It's not the same without you

Join the community to find out what other Atlassian users are discussing, debating and creating.

Atlassian Community Hero Image Collage

GDPR - compliance - do we store personal data?

tom lister Community Leader Jan 09, 2020

Hi

I'd like some feedback on GDPR issues.

Our Jira has many business related projects but we do not capture personal data. That is we have user data email/name/username in our directories. (emails are company emails)  But the issue data does not require any personal data.

My understanding so far is that this is not personal data is not a GDPR risk.

It does seem that there could be a situation where a user could ask us what we have stored and ask to 'remove' it. I think the former could be a report is user activity stored. And for the latter we could obfuscate the email/name/username to avoid any the work involved in deleting a user from Jira.

Does anyone have experiences to share?

Tom

1 answer

1 accepted

0 votes
Answer accepted

HI @tom lister ,

If you have any users that fall under the GDPR definition of originating in a location inside the EU, the the names or email of those individuals are viewable to others, the Short answer is Yes.

The longer detailed explanation can be found looking at the EU GDPR definition of Personally Identifiable Information it does note that an email or the users name will fall into one of the items covered by GDPR compliance if the email relates to the users actual name and is not anonymized

Personal data is any information that relates to an identified or identifiable living individual. Different pieces of information, which collected together can lead to the identification of a particular person, also constitute personal data.

Personal data that has been de-identified, encrypted or pseudonymised but can be used to re-identify a person remains personal data and falls within the scope of the GDPR.

Personal data that has been rendered anonymous in such a way that the individual is not or no longer identifiable is no longer considered personal data. For data to be truly anonymised, the anonymisation must be irreversible.

The GDPR protects personal data regardless of the technology used for processing that data – it’s technology neutral and applies to both automated and manual processing, provided the data is organised in accordance with pre-defined criteria (for example alphabetical order). It also doesn’t matter how the data is stored – in an IT system, through video surveillance, or on paper; in all cases, personal data is subject to the protection requirements set out in the GDPR.

 

 I recomend checking out the Server & Data Center GDPR Support GuideServer & Data Center GDPR FAQ we have put together to help out in understanding how certain product features and functionality can support your GDPR compliance requirements.

Regards,
Earl

Suggest an answer

Log in or Sign up to answer
TAGS
Community showcase
Posted in Jira Core

How to manage many similar workflows?

I have multiple projects that use variations of the same base workflow. The variations depend on the requirements of the project or issue type. The variations mostly come in the form of new statuses ...

3,388 views 11 5
Join discussion

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you