The document discloses the identity, location, and processing activity of each third party that Atlassian authorizes to process customer data in connection with its cloud products, fulfilling the transparency requirement under GDPR Article 28(2).
This analysis describes what Atlassian's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the formal subprocessor register that Atlassian is contractually and regulatorily required to maintain under its DPA and GDPR Article 28. Enterprise customers rely on this list to fulfill their own downstream subprocessor due diligence obligations and to maintain accurate records of processing activities.
This provision establishes that customer data flowing through Atlassian cloud products is processed by named third-party vendors covering infrastructure, analytics, support, and AI functions. Under these terms, customers can identify which vendors have access to their data and in which countries those vendors operate.
Cross-platform context
See how other platforms handle Subprocessor Disclosure Obligation and similar clauses.
Compare across platforms →"Atlassian subprocessors who process customer data.Excerpt from Atlassian's Sub-Processors
1) REGULATORY LANDSCAPE: GDPR Article 28(2) requires data processors to obtain prior written authorization before engaging subprocessors and to impose equivalent data protection obligations on them by contract.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes the formal subprocessor register that Atlassian is contractually and regulatorily required to maintain under its DPA and GDPR Article 28. Enterprise customers rely on this list to fulfill their own downstream subprocessor due diligence obligations and to maintain accurate records of processing activities.
This provision establishes that customer data flowing through Atlassian cloud products is processed by named third-party vendors covering infrastructure, analytics, support, and AI functions. Under these terms, customers can identify which vendors have access to their data and in which countries those vendors operate.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Atlassian.