The notice states that DocuSign acts as a data processor for eSignature customers, while asserting both processor and controller roles for CLM and Identity products depending on the processing activity, and directs data subject rights requests to the relevant customer where DocuSign acts as processor.
This analysis describes what DocuSign's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the structural data governance relationship between DocuSign and its enterprise customers, determining which party bears primary responsibility for data subject rights responses, lawful basis determinations, and regulatory obligations depending on the product in use. The assertion of a dual controller/processor role for CLM and Identity products creates compliance dependencies that enterprise customers should reflect in their data processing agreements.
Under this provision, individuals whose personal information is processed through DocuSign eSignature should direct data subject rights requests to the DocuSign customer (employer or requesting organization) rather than to DocuSign directly. For CLM and Identity products, DocuSign may independently determine processing purposes in certain circumstances, which affects the applicable rights framework.
Cross-platform context
See how other platforms handle Controller/Processor Dual Role by Product Line and similar clauses.
Compare across platforms →"When our business customers use certain Services, we generally process and store limited personal information on their behalf as a data processor. For example, in the context of Docusign eSignature, when a customer uploads contracts or other documents for review or signature, we act as a data processor and process the documents on the customer's behalf and in accordance with their instructions. In those instances, the customer is the data controller and is responsible for most aspects of the processing of the personal information. For certain products such as Docusign's Contract Lifecycle Management (CLM) and Identity products, we may act as a processor and as a controller in certain circumstances (e.g., retention of transactional data to comply with Docusign's legal obligations).Excerpt from DocuSign's Privacy Statement
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes the structural data governance relationship between DocuSign and its enterprise customers, determining which party bears primary responsibility for data subject rights responses, lawful basis determinations, and regulatory obligations depending on the product in use. The assertion of a dual controller/processor role for CLM and Identity products creates compliance dependencies that enterprise customers should reflect in their data …
Under this provision, individuals whose personal information is processed through DocuSign eSignature should direct data subject rights requests to the DocuSign customer (employer or requesting organization) rather than to DocuSign directly. For CLM and Identity products, DocuSign may independently determine processing purposes in certain circumstances, which affects the applicable rights framework.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by DocuSign.