You're on your way to the next level! Join the Kudos program to earn points and save your progress.
Level 1: Seed
25 / 150 points
Next: Root
1 badge earned
Challenges come and go, but your rewards stay with you. Do more to earn more!
What goes around comes around! Share the love by gifting kudos to your peers.
Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!
Join now to unlock these features and more
The Atlassian Community can help you and your team get more value out of Atlassian products and practices.
Hi
I'd like some feedback on GDPR issues.
Our Jira has many business related projects but we do not capture personal data. That is we have user data email/name/username in our directories. (emails are company emails) But the issue data does not require any personal data.
My understanding so far is that this is not personal data is not a GDPR risk.
It does seem that there could be a situation where a user could ask us what we have stored and ask to 'remove' it. I think the former could be a report is user activity stored. And for the latter we could obfuscate the email/name/username to avoid any the work involved in deleting a user from Jira.
Does anyone have experiences to share?
Tom
HI @Tom Lister ,
If you have any users that fall under the GDPR definition of originating in a location inside the EU, the the names or email of those individuals are viewable to others, the Short answer is Yes.
The longer detailed explanation can be found looking at the EU GDPR definition of Personally Identifiable Information it does note that an email or the users name will fall into one of the items covered by GDPR compliance if the email relates to the users actual name and is not anonymized
Personal data is any information that relates to an identified or identifiable living individual. Different pieces of information, which collected together can lead to the identification of a particular person, also constitute personal data.
Personal data that has been de-identified, encrypted or pseudonymised but can be used to re-identify a person remains personal data and falls within the scope of the GDPR.
Personal data that has been rendered anonymous in such a way that the individual is not or no longer identifiable is no longer considered personal data. For data to be truly anonymised, the anonymisation must be irreversible.
The GDPR protects personal data regardless of the technology used for processing that data – it’s technology neutral and applies to both automated and manual processing, provided the data is organised in accordance with pre-defined criteria (for example alphabetical order). It also doesn’t matter how the data is stored – in an IT system, through video surveillance, or on paper; in all cases, personal data is subject to the protection requirements set out in the GDPR.
I recomend checking out the Server & Data Center GDPR Support Guide & Server & Data Center GDPR FAQ we have put together to help out in understanding how certain product features and functionality can support your GDPR compliance requirements.
Regards,
Earl
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.