Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The notice establishes a Privacy Request Portal as the designated mechanism for submitting data subject rights requests including access, deletion, correction, and export, and states that identity verification is required for all requests, with account login accepted as verification for registered users.
This analysis describes what DocuSign's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the operational procedure for exercising data subject rights under GDPR, UK GDPR, CCPA, and applicable state privacy laws, including the identity verification standard and authorized agent process. The requirement to provide additional verification for non-account holders may affect the ease of exercising rights for individuals who receive documents through DocuSign without having a registered account.
Under this provision, individuals can submit rights requests including deletion, correction, access, and data export through the DocuSign Privacy Request Portal, with identity verification required as a condition of processing. Authorized agents may submit requests on behalf of individuals subject to verification of the agent's authority.
Cross-platform context
See how other platforms handle Data Subject Rights Request Process and similar clauses.
Compare across platforms →Monitoring
DocuSign has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"To exercise any of these rights, please contact us via the Docusign Privacy Request Portal. If you make a request to exercise the rights referenced above, we will require you to provide certain information for identity verification purposes. If you have an account with us, we may verify you through your login of your account. If you do not have an account with us, we may require you to provide additional information from which we can confirm your identity. You may authorize an agent to make a request to us on your behalf and we will verify the identity of your agent or authorized legal representative by either seeking confirmation from you or documents that establish the agent's authorization to act on your behalf.Excerpt from DocuSign's Privacy Statement
1. REGULATORY LANDSCAPE: This provision engages GDPR Articles 15 through 22 data subject rights, UK GDPR equivalent provisions, and CCPA Sections 1798.100 through 1798.125. The authorized agent mechanism reflects CCPA requirements. GDPR imposes response time obligations (generally 30 days, extendable by two months) that are not specified in the notice text itself. 2. GOVERNANCE EXPOSURE: Medium. The notice directs all rights requests to the Privacy Request Portal, which is consistent with industry practice. However, the notice separately states that where DocuSign acts as a processor, rights requests will be forwarded to the relevant customer, which may extend response timelines and create accountability gaps if not addressed in data processing agreements. 3. JURISDICTION FLAGS: EU/EEA and UK users have mandatory rights under GDPR and UK GDPR with specific response time requirements. California residents have CCPA rights including the right to appeal a denied request, which the notice acknowledges. Other state privacy law jurisdictions may impose additional rights or response obligations. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers whose employees or transaction counterparties submit rights requests to DocuSign should ensure their data processing agreements specify how DocuSign will forward and coordinate processor-context rights requests. The notice states that DocuSign will forward processor-context requests to the relevant customer, but does not specify a timeline for doing so. 5. COMPLIANCE CONSIDERATIONS: Legal teams should review whether the Privacy Request Portal's identity verification process satisfies GDPR and CCPA requirements for verifiable consumer requests without being unduly burdensome. The appeal process referenced in the notice should be documented internally for California and other state privacy law compliance.
This provision establishes the operational procedure for exercising data subject rights under GDPR, UK GDPR, CCPA, and applicable state privacy laws, including the identity verification standard and authorized agent process. The requirement to provide additional verification for non-account holders may affect the ease of exercising rights for individuals who receive documents through DocuSign without having a registered account.
Under this provision, individuals can submit rights requests including deletion, correction, access, and data export through the DocuSign Privacy Request Portal, with identity verification required as a condition of processing. Authorized agents may submit requests on behalf of individuals subject to verification of the agent's authority.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by DocuSign.