Atlassian
Last Reviewed: 03 Jun 2026
At a Glance
Atlassian's DPA covers the required processor obligations in respect of customer provided personal data. Atlassian's DPA explicitly permits Atlassian to "de-identify" and aggregate customer data to improve its own products — Atlassian is not acting solely as a processor. We recommend this contract is manually reviewed to ensure the data use terms are acceptable. NOTE: Currently published DPA takes effect on 17th August 2026. Prior to that date an archived version at https://www.atlassian.com/legal/archives/data-processing-addendum/data-processing-addendum-20260416#scope-and-term will still apply. This does not include the provisions around de-identified data.
Company & Product Details
HQ
Australia, United States
Products
Atlassian Cloud services
Product description
Cloud collaboration and work management services including Jira, Confluence and related support / advisory services.
What data is being processed?
Customer personal data contained in Atlassian Cloud products and support data, including account data, collaboration content, tickets, knowledge-base content and related usage / log data.
Document Details
Date of DPA
17 Aug 2026
Additional date information
Effective starting 17 August 2026, as stated on the DPA page.
What jurisdictions are covered?
The DPA explicitly covers: EU GDPR and UK GDPR (Schedule 2, clause 1); Swiss Data Protection Law (Schedule 2, clause 1.3); US State Privacy Laws including CCPA (Schedule 2, clause 2); South Korea Privacy Law (Schedule 2, clause 3); and Brazilian Data Protection Law (Schedule 2, clause 4).
Is the DPA incorporated into service or customer agreements?
Link
Location & Transfers
Where is data held or processed?
Not explicitly stated Customer personal data may be processed in Atlassian and sub-processor locations used to provide cloud services; customer data residency / product settings may also affect locations.
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
Atlassian commits to appropriate technical and organisational measures, security incident processes and regular third-party / internal audits; further security detail is linked from the DPA.
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
Without undue delay and, where feasible, no later than 72 hours after awareness of a Security Incident.
What happens to the data on termination?
Following expiration or termination of the Agreement, Atlassian must delete all Customer Personal Data in accordance with the Documentation. Atlassian may retain Customer Personal Data (i) as required by Applicable Data Protection Law or (ii) in accordance with its standard backup or record retention policies; in either case Atlassian must maintain confidentiality and not further process the retained data except as required by law (clause 6.2).