Right to rectification in Hipchat Server

Under Article 16 of the GDPR, you have the right to have inaccurate personal data rectified. The GDPR requires that you take reasonable steps to rectify the individual's personal data where requested.  An example of such a request may be an individual requesting their display name be updated to reflect a name change.  Whether or not modifying personal data stored within the product is within the scope of reasonable steps required to honor the individual's request will vary on a case-by-case basis, and is determination you should always make with the assistance of legal counsel.  Once you have determined you have an obligation to rectify personal data, we have provided the following instructions on how to do so within certain Atlassian products.  

Personal data stored within the product can be divided into one of two areas: 1) account-level personal data; and 2) free-form text.  Account-level personal data are data fields that exist within the product for the sole purpose of identifying an individual throughout the product.  Examples of account-level personal data include the user's display name, profile picture or avatar and email address.  These data elements are generally visible from the user's profile and are used throughout the product to point back to the user's profile when the user is @mentioned or tagged on in certain spaces or content.  Changing account-level personal data elements will automatically populate that change throughout the product where the relevant account-level data elements appear. 

If you have included personal data in free-form text, either typed into content spaces or as a custom field label, you will need to use the product's global search feature to surface this personal data and recitfy it on a case-by-case basis.    


Personal data for a specific user can be found in multiple components of the Hipchat service. We have compiled a checklist so that Hipchat administrators can make sure they can rectify or edit personal data for a specific user. Make sure you read every item and apply the recommended steps. 

Version compatibility

Hipchat Server 2.0 and later.

Workarounds for End-users

Correcting your Full Name, Mention Name, Job Title, Timezone

Some fields may not be editable if your Hipchat instance uses an external authentication system. In this case, contact your Hipchat administrator to correct the personal data in the external directory.

  1. Log in to your Hipchat Server instance.
  2. Click the Edit Profile button at the top right.
  3. Update any of the Full Name, Mention Name, Job Title or Timezone fields to the correct values.
  4. Click Save.

Correcting your Email Address

If your Hipchat instance uses external authentication, the change to the email address needs to be performed from the authentication provider. Contact your Hipchat administrator for assistance.

  1. Log in to your Hipchat Server instance.
  2. Click the Edit Profile button at the top right.
  3. Click Change Credentials in the left navigation.
  4. Enter the corrected email address in the Email field.
  5. Click Save.

Correcting or Removing your Avatar

  1. Log in to your Hipchat Server instance.
  2. Click the Edit Profile button at the top right.
  3. Your user photo appears on the right. Click Delete Photo to remove it, or click Change Photo to upload a correct replacement. 
    (If you never uploaded a photo a default image appears, and this cannot be removed.)

Workarounds for Hipchat Administrators

Correcting Full Name, Mention Name, Job Title, and Email Address for a user

Some fields may not be editable if your Hipchat instance uses external authentication. In this case, you will need to modify these in the authentication source (for example. LDAP or Active Directory).

  1. Log in to your Hipchat Server instance.
  2. Click the Group admin tab at the top.
  3. Click User management in the left navigation.
  4. Locate the user in the user roster. You may need to search or navigate through pages to find them.
  5. Click the username in the roster to view the user's profile page.
  6. Change the fields to correct values.
  7. Click Save.


  • Some chat messages and file attachments might contain personal data. After you identify such a message or file, you can follow the process in Hipchat Server Right to Erasure: Deleting Message or File Attachment.
  • The personal data in the Audit Log is not modifiable and can not be erased by anyone.  The purpose of the Audit Log is to make sure sure any changes to personal data are accounted for, and to assist in detecting malicious activities such as impersonation. The Audit Log is ONLY accessible to Hipchat Administrators.

Additional notes

There may be limitations based on your product version.

Note, the above-related GDPR workaround has been optimized for the latest version of this product. If you are running on a legacy version of the product, the efficacy of the workaround may be limited. Please consider upgrading to the latest product version to optimize the workarounds available under this article.

Third-party add-ons may store personal data in their own database tables or on the filesystem.

The above article in support of your GDPR compliance efforts applies only to personal data stored within the Atlassian server and data center products. To the extent you have installed third-party add-ons within your server or data center environment, you will need to contact that third-party add-on provider to understand what personal data from your server or data center environment they may access, transfer or otherwise process and how they will support your GDPR compliance efforts.

If you are a server or data center customer, Atlassian does not access, store, or otherwise process the personal data you choose to store within the products. For information about personal data Atlassian processes, see our Privacy Policy.

Last modified on Dec 10, 2018

Was this helpful?

Provide feedback about this article
Powered by Confluence and Scroll Viewport.