For Atlassian Cloud and Data Center
Data Protection Toolkit: GDPR, PII & DLP for Confluence
Last reviewed: 18 August 2026
Data Protection Toolkit: GDPR, PII & DLP for Confluence is an Atlassian Marketplace app that finds, redacts and anonymizes personal data (PII) in Confluence, on both Atlassian Cloud and Data Center. DPOs, compliance officers and Confluence admins use it to meet GDPR/DSGVO, HIPAA, CCPA and LGPD obligations, scanning pages, blog posts, comments, attachments and page history, then redacting or removing what it finds, in bulk and on a schedule. Discover all features in our documentation and say hello to risk-free data protection.
62 built-in detection patterns covering 27 countries, including 32 national identification formats (German Steuer-ID and Rentenversicherungsnummer, Austrian ZMR-Zahl, Italian Codice Fiscale, Polish PESEL, French INSEE, both Swiss AVS formats, British NINO and NHS numbers and more) and 20 country-specific phone formats, alongside email addresses, IBANs, credit cards, UUIDs and IP addresses. Need something else? Write your own RegEx rule, or let Actonic build, test and hand it over free of charge.
Formerly known as Data Protection and Security Toolkit for Confluence, and previously as GDPR (DSGVO) and Security for Confluence. Published on the Atlassian Marketplace by Actonic Products GmbH.
One toolkit for every data protection job in Confluence
Because editing pages one at a time is slow and misses things
Redact and replace personal data on Confluence pages, in bulk
Do you want to ensure, for example, the “right to be forgotten” according to article 17 GDPR/DSGVO in Confluence? Or de-identficate Confluence users as you should for HIPAA or CCPA? With just a few clicks, you can automatically anonymize and clean all personal data (PII). Transferring content ownership from one user to another user or when migrating from one to another account has never been so easy!
Collect and prove consent inside Confluence
Quickly and easily create announcements in Confluence that no one can overlook. It’s the perfect way to communicate data privacy policies and get consent. You can also send reminders for deadlines, cookies, or release notes. Choose the target audiences, the size of the Confluence announcement banner, and the position completely flexibly without any HTML knowledge. Clear statistics help you organize personal data.
Anonymize everything a user or space contains in Confluence
Planning a cleanup before a retention deadline, a space archive or a Cloud migration? Anonymize the content first, so what moves is already clean. The same applies before you open a space up to contractors or external collaborators.
What else the toolkit gives a Confluence admin
As a Confluence administrator, you’ll love this possibility to view thousands of current and historical permissions, manage profile visibility or export users. If you’re a data protection officer, you always need to know how to detect personal data and fix non-compliance to GDPR/DSGVO, CCPA, HIPAA, LGPD or more before any breaches are made. After all, you don’t want to risk heavy penalties. Here, you can easily detect and automatically change personal data such as passwords, API keys, credit card numbers and more.
Publish a policy notice and record who accepted it
You can easily communicate privacy policy announcements and get consent. Choose the target audiences, the size of the Confluence announcement banner, and the position completely flexibly without any HTML knowledge. Clear statistics help you organize personal data.
Find personal data in pages, blog posts and attachments
Do you want to ensure, for example, the “right to be forgotten” according to article 17 GDPR in Confluence? To anonymize Confluence users, you first need to find them. A clear user interface lets you find any personal data. Easily safeguard all data subjects’ privacy rights!
Find every page, comment and attachment a user touched
You can easily search for personal data with a pattern-based search and regular expressions. If any data matches the rule in this ticket/page, you’ll see the table with all found items right in the Check issue/page matches window.
Catch personal data in Confluence before it becomes a breach
As a Confluence administrator or data protection officer, you always need to know how to detect personal data and fix non-compliance before any breaches are made, which are followed by heavy penalties. Here you can easily detect and manually change personal data such as passwords, API keys, credit card numbers and more.
Want a short excursion? Discover information on data protection, data residency, AWS and much more easily explained in our knowledge base.
Everything a Confluence admin needs for GDPR, in one app
Maximum data protection and minimal time investment meet here. This Data Protection Toolkit for Confluence is unique in the Atlassian ecosystem worldwide because it can fully support compliance to any data protection law.

Your benefits with Data Protection Toolkit for Confluence
- Benefit from daily updated statistics
- Avoid human errors caused by manual updates
- Covers any data protection laws such as CCPA, HIPAA, GDPR/DSGVO or LGPD
- Collect consent for data processing easily
- Advantages beyond data protection (for announcements, authorizations, etc.)
- Save time and ensure risk-free data protection
Do you want to know what data privacy laws exist around the world and how to master their compliance? Then discover our up-to-date overview of the most important global data protection laws!
Data Protection Toolkit at work in Confluence
Clean personal data out of pages and page history
In this tutorial, discover how to create custom templates to search sensitive data, automate scans, and define actions such as sending mail or alerts.
Notify users when your data processing changes
Data privacy policies, server maintenance, and consent forms: In our tutorial, we show how you can comprehensively notify your users.
Explore every Data Protection Toolkit module for Confluence
In this tutorial, discover how to create custom templates to search sensitive data, automate scans, and define actions such as sending mail or alerts.
You are currently viewing a placeholder content from YouTube. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationData Protection Toolkit for Confluence: frequently asked questions
Data Protection Toolkit is an Atlassian Marketplace app that finds, redacts and anonymizes personal data inside Confluence, on both Atlassian Cloud and Data Center. It scans pages, blog posts, comments, tables, page history and attachments against a built-in library of 62 detection patterns covering 27 countries, or against your own regular expressions, then redacts, replaces or anonymizes what it finds, in bulk and on a schedule. It also handles user and space anonymization for right-to-erasure and data subject access requests, and includes consent forms with acceptance tracking so you can prove consent rather than assume it.
Formerly known as Data Protection and Security Toolkit for Confluence, and previously as GDPR (DSGVO) and Security for Confluence. Published on the Atlassian Marketplace by Actonic Products GmbH.
It is built for the people who are accountable when personal data turns up somewhere it should not be: Data Protection Officers, IT security managers, compliance teams and Confluence administrators. Confluence is a common blind spot because personal data arrives informally, in meeting notes, HR and onboarding spaces, customer tables, and CVs or contracts attached to a page, and it stays in page history after the page itself is cleaned. It works on a single space and on enterprise-scale instances.
Free on Atlassian Cloud for up to 10 users. Above that it is priced per user: USD 100 per month for 100 users and USD 395 for 500. Confluence Data Center is an annual subscription starting at the 500-user tier. Every module is included at every tier, there is no feature-gated edition. See the full pricing breakdown.
GDPR applies to any organisation that processes the personal data of people in the EU, whether or not it has an establishment there. Confluence is usually in scope because it accumulates personal data quietly: meeting notes with attendee names, HR and onboarding spaces, customer lists in tables, CVs and contracts as attachments. The obligations that bite are the right to erasure and being able to demonstrate you carried it out, including in page history. For the wider picture, see our orientation guide to data privacy laws worldwide.
The California Consumer Privacy Act, in force since 1 January 2020 and expanded by the CPRA, covers for-profit businesses handling the personal information of California residents above set revenue or volume thresholds. For Confluence the hard part is disclosure: answering what personal information you hold about one person means searching every space, including personal spaces and archived content, not just the ones you remember. Compare CCPA with the other major privacy laws.
HIPAA covers US healthcare providers, health plans, clearing houses and the business associates that process protected health information on their behalf. Confluence pages documenting clinical processes, incident write-ups or anything carrying patient identifiers in a table or an attached file count as PHI, and need restricted access, detection of anything that lands in the clear, and removal on request. See how HIPAA sits alongside GDPR and CCPA.
The Server and Data Center versions are identical. However, only a few modules are implemented in the Cloud version due to the limitations of the Cloud API.
The Jira and Confluence versions are similar, all modules are the same, but new features appear first in the Jira version and then in the Confluence version. Want to make sure your Confluence Cloud version is data privacy compliant? Then feel free to contact our Data Protection compliance service.
No. The app allows you to automate common data protection tasks, such as obtaining consent, anonymizing personal data, or investigating security breaches.
We advise you to consult your legal team about the data security requirements in your specific situation, refine the processes and then configure the app to automate most of your activities and cover all your needs.
We are happy to help you with the configuration, just contact us!
Confluence’s own anonymization changes the user account, not the content. The person’s name stays in page titles and bodies, in comments, in mentions that have been rendered as plain text, in tables, in blog posts and in page history, and it does not touch attachments at all. The Data Cleaner module finds those remaining instances by pattern, anonymizes users who were already deactivated, and logs what it changed so you can evidence that the request was completed.
Yes. Every question a security or procurement review normally asks is answered on our security and technical FAQ: what data the app accesses, what it stores and does not store, tenant isolation, encryption, security testing cadence, incident contact, browser support and licence tiering. The short version: on Cloud, scanning happens in the user’s browser and no personal data is stored by us. Actonic Products GmbH is ISO 27001 certified. Note that the app does not currently support Atlassian data residency.
No personal data is stored or passed on to third parties in our Cloud apps. We keep only meta and configuration data under an anonymized user ID. The apps fetch all relevant data from the Cloud and calculate all data directly in the user’s browser.
For more information, please refer to our Privacy Policy.
Both versions of Data Protection Toolkit (Jira and Confluence) are available over SSL only. We use a valid (not a self-signed) browser-trusted certificate without any human intervention. All the communications between “Client ↔︎ Jira (or Confluence) application ↔︎ Our app” are encrypted.
As a part of our internal audit process, once per quarter.
Enterprises that trust Actonic for data privacy
These companies are already using Data Protection Toolkit for Confluence successfully:

“For an important customer, we wanted to implement Confluence in a data protection-compliant way. Actonic supported us with detailed tips and trainings on their self-developed data protection add-on. In very close and trusting cooperation, we managed to meet our customer’s specific requirements to their complete satisfaction. We can’t wait to develop further smart solutions with Actonic!”
Anna Christina Schildberg
Atlassian-Consultant, Scolution GmbH & Co. KG


Migrating from Data Center to Cloud?
Continue protecting your data after migration. We offer a 12-week free trial, 20% first-year discount, and a dedicated onboarding specialist to rebuild your configuration in Cloud.





