Atlassian

Last Reviewed: 03 Jun 2026

Data Use Review

At a Glance

Atlassian's DPA covers the required processor obligations in respect of customer provided personal data. Atlassian's DPA explicitly permits Atlassian to "de-identify" and aggregate customer data to improve its own products — Atlassian is not acting solely as a processor. We recommend this contract is manually reviewed to ensure the data use terms are acceptable. NOTE: Currently published DPA takes effect on 17th August 2026. Prior to that date an archived version at https://www.atlassian.com/legal/archives/data-processing-addendum/data-processing-addendum-20260416#scope-and-term will still apply. This does not include the provisions around de-identified data.

Company & Product Details

HQ

Australia, United States

Products

Atlassian Cloud services

Product description

Cloud collaboration and work management services including Jira, Confluence and related support / advisory services.

What data is being processed?

Customer personal data contained in Atlassian Cloud products and support data, including account data, collaboration content, tickets, knowledge-base content and related usage / log data.

Document Details

Date of DPA

17 Aug 2026

Additional date information

Effective starting 17 August 2026, as stated on the DPA page.

What jurisdictions are covered?

The DPA explicitly covers: EU GDPR and UK GDPR (Schedule 2, clause 1); Swiss Data Protection Law (Schedule 2, clause 1.3); US State Privacy Laws including CCPA (Schedule 2, clause 2); South Korea Privacy Law (Schedule 2, clause 3); and Brazilian Data Protection Law (Schedule 2, clause 4).

Is the DPA incorporated into service or customer agreements?

Yes

Location & Transfers

Where is data held or processed?

Not explicitly stated Customer personal data may be processed in Atlassian and sub-processor locations used to provide cloud services; customer data residency / product settings may also affect locations.

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
The DPA incorporates EU SCCs (Modules 2 and 3) by reference for EU transfers, governed by Irish law (Schedule 2, clause 1.2); Swiss modifications to the EU SCCs for Swiss transfers, governed by Swiss law (Schedule 2, clause 1.3); UK International Data Transfer Addendum for UK transfers (Schedule 2, clause 1.4); Atlassian participates in and certifies compliance with the EU-U.S. Data Privacy Framework, UK Extension and Swiss-U.S. Data Privacy Framework (Schedule 2, clause 1.5); and Brazilian Transfer Clauses (ANPD Resolution CD/No. 19, August 23, 2024) for Brazilian transfers (Schedule 2, clause 4).

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

Atlassian commits to appropriate technical and organisational measures, security incident processes and regular third-party / internal audits; further security detail is linked from the DPA.

Non Processor Data Use

Does the company process data solely as a processor?

No
Schedule 1, Section 6.2 permits Atlassian to "de-identify" and aggregate Customer Data and use it to improve its products "generally" (i.e. not solely for the customer). This section defines “De-identified and Aggregated Data” as "Customer Data that cannot reasonably be used to single out, infer information about, or otherwise be linked to an individual data subject." but it's unclear whether this could include data that would constitute pseudonymised personal data under the GDPR.

Subprocessing

General authorization

General
General authorisation to use sub-processors is granted by entering the DPA; Atlassian must bind sub-processors by written agreement to the same data protection standard as the DPA and remains liable for their failures (clause 4.1); Atlassian publishes an up-to-date sub-processor list with a subscription mechanism and gives at least 30 days' notice before any new sub-processor processes Customer Personal Data (clause 4.2); Customer may object during the notice period, but its sole and exclusive remedy is termination of the affected Order for convenience (clause 4.3).

Do all the DPA terms flow down to sub-processors?

Yes
Atlassian must enter a written agreement with each sub-processor imposing data protection terms to the standard required by Applicable Data Protection Law and the same standard as the DPA, and remains liable to Customer if a sub-processor fails to fulfil its data protection obligations (clause 4.1).

Is data only processed on the instruction of the controller?

Yes
The DPA, Agreement, orders and product configurations / settings constitute documented instructions.

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
Atlassian must provide reasonable and timely assistance with data subject rights and related obligations.

Does the contract include staff confidentiality clauses?

Yes
authorised personnel must be under written or statutory confidentiality obligations.

Are there audit rights for the data?

Structured
Atlassian is regularly audited by independent third-party and internal auditors; upon request and under NDA, Atlassian provides a summary of relevant audit reports; if compliance cannot be verified from reports, Atlassian provides written responses to reasonable information requests, capped at once every 12 months (clause 7.1). On-site audits are available only where the customer cannot reasonably satisfy compliance through clause 7.1 rights; they require at least 60 calendar days' written notice, are limited to once every 12 months, conducted at the customer's expense, and restricted to information relevant to the customer (clause 7.2).

Is there assistance with DPIA requests?

Yes
Atlassian provides reasonable assistance with DPIAs and consultations with regulatory authorities where the customer cannot reasonably fulfil the obligation itself.

How much notice is provided for data breaches?

Without undue delay and, where feasible, no later than 72 hours after awareness of a Security Incident.

What happens to the data on termination?

Following expiration or termination of the Agreement, Atlassian must delete all Customer Personal Data in accordance with the Documentation. Atlassian may retain Customer Personal Data (i) as required by Applicable Data Protection Law or (ii) in accordance with its standard backup or record retention policies; in either case Atlassian must maintain confidentiality and not further process the retained data except as required by law (clause 6.2).