DPA · Read from the capture of 19 Sept 2026
The DPA has been substantially restructured and expanded. Key additions include: an explicit effective date (August 17, 2026); clarified roles (Customer as Controller/Processor, Atlassian as Processor/Sub-processor); a new confidentiality obligation (Section 2.2); a defined Security Incident with a 72-hour notification requirement (Section 3.2); a sub-processor objection mechanism with termination as sole remedy (Section 4.3); a new deletion and return section (Section 6) detailing post-termination retention; expanded audit rights including supply of audit reports and criteria for on-site audits (Section 7); Schedule 1 now lists categories of Personal Data, sensitive data, frequency of transfer (continuous), and splits Processing purposes for Customer Data, De-identified/Aggregated Data, and Controller activities; Schedule 2 (Europe, UK, Switzerland) now incorporates EU SCCs with specific module/option selections (e.g., Option 2 for Clause 9, Irish governing law/Swiss courts for Swiss transfers, UK Addendum with Table details), adds a Data Privacy Framework section, US State Privacy Laws now explicitly prohibit selling/sharing and include customer remediation steps (Section 2.2–2.3), adds new South Korea and Brazil sections with updated Brazilian Transfer Clauses (Resolution CD/ANPD No. 19, 2024), and adds numerous definitions (e.g., Applicable Data Protection Law, Personal Data, Processing, Processor, Security Incident, Sub-processor, Data Privacy Framework, etc.).