Anyone else facing Privacy Shield registration?

Andrew Skomski August 10, 2016

Hi all,

I am reaching out to determine if any other companies using Atlassian are registering for the Privacy Shield and how that is impacting your relationship with Atlassian. For those who aren't fully up to speed, the Privacy Shield is the program replacing the EU-US Safe Harbor standard - basically, it is a new standard that establishes control requirements for US-based companies to implement to protect the personal data of EU citizens. It should be noted that the EU defines personal data very liberally, meaning a simple transfer of an person's name along with their email address would qualify as a transfer of PII and be subject to the Privacy Shield.

 

A key difference in the Privacy Shield compared to the "Safe Harbor" standards is that if you register for Privacy Shield and transfer any EU citizens' data to a third-party, you are responsible to get that third-party to agree contractually to adhere to the Privacy Shield controls. If your use of Atlassian products includes transferring or potentially transferring the personal data of EU citizens to any Atlassian product hosted by Atlassian, you would need Atlassian to agree in your contract to adhere to the Privacy Shield standard of controls.

 

So far, Atlassian has not provided any concrete answer about whether they will be able to support Privacy Shield controls. The only answer they've given me is that they offer the "BTF" (behind the firewall) product where we would basically host our own instance within our own data center or colocation facility. It is my belief that my company is by no means the only Atlassian customer who faces the Privacy Shield registration and I am interested to see what other customers are doing to address this compliance issue. Are any other companies in discussions with Atlassian about getting their agreement to adhere to the Privacy Shield requirements?

 

Andrew

 

 

1 answer

0 votes
Robert Isaksen August 19, 2016

We are considering moving to Confluence online/cloud, but cannot do this since Atlassian don´t support Privacy Shield. Here is the answer from Atlassion, which will have big consequenses for European countries using Atlassion cloud:

 

Confluence Cloud, JIRA Cloud, and Bitbucket Cloud are hosted on servers located at our data centers (provided by NTT) in the United States. HipChat is hosted using Amazon Web Services (AWS).

Like many other companies offering cloud products, Atlassian is adjusting to the European Court of Justice's recent decision on October 6, 2015 that invalidates the Safe Harbor framework. In the short term, Atlassian recommends that customers who are concerned about the transfer of personal data from the EU to the US migrate from our Cloud products to our Server (i.e. downloadable software) products. Atlassian's downloadable software allows a customer's personal data to sit on servers controlled by that customer.

Suggest an answer

Log in or Sign up to answer