Atlassian's GDPR Commitment
Dedication to your data privacy
We are wholly invested in our customers' success and the protection of data. One way that we deliver on this promise is by helping Atlassian customers and users understand, and where applicable, comply with the General Data Protection Regulation (GDPR).
The GDPR is designed to give EU citizens more control over their data and seeks to unify a number of existing privacy and security laws under one comprehensive law within the EU. The GDPR not only applies to organizations located within the EU, but it also applies to all companies processing and holding the personal data of data subjects residing in the European Union, regardless of the company’s location (the so-called extraterritoriality principle).
The following sections outline our approach and investment in GDPR compliance in service of our customers and individual data subjects.
International data transfers
As a company with a global customer base and operations, Atlassian must be able to transfer and access data around the world. We understand and respect the rules for international transfers of personal data outside of the European Economic Area, UK, as well as Switzerland, and offer customers a robust international data transfer framework as a part of our commitment under Atlassian's Data Processing Addendum (DPA). The DPA ensures that our customers can lawfully transfer personal data to Atlassian Cloud products outside of the EEA by relying on the Standard Contractual Clauses.
Whenever we share your data with Atlassian sub-processors, we remain accountable to you for how it is used by any of these organizations. We require all sub-processors to undergo a thorough diligence process and enter into contracts that ensure our customers' personal data receives adequate protection and safeguards. We will continue to stay abreast of these legal requirements and any others issued by European data protection authorities as they arise. In the meantime, please note that Atlassian:
-  offers information relevant to the data transfers in our Data Transfer Impact Assessment 
-  allows customers to pin in-scope product content at rest to a location. Planned expansions to our data residency program are highlighted in Atlassian’s cloud roadmap 
- encrypts data in transit and at rest
- publishes an annual Transparency Report with information about government requests for users' data as well as government requests to remove content or suspend accounts
- provides additional information about our policies and procedures for responding to requests for user data in our Guidelines for Law Enforcement
To learn more about our Data Processing Addendum and the Standard Contractual Clauses, see our Privacy FAQs.
For more information on how we process personal data as a controller under the GDPR, see our Privacy Policy.
Data location and portability
Data hosting location determinations are based on reducing latency and achieving optimal performance for you and your users. We optimize where to host customer data based on how it is accessed around the world (rather than upon request). Though we don't guarantee that your data will be hosted in a specific location by default, you can use data residency to pin in-scope product content at rest to a location. Planned expansions to our data residency program are highlighted in Atlassian’s cloud roadmap.
We’re also ready to facilitate your customers' requests to export their data, should you host your customer data on Atlassian products. Atlassian provides robust data portability and data management tools for exporting product and user data. For more information on Atlassian Cloud data export, see our import and export documentation.
Individual privacy rights and consent
Data subject rights
Our tools help customers meet obligations under the GDPR right to be forgotten (or right to erasure) clause by making it easy to delete personal data from Atlassian Cloud products.
- Atlassian Organization Admins can facilitate the account deletion of their managed users from controls in their admin portal
- Unmanaged end users (an account that is not managed by an organization) may also request that their personal data be deleted by initiating an account deletion request from their Atlassian account profile page
- People who have provided their personal data or had their personal data provided to Atlassian, but do not have Atlassian accounts, may also initiate a request for deletion
Similar tools are available for access requests.
- Atlassian Organization Admins can facilitate access of their managed users' data from Atlassian support
- Unmanaged end users may also request that their personal data be accessed by initiating a data access request from Atlassian support
- People who have provided their personal data or had their personal data provided to Atlassian, but do not have Atlassian accounts, may also initiate a request for access
Both deletion and access requests can be serviced via telephone by leaving a message at 1 (800) 804-5281.
Choice and consent
We value choice and transparency around how we collect, use, and share information, and provide optionality within different product or account settings. Our Privacy Policy summarizes those choices, how to exercise them, and any relevant limitations.
For more information around end user data rights, see “Manage your personal data privacy”.
Please note for our EU end users, we surface consents for cookies and marketing messages to provide clarity and control at points of collection. Our internal processes centralize consents to ensure we’re consistently honoring your choices across our product suite.
Other commitments
Below are several other GDPR initiatives that have been implemented within our Cloud:
- We have ensured Atlassian staff that access and process Atlassian customer personal data have been trained in handling that data and are bound to maintain the confidentiality and security of that data
- We provide a list of our subprocessors on our Subprocessors page, and offer an RSS feed subscription so you can stay up-to-date on any changes
- We have committed to carrying out data impact assessments and consulting with EU regulators where appropriate
- We will assist with notifying regulators of security breaches and promptly communicating any breaches to customers and users
-  We are committed to honor our obligations as data importers under the EU Standard Model Clauses