Atlassian
Technology & SaaS
Clear age threshold of 16 with commitment to delete data if child discovered and restriction on sales/sharing for under-16s. Proactive child protection measures though no parental consent mechanism described. Overall: Good with minor gaps.
10 dimensions · 71 claims · assessed 11 May 2026 · methodology · source policy ↗
Score Breakdown
Transparency
Good with minor gaps
7.67/107.67/10
Transparency
Good with minor gaps
Transparency & Clarity
8/10Comprehensive scope statement, clear contact information, table of contents, multiple language availability, and version control with effective dates. Strong transparency measures with specific contact details for different regions.
Purpose Limitation & Use
7/10Clear primary purposes stated with secondary use disclosure and AI/ML applications detailed. Marketing opt-out available and consent required for additional uses, though purpose limitation commitment could be more explicit.
Policy Maintenance & Accountability
8/10Strong policy maintenance with multiple notification methods for changes, version history archive, designated privacy contacts including regional representatives, and legal update subscription service. Clear governance framework with specific contact details.
Data Protection
Good with minor gaps
7.11/107.11/10
Data Protection
Good with minor gaps
Data Collection Disclosure
7/10Detailed enumeration of data types collected through direct, automatic, and third-party methods with legal basis disclosure for EEA/UK. Good specificity on collection methods and sensitive data handling, though some categories remain broad.
Third-Party Sharing & Disclosure
8/10Comprehensive disclosure of sharing categories with specific purposes, contractual protections for service providers, detailed partner network sharing, and clear consent mechanisms. Strong coverage of government disclosure practices and business transfer scenarios.
Data Security
5/10Generic 'industry standard' measures with acknowledgment of limitations and some specific authentication measures. Includes security monitoring and payment processing security, but lacks specific encryption details or certifications.
Cross-Border Data Flows
9/10Comprehensive coverage with specific adequacy mechanisms (Data Privacy Framework, standard contractual clauses), named certified entities, onward transfer liability provisions, and reference to country list. Exceeds minimum requirements with detailed safeguards.
Your Rights
Good with minor gaps
6.6/106.6/10
Your Rights
Good with minor gaps
Consumer Rights & Control
7/10Clear access, correction, and deletion rights with multiple mechanisms for exercising rights including online settings and formal requests. Marketing opt-out and consent withdrawal available, though response timeframes not specified.
Automated Decision-Making
6/10Good disclosure of AI/ML usage in various contexts including customer support and security monitoring. Profiling for personalization disclosed, but lacks specific opt-out mechanisms for automated decisions and human review rights.
Children's Data
7/10Clear age threshold of 16 with commitment to delete data if child discovered and restriction on sales/sharing for under-16s. Proactive child protection measures though no parental consent mechanism described.
Sector Comparison
Technology & SaaS comparison