If your organization processes personal data using Atlassian products, a separate Data Processing Addendum governs how that data is handled, and it is legally part of your agreement with Atlassian.
This analysis describes what Atlassian's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The DPA is the operative document for GDPR and CCPA compliance purposes, and its terms govern data controller and processor obligations, sub-processor authorization, and cross-border transfer mechanisms for personal data processed through Atlassian products.
Interpretive note: The full scope of obligations depends on the terms of the separately published DPA, which is incorporated by reference but not reproduced in the base agreement text analyzed here.
Organizations processing personal data in Atlassian products are subject to the terms of the Data Processing Addendum, which governs how Atlassian handles that data and what sub-processors may have access to it.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
Further, you may take legal actions in relation to any potential breach of your rights regarding the processing of your Personal Information, as well as to lodge complaints before the competent data prot...
"To the extent Customer's use of the products involves the processing of personal data subject to applicable data protection laws (including the GDPR and CCPA), the parties' respective rights and obligations with respect to such processing are set forth in the Data Processing Addendum, which is incorporated into this Agreement by reference.Excerpt from Atlassian's Cloud Terms
REGULATORY LANDSCAPE: The DPA incorporation directly engages GDPR (for EU/EEA and UK customers), CCPA and CPRA (for California-based customers), and applicable national data protection laws globally.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The DPA is the operative document for GDPR and CCPA compliance purposes, and its terms govern data controller and processor obligations, sub-processor authorization, and cross-border transfer mechanisms for personal data processed through Atlassian products.
Organizations processing personal data in Atlassian products are subject to the terms of the Data Processing Addendum, which governs how Atlassian handles that data and what sub-processors may have access to it.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Atlassian.