Implementing the right to be forgotten in Confluence in accordance with the GDPR

Since the GDPR came into force, it must be possible to delete or amend both customer and employee data in such a way that it is no longer possible to trace it back to its source

Implementing the GDPR with Confluence

Article 17 states, amongst other things, that a data subject has the right to request that the controller erases personal data relating to them without delay if the personal data is no longer necessary for the purposes for which it was collected, or the data subject withdraws their consent to the processing of the data. Similarly, a controller who has made the personal data public must erase that data, taking into account available technologies and the costs of implementation.

Consequently, software providers have been obliged, at the very least since the GDPR came into force, to delete both customer and employee data, or to modify it in such a way that its origin can no longer be traced.

Pseudonymisation and anonymisation as ways of implementing the GDPR

  1. Personal data

    Max Mustermann appoints Sabine Schmidt as the company’s internal data protection officer.

  2. Pseudonymised data

    Sabine Schmidt, the company’s internal data protection officer, can be reached on staff number 1026.

  3. Anonymised data

    Sabine Schmidt has been appointed as the company’s internal data protection officer.

Handling the GDPR in Confluence

Since Confluence 6.13, Atlassian has offered pseudonymisation as a standard feature. This allows administrators to delete user data. As a result, the account, profile picture and personal details are removed, and the name is replaced with a code. In this example, the pseudonym is User-efb38. This name then appears on every page, comment, mention and so on.

However, with sufficient effort, it would be possible to identify the user. This could therefore infringe the right to be forgotten.

With the User Anonymizer for Confluence, on the other hand, it is possible to delete the relevant user data from the system in such a way that it can no longer be traced back. This deletion affects all personal data, areas, pages, preferences, comments, mentions and macros belonging to the target user. To implement the right to be forgotten in Jira in a GDPR-compliant manner, you can use the User Anonymizer for Jira.

As neither the anonymised names are temporarily stored in separate files nor are any codes generated, the user data is permanently deleted and can no longer be traced. The right to be forgotten is thus fulfilled.

Conclusion

Implementing the GDPR with Confluence

Since the GDPR came into force, software companies and their technologies have been obliged to delete customer and employee data or to alter it in such a way that its origin can no longer be traced. This can be achieved in Confluence using the User Anonymizer for Confluence. This app is also available for Jira, to ensure compliance with the GDPR guidelines there as well.

You can find more information about the products here:

We’d be happy to advise you on how to use Atlassian products

Arrange a personalised, no-obligation consultation with our Atlassian sales experts.

Marlen Kaiser, Team Leader Customer Acquisition bei Communardo Software GmbH

Your contact person

Your Atlassian Sales Team
We're happy to help you

Book an appointment now