Starting August 17, 2026, Atlassian is changing its data processing. As an Atlassian partner, we say: We need to address this.

- Starting August 17, 2026, Atlassian will use customer data for AI training. Approximately 300,000 companies worldwide are affected – those who do not actively object are included automatically.
- In-app data can be disabled on any plan. This is done under Atlassian Administration > Security > Data contribution and should be completed before August 17, 2026.
- For metadata, there is no opt-out for Free, Standard, and Premium customers. Those who cannot accept this for regulatory or ethical reasons should ask a more fundamental question: Is Atlassian Cloud still the right tool?
- Data protection must not be a premium feature. We say this as an Atlassian partner – and are available for honest consulting on what really fits you.
First off: We are an Atlassian partner. We value the products and stand behind the ecosystem. But for us, a partnership also means having the right to name uncomfortable things. And this change is uncomfortable. Starting August 17, 2026, Atlassian will use customer data to train its AI products, primarily Rovo. Approximately 300,000 companies worldwide are affected. Those who do not take active action are included automatically.
Two data categories, one problem
Atlassian distinguishes between metadata and in-app data. Metadata sounds more harmless than it is. Atlassian emphasizes that this data will be “de-identified and aggregated,” meaning names and email addresses are removed. A crucial detail here is that, according to Atlassian, aggregation occurs “at the customer level” — with the stated goal of gaining “deeper insights into customer behavior.” Individual users disappear, but the company as an evaluation unit remains.
What accumulates at this level is an surprisingly precise blueprint. Story points and sprint end dates show how fast teams work and under what pressure. SLA values reveal which response times a company has promised its customers. Task classifications like “Sales Work Item” reveal what departments are working on. And via the so-called Teamwork Graph, relationships between people, documents, and processes are captured, provided corresponding connectors are enabled. Even without clear names, roles, groups, and workflows remain recognizable.
In-app data comprises the actual content: Confluence pages, Jira ticket titles, descriptions, and comments. In other words, what teams produce daily: decisions, concepts, customer cases, security incidents.
Whether this data usage is compatible with the GDPR has not been legally clarified. In our view, much suggests that Atlassian could become a controller rather than a processor for this processing — with the consequence that a separate legal basis would be required. A final assessment is pending and should be checked on a case-by-case basis. Regardless, it is worth considering whether you want to share this data or not.

Data protection, equal for everyone?
Different rules apply depending on the purchased plan.
Free and Standard: Metadata is always collected, no opt-out possible. In-app data is enabled by default but can be disabled.
Premium: Metadata also without opt-out. In-app data is disabled by default but can be enabled.
Enterprise: Both categories can be completely disabled.
Those who pay less have less control over their own data. In the result, it appears as if larger companies have more data worthy of protection than smaller ones. We consider this assumption questionable.
But is that true? A small law firm on a Standard plan handles highly sensitive client matters in Jira. A tax advisory firm documents confidential financial strategies in Confluence. A non-profit organization manages vulnerable persons in its tickets. All these organizations must actively object, while a large corporation with possibly less sensitive data is protected by default simply because it can afford an Enterprise plan.
Either you handle data responsibly or you don’t. The customer’s account balance should not play a role here. This is not a data protection strategy; this is data protection as a premium feature.
What to do now
Immediate measure for all plans: In-app data can be disabled on any plan, under Atlassian Administration > Security > Data contribution. This should be done before August 17, 2026.
For metadata, there is no opt-out option for Free, Standard, and Premium customers. Those who cannot accept this for regulatory, legal, or ethical reasons must ask a more fundamental question: Is Atlassian Cloud still the right tool?
For organizations in regulated industries, we recommend involving your own data protection officer and obtaining written clarification from Atlassian. The new Data Processing Agreement also comes into force on August 17.
Conclusion
We say this as a partner, not an opponent: Atlassian, this model is inconsistent. Whoever understands trust as the foundation of a partnership protects all customers equally, regardless of what they pay.
We need to talk about data protection. As a fundamental right. Not as an Enterprise feature.
Those who, in light of this development, ask about the right path: The answer depends on your requirements – not on a product. Atlassian Cloud makes sense where compliance and flexibility allow it. Where full data control is required, there are alternatives like Plane in the On-Premise version. We advise you on what really fits you. Feel free to contact us.