Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Figma updated its Privacy Policy effective May 27, 2026 to expand and clarify rules governing how children's personal information is collected and used. The updated policy restricts how children's data can be used with AI services, advertising, and tracking, specifies that children may only use Figma through educational institution agreements, broadens the definition of 'child' to include ages up to 16 in California and the EU and 18 in Japan, and consolidates data protection officer contact information. The practical effect is that children using Figma outside of educational agreements, or whose parents believe they have been added without consent, now have clearer notification procedures and stronger stated protections around AI training and marketing uses.
The updated terms establish specific restrictions on how Figma may use personal information collected from minors. Children under 13 in the US, under 16 in California and the EU, and under 18 in Japan may now use the Services only through agreements with educational institutions. Figma states it will not use children's personal information to train, fine-tune, or improve AI services, nor will it permit service providers to do so. The policy also prohibits using children's data for marketing purposes, targeted advertising, or enabling third-party tracking. If a parent learns their child provided personal information without consent outside an educational agreement, they may contact Figma to report the issue.
The updated terms establish enforceable restrictions on how children's personal information may be processed, moving beyond general principles to specific contractual prohibitions around AI training, advertising, and tracking. The mandatory institutional agreement requirement for child users creates a new gating mechanism that affects any organization using Figma in an educational context. The explicit AI training prohibition directly addresses a significant regulatory and public policy concern regarding use of minors' data in machine learning.
→ Parents who believe their child has accessed Figma without authorization or consent should contact privacy@figma.com to report the issue.
→ Schools considering or currently using Figma should verify they have executed a Figma for Education Enterprise agreement covering their student users.
→ Children who access Figma outside of an educational institution agreement will not be permitted to use the service under the updated terms.
→ Personal information collected from children will be governed by the stated prohibitions on AI training and marketing uses, regardless of whether parents are notified of the restrictions.
Figma and its service providers are prohibited from using personal information collected from children to train, fine-tune, or improve AI services, including large language models.
Children may only use Figma through a Figma for Education Enterprise agreement entered into with their educational institution; prior language permitting use 'in some cases' has been removed.
Definition of 'child' now explicitly includes minors up to age 16 in California and the EU, and up to age 18 in Japan, in addition to age 13 in the US.
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
You can contact Figma if your child provided personal information without your permission outside of a school agreement.
Schools must have a contract with Figma in order for their students to use the service.
Children's data will not be used to improve Figma's AI tools or other companies' AI services.
Children will not see targeted ads or have their data shared with ad partners on Figma.
Companies providing AI services to Figma cannot use the data they process for children to improve their own AI models.
More young people now receive the stronger privacy protections, depending on where they live.
Children no longer have the option to use Figma outside of a school agreement; they must use it through their school.
Figma expanded its children's privacy framework effective May 27, 2026, moving from a general prohibition on knowingly collecting children's data to specific contractual requirements (educational institution agreements) and explicit opt-out language for unauthorized access. The policy now addresses AI services, marketing, and third-party tracking with stated prohibitions rather than general principles. Organizations using Figma to serve educational customers should verify that their implementations comply with the requirement to route child users through institutional agreements. The broadened age definition (up to 18 in Japan) and explicit AI training restrictions engage COPPA in the US and equivalent child privacy regimes in California, the EU, and Japan, though the extent to which educational agreements may operate as an alternative compliance pathway depends on how regulators interpret such arrangements.
Full institutional analysis
Regulatory exposure, obligation analysis, escalation trigger, board language, and recommended action.
Analyst $49/moConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-002410.
Figma's Privacy Policy footer now includes a link to 'Digital Regulation Help Centre' alongside existing links to Community Code of …
Figma updated its Terms of Service footer navigation on July 7, 2026 to add a link to 'Digital Regulation Help …
Figma updated its privacy policy footer navigation on July 7, 2026 to add a link to 'Digital Regulation Help Centre' …
Get alerted when this policy changes again, including what changed and why it matters.