6 Total
0 High severity
4 Medium severity
2 Low severity
Summary

This is Atlassian's official list of subprocessors, meaning the third-party companies that Atlassian authorizes to access or process customer data as part of delivering its cloud products such as Jira, Confluence, and Jira Service Management. The document discloses each subprocessor's name, country of operation, and the category of processing activity performed, covering infrastructure hosting (Amazon Web Services, Google Cloud Platform), analytics, customer support tooling, payment processing, and AI-related functions. Atlassian states that it will provide advance notice of changes to this list, giving customers the opportunity to object to new subprocessors under the terms of its DPA.

Technical / Legal Breakdown

This document is Atlassian's publicly disclosed list of third-party subprocessors authorized to process customer data in connection with Atlassian's cloud products and services, published under Atlassian's Data Processing Addendum (DPA) framework, which governs subprocessor engagement as required under GDPR Article 28 and equivalent data protection obligations. The document discloses the names, locations, and processing activities of each subprocessor, establishing that Atlassian engages third parties for functions including cloud infrastructure hosting, analytics, customer support, security monitoring, payment processing, and AI-related processing. The list covers a broad set of subprocessors spanning multiple jurisdictions including the United States, European Economic Area, Australia, and India, with infrastructure providers such as Amazon Web Services and Google Cloud Platform identified as primary hosting subprocessors; the geographic distribution of subprocessors is operationally significant for customers subject to data residency or cross-border transfer restrictions. The document engages GDPR (particularly Articles 28 and 46 on subprocessor contracts and transfer mechanisms), the UK GDPR, the Australian Privacy Act, and potentially CCPA, as Atlassian's customer base and subprocessor network are global. Enterprise customers with contractual data residency commitments or sector-specific regulatory requirements (financial services, healthcare, public sector) should evaluate the subprocessor list against their own DPA obligations, transfer mechanism documentation, and vendor management policies.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Get Compliance
Featured — Medium severity
Featured — Low severity

Monitoring

Atlassian has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Get Compliance

Cross-platform context

See how other platforms handle AI-Related Subprocessor Disclosure and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
DMA
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured July 7, 2026 00:21 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000938
Version ID CA-V-004549
SHA-256 70b0ff62aa8a93146dd04f30189233f09aff432c83453702c8c36df25a7c0092
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans