monday Workform GDPR concerns
Dear Users,
I was deeply alarmed by an issue I encountered this week with Monday.com’s Workforms.
I rely heavily on Workforms to gather consolidated — and often highly sensitive — information such as expense reports, benefit requests, and employee performance reviews (both mid-year and end-of-year).
To my surprise, despite applying restrictions using the “People” column on my end-of-year review form, I discovered a serious flaw: when someone clicks Form → Results, they are able to see all responses and comments from every respondent — including other teams’ entries containing confidential data.
In my case, employees completed their mid-year review, and everything appeared correctly restricted on the board. However, once “Results” is opened, any user can view responses from anyone else, including sensitive information such as salary requests and personal details.
This raises an obvious question: How can this be GDPR-compliant? Allowing employees to access private, identifiable data from colleagues without authorization appears to be a major data protection breach.
I consulted two independent Monday consultants, both of whom confirmed this behavior is highly irregular and likely a serious violation of data security best practices. Yet, when I reached out to Monday.com support, I was told this is “normal” behavior, cannot be disabled, and that the only option is to use a workaround.