DocuSign · DocuSign Privacy Statement · View original document ↗

EU/UK Data Subject Rights and Cross-Border Transfers

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity DocuSign recorded 2 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for DocuSign Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

EU and UK users have extensive legal rights over their personal data held by DocuSign, and their data is transferred internationally using Standard Contractual Clauses as the legal safeguard.

This analysis describes what DocuSign's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

EU and UK data protection law provides some of the strongest privacy rights globally, and the use of Standard Contractual Clauses for transfers to the US means those rights travel with your data, though the practical enforceability depends on the transfer mechanism's ongoing validity.

Consumer impact (what this means for users)

If you are in the EU or UK, you can request access to, correction, or deletion of your DocuSign data, and can object to certain processing. Cross-border transfers of your data to the US are governed by Standard Contractual Clauses, which are currently the primary approved mechanism under GDPR.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    EU and UK users can submit data subject rights requests including access, erasure, rectification, and objection through DocuSign's privacy portal at https://www.docusign.com/privacy.

How other platforms handle this

OpenAI Medium

OpenAI is based in the United States and the information we collect is governed by U.S. law. If you are accessing our services from outside of the United States, please be aware that your information may be transferred to, stored, and processed by us in our facilities in the United States and by tho...

Figma Medium

When we transfer personal information from the European Economic Area, United Kingdom, or Switzerland to countries that have not been found to provide an adequate level of protection under applicable law, we take steps to provide appropriate safeguards, including through the use of Standard Contract...

Ideogram Medium

We may transfer your personal information to countries other than the country in which you live. We transfer personal data from the European Economic Area, United Kingdom, and Switzerland to other countries, some of which have not been determined by the European Commission to have an adequate level ...

See all platforms with this clause type →

Monitoring

DocuSign has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
If you are located in the European Economic Area (EEA) or United Kingdom, you have certain rights under applicable data protection laws, including the right of access, the right to rectification, the right to erasure, the right to restriction of processing, the right to data portability, and the right to object. Docusign relies on Standard Contractual Clauses as a legal mechanism for transfers of personal data from the EEA and UK to countries that have not received an adequacy decision.

— Excerpt from DocuSign's DocuSign Privacy Statement

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

(1) REGULATORY LANDSCAPE: These provisions are grounded in GDPR Articles 15-22 for data subject rights and Articles 46 and 47 for transfer mechanisms. The UK GDPR mirrors these provisions post-Brexit. Standard Contractual Clauses adopted by the European Commission in 2021 are the referenced transfer mechanism. The Irish Data Protection Commission and UK ICO are the primary supervisory authorities for DocuSign's EU and UK operations respectively. (2) GOVERNANCE EXPOSURE: Medium. The adequacy of Standard Contractual Clauses for US transfers remains subject to regulatory and legal scrutiny following Schrems II, and organizations relying on SCCs must conduct transfer impact assessments. DocuSign's reliance on SCCs without explicit reference to supplementary measures or transfer impact assessments may warrant closer review by EU enterprise customers. (3) JURISDICTION FLAGS: EEA and UK users are directly affected. Organizations subject to sector-specific requirements such as financial services or healthcare should assess whether SCCs alone are sufficient for their data flows through DocuSign. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers in the EU and UK should obtain DocuSign's current SCC documentation and any available transfer impact assessment summaries. Procurement teams should confirm that DocuSign's DPA incorporates the 2021 module SCCs appropriate to the controller-processor relationship. (5) COMPLIANCE CONSIDERATIONS: Enterprise customers should log DocuSign as a sub-processor or processor in their records of processing activities as required by GDPR Article 30, noting the cross-border transfer mechanism and any supplementary measures in place.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
DocuSign Privacy Statement
Entity
DocuSign
Document last updated
May 5, 2026
Tracking information
First tracked
May 10, 2026
Last verified
May 10, 2026
Record ID
CA-P-008914
Document ID
CA-D-00198
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
abf1dbd66c3a271b9485e1a8df8054ad589206ec0ecf9e390fb45323aebd8925
Analysis generated
May 10, 2026 12:30 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: DocuSign
Document: DocuSign Privacy Statement
Record ID: CA-P-008914
Captured: 2026-05-10 12:30:52 UTC
SHA-256: abf1dbd66c3a271b…
URL: https://conductatlas.com/platform/docusign/docusign-privacy-statement/euuk-data-subject-rights-and-cross-border-transfers/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does DocuSign's EU/UK Data Subject Rights and Cross-Border Transfers clause do?

EU and UK data protection law provides some of the strongest privacy rights globally, and the use of Standard Contractual Clauses for transfers to the US means those rights travel with your data, though the practical enforceability depends on the transfer mechanism's ongoing validity.

How does this clause affect you?

If you are in the EU or UK, you can request access to, correction, or deletion of your DocuSign data, and can object to certain processing. Cross-border transfers of your data to the US are governed by Standard Contractual Clauses, which are currently the primary approved mechanism under GDPR.

Is ConductAtlas affiliated with DocuSign?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by DocuSign.