Administration and maintenance

Privacy and data erasure

Purpose

The app processes personal data (account names in roles, RACI fields, document-control logs). Under Setup & ConfigurationLicense & advanced → card Privacy — personal data, administrators control retention and run erasure requests under GDPR Art. 17.

Who can do this

Jira administrators only.

Background

The app reports stored accounts to Atlassian daily and processes account closures itself. The card shows the number of accounts in the register and open jobs. An erasure request can additionally be triggered manually here — it takes effect immediately instead of waiting for the daily run.

Setting the retention period

  1. In the Retention period section, enter the period in years and click Save period.

The period determines how long the pseudonymous evidence key (account id without a name) is kept after an account closure. Your organisation makes this decision as the controller, not the vendor. Default: certification cycle plus one follow-on cycle.

Setup & Configuration: card “Privacy — personal data” with the “Retention period” section (input in years, “Save period”) and the “Run an erasure request” section.

Running an erasure request (GDPR Art. 17)

  1. In the Run an erasure request section, search for the person (Search person, at least 2 characters).
  2. Click Check records — the card shows since when the person is in the register and which sources are affected. A run is possible even without a register entry; it scans all records.
  3. Click Erase this person's data and confirm: “Display names and comments of this person will be removed from all app records. This cannot be undone. Continue?”

Expected result

The person’s display names and self-authored comments are removed from all app records. The evidence that and when decisions were made is kept pseudonymously — it is your ISO 27001 proof.

Screenshots from the development environment with sample data.

Documentation baseline: app version 1.1.15 · 2026-08-20