Atlassian · Atlassian Privacy Policy · View original document ↗

Business Transfer Disclosure

Low severity High confidence Explicitdocumentlanguage Rare · 6 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Atlassian Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

If Atlassian is acquired or merges with another company, your personal data may be transferred to the new owner, and Atlassian states it will notify you by email or website notice and describe any changes in how your data is used.

This analysis describes what Atlassian's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision authorizes the transfer of your personal data to an acquiring entity in a corporate transaction, with post-transaction notification rather than prior consent as the stated mechanism for informing users of changes.

Consumer impact (what this means for users)

In a merger or acquisition, personal data including account information, usage history, and content may be transferred to a new corporate owner. The policy states Atlassian will provide notification and describe choices available, but does not guarantee that the acquiring entity will maintain identical data practices.

How other platforms handle this

Skillshare Medium

In connection with any reorganization, restructuring, merger or sale, or other transfer of assets, we will transfer information, including personal information, provided that the receiving party agrees to respect your personal information in a manner that is consistent with our Privacy Policy.

Canva Medium

If Canva is involved in a merger, acquisition, or sale of all or a portion of its assets, your information may be transferred as part of that transaction. We will notify you via email or a prominent notice on our website prior to your information becoming subject to a different privacy policy.

Meta Medium

We may access, preserve, and share information with regulators, law enforcement, or others if we believe it is reasonably necessary to: detect, prevent, and address fraud and other illegal activity; protect ourselves, you, and others, including as part of investigations; and prevent death or imminen...

See all platforms with this clause type →

Monitoring

Atlassian has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
If we are involved in a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website of any change in ownership or uses of your personal information, as well as any choices you may have regarding your personal information.

— Excerpt from Atlassian's Atlassian Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

(1) REGULATORY LANDSCAPE: GDPR requires a legal basis for data transfers including in business transaction scenarios; legitimate interests or contract performance may apply, but a change of controller following an acquisition may require fresh legal basis assessment and updated data subject notices. CCPA does not categorically prohibit business transfer data sharing but may require updated disclosures. (2) GOVERNANCE EXPOSURE: Low to medium. The post-notification approach is standard but the practical ability to enforce data use limitations after a transfer to an acquiring entity depends on contractual commitments in the acquisition agreement, which are not described in this policy. (3) JURISDICTION FLAGS: EU and UK users may have objection rights if an acquisition results in materially changed processing purposes. Regulators in those jurisdictions may scrutinize whether post-acquisition data use aligns with the original legal basis under which data was collected. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers should include provisions in their DPA addressing what happens to their organization's data in the event of an Atlassian acquisition, including data return or deletion rights. (5) COMPLIANCE CONSIDERATIONS: Organizations should monitor Atlassian's corporate announcements and assess whether any business transfer triggers their own vendor reassessment obligations under internal third-party risk management programs.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
DMA
European Union
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US
VPPA
United States Federal

Provision details

Document information
Document
Atlassian Privacy Policy
Entity
Atlassian
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
May 12, 2026
Record ID
CA-P-011767
Document ID
CA-D-00708
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
8a1c5acb713e644f1bae9303aa9bc97bc64e447bd57ce9ec70ff0d9b296b971e
Analysis generated
May 8, 2026 04:39 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Atlassian
Document: Atlassian Privacy Policy
Record ID: CA-P-011767
Captured: 2026-05-08 04:39:00 UTC
SHA-256: 8a1c5acb713e644f…
URL: https://conductatlas.com/platform/atlassian/atlassian-privacy-policy/business-transfer-disclosure/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Related Analysis

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Atlassian's Business Transfer Disclosure clause do?

This provision authorizes the transfer of your personal data to an acquiring entity in a corporate transaction, with post-transaction notification rather than prior consent as the stated mechanism for informing users of changes.

How does this clause affect you?

In a merger or acquisition, personal data including account information, usage history, and content may be transferred to a new corporate owner. The policy states Atlassian will provide notification and describe choices available, but does not guarantee that the acquiring entity will maintain identical data practices.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 6 platforms. See the full comparison.

Is ConductAtlas affiliated with Atlassian?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Atlassian.