible to all group members, and shared information may remain visible after an account is closed.[1]
Retention and deletionElsevier keeps personal information "as long as necessary" for stated purposes. Users can delete content with the account deactivation tool; backups may be kept "for a reasonable period of time", and shared content may not be deletable.[1] [2]
AI featuresThe Mendeley Reference Manager page lists an "Ask AI" feature. Documentation on which models process library content, and whether content is used for training, was not found publicly (checked 7 October 2026).[3]
Security certificationsElsevier's trust centre lists ISO/IEC 27001:2022, 27017, 27018, 27701, 22301 and 42001, among others, at company level. Whether Mendeley is in scope is not stated publicly.[9]

Elsevier deserves credit for a privacy policy that names a Data Protection Officer and an EU representative, lists the legal bases it relies on, gives an explicit list of storage countries rather than "worldwide", and keeps an active DPF certification alongside its public DPA. Its trust centre also lists a wide set of certifications, including ISO/IEC 42001 for AI management.

What this means for research and teaching

Validemic's analysis

Elsevier is the controller. Mendeley is a consumer-style service: a researcher signs up with an email address and accepts Elsevier's terms. Without an institutional agreement, the university is not the controller of that data and has no Article 28 GDPR [10] contract with Elsevier for it. That is common for reference managers. It means the university's role is mainly guidance: what staff may store, and what they should tell co-authors and students.

Cross-service profiling is the distinctive point. A reading list says a lot about a researcher's work in progress. Elsevier's policy is open that Mendeley library content feeds recommendations elsewhere in Elsevier, and that usage data may support targeted advertising and promotional messages. Many researchers will be comfortable with that. Some, for example those working on commercially sensitive or security-related topics, may not be, and should be told before they adopt it.

Sensitive attachments. The Mendeley terms remind users to follow best practice when sharing data about research participants [2]. In practice, keep interview material, consent forms and any special category data under Article 9 GDPR [10] out of Mendeley libraries and groups.

Transfers. Data may be stored in several countries outside the EEA, including India, the Philippines, Singapore and the United States [1]. The DPF covers transfers to Elsevier Inc. Transfers to other non-EEA locations rely on contractual safeguards that the policy describes only briefly. For individual accounts this is Elsevier's responsibility as controller, not the university's.

DPIA likelihood. Recommending Mendeley as a reference manager is unlikely to require a full DPIA under Article 35 GDPR [10]. Mandating it for a programme, or encouraging use of its AI features on unpublished manuscripts, is a reason to run a screening first with our DPIA screening tool.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask Elsevier before recommending it

  1. Can our university contract for Mendeley so that Elsevier acts as processor for our users' libraries, and would the Elsevier DPA then apply?
  2. Where are Mendeley libraries and attached files hosted, and is an EU-only option available?
  3. Which subprocessors process Mendeley data?
  4. Which models power "Ask AI", where is that processing done, and is library content excluded from training?
  5. Can users opt out of their Mendeley library being used for recommendations on ScienceDirect and Scopus?
  6. Which institution-level aggregate statistics about our users are shared, and with whom?
  7. How long are backups of deleted Mendeley accounts kept?
  8. Are Mendeley's systems within the scope of Elsevier's ISO 27001 and 27701 certificates?

The EU AI Act angle

Reference management and "Ask AI" style features are general research aids, not one of the high-risk education uses in Annex III (admission, evaluating learning outcomes, assessing the level of education, or monitoring students during tests) [11]. Those obligations now apply from 2 December 2027 under the amended Article 113 [12]. Article 4 on AI literacy, as amended, asks deployers to take measures to support the AI literacy of their staff [13]. A university that recommends Mendeley should explain that AI answers can be wrong and must be checked against the source papers.

Sources

  1. Elsevier Privacy Policy (linked from mendeley.com/privacy), last updated 1 September 2026, retrieved 7 October 2026
  2. Mendeley Terms of Use, last updated 21 January 2022, retrieved 7 October 2026
  3. Mendeley Reference Manager features, retrieved 7 October 2026
  4. Mendeley Reference Manager guide: Introduction, retrieved 7 October 2026
  5. Elsevier Data Processing Addendum, last updated 28 January 2025, retrieved 7 October 2026
  6. Elsevier sub-processors, retrieved 7 October 2026
  7. Data Privacy Framework List, entry for RELX (covered entity Elsevier Inc.), retrieved 7 October 2026
  8. RELX Data Privacy Framework Notice (PDF), last updated 14 August 2026, retrieved 7 October 2026
  9. Elsevier Trust Center, retrieved 7 October 2026
  10. Regulation (EU) 2016/679 (GDPR), Articles 9, 28 and 35, text read from the Publications Office copy, retrieved 7 October 2026
  11. AI Act Annex III: High-risk AI systems, AI Act Service Desk, retrieved 7 October 2026
  12. AI Act Article 113: Entry into force and application, AI Act Service Desk (as amended by Regulation (EU) 2026/1744), retrieved 7 October 2026
  13. AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026

About this page

We read Elsevier's privacy policy, data processing addendum and subprocessor pages, the Mendeley terms and product pages, RELX's DPF notice and Elsevier's trust centre on 7 October 2026, and checked the official Data Privacy Framework list through its public search interface on the same day. Some pages were read through a text-rendering proxy because they load content with scripts. "Not found" means we could not find the information in public documentation; it does not mean Elsevier lacks it.

This page is not legal advice and does not say whether any particular use of Mendeley complies with the GDPR. If you work for Elsevier and see an error, please contact us and we will correct it.

Frequently asked questions

Is Mendeley GDPR compliant?

No tool is GDPR compliant on its own. Mendeley is covered by Elsevier's privacy policy, which sets out legal bases, data subject rights, a Data Protection Officer and an EU representative. Most Mendeley use is on individual accounts, where Elsevier acts as controller. Whether a university's use complies depends on how staff and students use it and what they store.

Does Mendeley share my library with Elsevier?

Mendeley is an Elsevier service. Elsevier's privacy policy says it shares usage activity, preferences and other information across ScienceDirect, Scopus, Mendeley and related services, for example so that ScienceDirect may recommend content based on your Mendeley library. The Mendeley terms also allow metadata from synced papers to be used for recommendations and anonymous aggregate statistics.

Where is Mendeley data stored?

Elsevier's privacy policy says personal information may be stored and processed in your region or in countries including Australia, France, Germany, India, Ireland, the Netherlands, the Philippines, Singapore, the United Kingdom and the United States. A Mendeley-specific hosting location was not found in public documentation (checked 7 October 2026).

Does Elsevier sign a DPA for Mendeley?

Elsevier publishes a Data Processing Addendum for subscription agreements that reference it. Its privacy policy names Digital Commons, Interfolio, Pure, Researchfish and SciBite as services where Elsevier processes uploaded data on the institution's behalf, and Mendeley is not on that list or on Elsevier's subprocessor pages. A Mendeley-specific DPA was not found publicly (checked 7 October 2026).

Is Elsevier certified under the EU-U.S. Data Privacy Framework?

On 7 October 2026 the official DPF list showed RELX as an active participant under the EU-U.S. DPF, the UK Extension and the Swiss-U.S. DPF for non-HR data, with Elsevier Inc. among the covered entities. Elsevier's privacy policy says Elsevier Inc. has certified certain of its services. The Mendeley terms say the services are provided by Mendeley Limited.