Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The notice states that DocuSign trains AI models using de-identified customer data only where customer consent has been obtained, and that systems are designed to avoid using personal information for AI training without consent.
This analysis describes what DocuSign's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the conditions under which DocuSign may use customer data for AI model development, requiring consent and de-identification as stated preconditions. The notice does not specify the consent mechanism or what 'de-identification' standard is applied, which may require evaluation under applicable AI governance frameworks, particularly GDPR and emerging EU AI Act requirements.
Interpretive note: The notice does not specify the consent mechanism, de-identification standard, or customer opt-out process for AI training, creating interpretive uncertainty about the operational scope of this provision.
Under this provision, DocuSign states it uses de-identified customer data to train AI models only with customer consent, and that a separate carve-out explicitly prohibits using Google Workspace API data for generalized AI or ML model training. The agreement does not describe the specific opt-in mechanism or de-identification methodology applied.
Cross-platform context
See how other platforms handle AI Model Training Using Customer Data and similar clauses.
Compare across platforms →Monitoring
DocuSign has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Building, training and maintaining our artificial intelligence models through machine learning that power certain of our Services using de-identified Customer Data (with customer consent)... We intentionally design our systems with functionality to avoid training models using personal information that customers may enter into our Services (except when we have consent from a customer to do so). Docusign is committed to developing our Services that involve AI technology in accordance with our AI Innovation Principles.Excerpt from DocuSign's Privacy Statement
1. REGULATORY LANDSCAPE: This provision engages GDPR Article 5 data minimization and purpose limitation principles, as well as consent requirements under Article 6 and Article 7, given that customer data is used for AI model training. The EU AI Act may impose additional transparency and documentation obligations depending on the classification of AI systems DocuSign operates. The FTC Act is implicated through representations about de-identification practices and consent-based data use. 2. GOVERNANCE EXPOSURE: Medium. The provision asserts consent and de-identification as conditions for AI training, but the notice does not specify the consent mechanism granularity, de-identification standard applied, or whether customers can audit or withdraw consent after initial grant. This creates due diligence exposure for enterprise customers whose own regulatory obligations may require documented assurances about downstream data use. 3. JURISDICTION FLAGS: EU/EEA customers face heightened exposure given GDPR requirements for explicit, specific, and informed consent for processing beyond original purpose. The EU AI Act may require additional transparency disclosures for high-risk AI systems. California customers may evaluate whether AI training constitutes a secondary use of personal information requiring CCPA-compatible notice. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers with data processing agreements in place should verify whether those agreements address AI training use cases, consent terms, and de-identification standards. The notice's reference to customer consent without specifying the mechanism may create ambiguity in B2B data processing agreement negotiations, particularly for customers with internal AI governance policies. 5. COMPLIANCE CONSIDERATIONS: Legal teams should request from DocuSign documentation of the de-identification methodology applied to customer data used for AI training, as well as the specific consent mechanism available to enterprise customers. Data processing agreements should be reviewed to confirm whether AI training provisions are addressed, and whether customers retain the right to restrict such use.
This provision establishes the conditions under which DocuSign may use customer data for AI model development, requiring consent and de-identification as stated preconditions. The notice does not specify the consent mechanism or what 'de-identification' standard is applied, which may require evaluation under applicable AI governance frameworks, particularly GDPR and emerging EU AI Act requirements.
Under this provision, DocuSign states it uses de-identified customer data to train AI models only with customer consent, and that a separate carve-out explicitly prohibits using Google Workspace API data for generalized AI or ML model training. The agreement does not describe the specific opt-in mechanism or de-identification methodology applied.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by DocuSign.