8 Total
0 High severity
7 Medium severity
1 Low severity
Summary

DocuSign's Privacy Statement establishes the company's data collection, processing, and sharing practices for personal information generated through its document signing and management platform. The statement authorizes DocuSign to process document content and metadata, and permits sharing of personal data with third-party service providers and business partners for service delivery, analytics, and marketing purposes. The statement defines data subject rights available to California residents and EU users, including access, deletion, and opt-out mechanisms available through DocuSign's privacy portal.

Technical / Legal Breakdown

This document is DocuSign's global Privacy Notice, governing the collection, use, storage, and disclosure of personal data across DocuSign's products and services, with legal bases including consent, contractual necessity, and legitimate interests depending on jurisdiction. The notice states that DocuSign collects identifiers, contact data, device and usage data, geolocation, payment information, and the contents of documents processed through its platform, and the terms authorize sharing this data with service providers, business partners, and in connection with corporate transactions such as mergers or acquisitions. A notable operational distinction is DocuSign's role as both a data controller (for account and marketing data) and a data processor (for customer-submitted document content), meaning the privacy protections applicable to document content depend substantially on the enterprise customer's own data agreements rather than this notice alone. The notice engages GDPR and UK GDPR for EEA and UK users, CCPA and CPRA for California residents, and references additional regional frameworks including Brazil's LGPD, Australia's Privacy Act, and Canadian PIPEDA; cross-border data transfer mechanisms including Standard Contractual Clauses are referenced for EU data flows. Material compliance considerations include the adequacy of consent mechanisms for marketing communications, the scoping of processor versus controller obligations for enterprise customers, and the exercise of data subject rights across multiple applicable regimes.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial

2 important changes detected

4 versions captured · Last updated: May 2026

What changed DocuSign removed 'English' from the list of languages in which its Privacy Statement is available. The Privacy Statement itself remains unchanged in content; only the language availability list was modified. This is a minor administrative update with no impact on privacy rights or protections.
Why this matters This change removes English from the list of languages in which DocuSign's Privacy Statement is published. For English-speaking users, the Privacy Statement content itself remains unchanged and available; only the language header was modified. This is a formatting change with no material impact on privacy rights, data practices, or consumer protections.
View full change record →
What changed DocuSign's privacy policy now displays language indicating available translations (French, German, Japanese, Portuguese, Spanish, Dutch, Italian, and English) at the beginning of the document. This is a formatting and accessibility update that does not change the actual privacy protections or data handling practices described in the policy.
Why this matters This change is a formatting and accessibility update that does not alter DocuSign's privacy practices or consumer protections. The policy now explicitly indicates that translations are available in seven languages in addition to English. This may improve access to privacy information for non-English speakers but does not change what data DocuSign collects, how it uses it, or what rights consumers have.
View full change record →

Medium — 7 provisions
Low — 1 provision

Monitoring

DocuSign has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Identity Verification and Biometric-Adjacent Data Collection and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 6, 2026 21:09 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000198
Version ID CA-V-002308
SHA-256 935a4067a7272e606a991d5974159c4c704ff5a1373484146fd72e5df1d95cfb
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans