Overview
Notion is a collaborative workspace platform used for documentation, project management, wikis, and knowledge bases. When organizations embed public Notion pages into their websites — via iframes or direct embeds — Notion's rendering engine loads and executes scripts on the visitor's browser to display the page content dynamically. This means visitors interact with Notion's infrastructure even though they're on your site.
Embedded Notion content is fetched from Notion's servers in real time, so each page load involves network requests to Notion domains. The platform is widely used by startups and teams as a lightweight CMS alternative, embedding changelogs, help docs, or product roadmaps directly into their marketing or product pages.
What This Script Does
When a Notion embed loads on your website, the following occurs:
- Content rendering: Notion's JavaScript fetches page blocks, databases, and media from Notion's API and renders them in the visitor's browser.
- Page view tracking: Notion records page view events for its own analytics, giving page owners insight into how many times embedded content is accessed.
- Asset loading: Images, files, and other media hosted on Notion's CDN are fetched directly from Notion's servers, exposing visitor IP addresses and browser metadata to Notion infrastructure.
- Dynamic content: Notion pages can include linked databases, toggles, and interactive elements that generate additional requests as visitors interact with the content.
Notion does not drop traditional tracking cookies on visitors, but the network requests themselves transmit standard browser information including IP address, user agent, and referrer to Notion's servers.
Consent & Compliance
From a GDPR and ePrivacy perspective, Notion embeds create a data-sharing scenario. Visitor IP addresses and browser metadata are transmitted to Notion (a third-party processor) with every page load. Under the GDPR, IP addresses are considered personal data.
However, Notion embeds typically serve a functional purpose — displaying documentation or content that is integral to the site experience. If the embedded content is genuinely necessary for the page to function as intended, a legitimate interest basis may apply. If the embed is supplementary (e.g., a changelog that could be hosted directly), the case for requiring consent is stronger.
Notion's own privacy policy governs how they handle data from embedded page views. Site operators should review this and consider whether a Data Processing Agreement is appropriate.
Should You Block This Without Consent?
Conditional. If Notion embeds serve core functional content on your site (like documentation or help articles), they can reasonably load without consent under legitimate interest. If they're used for supplementary content or if you want to minimize third-party data exposure, gating them behind consent is the safer approach.
Is Notion GDPR compliant?
Notion typically loads functional and analytics trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Notion can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Notion, not on Notion itself.
Consent Categories
Also Known As
Industries
Tracked Domains (2)
notion.soFunctionalnotion.so is a functional domain operated by Notion, used to run site features like chat, video, embeds, and preferences.
notion.comFunctionalnotion.com is a functional domain operated by Notion, used to run site features like chat, video, embeds, and preferences.
Frequently Asked Questions
Related Vendors
Manage consent for Notion
ConsentStack automatically detects and manages Notion trackers so your site stays compliant with global privacy regulations.