PII Detections by Project(5.4.5)

Visual
Where to find it:CompliancePII Detector
Ent AdvancedPii Detector add-on
Open in dashboard

Jira issue summaries and comments are rarely meant to hold personal data. When one does, whether an email address, a phone number, or a personal ID number, that is personal data sitting in a field that was probably not intended to hold it, and your data protection function decides what follows. This visual shows how detections are distributed across projects and which patterns are appearing most frequently.

What you can conclude

  • For a project with a high detection count, a reviewer could ask whether personal data is routinely being written into issue text, and where it comes from.
  • The dominant type shows which pattern appears most: email addresses are often copy-pasted from support tickets, phone-shaped digits from customer records.
  • A project with zero detections either holds none of these patterns or has little text in its issues, so context matters.
  • Only the email bar should be read as near-certain.

How this chart works

Stacked bar chart of detection counts per project, broken down by pattern (email address, phone-shaped digits, numeric ID). Each issue is counted once per type, so an issue matching two patterns appears in both bars. Use the date and project filters to focus on specific periods.

What each pattern actually matches. Email is a conventional address pattern and is the most reliable of the three. Phone-shaped digits means a standalone run of 7 to 15 digits that does not parse as a calendar date or a timestamp; runs that do parse as dates (20260421) or timestamps (20260730180000) are excluded, but a build number or an account reference of the right length will still match. Numeric ID is a standalone run of 6 to 12 digits and is the loosest of the three. Digits that are part of an Atlassian account id, such as the one behind a mention of a colleague, or of an identifier in the standard UUID format, such as the id of a file embedded in a comment, are not counted by either digit pattern. Nor are the digits Jira writes into a comment's own formatting: the file name it records for an embedded image or file (a pasted screenshot is named like image-20260421-185001.png), the editor's internal element ids, and the stored value of a date inserted with the date picker. Digits in a link address still count.

Teams preparing a GDPR review commonly start here to see where personal data is concentrated.