# BaFin Compliance for Atlassian Cloud – What Financial Institutions Need to Know Now

> New EU FSA rules effective December 2024 for BaFin compliance with Jira and Confluence Cloud – with checklist and real-world example.

Source: https://www.xalt.de/en/blog/bafin-compliance-atlassian-cloud-migration/

TEAM XALT Atlassian Platinum Partner · 2 July 2026 · 8 min

Imagine your IT department has the perfect case for Atlassian Cloud: lower operating costs, automatic updates, no infrastructure to manage. Then the compliance department steps in and the project stalls. BaFin requirements, EBA guidelines, DORA: for banks, insurers, and FinTechs, Atlassian Cloud has long sounded like a regulatory obstacle course.

What was once a valid concern looks very different today.

Atlassian has specifically addressed the concerns of regulated institutions with the EU Financial Services Addendum and a structured compliance framework. In this article, you'll get a clear overview of what this means in practice and how, as an IT leader, you can plan your path to the cloud while remaining fully compliant.

## Why financial institutions hesitate on cloud migration

The reluctance toward cloud solutions in the financial sector is well justified from a regulatory perspective. The EBA (European Banking Authority) and BaFin (Federal Financial Supervisory Authority) treat cloud services as outsourcing with far-reaching obligations:

- **Audit rights:** The institution must be able to audit the cloud provider and its subcontractors.
- **Right to issue instructions:**Clear rules on who is authorized to do what with the data.
- **Data security and data location:**Where is data processed and stored?
- **Exit clauses:**What does the exit process look like if the contract ends or the provider becomes insolvent?
- **Chain outsourcing:**Subcontractors of the cloud provider must also meet the requirements.

BaFin is regarded as one of the most demanding national regulatory authorities within the EU. Its guideline on outsourcing to cloud providers, last updated in February 2024 with an explicit reference to DORA, contains requirements that go beyond the EBA guidelines.

> According to the [Capgemini World Cloud Report Financial Services 2025](https://www.capgemini.com/insights/research-library/world-cloud-report-financial-services-2025/) – a survey of 600 banking and insurance decision-makers – only 12% of financial institutions worldwide are true cloud innovators that consistently leverage the cloud for competitive advantage. The majority still struggle to translate cloud investments into measurable business value. The most common reason is a lack of a regulatory foundation for migration.

## What Atlassian has changed since 2021

**EU Financial Services Addendum (EU FSA):**Since December 2021, Atlassian has offered this contract addendum to qualifying European financial service providers. The EU FSA contractually ensures compliance with the requirements of the EBA and BaFin regarding cloud outsourcing.

With the EU FSA, you as an institution receive:

- Comprehensive audit rights for you, your auditors, and regulatory authorities, including downstream for AWS as the infrastructure provider
- Enhanced record-keeping and reporting obligations on Atlassian's part
- Obligation to cooperate with the customer's regulatory authorities
- Service continuity following termination or insolvency

**[DORA (Digital Operational Resilience Act)](https://www.atlassian.com/trust/compliance/resources/dora):**Binding for all EU financial institutions since January 17, 2025. Atlassian supports affected institutions through a robust contractual framework, compliance evidence, and transparency regarding security practices.

**[BaFin Outsourcing Guidance](https://www.atlassian.com/trust/compliance/resources/bafin):**Atlassian publishes a specific mapping document showing how Atlassian Cloud Enterprise addresses individual BaFin requirements.

Atlassian provides the regulatory foundation: contract, certifications, and documentation. Responsibility for configuration and data management lies with the institution.

## In 4 Steps to a BaFin-Compliant Atlassian Cloud

### Step 1: Check the Prerequisites for the EU FSA

The EU FSA is not available to every customer. Prerequisites:

- Status as a European financial services institution (bank, insurance company, or qualified FinTech in the EEA or UK)
- Enterprise Edition of Confluence Cloud, Jira Software Cloud, Jira Service Management Cloud, or Jira Align Cloud
- MSA agreement with a minimum spend of EUR 150,000; request via the Atlassian Partner Service Desk

### Step 2: Bring Compliance On Board Early

This is the most common mistake in practice: IT plans the migration, and Compliance finds out six weeks before go-live. Do it the other way around. Start with a mapping session between IT, the compliance team, and the data protection officer. Clarify upfront:

- Which data is processed in Jira/Confluence, and what classification does it have?
- Which outsourcing approvals do you need internally?
- Are there existing internal policies for cloud services that need to be updated first?
- Which data may be processed for which purposes?

### Step 3: Map BaFin Requirements Against Atlassian Controls

Atlassian's [BaFin Outsourcing Guidance](https://www.atlassian.com/trust/compliance/resources/bafin)provides the precise mapping. The key areas:

- **Audit rights:**Atlassian grants inspection rights also downstream at AWS
- **Data security:**ISO 27001, SOC 2, SOC 3, and [BSI C5 certified](https://www.atlassian.com/trust/compliance/resources/c5); Data Residency for EU available
- **Incident Report:**72-hour standard for security incidents embedded in the Atlassian DPA
- **Exit Management:**EU FSA ensures service continuity even in case of termination or insolvency

### Step 4: Document everything as an evidence package

- Completed outsourcing register with the EU FSA as contractual evidence
- Mapping document: BaFin requirements vs. Atlassian controls
- Configuration documentation of all admin settings
- Incident Response Matrix
- Regular review schedule (at least annually)

## DORA from 2025: What changes for Atlassian users

For Atlassian users, DORA means five key action areas:

- **ICT Risk Management:**Clear frameworks for risk identification and control
- **Incident Reporting:**Standardized reporting processes for ICT disruptions
- **Resilience Testing:**Regular penetration tests and stress tests
- **Third-Party Management:**Monitoring and oversight of critical ICT service providers
- **Information Sharing:**Voluntary sharing of cyber threat information

## Conclusion: Key takeaways for IT leaders in the financial sector

- **The EU FSA makes Atlassian Cloud fit for regulatory use**(available to qualifying financial institutions since 2021)
- **DORA has been mandatory since January 2025**(Atlassian provides the framework agreement)
- **Shared Responsibility:**Atlassian provides the foundation, you provide the configuration.
- **Engaging compliance early accelerates projects**(not the other way around)
- **The Enterprise Edition is a prerequisite for the EU FSA**

You're planning a migration to the Atlassian Cloud and want to comply with BaFin, EBA, and DORA from the very beginning? XALT supports you from the regulatory assessment through to an audit-ready cloud environment.

[**Request a BaFin Compliance Assessment Now**](https://www.xalt.de/en/contact/)

## FAQ: Atlassian Cloud and BaFin Compliance

**How does Atlassian support compliance with BaFin BAIT requirements?**
Atlassian offers through the **Financial Services Addendum (FSA)** and the **EU Data Residency**the necessary contractual and technical foundations. The Atlassian Trust Center also provides specific compliance mappings for German financial institutions to meet the requirements of BAIT and MaRisk.

**Is the Atlassian Cloud DORA-compliant for banks in Germany?**
Yes, Atlassian is actively preparing for the [**Digital Operational Resilience Act (DORA)**](https://www.atlassian.com/trust/compliance/resources/dora). They already provide the necessary transparency and audit rights as well as security certifications (ISO 27001, SOC 2) required for ICT third-party risk management under DORA.

**What is the Atlassian Financial Services Addendum (FSA)?**
The FSA is a contract addendum for clients in the financial sector. It contains specific clauses on audit rights, disclosure obligations, and subcontractor oversight to meet the requirements of BaFin and the EBA (European Banking Authority).

**Can I use Atlassian Jira and Confluence Cloud with BSI C5?**
Yes, Atlassian Cloud products have a [**BSI C5 certification**](https://www.atlassian.com/trust/compliance/resources/c5) (Cloud Computing Compliance Controls Catalogue). This is essential for German companies to demonstrate the security of their cloud infrastructure to regulatory authorities. XALT has already successfully migrated clients (such as AKDB) to a C5-compliant environment.

**Where can I find the current audit reports for my risk analysis?**
All relevant [certifications](https://www.atlassian.com/trust/compliance/resources), SOC reports, and compliance attestations are centrally stored in the **Atlassian Trust Center**. Some detailed reports can be requested directly through the compliance portal.

## More articles

### [Personal AI Agents Compared: Rovo, OpenClaw, and Agent SDKs Like Claude or OpenAI](https://www.xalt.de/en/blog/personal-ai-agents-compared-rovo-openclaw-and-agent-sdks/)

Rovo, OpenClaw, or Claude/OpenAI: how personal AI agents differ in 2026 and which approach fits your team.

*Atlassian*

### [Atlassian Team '26 Recap: The Shift to the AI-Native Organization and the Role of the Teamwork Graph](https://www.xalt.de/en/blog/atlassian-team-26-recap-teamwork-graph/)

XALT was on the ground at Atlassian Team '26 in Anaheim. Our recap covers the Teamwork Graph, Rovo, and the new Teamwork, Service, Product, Software, and Strategy Collections – and what it means for enterprises in Germany.

*Atlassian*

### [Atlassian Is Changing Data Use for AI as of August 17, 2026: Your Checklist](https://www.xalt.de/en/blog/atlassian-changes-ai-data-use-checklist/)

Atlassian is updating its data-use policy for AI and rolling out new data contribution settings. What admins need to know and do before the August 17, 2026 deadline – including a 6-step checklist.

*Atlassian*

---

*This version is for AI agents. Every page of this site is available as Markdown: append `index.md` to its path. Index of all pages: [llms.txt](https://www.xalt.de/llms.txt)*
