Atlassian · Atlassian Privacy Policy · View original document ↗

Cross-Border Data Transfers

Medium severity Medium confidence Explicitdocumentlanguage Common · 78 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Atlassian Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Atlassian transfers personal data internationally and states it uses Standard Contractual Clauses approved by EU and UK regulators to provide a legal basis for those transfers when data moves outside of Europe.

This analysis describes what Atlassian's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The policy states that personal data from EU and UK users may be transferred internationally and that Standard Contractual Clauses are the stated mechanism, which matters because the adequacy of these mechanisms for transfers to certain jurisdictions may require ongoing assessment under post-Schrems II guidance.

Interpretive note: The specific adequacy of Atlassian's SCCs and supplementary measures for transfers to particular jurisdictions cannot be confirmed from the policy text alone and depends on Atlassian's DPA documentation and the specific destination country.

Consumer impact (what this means for users)

Personal data of EU and UK users may be transferred to Atlassian entities or service providers in other countries, including the United States, under Standard Contractual Clauses. EU and UK users can request information about the specific safeguards in place for their data by contacting Atlassian's privacy team.

How other platforms handle this

OpenAI Medium

OpenAI is based in the United States and the information we collect is governed by U.S. law. If you are accessing our services from outside of the United States, please be aware that your information may be transferred to, stored, and processed by us in our facilities in the United States and by tho...

Figma Medium

When we transfer personal information from the European Economic Area, United Kingdom, or Switzerland to countries that have not been found to provide an adequate level of protection under applicable law, we take steps to provide appropriate safeguards, including through the use of Standard Contract...

Ideogram Medium

We may transfer your personal information to countries other than the country in which you live. We transfer personal data from the European Economic Area, United Kingdom, and Switzerland to other countries, some of which have not been determined by the European Commission to have an adequate level ...

See all platforms with this clause type →

Monitoring

Atlassian has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Atlassian may transfer your personal information to countries other than the country where you initially provided it. When we transfer personal information outside of the EEA or the UK, we ensure appropriate safeguards are in place, including standard contractual clauses approved by the European Commission or the UK Information Commissioner's Office.

— Excerpt from Atlassian's Atlassian Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

(1) REGULATORY LANDSCAPE: GDPR Chapter V and UK GDPR equivalent provisions govern international data transfers and require appropriate safeguards. Standard Contractual Clauses must comply with the updated 2021 EU SCCs. The CJEU's Schrems II decision requires supplementary measures when transferring to jurisdictions where government access to data may impair SCC protections. The European Data Protection Board and UK ICO are the relevant enforcement authorities. (2) GOVERNANCE EXPOSURE: Medium. Organizations relying on Atlassian's SCCs for their own GDPR compliance must confirm that Atlassian's SCCs are the correct module for the controller-processor relationship and that supplementary measures are documented where required. (3) JURISDICTION FLAGS: EEA and UK organizations have heightened exposure. Transfers to the United States must be assessed following the EU-US Data Privacy Framework; organizations should confirm whether Atlassian is certified under that framework. Swiss organizations should assess adequacy under Switzerland's revised Federal Act on Data Protection. (4) CONTRACT AND VENDOR IMPLICATIONS: The DPA should reference the applicable SCCs module (Module 2 for controller-to-processor transfers) and include supplementary measures documentation. Procurement teams should request Atlassian's Transfer Impact Assessment or equivalent documentation if required by their DPA counterparts. (5) COMPLIANCE CONSIDERATIONS: Legal teams should confirm Atlassian's current DPA references the 2021 updated SCCs, review the sub-processor list for recipients in non-adequate countries, and maintain documentation of transfer safeguards in Article 30 records.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
DMA
European Union
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US
VPPA
United States Federal

Provision details

Document information
Document
Atlassian Privacy Policy
Entity
Atlassian
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
May 12, 2026
Record ID
CA-P-011765
Document ID
CA-D-00708
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
8a1c5acb713e644f1bae9303aa9bc97bc64e447bd57ce9ec70ff0d9b296b971e
Analysis generated
May 8, 2026 04:39 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Atlassian
Document: Atlassian Privacy Policy
Record ID: CA-P-011765
Captured: 2026-05-08 04:39:00 UTC
SHA-256: 8a1c5acb713e644f…
URL: https://conductatlas.com/platform/atlassian/atlassian-privacy-policy/cross-border-data-transfers/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Atlassian's Cross-Border Data Transfers clause do?

The policy states that personal data from EU and UK users may be transferred internationally and that Standard Contractual Clauses are the stated mechanism, which matters because the adequacy of these mechanisms for transfers to certain jurisdictions may require ongoing assessment under post-Schrems II guidance.

How does this clause affect you?

Personal data of EU and UK users may be transferred to Atlassian entities or service providers in other countries, including the United States, under Standard Contractual Clauses. EU and UK users can request information about the specific safeguards in place for their data by contacting Atlassian's privacy team.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 78 platforms. See the full comparison.

Is ConductAtlas affiliated with Atlassian?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Atlassian.