
Implementing the right to be forgotten in Confluence in accordance with the GDPR
Since the GDPR came into force, it must be possible to delete or amend both customer and employee data in such a way that it is no longer possible to trace it back to its source
Implementing the GDPR with Confluence
Article 17 states, amongst other things, that a data subject has the right to request that the controller erases personal data relating to them without delay if the personal data is no longer necessary for the purposes for which it was collected, or the data subject withdraws their consent to the processing of the data. Similarly, a controller who has made the personal data public must erase that data, taking into account available technologies and the costs of implementation.
Consequently, software providers have been obliged, at the very least since the GDPR came into force, to delete both customer and employee data, or to modify it in such a way that its origin can no longer be traced.
Pseudonymisation and anonymisation as ways of implementing the GDPR
Personal data
Max Mustermann appoints Sabine Schmidt as the company’s internal data protection officer.
Pseudonymised data
Sabine Schmidt, the company’s internal data protection officer, can be reached on staff number 1026.
Anonymised data
Sabine Schmidt has been appointed as the company’s internal data protection officer.
Handling the GDPR in Confluence
Since Confluence 6.13, Atlassian has offered pseudonymisation as a standard feature. This allows administrators to delete user data. As a result, the account, profile picture and personal details are removed, and the name is replaced with a code. In this example, the pseudonym is User-efb38. This name then appears on every page, comment, mention and so on.
However, with sufficient effort, it would be possible to identify the user. This could therefore infringe the right to be forgotten.
With the User Anonymizer for Confluence, on the other hand, it is possible to delete the relevant user data from the system in such a way that it can no longer be traced back. This deletion affects all personal data, areas, pages, preferences, comments, mentions and macros belonging to the target user. To implement the right to be forgotten in Jira in a GDPR-compliant manner, you can use the User Anonymizer for Jira.
As neither the anonymised names are temporarily stored in separate files nor are any codes generated, the user data is permanently deleted and can no longer be traced. The right to be forgotten is thus fulfilled.
Conclusion

Since the GDPR came into force, software companies and their technologies have been obliged to delete customer and employee data or to alter it in such a way that its origin can no longer be traced. This can be achieved in Confluence using the User Anonymizer for Confluence. This app is also available for Jira, to ensure compliance with the GDPR guidelines there as well.
You can find more information about the products here:
We’d be happy to advise you on how to use Atlassian products
Arrange a personalised, no-obligation consultation with our Atlassian sales experts.

Your contact person
Your Atlassian Sales TeamWe're happy to help you
- Kleiststraße 10a, 01129 Dresden, Germany
- Tel: 0800 8 776 776
- sales@communardo.de



