DocuSign · DocuSign Privacy Statement · View original document ↗

Controller/Processor Dual Role by Product Line

High severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time DocuSign changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for DocuSign Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The notice states that DocuSign acts as a data processor for eSignature customers, while asserting both processor and controller roles for CLM and Identity products depending on the processing activity, and directs data subject rights requests to the relevant customer where DocuSign acts as processor.

This analysis describes what DocuSign's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes the structural data governance relationship between DocuSign and its enterprise customers, determining which party bears primary responsibility for data subject rights responses, lawful basis determinations, and regulatory obligations depending on the product in use. The assertion of a dual controller/processor role for CLM and Identity products creates compliance dependencies that enterprise customers should reflect in their data processing agreements.

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this provision, individuals whose personal information is processed through DocuSign eSignature should direct data subject rights requests to the DocuSign customer (employer or requesting organization) rather than to DocuSign directly. For CLM and Identity products, DocuSign may independently determine processing purposes in certain circumstances, which affects the applicable rights framework.

Cross-platform context

See how other platforms handle Controller/Processor Dual Role by Product Line and similar clauses.

Compare across platforms →

Monitoring

DocuSign has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
When our business customers use certain Services, we generally process and store limited personal information on their behalf as a data processor. For example, in the context of Docusign eSignature, when a customer uploads contracts or other documents for review or signature, we act as a data processor and process the documents on the customer's behalf and in accordance with their instructions. In those instances, the customer is the data controller and is responsible for most aspects of the processing of the personal information. For certain products such as Docusign's Contract Lifecycle Management (CLM) and Identity products, we may act as a processor and as a controller in certain circumstances (e.g., retention of transactional data to comply with Docusign's legal obligations).

Excerpt from DocuSign's Privacy Statement

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision directly engages GDPR Article 4 definitions of controller and processor, Article 28 data processing agreement requirements, and Article 82 liability allocation between controllers and processors. UK GDPR applies equivalent obligations. The characterization of DocuSign as a controller for certain CLM and Identity processing activities creates independent GDPR accountability obligations for DocuSign beyond those applicable in a pure processor context. 2. GOVERNANCE EXPOSURE: High. The dual role assertion across product lines means that enterprise customers cannot apply a uniform data processing agreement framework across all DocuSign products. Customers must map each product's data flows to the correct controller/processor characterization and ensure their DPAs reflect the specific role DocuSign asserts for each product. Failure to do so may create gaps in regulatory accountability and data subject rights coverage. 3. JURISDICTION FLAGS: EU/EEA and UK customers face the highest exposure given mandatory DPA requirements under GDPR Article 28. California customers should assess whether the controller characterization for CLM and Identity products affects their own CCPA service provider exception claims. Healthcare and financial services customers should evaluate whether DocuSign's independent controller role for certain processing activities engages sector-specific data governance obligations. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement and legal teams should ensure that data processing agreements with DocuSign specifically address the product-by-product controller/processor characterization described in this notice. Agreements should specify DocuSign's obligations as an independent controller for CLM and Identity-related processing, including lawful basis, retention, and data subject rights handling. Standard DPA templates may not adequately address the dual-role structure. 5. COMPLIANCE CONSIDERATIONS: Legal teams should conduct a product-level data mapping exercise to identify which DocuSign products are in use and which controller/processor characterization applies to each. Where DocuSign acts as a controller, enterprise customers should evaluate whether their own privacy notices accurately describe DocuSign as a third-party data controller rather than a service provider.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has jurisdiction over data handling representations and accountability structures under the FTC Act, relevant where DocuSign asserts independent controller responsibilities.
    File a complaint →

Provision details

Document information
Document
DocuSign Privacy Statement
Entity
DocuSign
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014907
Document ID
CA-D-00198
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
db171ce667d98db1d8936fb125acc66e0d283cc7f0c00e08307fb68fd757092c
Analysis generated
July 9, 2026 06:43 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: DocuSign
Document: DocuSign Privacy Statement
Record ID: CA-P-014907
Captured: 2026-07-09 06:43:10 UTC
SHA-256: db171ce667d98db1…
URL: https://conductatlas.com/platform/docusign/docusign-privacy-statement/provision/CA-P-014907/controllerprocessor-dual-role-by-product-line/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does DocuSign's Controller/Processor Dual Role by Product Line clause do?

This provision establishes the structural data governance relationship between DocuSign and its enterprise customers, determining which party bears primary responsibility for data subject rights responses, lawful basis determinations, and regulatory obligations depending on the product in use. The assertion of a dual controller/processor role for CLM and Identity products creates compliance dependencies that enterprise customers should reflect in their data …

How does this clause affect you?

Under this provision, individuals whose personal information is processed through DocuSign eSignature should direct data subject rights requests to the DocuSign customer (employer or requesting organization) rather than to DocuSign directly. For CLM and Identity products, DocuSign may independently determine processing purposes in certain circumstances, which affects the applicable rights framework.

Is ConductAtlas affiliated with DocuSign?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by DocuSign.