Monitored vendor

Atlassian

atlassian.com

Record begins
28 Aug 2026
Last change detected
25 Sept 2026
Recent changes
3

Documents monitored

We link to each document at its source. We don't reproduce it here.

What changed

DPA · Read from the capture of 19 Sept 2026

The DPA has been substantially restructured and expanded. Key additions include: an explicit effective date (August 17, 2026); clarified roles (Customer as Controller/Processor, Atlassian as Processor/Sub-processor); a new confidentiality obligation (Section 2.2); a defined Security Incident with a 72-hour notification requirement (Section 3.2); a sub-processor objection mechanism with termination as sole remedy (Section 4.3); a new deletion and return section (Section 6) detailing post-termination retention; expanded audit rights including supply of audit reports and criteria for on-site audits (Section 7); Schedule 1 now lists categories of Personal Data, sensitive data, frequency of transfer (continuous), and splits Processing purposes for Customer Data, De-identified/Aggregated Data, and Controller activities; Schedule 2 (Europe, UK, Switzerland) now incorporates EU SCCs with specific module/option selections (e.g., Option 2 for Clause 9, Irish governing law/Swiss courts for Swiss transfers, UK Addendum with Table details), adds a Data Privacy Framework section, US State Privacy Laws now explicitly prohibit selling/sharing and include customer remediation steps (Section 2.2–2.3), adds new South Korea and Brazil sections with updated Brazilian Transfer Clauses (Resolution CD/ANPD No. 19, 2024), and adds numerous definitions (e.g., Applicable Data Protection Law, Personal Data, Processing, Processor, Security Incident, Sub-processor, Data Privacy Framework, etc.).

atlassian.com/legal/data-processing-addendum

DPA · Read from the capture of 15 Sept 2026

The new version is a restructured and expanded version of the DPA that now includes its own numbering system (e.g., Section 1.3 with a '1)' hierarchy), adds a repeated 'Authorised Affiliate' definition requiring that the affiliate be subject to Applicable Data Protection Law, and adds a new 'Applicable Data Protection Law' definition. It also introduces new provisions: (1) Atlassian is not responsible for monitoring Customer's compliance with Applicable Data Protection Law, (2) Customer is responsible for determining whether the Products are appropriate for Processing under Applicable Data Protection Law, (3) a Security Incident notification obligation (without undue delay, no later than 72 hours after becoming aware), (4) a new termination remedy for Customer's objection to a Sub-processor, (5) a new right for Customer to request a summary copy of relevant audit report(s), and (6) new restrictions on Atlassian's use of De-identified Data (before sharing with Recipients, Atlassian must contractually obligate Recipients to comply with requirements). The new version also clarifies that 'Processing' includes Personal Data and Customer Data, and adds language that transfers to Sub-processors are permitted as per Section 4. It also adds a new 'Service Provider' definition and specifies that the CCPA includes the CPRA. The effective date of the new version is not stated. The new version also removes the prior 'purposes of the Processing' sub-clauses (a), (b), (c) and replaces them with a single purpose clause, and removes the prior clause about Atlassian maintaining a list of Sub-processors (though the new version still references Section 4). The new version adds an explicit statement that Customer must exercise rights 'in a combined manner' (which was already present in the old version). The new version also adds a new clause that Atlassian must notify Customer if it determines it can no longer meet obligations under US State Privacy Laws. The new version adds a new definition of 'Authorised Affiliate' that requires the affiliate to be subject to Applicable Data Protection Law. The new version also adds a new clause that Atlassian will provide reasonable and timely assistance to Customer to enable Customer to respond to requests for exercising data subject's rights. The new version also adds a new clause that after expiration or termination, Atlassian must delete all Customer Personal Data in accordance with the Documentation. The new version also adds a new clause that Atlassian will maintain confidentiality of retained Customer Personal Data and not further Process it except as required by Applicable Data Protection Law. The new version also adds a new clause that upon request, Atlassian will supply a summary copy of relevant audit report(s) to Customer, on condition that Customer has entered into an applicable non-disclosure agreement. The new version also adds a new clause that Atlassian will provide reasonable assistance to Customer in fulfilling Customer's obligations under Applicable Data Protection Law (including data subject rights). The new version also adds a new clause that Atlassian will notify Customer without undue delay of Security Incidents. The new version also adds a new clause that Customer's audit rights are limited to when Customer cannot reasonably satisfy Atlassian's compliance through other rights, or where required by Applicable Data Protection Law or regulatory authority. The new version also adds a new clause that Atlassian will not provide information unless required by Law, and that it will inform Customer of legal requirements before Processing unless prohibited. The new version also adds a new clause that Customer is responsible for compliance obligations addressed in Clauses 4.1(a)-(c) of the EU SCCs. The new version also adds a new clause that the CCPA includes the CPRA.

atlassian.com/legal/data-processing-addendum

Privacy policy · From before we started monitoring · 17 Aug 2026

The previous document was an archive listing historical versions of various Atlassian legal policies. The new document is a full privacy policy, effective August 17, 2026, replacing that listing with binding terms. Key substantive changes include:

  • Effective date: The policy now states an effective date of August 17, 2026, whereas the previous archive page had no single effective date.
  • Data collection categories: The policy now describes specific categories of information collected (account info, content, payment info, device/connection info, cookies, identity management data) and sources (users, partners, third parties). Previously no such descriptions existed.
  • Data use purposes: The policy now lists purposes such as providing and personalizing Services, developing/improving Services, communicating, marketing, customer support, safety/security, legal compliance, consent, and aggregation/de-identification.
  • Data sharing: The policy now details disclosures to service providers, partners, third-party services, affiliates, and for legal compliance. It includes new wording: 'All the above categories exclude text messaging originator opt-in data and consent. This information will not be shared with any third parties...' — a restriction not present before.
  • Retention periods: The policy now specifies retention criteria for account info, content, managed accounts, and marketing info (e.g., 'as long as your account is active and a reasonable period thereafter'). Previously no retention periods were stated.
  • User rights: The policy now provides detailed rights (access, deletion, opt-out of communications and targeted advertising, data portability) and instructions for exercising them. No such rights were described in the previous version.
  • Regional disclosures: The policy now includes separate EEA/UK disclosures (legal bases, rights, international transfers, DPF compliance) and U.S. state disclosures (categories table, sale/sharing opt-out, sensitive info handling).
  • Contact details: The policy now provides privacy@atlassian.com and EU/UK representative emails and addresses. No contact info was in the previous archive.
  • Children policy: The policy now states Services are not for under-16s and that it will delete such data if discovered.
  • Data Privacy Framework (DPF): The policy now includes a DPF notice, certification, and dispute resolution mechanisms.
  • Changes to policy: The policy now describes how changes will be communicated (prominent notice or email for significant changes) and directs to an archive of prior versions.
atlassian.com/legal/privacy-policy

Get notified when Atlassian changes this

We check the document on a schedule and email a plain-language summary of what moved.

Start monitoring free