Atlassian's GDPR Commitment
Dedication to your data privacy
We are wholly invested in our customers' success and the protection of data. One way that we deliver on this promise is by helping Atlassian customers and users understand, and where applicable, comply with the General Data Protection Regulation (GDPR).
The GDPR is designed to give EU citizens more control over their data and seeks to unify a number of existing privacy and security laws under one comprehensive law within the EU. The GDPR not only applies to organizations located within the EU, but it also applies to all companies processing and holding the personal data of data subjects residing in the European Union, regardless of the company’s location (the so-called extraterritoriality principle).
The following sections outline our approach and investment in GDPR compliance in service of our customers and individual data subjects.
International data transfers
Data location and portability
Data hosting location determinations are based on reducing latency and achieving optimal performance for you and your users. We optimize where to host customer data based on how it is accessed around the world (rather than upon request). Though we don't guarantee that your data will be hosted in a specific location by default, you can use data residency to pin in-scope product content at rest to a location. Planned expansions to our data residency program are highlighted in Atlassian’s cloud roadmap.
We’re also ready to facilitate your customers' requests to export their data, should you host your customer data on Atlassian products. Atlassian provides robust data portability and data management tools for exporting product and user data. For more information on Atlassian Cloud data export, see our import and export documentation.
Individual privacy rights and consent
Data subject rights
Our tools help customers meet obligations under the GDPR right to be forgotten (or right to erasure) clause by making it easy to delete personal data from Atlassian Cloud products.
- Atlassian Organization Admins can facilitate the account deletion of their managed users from controls in their admin portal
- Unmanaged end users (an account that is not managed by an organization) may also request that their personal data be deleted by initiating an account deletion request from their Atlassian account profile page
- People who have provided their personal data or had their personal data provided to Atlassian, but do not have Atlassian accounts, may also initiate a request for deletion
Similar tools are available for access requests.
- Atlassian Organization Admins can facilitate access of their managed users' data from Atlassian support
- Unmanaged end users may also request that their personal data be accessed by initiating a data access request from Atlassian support
- People who have provided their personal data or had their personal data provided to Atlassian, but do not have Atlassian accounts, may also initiate a request for access
Both deletion and access requests can be serviced via telephone by leaving a message at 1 (800) 804-5281.
Choice and consent
We value choice and transparency around how we collect, use, and share information, and provide optionality within different product or account settings. Our Privacy Policy summarizes those choices, how to exercise them, and any relevant limitations.
For more information around end user data rights, see “Manage your personal data privacy”.
Please note for our EU end users, we surface consents for cookies and marketing messages to provide clarity and control at points of collection. Our internal processes centralize consents to ensure we’re consistently honoring your choices across our product suite.
Other commitments
Below are several other GDPR initiatives that have been implemented within our Cloud:
- We have ensured Atlassian staff that access and process Atlassian customer personal data have been trained in handling that data and are bound to maintain the confidentiality and security of that data
- We provide a list of our subprocessors on our Subprocessors page, and offer an RSS feed subscription so you can stay up-to-date on any changes
- We have committed to carrying out data impact assessments and consulting with EU regulators where appropriate
- We will assist with notifying regulators of security breaches and promptly communicating any breaches to customers and users
-
We are committed to honor our obligations as data importers under the EU Standard Model Clauses