Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
Community Members
Community Events
Community Groups

GDPR - compliance - do we store personal data?

Tom Lister Community Leader Jan 09, 2020


I'd like some feedback on GDPR issues.

Our Jira has many business related projects but we do not capture personal data. That is we have user data email/name/username in our directories. (emails are company emails)  But the issue data does not require any personal data.

My understanding so far is that this is not personal data is not a GDPR risk.

It does seem that there could be a situation where a user could ask us what we have stored and ask to 'remove' it. I think the former could be a report is user activity stored. And for the latter we could obfuscate the email/name/username to avoid any the work involved in deleting a user from Jira.

Does anyone have experiences to share?


1 answer

1 accepted

1 vote
Answer accepted

HI @Tom Lister ,

If you have any users that fall under the GDPR definition of originating in a location inside the EU, the the names or email of those individuals are viewable to others, the Short answer is Yes.

The longer detailed explanation can be found looking at the EU GDPR definition of Personally Identifiable Information it does note that an email or the users name will fall into one of the items covered by GDPR compliance if the email relates to the users actual name and is not anonymized

Personal data is any information that relates to an identified or identifiable living individual. Different pieces of information, which collected together can lead to the identification of a particular person, also constitute personal data.

Personal data that has been de-identified, encrypted or pseudonymised but can be used to re-identify a person remains personal data and falls within the scope of the GDPR.

Personal data that has been rendered anonymous in such a way that the individual is not or no longer identifiable is no longer considered personal data. For data to be truly anonymised, the anonymisation must be irreversible.

The GDPR protects personal data regardless of the technology used for processing that data – it’s technology neutral and applies to both automated and manual processing, provided the data is organised in accordance with pre-defined criteria (for example alphabetical order). It also doesn’t matter how the data is stored – in an IT system, through video surveillance, or on paper; in all cases, personal data is subject to the protection requirements set out in the GDPR.


 I recomend checking out the Server & Data Center GDPR Support GuideServer & Data Center GDPR FAQ we have put together to help out in understanding how certain product features and functionality can support your GDPR compliance requirements.


Suggest an answer

Log in or Sign up to answer
Community showcase
Published in Confluence

An update on Confluence Cloud customer feedback – June 2022

Hi everyone, We’re always looking at how to improve Confluence and customer feedback plays an important role in making sure we're investing in the areas that will bring the most value to the most c...

124 views 1 3
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you