DocuSign · DocuSign Privacy Statement · View original document ↗

AI Model Training Using Customer Data

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time DocuSign changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for DocuSign Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The notice states that DocuSign trains AI models using de-identified customer data only where customer consent has been obtained, and that systems are designed to avoid using personal information for AI training without consent.

This analysis describes what DocuSign's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes the conditions under which DocuSign may use customer data for AI model development, requiring consent and de-identification as stated preconditions. The notice does not specify the consent mechanism or what 'de-identification' standard is applied, which may require evaluation under applicable AI governance frameworks, particularly GDPR and emerging EU AI Act requirements.

Interpretive note: The notice does not specify the consent mechanism, de-identification standard, or customer opt-out process for AI training, creating interpretive uncertainty about the operational scope of this provision.

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this provision, DocuSign states it uses de-identified customer data to train AI models only with customer consent, and that a separate carve-out explicitly prohibits using Google Workspace API data for generalized AI or ML model training. The agreement does not describe the specific opt-in mechanism or de-identification methodology applied.

Cross-platform context

See how other platforms handle AI Model Training Using Customer Data and similar clauses.

Compare across platforms →

Monitoring

DocuSign has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Building, training and maintaining our artificial intelligence models through machine learning that power certain of our Services using de-identified Customer Data (with customer consent)... We intentionally design our systems with functionality to avoid training models using personal information that customers may enter into our Services (except when we have consent from a customer to do so). Docusign is committed to developing our Services that involve AI technology in accordance with our AI Innovation Principles.

Excerpt from DocuSign's Privacy Statement

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision engages GDPR Article 5 data minimization and purpose limitation principles, as well as consent requirements under Article 6 and Article 7, given that customer data is used for AI model training. The EU AI Act may impose additional transparency and documentation obligations depending on the classification of AI systems DocuSign operates. The FTC Act is implicated through representations about de-identification practices and consent-based data use. 2. GOVERNANCE EXPOSURE: Medium. The provision asserts consent and de-identification as conditions for AI training, but the notice does not specify the consent mechanism granularity, de-identification standard applied, or whether customers can audit or withdraw consent after initial grant. This creates due diligence exposure for enterprise customers whose own regulatory obligations may require documented assurances about downstream data use. 3. JURISDICTION FLAGS: EU/EEA customers face heightened exposure given GDPR requirements for explicit, specific, and informed consent for processing beyond original purpose. The EU AI Act may require additional transparency disclosures for high-risk AI systems. California customers may evaluate whether AI training constitutes a secondary use of personal information requiring CCPA-compatible notice. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers with data processing agreements in place should verify whether those agreements address AI training use cases, consent terms, and de-identification standards. The notice's reference to customer consent without specifying the mechanism may create ambiguity in B2B data processing agreement negotiations, particularly for customers with internal AI governance policies. 5. COMPLIANCE CONSIDERATIONS: Legal teams should request from DocuSign documentation of the de-identification methodology applied to customer data used for AI training, as well as the specific consent mechanism available to enterprise customers. Data processing agreements should be reviewed to confirm whether AI training provisions are addressed, and whether customers retain the right to restrict such use.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Applicable agencies

  • FTC
    The FTC oversees representations about data use practices including AI training and de-identification claims under the FTC Act's prohibition on unfair or deceptive practices.
    File a complaint →

Provision details

Document information
Document
DocuSign Privacy Statement
Entity
DocuSign
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014904
Document ID
CA-D-00198
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
db171ce667d98db1d8936fb125acc66e0d283cc7f0c00e08307fb68fd757092c
Analysis generated
July 9, 2026 06:43 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: DocuSign
Document: DocuSign Privacy Statement
Record ID: CA-P-014904
Captured: 2026-07-09 06:43:10 UTC
SHA-256: db171ce667d98db1…
URL: https://conductatlas.com/platform/docusign/docusign-privacy-statement/provision/CA-P-014904/ai-model-training-using-customer-data/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Frequently Asked Questions

What does DocuSign's AI Model Training Using Customer Data clause do?

This provision establishes the conditions under which DocuSign may use customer data for AI model development, requiring consent and de-identification as stated preconditions. The notice does not specify the consent mechanism or what 'de-identification' standard is applied, which may require evaluation under applicable AI governance frameworks, particularly GDPR and emerging EU AI Act requirements.

How does this clause affect you?

Under this provision, DocuSign states it uses de-identified customer data to train AI models only with customer consent, and that a separate carve-out explicitly prohibits using Google Workspace API data for generalized AI or ML model training. The agreement does not describe the specific opt-in mechanism or de-identification methodology applied.

Is ConductAtlas affiliated with DocuSign?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by DocuSign.