Last updated 2026-10-08

GDPR, NIS2, DORA — what does MetaFrazo give me?

If your organization operates in the EU and runs Jira at scale, three regulatory regimes likely shape the questions your auditors ask:

  • GDPR (General Data Protection Regulation) — reviewers typically ask what data you hold, what you do with it, and how you would evidence that.
  • NIS2 (Network and Information Security Directive 2) — reviewers typically ask how incidents are handled and how risk is managed over time.
  • DORA (Digital Operational Resilience Act) — reviewers in the financial sector typically ask about third-party risk and operational resilience.

US-equivalent regimes (SOX, HIPAA when applicable, sector-specific evidence requests) ask very similar questions in different language.

MetaFrazo doesn't claim to be your end-to-end compliance platform. We produce one specific kind of evidence — what happened in your Jira workspace, when, who did it, and how patterns are trending — and we make that record durable and queryable. Exports are available on request; see the limits below. Below is what reviewers commonly ask for, and what we make easy.

Records of processing — what data we hold and what we do with it

MetaFrazo holds the events your Jira workspace produces from the moment you installed the connector forward. The event record is forward-only from your install date — we do not backfill historical issue activity. We do read your current Jira configuration through the API (projects, fields, and workflow definitions), so the dashboards can describe what your events mean.

What we hold per organization:

  • Jira events as they arrive: who acted, when, on which issue, and the before / after of the change.
  • Account types for the Jira accounts that act in your events: for each account ID, whether Jira reports it as a person, an app, a customer, or gives no type. Only the ID and the type are kept from that lookup, plus the name of an app account (an integration or automation, such as Slack); never the name of a person or a service-desk customer, and no email address or avatar. They are erased with the account's other data, as described in How do I delete my account, and how is personal data erased?, and with your site's data after an uninstall. People, automation and AI activity explains how the type is used.
  • Configuration changes that your Jira admins make over time, in the same event-stream form.
  • Membership changes within your MetaFrazo organization itself: invites, role changes, removals, with the actor and timestamp for each.
  • Provider settings for AI features (when you change which AI provider is active, with the actor and timestamp).
  • The install record: the name and email address of the admin who installs or upgrades the app, which we use for onboarding and install support.

What we don't hold:

  • We don't store anyone's personal Jira credentials. Authentication to your Jira workspace happens through Atlassian's signed app-invocation tokens; there is no Jira password or API token of yours sitting in MetaFrazo.
  • Display names and avatars are removed from Jira user events before they are sent to MetaFrazo, and no Jira credentials are ever stored. The event payloads we do store still include free-text fields: issue summaries, descriptions, and comment bodies.

For your own records of processing, the factual position is this: MetaFrazo receives a derived event stream from your Jira workspace, stores it in European infrastructure, and surfaces it to your authorized personnel via a web dashboard. How you record that is your determination to make, not ours. We're happy to provide a vendor-side data processing agreement and a sub-processor disclosure list on request — see the request route at the bottom of this page.

Incident-pattern evidence for NIS2

Reviewers preparing a NIS2 review typically ask how risk on the systems you operate is managed and evidenced over time. For Jira-driven workflows, MetaFrazo's Risk & Alerts dashboards directly support this:

  • High-risk issues — issues that score high on a composite of staleness, reopen rate, and priority.
  • Incident patterns — projects with recurring high-priority incidents over time, with mean-time-between-incident statistics.
  • SLA breach and warning zones — current and historical breach counts, with the worst-multiplier marker.
  • Risk escalation — projects sliding into "needs board attention" territory, week over week.

These dashboards aren't an alerting system in the real-time sense — they're a pattern-recognition system. The combination of "what has been trending wrong" plus "for how long" is what most NIS2 reviewers actually want to see.

Operational-resilience evidence for DORA

Reviewers working a DORA file typically ask about the operational resilience of the systems the firm depends on. MetaFrazo supports this in two ways:

  • As an analytics surface for your own work-tracking — the Executive dashboards (portfolio heatmaps, governance composite scores, forecast indicators, team activity) give your DORA evidence pack concrete numbers rather than narrative summaries.
  • As a third-party vendor that operates in DORA scope — for the part of your DORA evidence that covers third parties, we can provide our own resilience documentation (service-level commitments, incident-response posture, backup and recovery posture) on request.

The audit trail itself

Underneath every dashboard is an append-only audit trail of every membership change, configuration change, and AI-provider change made inside your MetaFrazo organization. Owners, Admins, and Auditors can read it (see Roles and permissions). Nothing in it is edited or deleted in the ordinary course. The one exception is a data-subject erasure request, which tombstones the actor on the row while keeping the audit fact itself — the record is there to show what happened, not who it was.

This is the artifact your internal audit team or external auditor will most often ask for. The fact that it's append-only is what makes it useful as evidence — there is no "edit history" question to answer about the audit trail itself.

Exports for external audit

When you need to hand evidence to an external auditor, you have two options today:

  • Evidence requests via support. This is the route for anything broader: sample-based audits, full-quarter exports, or a specific date range. Contact support (top-right menu → Contact support) and we'll produce the export. We aim to turn around routine evidence requests within two business days.
  • Two visuals export directly. Workflow Discovery has an Export PDF button that opens your browser's print dialog — choose "Save as PDF" as the destination. Audit Compass can bundle a selected event together with its pinned notes into a downloadable evidence pack.

Those two are the whole of today's self-service export. Other visuals have no download in their menu, so for anything else the support route above is the way to get data out.

Outstanding limitations to be aware of

We're honest about where the product hasn't reached its goal state:

  • Self-service account deletion is now in the dashboard — any user can permanently erase their own account from Profile → Danger Zone. See How do I delete my account, and how is personal data erased? for what's removed and how Jira-actor data is handled. A subject-access or data-portability export request is still handled manually — contact support and we'll process it within the statutory timeline.
  • Real-time alerting on individual events is intentionally not a MetaFrazo feature — we focus on patterns over time, not single-event notifications. If you need a real-time alert when a specific Jira event fires, Jira's own automation is the right place for that.

Request a vendor risk packet

If you're starting a vendor risk assessment of MetaFrazo, we can provide a standard vendor risk packet on request that covers the questions most enterprise procurement teams ask: data processing agreement template, sub-processor list, security and resilience overview, incident-response posture, and the relevant certifications held by our European infrastructure providers (such as the ISO 27001 family). MetaFrazo itself does not yet hold a security certification of its own — we state that plainly rather than imply otherwise. Request it via the Contact support menu in the top-right of the dashboard, and we'll send it back within two business days.

Where to go from here