108 Total
26 High severity
64 Medium severity
18 Low severity

Key Facts

Is Atlassian responsible for the privacy and security practices of its customers?
Atlassian is not responsible for the privacy or security practices of its customers, which may differ from those described in its privacy policy.
What practices is Atlassian not responsible for?
Atlassian is not responsible for the privacy or security practices of its customers, which may differ from those described in its privacy policy.
Will Atlassian take steps to delete personal information if a child under 16 provides it?
Atlassian's Services are not intended for anyone under the age of 16, and Atlassian will take steps to delete personal information if it becomes aware a child under 16 has provided it.
What account information can become accessible to an organization's administrator?
Atlassian allows certain account information—including name, profile picture, contact info, content, and past account use—to become accessible to an organization's administrator and other Service users sharing the same domain.
To whom may Atlassian disclose information about you?
Atlassian may disclose information about you to government authorities, law enforcement, or industry peers if it believes sharing is reasonably necessary to comply with any applicable law, regulation, legal process, or enforceable governmental request.
May Atlassian disclose information to law enforcement if it believes sharing is reasonably necessary to comply with applicable law?
Atlassian may disclose information about you to government authorities, law enforcement, or industry peers if it believes sharing is reasonably necessary to comply with any applicable law, regulation, legal process, or enforceable governmental request.
Does Atlassian's privacy policy apply when Atlassian processes personal information as a processor on behalf of its customers?
Atlassian's privacy policy does not apply to the extent that Atlassian processes personal information in the role of a processor or service provider on behalf of its customers.
To what extent does Atlassian's privacy policy apply?
Atlassian's privacy policy does not apply to the extent that Atlassian processes personal information in the role of a processor or service provider on behalf of its customers.
Does Atlassian use or disclose sensitive personal information for other purposes than those permitted under applicable law?
Atlassian does not use or disclose sensitive personal information for purposes other than those permitted under applicable law.
What can third-party services connected to your account access?
Atlassian allows third-party services connected to your account to access your account and information about you, such as your name and email address.
Stay ahead of the changes
Track Atlassian and get the diff the day its terms change.
Summary

This policy explains what information Atlassian collects about you, how it uses that information—including for targeted advertising—and who it may share it with, including your organization's administrator, colleagues on the same domain, and government authorities. If you use Atlassian through an employer or organization, much of how your data is actually handled falls under your organization's control, not this policy. You can opt out of targeted advertising using the 'Manage Preferences' control where local law makes that right available.

Analysis

Atlassian's Privacy Policy establishes the conditions under which Atlassian collects, uses, shares, and retains personal information in its role as a data controller, while explicitly carving out processing activities Atlassian performs as a processor or service provider on behalf of its customers—which fall entirely outside this policy's scope. The document sets out Atlassian's use of personal information for operational purposes and for marketing, including targeted advertising, and discloses that cookies and tracking technologies are deployed by both Atlassian and third-party partners across Services and devices. Data sharing obligations are defined to include access by organizational administrators and domain-sharing users, disclosure to government and law enforcement where Atlassian determines compliance requires it, and access by connected third-party services. The policy restricts Services to users 16 and older, limits sensitive personal information use to purposes permitted under applicable law, and disclaims responsibility for the privacy or security practices of Atlassian's customers.

What this means for you

When you use Atlassian's Services through an organization, your name, profile picture, contact information, content, and account usage history may be accessible to your organization's administrator and other users sharing the same domain—not just Atlassian. Third-party services you connect to your account also receive access to your account information, including at minimum your name and email address. If you are subject to a local law that grants targeted advertising opt-out rights, you can exercise that right by clicking 'Manage Preferences' and following the instructions provided there.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

Featured, High severity
Featured, Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

108 provisions
12 featured
18 clause types
26 high severity
Disclosure and Transparency Requirements 2 1 high
Targeting and Audience Restrictions 2 1 high
Acceptable Use Restrictions 1 1 high
Restricted or Prohibited Content/Industries 1 1 high
Stay ahead of the changes

Monitoring

Atlassian has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Atlassian Not Responsible For Customer Privacy Practices and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
DMA
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 5, 2026 06:38 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000708
Version ID CA-V-001342
SHA-256 065111cefdcb43fb98af94e05eac5a4f3ea251c3de569497bcc23b06b5e2755c
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans