International data transfers following the Schrems II decision What did the Court of Justice of the European Union recently decide regarding data transfers from the EU? <p>On July 16, 2020 the Court of Justice of the European Union (the Court) invalidated the EU-US Privacy Shield, which was one of the ways for companies to transfer data legally from the EU to the US. At the same time, the Court confirmed that Standard Contractual Clauses (SCCs) continue to provide a valid mechanism for companies to transfer personal data outside the EU.</p> <p>However, we understand the Court stated that the suitability of data transfers under the SCCs may be challenged on a case-by-case basis, and that, in addition to the SCCs, supplementary measures may be necessary to ensure an adequate level of protection. The Court did not clarify what those supplementary measures might be.</p> <p>Privacy and Security are among the highest priorities at Atlassian, and we&rsquo;re closely following the recent Court decision about the EU-US Privacy Shield - and subsequent developments related to the Swiss-US Privacy Shield. We&rsquo;re aware the European Data Protection Board recently issued further guidance on supplementary measures to meet the adequacy requirements of GDPR. We will continue to analyze these requirements and any others issued by European data protection authorities as they arise.</p> What does this mean for Atlassian customers? <p><strong>To address the court&rsquo;s decision, we have updated <a href="/legal/data-processing-addendum">our DPA</a> to include a full copy of the Standard Contractual Clauses (SCCs). Additionally, older versions of our DPA include the SCCs as a fallback data transfer mechanism in the event of invalidation of the Privacy Shield.</strong></p> <p><strong>While these older versions of the DPA should be legally sufficient, we anticipate that many customers will want to take advantage of the new DPA. If you wish to update to the latest DPA, please follow the instructions <a href="/legal/data-processing-addendum">here</a>.</strong></p> <p>We remain committed to ensuring our customers&#39; data is protected with the utmost care and in compliance with applicable data privacy laws and requirements.</p> How does Atlassian ensure that data remains protected outside of Europe? <p>Atlassian has put in place a number of measures to ensure that EU, UK and Swiss data remains protected when it is transferred outside of Europe.</p> <p>In addition to incorporating the SCCs, our DPA also sets out Atlassian&rsquo;s commitments to confidentiality, security of processing, customer controls and how Atlassian helps to notify of incidents, and helps our customers honor data subject rights. The combination of the Atlassian DPA, SCCs, security commitments and additional measures continues to offer our customers a robust level of protection.</p> <p>Please also note that Atlassian:</p> <ul> <li>already encrypts data in transit and at rest (see <a href="/trust/security/security-practices#encryption-and-key-management">here</a> for more information)</li> <li>publishes an annual <a href="/trust/privacy/transparency-report">Transparency Report</a> with information about government requests for users&#39; data as well as government requests to remove content or suspend accounts</li> <li style="margin-bottom: 24px">provides additional information about our policies and procedures for responding to requests for user data in our <a href="/trust/privacy/guidelines-for-law-enforcement">Guidelines for Law Enforcement</a>. Atlassian responds to government requests in accordance with our <a href="/legal/privacy-policy">Privacy Policy</a>, <a href="/legal/cloud-terms-of-service">customer agreements</a>, <a href="/legal/acceptable-use-policy">Acceptable Use Policy</a>, and any applicable <a href="/legal/product-specific-terms">Product-Specific Terms</a>.&nbsp;Your trust is important to us, and we will continue to prioritize transparency around our practices moving forward.</li> </ul> <p>We&rsquo;re closely monitoring the developments following the Court&rsquo;s decision to determine whether we need to make any additional changes to our privacy practices.</p>