FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Other
  4. Asana

Asana

OtherWebsite

Related services

AccuWeather

AccuWeather is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AccuWeather supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AccuWeather ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
A

Acuity Scheduling

Acuity Scheduling is a user preference and personalization service that helps websites deliver customized experiences based on individual visitor settings and choices. It manages preferences for content display, communication channels, and interaction styles. Acuity Scheduling integrates with website platforms to remember and apply user choices consistently across sessions. With privacy-compliant preference storage, Acuity Scheduling enhances satisfaction by ensuring tailored browsing experiences for every visitor.

Preferences

Affirm

Affirm is a versatile web technology that supports digital platforms with specialized functionality and enhanced capabilities. It provides robust tools and services that integrate with modern websites and applications seamlessly. Affirm is designed to improve operational efficiency, user experience, and digital performance. Trusted by developers and businesses alike, Affirm offers reliable solutions that scale with organizational needs and evolving web standards.

Other

Algolia

Algolia is a versatile web technology that supports digital platforms with specialized functionality and enhanced capabilities. It provides robust tools and services that integrate with modern websites and applications seamlessly. Algolia is designed to improve operational efficiency, user experience, and digital performance. Trusted by developers and businesses alike, Algolia offers reliable solutions that scale with organizational needs and evolving web standards.

Other
A

AppDynamics

AppDynamics is an analytics and measurement platform providing deep insights into digital ecosystem performance. It tracks user interactions, measures campaign effectiveness, and identifies optimization opportunities across web and mobile. AppDynamics offers customizable dashboards, automated alerts, and data export capabilities. By transforming raw data into actionable intelligence, AppDynamics empowers organizations to optimize strategy and maximize return on investment.

Analytics
A

Apple App Store

Apple App Store is a comprehensive e-commerce platform that provides businesses with all the tools needed to build, manage, and grow an online store. From product catalog management and secure payment processing to inventory tracking and order fulfillment, Apple App Store delivers a complete commerce solution. It features responsive storefront themes, SEO-optimized product pages, and powerful marketing tools to help merchants increase visibility and drive sales across channels.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Asana do?

Asana is a cloud based project management and work collaboration platform developed by Asana Inc. (US). It enables teams to manage tasks, projects, portfolios, goals, and workflows. The platform processes personal data including user profiles, task assignments, comments, and file attachments, and transfers data internationally via US based infrastructure, requiring GDPR compliance through Asana's Data Processing Addendum.

What Asana actually does

Asana is a work management SaaS operated by Asana Inc. since 2008. It provides task management, projects, portfolios, goals, workflows, forms, time tracking, and the Asana Intelligence generative features powered by OpenAI and Anthropic. EU customers typically interact with Asana via the asana.com domain and through API integrations with Slack, Microsoft Teams, Google Drive and others. The Enterprise plan offers SAML SSO, SCIM provisioning, audit logs and the optional EU data residency add on.

Cookies and storage in the Asana app and on embeds

Inside the Asana web application, authenticated users have the cookies asana_session_id (session), asana_user_id (identifier), __cf_bm (Cloudflare bot management) and several CSRF cookies. On the marketing site asana.com, Asana loads Google Analytics 4, LinkedIn Insight Tag, Marketo and Vidyard, which set their own cookies and require consent. When a publisher embeds a public Asana Form on its own site, the page is in fact an iframe to asana.com that drops the same cookies before any consent and therefore requires the visitor opt in under ePrivacy art. 5(3).

Lawful basis and Data Processing Agreement

For internal use the lawful basis is the employment relationship and the legitimate interest of the controller in running its work management environment. For external guests invited to projects, performance of a contract or pre contract applies. The Asana Data Processing Addendum is incorporated by reference into the Master Subscription Agreement and includes the EU Standard Contractual Clauses (module 3 processor to sub processor). Customers using Asana Intelligence must accept an additional addendum covering generative AI use.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

International data transfers and EU residency

Asana Inc. is certified under the EU US Data Privacy Framework since 4 October 2023. By default workspace data is hosted on AWS US East (Virginia) and US West (Oregon). The EU data residency add on, available on the Enterprise plan since 2023, pins workspace content to AWS Frankfurt. Operational telemetry, abuse detection, billing and Asana Intelligence inference continue to be processed in the United States, even with the EU add on. The Asana Trust Center publishes the active list of sub processors (AWS, Google, OpenAI, Anthropic, Twilio, Salesforce).

Practical compliance checklist

Sign the Asana DPA and activate the EU data residency add on for high risk projects. Disable Asana Intelligence on workspaces handling special categories of data (HR, legal, health). Restrict guest access through SAML SSO and conditional access. Document Asana and its sub processors in your records of processing (GDPR art. 30) and in the privacy notice. Run a DPIA when Asana Intelligence is used to evaluate employees performance or to take decisions producing legal effects under GDPR art. 22. Refresh the transfer impact assessment annually.

Alternatives

Direct alternatives include Monday.com (Israel), ClickUp (US), Notion (US), Trello (Atlassian, Australia and US), Wrike (US, Citrix), Jira (Atlassian). EU sovereign alternatives are Stackfield (Germany), Tem.io (France), Plane (India and EU hosting) and the open source Vikunja, OpenProject and Taiga.

GDPR consent category

Other

Websites using Asana must obtain user consent under GDPR regulations.

Legal basisFor internal use by employees and seats: legitimate interest of the controller in operating its work management environment (GDPR art. 6(1)(f)) and performance of the employment contract. For external guests invited to projects: performance of a contract or consent depending on the use case. Public Asana forms embedded on a website that drop cookies on the visitor browser require consent under ePrivacy art. 5(3).
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive 2002/58/EC, EU US Data Privacy Framework, EDPB recommendations 01/2020, AI Act (when Asana Intelligence is used for decisions affecting workers), TTDSG (Germany), LOPDGDD (Spain), LIL (France)

DPIA considerations

A DPIA is recommended for Asana deployments when used across an organisation to manage projects involving personal data. Key areas to assess include: scope of personal data stored in tasks, comments, attachments, and forms (which may contain employee, customer, or partner data), international data transfers to US based AWS infrastructure, third party integrations connected via the Asana API (Slack, Google Drive, Microsoft Teams, Salesforce), data retention policies and export capabilities, access controls and permission settings across workspaces, and the use of Asana Forms on public facing pages that may collect personal data from external users.

Sample consent text

Our team uses Asana, a work management platform operated by Asana Inc. in the United States, to plan and track our work. We have signed the Asana Master Subscription Agreement including the Data Processing Addendum. If we are on the Enterprise plan we activate the EU data residency add on so that the workspace content stays in Frankfurt; otherwise data is processed in the United States under the EU US Data Privacy Framework and the EU Standard Contractual Clauses. If you contact us through a shared Asana form or project, your data is processed under those safeguards. You can request access, rectification or erasure at any time.

Technical details

Tracking methodsaas_collaboration_application_account_based
Server locationAsana operates primarily from the United States (AWS US East Virginia and US West Oregon). The Asana Enterprise EU data residency add on (launched 2023) keeps customer data at rest inside AWS Frankfurt. Some operational metadata and AI features (Asana Intelligence) continue to be processed in the US.
Data transferred outside the EUAsana Inc. is established in San Francisco, California. Customer data is processed in the United States by default. Enterprise customers can opt for the EU data residency add on, but operational telemetry, support tickets and Asana Intelligence inference remain in the US. Transfers rely on the EU US Data Privacy Framework certification of Asana Inc. (active since 4 October 2023) and on the EU Standard Contractual Clauses appended to the Asana Master Subscription Agreement.

Third-party domains contacted

app.asana.comapi.asana.comform.asana.comcdn.asana.comassets.asana.bizapi.amplitude.com

Cookies placed

NameTypeDurationPurpose
asana_sessionauthenticationSessionMaintains the authenticated user session for the Asana web application.
xsrf_tokensecuritySessionCSRF protection token preventing cross site request forgery attacks on form submissions and API calls.
asana_feature_flagsfunctionality1 yearStores feature flag assignments for A/B testing and gradual feature rollouts.
amp_device_idanalytics1 yearAmplitude analytics device identifier tracking product usage patterns across sessions.
ajs_anonymous_idanalytics1 yearSegment analytics anonymous identifier used for tracking user journeys before and after authentication.
asana_prefsfunctionality1 yearStores user interface preferences including sidebar state, view mode, and notification settings.

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does Asana set?

Asana sets session authentication cookies, CSRF protection tokens, feature flag cookies for product testing, and analytics cookies. Third party services integrated into Asana's platform, such as Amplitude and Segment, may also set analytics cookies. When Asana Forms are embedded on external sites, cookies from app.asana.com and related analytics domains may be deposited on visitor browsers. Asana also uses local storage for caching application state and user preferences.

Is consent required for Asana under GDPR?

For internal team use within an organisation, consent is generally not required as contract performance or legitimate interest applies. However, when Asana Forms are embedded on public facing websites, consent is recommended before collecting personal data from external users, especially if cookies are set. Cookie consent under the ePrivacy Directive is required for non essential analytics cookies on any page embedding Asana widgets.

What is the legal basis for processing data through Asana?

Internal project management use relies on contract performance (Art. 6(1)(b)) or legitimate interest (Art. 6(1)(f)). Security logging and fraud prevention are covered by legitimate interest. Public facing Asana Forms collecting external user data should rely on consent (Art. 6(1)(a)). Third party integration data flows should be assessed individually. Each processing activity should be documented in your Records of Processing Activities.

Does Asana transfer data to the United States?

Yes. Asana Inc. is a US based company and data is primarily hosted on AWS infrastructure in the United States. International transfers are covered by Asana's DPA incorporating SCCs and Asana's certification under the EU US Data Privacy Framework. Enterprise customers can enable EU data residency, keeping data at rest in AWS Frankfurt data centers. Some processing operations and support activities may still involve US systems.

Is a DPIA required for Asana?

A DPIA is recommended when Asana is used to manage workflows containing personal data, such as HR processes, recruitment pipelines, customer relationship management, or any project involving sensitive personal data. The assessment should cover data categories stored in tasks and comments, international transfers to US infrastructure, connected third party integrations, and access control configurations across workspaces.

How do I implement GDPR compliance for Asana?

Execute Asana's DPA from the Trust page. Enable EU data residency if available. Configure workspace permissions and access controls. Establish data retention policies and regularly clean completed projects. Audit third party integrations for GDPR compliance. Deploy cookie consent for embedded Asana Forms. Train team members on data minimisation in task descriptions. Include Asana in your DPIA if it processes sensitive data.

Are there privacy friendly alternatives to Asana?

Alternatives include OpenProject (open source, self hosted project management), Taiga (open source agile platform), Nextcloud Deck (self hosted Kanban boards), Vikunja (open source task management), and Cryptpad with Kanban (encrypted collaboration). For EU hosted SaaS alternatives, consider Hive or Teamwork. Each alternative should be evaluated for GDPR compliance, data processing agreements, and feature parity with your requirements.

How should I update my cookie policy for Asana?

If you embed Asana Forms on your website, document the cookies set by app.asana.com and any analytics domains. Specify whether each cookie is essential or requires consent. Describe the personal data collected through embedded forms. Reference Asana's role as data processor, the DPA with SCCs, and the EU US Data Privacy Framework certification. Provide instructions for managing consent and inform users about their data subject rights regarding form submissions.