130 Total
38 High severity
79 Medium severity
13 Low severity

Key Facts

With what does DocuSign use de-identified Customer Data?
DocuSign uses de-identified Customer Data, with customer consent, to build, train, and maintain the artificial intelligence models that power certain of its Services.
Does DocuSign use de-identified Customer Data to build, train, and maintain artificial intelligence models?
DocuSign uses de-identified Customer Data, with customer consent, to build, train, and maintain the artificial intelligence models that power certain of its Services.
What has DocuSign adopted to facilitate transfer of personal information?
DocuSign has adopted Binding Corporate Rules to facilitate the transfer of personal information from the European Economic Area and/or United Kingdom to DocuSign outside of the EEA.
Has DocuSign adopted Binding Corporate Rules to facilitate the transfer of personal information from the European Economic Area and/or United Kingdom?
DocuSign has adopted Binding Corporate Rules to facilitate the transfer of personal information from the European Economic Area and/or United Kingdom to DocuSign outside of the EEA.
For what is DocuSign not responsible regarding Customer Data or information?
DocuSign is not responsible for any use, transfer, or storage of Customer Data or information that occurs through third-party integrations outside of its Services.
Is DocuSign responsible for use, transfer, or storage of Customer Data that occurs through third-party integrations outside of its Services?
DocuSign is not responsible for any use, transfer, or storage of Customer Data or information that occurs through third-party integrations outside of its Services.
Can the employing organization find that account and take certain actions that may affect it?
When an employee creates a DocuSign account using a work-assigned email address, the employing organization—if it is a DocuSign customer with certain features—can find that account and take certain actions that may affect it.
Does DocuSign knowingly sell the personal information of minors under 16 years of age without legally required affirmative authorization?
DocuSign does not knowingly sell the personal information of minors under 16 years of age without legally required affirmative authorization.
Does DocuSign use Google Workspace APIs or Customer Data obtained through those APIs to develop, improve, or train generalized AI or ML models?
DocuSign does not use Google Workspace APIs or Customer Data obtained through those APIs to develop, improve, or train generalized AI or ML models.
What rights may users have regarding their information?
DocuSign states that users may have the right to opt out of sales of their information and processing of their information for targeted advertising purposes.
Stay ahead of the changes
Track DocuSign and get the diff the day its terms change.
Summary

This document explains what personal information DocuSign collects about you—including how you use its services and your devices—and how it may share that information with event sponsors or marketing partners. Your employer can locate and take actions on a DocuSign account you created with a work email address if your employer is a DocuSign customer with certain features. DocuSign does not place third-party advertising cookies in its core products, and you may have the right to opt out of sales of your information or its use for targeted advertising, depending on your jurisdiction.

Analysis

DocuSign's Privacy Statement establishes the basis on which DocuSign collects, uses, and shares personal information across its Services, including behavioral and device-level data, with use of the Services framed as acknowledgment of those practices. It sets out DocuSign's use of de-identified Customer Data—with customer consent—to build and maintain AI models powering certain Services, while categorically prohibiting any use of Google Workspace API data for generalized AI or ML development. The statement defines cross-border transfer mechanisms, specifically Binding Corporate Rules for transfers of EEA and UK personal data to DocuSign outside those jurisdictions, and identifies sharing with event sponsors and joint marketing partners as a permitted data flow. DocuSign expressly disclaims responsibility for data handling by third-party integrations outside its platform, and establishes that its customer-facing products do not deploy third-party advertising cookies or disclose customer data to advertising and marketing partners.

What this means for you

Using DocuSign's Services means your personal information—including behavioral and device data—will be collected and used as described in its Privacy Notice. If you register for DocuSign-hosted events, webinars, or sweepstakes, your personal information may be shared with the sponsors of those events and with joint marketing partners. Importantly, if you created a DocuSign account with a work-assigned email, your employing organization may be able to locate that account and take actions affecting it. DocuSign uses de-identified Customer Data to train AI models only where customer consent has been obtained, and it does not use Google Workspace API data for AI development. If applicable law gives you the right to opt out of the sale of your information or its use for targeted advertising, you may exercise that right by contacting DocuSign as described in its Privacy Notice.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

3 important changes detected

5 versions captured · Last updated: May 2026

What changed DocuSign updated its Privacy Statement on May 21, 2026 to expand the scope of personal information collection and describe data sources more explicitly. The updated language now states that DocuSign collects personal information from individuals 'with whom we otherwise communicate in connection with the Services' (broader than website and app users alone) and explicitly identifies 'Marketing Contact Data' collected from third-party provider Clay to support sales and marketing efforts. The policy also clarifies that DocuSign maintains opt-out list data to honor email marketing preferences.
Why this matters The updated privacy statement explicitly discloses that DocuSign collects marketing contact data (professional details such as email, phone number, job title, employer, and location) from third-party provider Clay to support sales and marketing activities. The policy now clarifies that its data collection scope includes individuals with whom DocuSign communicates about services, extending beyond active website or app users. The policy states DocuSign maintains minimal data (such as email address on an opt-out list) when users have opted out of email marketing to honor that request.
View full change record →
What changed DocuSign removed 'English' from the list of languages in which its Privacy Statement is available. The Privacy Statement itself remains unchanged in content; only the language availability list was modified. This is a minor administrative update with no impact on privacy rights or protections.
Why this matters This change removes English from the list of languages in which DocuSign's Privacy Statement is published. For English-speaking users, the Privacy Statement content itself remains unchanged and available; only the language header was modified. This is a formatting change with no material impact on privacy rights, data practices, or consumer protections.
View full change record →

May 6, 2026 low

DocuSign's privacy policy now displays language indicating available translations (French, German, Japanese, Portuguese, Spanish, Dutch, Italian, and English) at the beginning of the document. This is a formatting and accessibility …

View change record →
Featured, High severity
Featured, Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

130 provisions
12 featured
16 clause types
38 high severity
Privacy Rights 37 8 high
Show all 37 privacy rights provisions
Targeting and Audience Restrictions 1 1 high
Stay ahead of the changes

Monitoring

DocuSign has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle AI Models Designed to Avoid Personal Information Training and similar clauses.

Compare across platforms →
Archival ProvenanceSource & Archival Record
Last Captured May 21, 2026 00:21 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000198
Version ID CA-V-002818
SHA-256 db171ce667d98db1d8936fb125acc66e0d283cc7f0c00e08307fb68fd757092c
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans