GDPR check

Is Trello GDPR compliant? What universities should check

Trello is a board and card tool that students, research groups and administrative teams often adopt on their own. This page sets out what Atlassian publicly documents about Trello's hosting, the data processing addendum, subprocessors, transfers, AI and board visibility, and what that means for a university.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

Trello is an Atlassian product. Atlassian's data processing addendum applies automatically under the Atlassian Customer Agreement, incorporates the EU standard contractual clauses, and Atlassian states that its US entities, including Trello, Inc., adhere to the EU-US Data Privacy Framework. Trello is listed in the scope of Atlassian's ISO 27001 and SOC 2 programmes. Two points stand out for universities: Trello is not among the products covered by Atlassian's data residency feature, and AI features were switched on by default for many paid workspaces. The detailed answer depends on your plan and how boards are shared.

What Atlassian documents publicly

The table summarises what Atlassian states in its own documentation for Trello, read on 7 October 2026.

TopicWhat the vendor statesSource
Company and establishmentDocumented The privacy policy (effective 17 August 2026) covers Atlassian Pty Ltd, Atlassian US, Inc. and their affiliates, including Trello, Inc.Privacy Policy [1]
Where data is stored and processedNot selectable for Trello Amazon Web Services hosts Trello and other cloud products, with locations listed as the EEA (Sweden, Ireland, Germany), Switzerland, UK, Canada, Australia, Singapore, South Korea, USA, India and Japan. Data residency covers Jira, Jira Service Management, Jira Product Discovery, Confluence and Loom; Trello is not listed.Sub-processors [2], Data residency [3]
Data processing agreementDocumented The DPA (effective 17 August 2026) applies automatically when an organisation accepts the Atlassian Customer Agreement, so no separate signature is needed. After termination, Atlassian deletes customer personal data in line with its documentation, subject to legal and backup retention.DPA [4]
SubprocessorsDocumented Public list by product. Entries for Trello include AWS, Clumio for backups (EEA, UK, Australia, USA, Singapore) and Databricks (USA), described as an "infrastructure provider for machine learning development, processing and training". Subscribers get 30 days' notice of new subprocessors and may object by terminating the affected order.[2], [4]
International transfers (DPF, SCCs)Documented Atlassian states that Atlassian, Inc. and its US subsidiaries, including Trello, Inc., adhere to the EU-US DPF, the UK Extension and the Swiss-US DPF (DPF status read from the vendor's privacy policy; the official list API returned no results for any query on the check date). The DPA incorporates the EU SCCs by reference.[1], [4]
AI features and trainingPlan-dependent AI in Trello is available on Standard, Premium and Enterprise and was activated automatically unless the organisation opted out before 9 July 2024. OpenAI, AWS Bedrock and Google Vertex AI are listed for products with AI enabled. Atlassian says its LLM providers do not store or train on inputs and outputs, and that it may use de-identified, aggregated metadata to fine-tune open-source models, subject to data contribution settings.Activate AI in Trello [5], AI trust page [6], [2]
Board visibilityDocumented Boards can be private, workspace-visible or public. Public boards are visible to anyone on the internet but not indexed by search engines. Trello Enterprise adds organisation-visible boards and data restrictions that stop Enterprise content being moved out.Board visibility [7], Enterprise data restrictions [8]
Security certificationsDocumented Trello is listed among the relevant products on Atlassian's ISO/IEC 27001 (with ISO/IEC 27018 controls) and SOC 2 compliance pages.ISO 27001 [9], SOC 2 [10]

Atlassian's documentation is thorough and easy to check. The DPA, SCCs and subprocessor list are public and dated, the subprocessor list says which entries apply to Trello, and the AI trust page answers training questions directly. The Enterprise data restrictions are a useful control for institutions that want university content to stay inside managed workspaces.

What this means for a university

Validemic's analysis

Shadow use. Trello's main privacy risk at universities is how it arrives. Research groups, student societies and course teams often start free workspaces with personal accounts. Those boards sit outside any institutional contract, and staff may not know that the DPA only becomes the university's when the university is the customer.

What goes on cards. Boards used for thesis supervision, admissions or student cases can hold names, grades, health information behind extension requests and attached files. Attached presentation videos or recorded supervision meetings add students' images and voices. Treat attachments as part of the data set, and keep sensitive casework in systems designed for it.

Hosting location. Since Trello is not covered by data residency, a university cannot pin Trello data to the EU through Atlassian's admin settings. The DPF and SCCs cover transfers, but institutions with strict residency rules for research data should keep that data out of Trello.

AI defaults. Automatic activation means AI may already be on in paid workspaces. Admins should review the setting and decide deliberately. The listing of Databricks for machine learning training for Trello deserves a direct question, read alongside Atlassian's statement about data contribution settings.

Transfers. The European Commission adopted its adequacy decision for the EU-US Data Privacy Framework on 10 July 2023 [11], and Atlassian states that it participates. Keep the SCCs on file as a fallback.

DPIA likelihood. Article 35 GDPR requires a DPIA where processing is likely to result in a high risk [12]. Ordinary project boards rarely reach that threshold. Boards holding student casework or special category data, or AI processing of them, may.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask Atlassian before approving Trello

  1. Which Trello plan and Atlassian entity will our contract use, and is the DPA in force for all our workspaces?
  2. Where is Trello data for our organisation actually hosted, and is EU data residency planned for Trello?
  3. Is AI active in our workspaces, and can we disable it centrally for all of them?
  4. What does the Databricks entry for machine learning training mean for Trello content, and how do data contribution settings apply to us?
  5. Can we restrict or disable public boards across our Enterprise?
  6. How can we bring existing staff and student workspaces under institutional management?
  7. To which address should 30-day subprocessor notices be sent?

The EU AI Act angle

Atlassian describes Trello's AI as helping users write or edit content [5]. These are productivity functions, not the education uses listed as high-risk in Annex III of the AI Act. The relevant duty for most universities is AI literacy: Article 4, as amended, requires deployers to take measures to support the AI literacy of staff using AI systems [13].

If a team used Trello AI to rank applicants or assess students, that use could fall under Annex III, whose obligations apply from 2 December 2027 under the amended Article 113 [14]. Article 5(1)(f) prohibits AI that infers emotions in education institutions, except for medical or safety reasons [15]. We found nothing in Atlassian's Trello documentation describing emotion inference.

Sources

  1. Atlassian Privacy Policy (effective 17 August 2026), retrieved 7 October 2026
  2. Atlassian Sub-processors, retrieved 7 October 2026
  3. Understand data residency, Atlassian Support, retrieved 7 October 2026
  4. Atlassian Data Processing Addendum (effective 17 August 2026), retrieved 7 October 2026
  5. Activate AI for your Trello Workspace or Enterprise, Atlassian Support, retrieved 7 October 2026
  6. Atlassian AI trust page, retrieved 7 October 2026
  7. Changing the visibility of a board, Atlassian Support, retrieved 7 October 2026
  8. What are Enterprise data restrictions?, Atlassian Support, retrieved 7 October 2026
  9. Atlassian ISO/IEC 27001, retrieved 7 October 2026
  10. Atlassian SOC 2, retrieved 7 October 2026
  11. EU-US data transfers, European Commission, retrieved 7 October 2026
  12. Regulation (EU) 2016/679 (GDPR), Article 35, retrieved 7 October 2026
  13. AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026
  14. AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026
  15. AI Act Article 5: Prohibited AI practices, AI Act Service Desk, retrieved 7 October 2026

About this page

We read Atlassian's privacy policy, DPA, subprocessor list, data residency documentation, AI trust page, Trello help articles and compliance pages, and the relevant EU sources, on 7 October 2026. The official Data Privacy Framework list API returned no results on that date, so DPF status comes from Atlassian's own statement. Every statement about Trello above comes from those pages, and our own view is labelled as Validemic's analysis. This page is not legal advice and does not say whether any particular use of Trello complies with the GDPR. If you spot an error or Atlassian has updated a document, please contact us and we will correct it.

Frequently asked questions

Is Trello GDPR compliant?

No tool is GDPR compliant on its own. Atlassian's data processing addendum applies automatically when an organisation accepts the Atlassian Customer Agreement, it incorporates the EU standard contractual clauses, and Atlassian states that its US entities, including Trello, Inc., adhere to the EU-US Data Privacy Framework. Whether a university's use complies depends on its plan, settings and how staff and students use boards.

Can Trello data be kept in the EU?

Atlassian's data residency documentation lists Jira, Jira Service Management, Jira Product Discovery, Confluence and Loom as in scope. Trello is not listed. Atlassian's subprocessor list shows Amazon Web Services hosting Trello among other products, with locations in the EEA, the US and several other countries.

Is AI switched on in Trello by default?

Atlassian says AI is automatically activated in Standard and Premium Workspaces and in Trello Enterprises unless the organisation opted out before 9 July 2024, and AI is available on Standard, Premium and Enterprise plans. Admins can deactivate it at any time. Atlassian states that its third-party LLM providers do not store or train on customer inputs and outputs.

Are public Trello boards visible to anyone?

Yes. Atlassian's help page says public boards are visible to anyone on the internet, although not indexed by search engines, and anyone with the link can view them. A board containing student names or grades should never be public.

Can a university use the free version of Trello?

It can, but institutional controls are much weaker. Free workspaces have no AI features, but they also lack Enterprise controls such as data restrictions and managed accounts. Where staff process student or research data, an institutional plan under the Atlassian Customer Agreement gives the university a contract and administrative oversight.