Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The document lists US-based subprocessors including Amazon Web Services and Google Cloud Platform as infrastructure providers, establishing that customer data may be hosted and processed in the United States.
This analysis describes what Atlassian's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision is operationally significant for EU, UK, and Australian customers because it establishes that personal data may be transferred to and processed in the United States, requiring valid transfer mechanisms such as Standard Contractual Clauses to be in place between Atlassian and each US-based subprocessor.
Interpretive note: The document lists subprocessors and their locations but does not specify which transfer mechanism applies to each cross-border transfer; the applicable mechanism must be determined by reference to Atlassian's DPA.
Under these terms, customer data processed by Atlassian cloud products may be transferred to and stored on infrastructure operated by US-based providers. Customers subject to GDPR or UK GDPR should confirm that Atlassian's DPA includes valid transfer safeguards covering these providers.
Cross-platform context
See how other platforms handle Cross-Border Data Transfer to US-Based Infrastructure Providers and similar clauses.
Compare across platforms →Monitoring
Atlassian has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Atlassian subprocessors who process customer data.Excerpt from Atlassian's Sub-Processors
1) REGULATORY LANDSCAPE: GDPR Chapter V (Articles 44-49) governs transfers of personal data to third countries. Transfers to US-based subprocessors require a valid transfer mechanism; the EU-US Data Privacy Framework, Standard Contractual Clauses, or Binding Corporate Rules are the primary available mechanisms. UK GDPR requires equivalent safeguards under the UK International Data Transfer Agreement or UK Addendum to SCCs. The Australian Privacy Act APP 8 requires reasonable steps to ensure overseas recipients handle data in accordance with the APPs. 2) GOVERNANCE EXPOSURE: High for EU and UK enterprise customers. The presence of US-based hyperscale infrastructure providers as primary subprocessors means that substantially all customer data may transit or reside in the US. Customers must independently verify that Atlassian's executed SCCs cover these subprocessors and that the SCCs reflect the current EU Commission-approved versions post-Schrems II. 3) JURISDICTION FLAGS: EU and EEA customers have the highest exposure. UK customers must evaluate under UK GDPR and the UK IDTA framework. Australian customers should assess App 8. Customers in sectors with explicit data localization requirements (certain financial services, healthcare, or public sector contexts) may face additional restrictions beyond general GDPR compliance. 4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise DPAs with Atlassian should specify which transfer mechanism applies to US-based subprocessors and should include a warranty from Atlassian that SCCs or equivalent instruments are in place with each listed US subprocessor. Procurement teams should request copies of transfer mechanism documentation where contractually permitted. 5) COMPLIANCE CONSIDERATIONS: Legal teams should conduct a Transfer Impact Assessment (TIA) for transfers to US-based subprocessors as recommended by the European Data Protection Board. Data mapping documentation should identify US-based subprocessors and the applicable transfer mechanism for each. Where Atlassian offers data residency options, customers should evaluate whether those options effectively restrict processing to approved jurisdictions or merely apply to primary storage.
This provision is operationally significant for EU, UK, and Australian customers because it establishes that personal data may be transferred to and processed in the United States, requiring valid transfer mechanisms such as Standard Contractual Clauses to be in place between Atlassian and each US-based subprocessor.
Under these terms, customer data processed by Atlassian cloud products may be transferred to and stored on infrastructure operated by US-based providers. Customers subject to GDPR or UK GDPR should confirm that Atlassian's DPA includes valid transfer safeguards covering these providers.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Atlassian.