TL;DR: Notion’s baseline encryption, authentication, and permission controls reduce some risk, but the article argues they do not prevent accidental disclosure, insecure integrations, or content-level leakage without DLP, according to Strac. The practical issue is not whether the app is usable, but whether governance can see, classify, and stop sensitive data movement before it spreads across collaboration workflows.
NHIMG editorial — based on content published by Strac: Notion Data Loss Prevention (DLP) and security analysis for sensitive data in Notion
By the numbers:
- According to Gartner's research, by 2025 approximately 90% of organisations that do not properly manage public cloud usage will unknowingly expose confidential information.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, including 46% confirmed and 26% suspected.
- 33% of organisations report their AI agents have accessed inappropriate or sensitive data beyond their intended scope.
Questions worth separating out
Q: What breaks when sensitive credentials are shared through normal collaboration tools?
A: What breaks is governance.
Q: Why do SaaS collaboration tools create governance risk for sensitive information?
A: They combine human access, external sharing, and machine-connected integrations in one workspace, which makes leakage possible through both misuse and automation.
Q: How do security teams know whether collaboration access is out of control?
A: Look for orphaned guests, stale group membership, repeated external sharing, and integrations with broad permissions that no one regularly reviews.
Practitioner guidance
- Review Notion permissions on a fixed cadence Revalidate page, workspace, guest, and group permissions after role changes, project closures, and employee offboarding so stale access does not persist.
- Treat integrations as delegated access paths Inventory connected apps, confirm the minimum scopes each app needs, and remove tokens or permissions that no longer have a business justification.
- Add content-aware DLP to collaboration workflows Scan pages, pasted text, and file attachments for PII, PHI, credentials, and other sensitive data, then apply redaction, blocking, or alerting before content spreads through sharing links or exports.
What's in the full article
Strac's full article covers the operational detail this post intentionally leaves for the source:
- Step-by-step DLP deployment guidance for Notion workspaces, including scanning, redaction, blocking, and alerting workflows.
- A practical checklist for reviewing permissions, groups, and connected apps in collaboration tools that store sensitive content.
- Examples of sensitive data types detected in Notion, including PII, PHI, credentials, API keys, and financial records.
- Compliance mapping for DLP use across PCI, HIPAA, SOC 2, GDPR, CCPA, and related obligations.
👉 Read Strac’s analysis of Notion DLP gaps and sensitive data exposure →
Notion DLP gaps: are SaaS permissions enough to protect sensitive data?
Explore further
Notion security is a governance problem disguised as a product question. The article correctly points out that encryption and authentication do not stop content from being overshared, copied, or inherited through weak integrations. In practice, the control failure is not at the storage layer but at the decision layer that defines who should see which information and for how long. Practitioners should treat collaboration tools as governed data systems, not just note-taking applications.
A question worth separating out:
Q: Who is accountable when sensitive data leaks from a collaboration workspace?
A: Accountability usually sits across security, IT, data owners, and the business teams that approved the workspace structure. The practical test is whether there is a defined owner for classification, access review, integration approval, and offboarding. Without clear ownership, DLP becomes reactive and permission drift becomes normal.
👉 Read our full editorial: Notion DLP gaps expose the limits of SaaS access controls