Atlassian · Atlassian Sub-Processors · View original document ↗

Cross-Border Data Transfer to US-Based Infrastructure Providers

Medium severity Medium confidence Inferredfromcontext Unique · 0 of 352 platforms
Get alerted the next time Atlassian changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Atlassian Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The document lists US-based subprocessors including Amazon Web Services and Google Cloud Platform as infrastructure providers, establishing that customer data may be hosted and processed in the United States.

This analysis describes what Atlassian's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision is operationally significant for EU, UK, and Australian customers because it establishes that personal data may be transferred to and processed in the United States, requiring valid transfer mechanisms such as Standard Contractual Clauses to be in place between Atlassian and each US-based subprocessor.

Interpretive note: The document lists subprocessors and their locations but does not specify which transfer mechanism applies to each cross-border transfer; the applicable mechanism must be determined by reference to Atlassian's DPA.

Consumer impact (what this means for users)

Under these terms, customer data processed by Atlassian cloud products may be transferred to and stored on infrastructure operated by US-based providers. Customers subject to GDPR or UK GDPR should confirm that Atlassian's DPA includes valid transfer safeguards covering these providers.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Export Your Data
    Review Atlassian's GDPR FAQ and Data Processing Addendum documentation to confirm transfer mechanisms applicable to US-based subprocessors, then document findings in your organization's transfer impact assessment.

Cross-platform context

See how other platforms handle Cross-Border Data Transfer to US-Based Infrastructure Providers and similar clauses.

Compare across platforms →

Monitoring

Atlassian has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Atlassian subprocessors who process customer data.

Excerpt from Atlassian's Sub-Processors

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: GDPR Chapter V (Articles 44-49) governs transfers of personal data to third countries. Transfers to US-based subprocessors require a valid transfer mechanism; the EU-US Data Privacy Framework, Standard Contractual Clauses, or Binding Corporate Rules are the primary available mechanisms. UK GDPR requires equivalent safeguards under the UK International Data Transfer Agreement or UK Addendum to SCCs. The Australian Privacy Act APP 8 requires reasonable steps to ensure overseas recipients handle data in accordance with the APPs. 2) GOVERNANCE EXPOSURE: High for EU and UK enterprise customers. The presence of US-based hyperscale infrastructure providers as primary subprocessors means that substantially all customer data may transit or reside in the US. Customers must independently verify that Atlassian's executed SCCs cover these subprocessors and that the SCCs reflect the current EU Commission-approved versions post-Schrems II. 3) JURISDICTION FLAGS: EU and EEA customers have the highest exposure. UK customers must evaluate under UK GDPR and the UK IDTA framework. Australian customers should assess App 8. Customers in sectors with explicit data localization requirements (certain financial services, healthcare, or public sector contexts) may face additional restrictions beyond general GDPR compliance. 4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise DPAs with Atlassian should specify which transfer mechanism applies to US-based subprocessors and should include a warranty from Atlassian that SCCs or equivalent instruments are in place with each listed US subprocessor. Procurement teams should request copies of transfer mechanism documentation where contractually permitted. 5) COMPLIANCE CONSIDERATIONS: Legal teams should conduct a Transfer Impact Assessment (TIA) for transfers to US-based subprocessors as recommended by the European Data Protection Board. Data mapping documentation should identify US-based subprocessors and the applicable transfer mechanism for each. Where Atlassian offers data residency options, customers should evaluate whether those options effectively restrict processing to approved jurisdictions or merely apply to primary storage.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • FTC
    The FTC enforces the EU-US Data Privacy Framework and has jurisdiction over US-based companies' data handling representations, relevant to the US-based infrastructure subprocessors listed in this document.
    File a complaint →

Provision details

Document information
Document
Atlassian Sub-Processors
Entity
Atlassian
Document last updated
July 6, 2026
Tracking information
First tracked
July 7, 2026
Last verified
July 7, 2026
Record ID
CA-P-013471
Document ID
CA-D-00938
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
c0e40771c27ef2ab6cb0610288266f89dd934528062513e5a5324aee9f29e429
Analysis generated
July 7, 2026 00:31 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Atlassian
Document: Atlassian Sub-Processors
Record ID: CA-P-013471
Captured: 2026-07-07 00:31:59 UTC
SHA-256: c0e40771c27ef2ab…
URL: https://conductatlas.com/platform/atlassian/atlassian-sub-processors/provision/CA-P-013471/cross-border-data-transfer-to-us-based-infrastructure-providers/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Atlassian's Cross-Border Data Transfer to US-Based Infrastructure Providers clause do?

This provision is operationally significant for EU, UK, and Australian customers because it establishes that personal data may be transferred to and processed in the United States, requiring valid transfer mechanisms such as Standard Contractual Clauses to be in place between Atlassian and each US-based subprocessor.

How does this clause affect you?

Under these terms, customer data processed by Atlassian cloud products may be transferred to and stored on infrastructure operated by US-based providers. Customers subject to GDPR or UK GDPR should confirm that Atlassian's DPA includes valid transfer safeguards covering these providers.

Is ConductAtlas affiliated with Atlassian?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Atlassian.