What Confluence data residency is
Confluence data residency is an Atlassian Cloud feature that lets you choose the geographic location where your site's in-scope Confluence data is hosted. Atlassian calls this pinning: once your Confluence site is pinned to a location, the data Atlassian lists as in scope is held in that location's cloud regions rather than wherever Atlassian finds most efficient.
If you never choose, your site sits in the Global location. Global spans all of Atlassian's hosting regions, and Atlassian decides where the data lives and may move it between regions as it needs to. For many teams that is fine. It stops being fine when a customer contract, a regulator or your own data protection policy says data must stay in a particular country or region.
Two words are worth getting straight before you go further:
- Location is what an admin chooses, for example "EU" or "Australia".
- Region is the underlying cloud hosting region (or regions) that a location maps to. Some locations use one region, some use two.
Which Confluence plans include data residency
Atlassian currently lists data residency for Confluence on the Standard, Premium and Enterprise plans. The Free plan doesn't include it. Atlassian has widened plan eligibility over time, so if you are making a purchasing decision on this point, confirm it against your own plan before you rely on it.
You manage it in Atlassian Administration, under Data management and then Data residency. That page shows where each of your Atlassian apps is hosted today, and moves are requested there by an organization admin.
Atlassian data residency locations
At the time of writing, Atlassian offers these locations for Confluence:
| Location | Hosting region(s) |
|---|---|
| Australia | Sydney |
| Canada | Central |
| EU | Frankfurt and Dublin |
| Germany | Frankfurt |
| India | Mumbai |
| Japan | Tokyo |
| Singapore | Singapore |
| South Korea | Seoul |
| Switzerland | Zurich |
| United Kingdom | London |
| USA | US East (N. Virginia) and US West (Oregon) |
The list grows from time to time, and some features can behave differently in particular locations. Check the current list in Atlassian Administration before you promise a location to anyone.
Tip: Pick the location your contracts actually require, not the one closest to the most people. A clause that says "data stays in the EU" is satisfied by the EU location; a clause that names Germany specifically needs the Germany location.
Where Confluence data is stored: what is pinned and what isn't
This is the part that trips people up. Pinning covers Confluence's content, not everything Atlassian holds about your site. Atlassian publishes the list, and for Confluence it looks like this:
| Data | Pinned to your location? |
|---|---|
| Pages and blog posts, and page metadata | Yes |
| Attachments | Yes |
| Comments, page likes and comment likes | Yes |
| Whiteboards and databases | Yes |
| Confluence search data | Yes |
| In-app notifications and the source data for email notifications | Yes |
| Permission and restriction configuration | No |
| Space keys | No |
| AI data | No |
Beyond Confluence's own list, Atlassian names categories that data residency doesn't cover across its apps. The ones most likely to come up in a review:
- User account information such as names, email addresses and avatars, which live in a central identity service.
- Logs: app, audit and operational logs.
- Analytics about the app and about users.
- Cached content and data in transit, such as emails and notifications, for a limited period.
- Third-party app integration data, which is where Marketplace apps come in (see below).
So the accurate sentence for a contract or a questionnaire is something like "our in-scope Confluence content is pinned to the EU location", not "all our Confluence data is in the EU". The difference matters when a customer's lawyer reads it.
How to choose or move your Confluence location
There are two ways to end up pinned:
- Set a default location. Admins can set a default data residency location for the organization (or site, depending on how your organization is managed). Apps activated after that inherit it, so new sites start out pinned. Some Atlassian apps can only have their location set when they are activated, so set the default before you add products if you can.
- Request a move. For a site that already exists, an organization admin requests a move to a new location from the Data residency page.
What happens during a move
A move is not invisible. Based on Atlassian's current documentation:
- Confluence goes offline when the move starts, and people can't use it until it finishes. Atlassian says a move takes roughly 2 to 24 hours depending on how much data you have.
- You choose the window. Atlassian offers a maintenance window for small moves, a slot within 48 hours, or a custom 24 hour window booked at least three days ahead. The options you see depend on the estimated downtime.
- Unsaved edits are lost. Anything someone is still editing when Confluence goes offline won't be saved. Tell people in advance.
- Search catches up afterwards. Confluence search has to be re-indexed in the new location. That can take a few hours and occasionally up to three days.
- Sandboxes don't move with the site they are linked to.
Treat a move like any other planned change: schedule it, announce it, keep the confirmation, and record it in your change log. If you are working toward a SOC 2 report, that record is evidence that the change was planned and approved.
Data residency and Marketplace apps
Pinning Confluence does not automatically pin every app installed on it. Each Marketplace app stores its own data, and where that data goes depends on how the app is built.
Apps that store data in Forge hosted storage
Apps built on Atlassian Forge can store data in storage Atlassian hosts for them. Atlassian's developer documentation says all persistent Forge hosted storage supports data residency. When such an app is installed on a pinned site, its hosted data is placed in the same location, and when an admin moves the site, the app's hosted data moves with it as part of the same move.
Apps with their own back end
Some apps send data to servers run by the vendor or a third party. That data is under the vendor's control, not Atlassian's. A vendor can support data residency by running its back end in matching regions and declaring that to Atlassian, but you have to check app by app. Some of these apps move after the main site move, as a separate step the vendor handles.
How to see an app's data residency support
- On the Data residency page in Atlassian Administration, apps show a status. Pinned means the app's data is already in your Confluence location. Eligible means the app supports your location and can be moved. Not eligible means it can't be pinned there. No action available means the vendor says the app stores data only in the Atlassian product, or stores none.
- On the Marketplace listing, the Privacy and Security tab describes the app's data residency support, and the vendor's privacy policy should say where data is stored.
Important: One app with a vendor-hosted back end in another region can undo the promise you made about your Confluence site. Before you sign a data location clause, list every installed app and check its status. Repeat the check whenever someone installs a new one.
Atlassian's "Runs on Atlassian" program is a quick signal here. Apps that carry it run on Atlassian-hosted compute and storage, support data residency that matches the host product, and let admins control egress.
Why data residency matters for compliance
Data residency usually shows up in three places:
- Customer contracts. Enterprise customers, especially in the public sector, health and finance, often ask where their data is stored and processed, and some write a location into the contract.
- Regulators and data protection law. Rules on cross-border transfers make some companies prefer to keep personal data in a particular region. Data residency helps, but it is one control among several, and your legal advisers decide whether it is enough.
- Security questionnaires. "Where is our data stored?" and "Which subprocessors handle it?" appear in almost every security questionnaire. Answer with the location, what is in scope, and the apps you have checked.
Data residency is not a SOC 2 requirement in itself. If your system description or your customer commitments name a location, though, your auditor may ask how you keep that promise, and your installed apps belong in the same vendor risk review as any other supplier.
Where Compliance in a Box keeps its data
If you run your SOC 2 program in Confluence, your compliance app should not be the exception in your residency answer. Compliance in a Box runs on Atlassian and calls no external services. Its data lives in two places:
- Your content stays in Confluence. Policies, evidence pages and the generated reports are ordinary pages in your compliance space, so they are covered by your Confluence site's data residency like any other page.
- The app's records follow your site. Versions, approvals, acknowledgements, activity periods, settings and the audit log are kept in Forge hosted storage for your site, and that app data follows the data residency location of your Confluence site.
People are stored only as Atlassian account IDs, and names are looked up live when shown. The Data and privacy section of the user guide has the details, and the privacy policy covers retention.
FAQ
Where is Confluence data stored by default?
In Atlassian's Global location, which spans all of its hosting regions. Atlassian decides where in-scope data sits and can move it between regions. Pinning to a specific location changes that for in-scope data.
Does Confluence data residency cover user names and email addresses?
No. Atlassian keeps user account information in a central identity service that data residency doesn't cover. Logs and analytics are also outside it.
Do Marketplace apps follow my Confluence data residency location?
Only if they support it. Apps that keep their data in Forge hosted storage follow the site automatically. Apps with their own back end depend on the vendor. Check each app's status on the Data residency page and its Privacy and Security tab.
Is Confluence unavailable during a data residency move?
Yes. Confluence goes offline for the move, which Atlassian estimates at 2 to 24 hours depending on data size, and search can take longer to fully catch up.