Atlassian has had a clear cloud-first strategy for its products, such as Jira and Confluence, for some time. As a customer, you benefit from significantly shorter innovation cycles with significantly reduced maintenance costs. In concrete terms, this means:
Regardless of whether you already use Atlassian cloud products or are planning to switch, our cloud updates summarize the most important new features of the Atlassian Cloud.
In this article, we focus on data protection and information security from a Swiss perspective.
Atlassian has developed a structured cloud migration process with its solution partners. We're with you all the way with our technical expertise and migration experience.
Our free Cloud Readiness Assessment is the perfect start. This provides you with answers to questions such as:
As a Swiss Atlassian Platinum Solution Partner, it is important to us to focus on the needs and requirements of our Swiss and European customers. For this reason, we deliberately focus on the topic of information security in SaaS solutions and the Atlassian Cloud in this blog post.
When it comes to information security, dividing it into the following subject areas helps:
The relevance and application of legal principles depend initially on three issues:
It is important to know which data you will be keeping in your Atlassian cloud. Once you have an overview of the data stored in your Atlassian Cloud, you can categorize it according to the following aspects:
Basically: Is it exclusively non-personal data or do you also process personal data? If yes, then there are certain legal and regulatory requirements.
Private companies
Private companies in Switzerland belong to Swiss Federal Act on Data Protection insinuates. If you offer products or services on the European market, you must also consider the market location principle. In this case, the European GDPR also applies (Article 3 of the Regulation).
The following aspects are relevant to the storage of personal data:
financial institutions
Atlassian is constantly investing in legal and regulatory compliance in Europe. The requirements of the following authorities are currently being met (among others):
Swiss financial institutions are primarily subject to the Financial Market Supervisory Authority (FINMA). Customer-identifying data (CID) represents a particular need for protection. This protection is governed by bank client secrecy. For a long time, CID data was not allowed to leave Switzerland in accordance with the “over-the-border out-of-control principle.”
However, since the FINMA guidelines were amended, this principle no longer applies in principle. As soon as the following elements are met, bank customer data can be stored in the cloud:
Administration & authorities
As a cantonal or municipal administration or authorities, you are subject to the data protection legislation of your canton. Key aspects for possible storage of personal data in the cloud are:
In accordance with the legal principles described above, data storage is often relevant.
Atlassian therefore offers the option of explicitly defining the location of data storage for all cloud plans (Standard, Premium, Enterprise). This option is available free of charge.
Atlassian has already taken various measures to secure your data:
Take further steps to ensure the integrity of your data.
Atlassian Access is required to use these options. Benefit from other security features that are available with Access (e.g. IP whitelisting)
The information is extensive and sometimes complex. We are happy to help you use the possibilities of the cloud to your advantage.
Would you like to use our expertise and implement technological innovations?
Do you have a question or are you looking for more information? Provide your contact information and we'll call you back.