10 Total
0 High severity
7 Medium severity
3 Low severity
Summary

DocuSign's privacy policy explains what personal information they collect when you use their document signing and agreement services, including your name, email, IP address, and the content of documents you sign. They share some of this data with partners and use it for marketing, product improvement, and service delivery. Depending on where you live, you may have rights to access, delete, or opt out of certain uses of your data.

Technical Summary

DocuSign's Privacy Notice governs the collection, use, disclosure, and retention of personal information across its eSignature, agreement management, and related digital services. The notice addresses data collected from account holders, signers, website visitors, and third-party sources, covering categories including identity, contact, financial, device, and behavioral data. It establishes user rights including access, deletion, correction, and portability, with specific provisions for GDPR (EEA/UK), CCPA/CPRA (California), and other regional frameworks. Notable provisions include data sharing with third-party service providers and advertising partners, use of cookies and tracking technologies, and cross-border data transfers under Standard Contractual Clauses. The notice also addresses DocuSign's role as both a data controller (for its own marketing and website operations) and a data processor (when processing data on behalf of enterprise customers).

Institutional Analysis

This notice engages GDPR (EU and UK), CCPA/CPRA, and various Asia-Pacific privacy frameworks, with DocuSign operating as both a data controller and data processor depending on context — a distinction…

This notice engages GDPR (EU and UK), CCPA/CPRA, and various Asia-Pacific privacy frameworks, with DocuSign operating as both a data controller and data processor depending on context — a distinction with significant liability implications for enterprise customers. Cross-border data transfers from …

🔒

Compliance intelligence locked

Regulatory exposure, material risk, and due diligence action items.

Evidence Provenance
Captured March 19, 2026 14:54 UTC
Document ID CA-D-000198
Version ID CA-V-000142
Wayback Machine View archived versions →
SHA-256 b6a71f1218eb206e107ee942057507b74a69437a208945a5d560a6b4dec14355
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Cryptographically signed
Change Timeline
Medium Severity — 7 provisions
Low Severity — 3 provisions