Skip to content

Notion data sharing & exposure security checks

External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.

On Notion, Black Cat runs 7 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Notion connector needs.

Checks (7)

severity: high Publicly Shared Page fix difficulty: easy #

Disable public web sharing for the flagged Notion page

  1. Open the flagged Notion page
  2. Click the Share button in the top-right corner
  3. Toggle off Share to web
  4. Confirm the change in the dialog if prompted
  5. Review other pages in the same workspace for similar public sharing settings

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: high Stale Public Page fix difficulty: easy #

Update or disable public sharing for stale publicly accessible pages

  1. Open the flagged Notion page
  2. Review the content to determine if it is still relevant and should remain public
  3. If the content is outdated or should not be public, click the Share button
  4. Toggle off Share to web
  5. If the page is still needed publicly, update its content and last-edited date
  6. Consider setting a reminder to review public pages periodically

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: high Publicly Shared Database fix difficulty: easy #

Disable public web sharing for the flagged Notion database

  1. Open the flagged Notion database
  2. Click the Share button in the top-right corner
  3. Toggle off Share to web
  4. Confirm the change if prompted
  5. Review all linked views and inline databases on the same page to ensure they are also not publicly shared

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: high Root Level Public Page fix difficulty: easy #

Move publicly shared pages out of the workspace root or disable public sharing

  1. Open the flagged Notion page at the workspace root
  2. Evaluate whether the page should remain publicly shared
  3. If not needed publicly, click Share and toggle off Share to web
  4. If it must remain public, move it into a dedicated Public section for better organization
  5. Ensure no sensitive internal content is exposed through the public page

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: high Stale Publicly Shared Database fix difficulty: easy #

Update or disable public sharing for databases not edited in over 90 days

  1. Open the flagged Notion database
  2. Review the content to determine if it should remain publicly shared
  3. If outdated, click Share and toggle off Share to web
  4. If still needed publicly, update the database content to keep it current
  5. Consider setting a reminder to review publicly shared databases periodically

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: high Root Level Public Database fix difficulty: easy #

Move publicly shared databases out of the workspace root or disable public sharing

  1. Open the flagged Notion database at the workspace root
  2. Evaluate whether the database should remain publicly shared
  3. If not needed publicly, click Share and toggle off Share to web
  4. If it must remain public, move it into a dedicated Public section for better organization
  5. Ensure no sensitive structured data is exposed through the public database

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: medium Inline Public Database fix difficulty: easy #

Disable public sharing for inline databases that may expose structured data

  1. Open the parent page containing the flagged inline database
  2. Click the Share button on the parent page
  3. Toggle off Share to web if the inline database should not be publicly accessible
  4. If only the parent page should be public, consider moving sensitive data to a separate private database
  5. Review all inline databases on the page for similar exposure

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

More Notion checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial