Administration and maintenance
Privacy and data erasure
Purpose
The app processes personal data (account names in roles, RACI fields, document-control logs). Under Setup & Configuration → License & advanced → card Privacy — personal data, administrators control retention and run erasure requests under GDPR Art. 17.
Who can do this
Jira administrators only.
Background
The app reports stored accounts to Atlassian daily and processes account closures itself. The card shows the number of accounts in the register and open jobs. An erasure request can additionally be triggered manually here — it takes effect immediately instead of waiting for the daily run.
Setting the retention period
- In the Retention period section, enter the period in years and click Save period.
The period determines how long the pseudonymous evidence key (account id without a name) is kept after an account closure. Your organisation makes this decision as the controller, not the vendor. Default: certification cycle plus one follow-on cycle.
Running an erasure request (GDPR Art. 17)
- In the Run an erasure request section, search for the person (Search person, at least 2 characters).
- Click Check records — the card shows since when the person is in the register and which sources are affected. A run is possible even without a register entry; it scans all records.
- Click Erase this person's data and confirm: “Display names and comments of this person will be removed from all app records. This cannot be undone. Continue?”
Expected result
The person’s display names and self-authored comments are removed from all app records. The evidence that and when decisions were made is kept pseudonymously — it is your ISO 27001 proof.
Related pages
Screenshots from the development environment with sample data.
Documentation baseline: app version 1.1.15 · 2026-08-20