Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The notice states that DocuSign acts as a data processor for eSignature customers, while asserting both processor and controller roles for CLM and Identity products depending on the processing activity, and directs data subject rights requests to the relevant customer where DocuSign acts as processor.
This analysis describes what DocuSign's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the structural data governance relationship between DocuSign and its enterprise customers, determining which party bears primary responsibility for data subject rights responses, lawful basis determinations, and regulatory obligations depending on the product in use. The assertion of a dual controller/processor role for CLM and Identity products creates compliance dependencies that enterprise customers should reflect in their data processing agreements.
Under this provision, individuals whose personal information is processed through DocuSign eSignature should direct data subject rights requests to the DocuSign customer (employer or requesting organization) rather than to DocuSign directly. For CLM and Identity products, DocuSign may independently determine processing purposes in certain circumstances, which affects the applicable rights framework.
Cross-platform context
See how other platforms handle Controller/Processor Dual Role by Product Line and similar clauses.
Compare across platforms →Monitoring
DocuSign has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"When our business customers use certain Services, we generally process and store limited personal information on their behalf as a data processor. For example, in the context of Docusign eSignature, when a customer uploads contracts or other documents for review or signature, we act as a data processor and process the documents on the customer's behalf and in accordance with their instructions. In those instances, the customer is the data controller and is responsible for most aspects of the processing of the personal information. For certain products such as Docusign's Contract Lifecycle Management (CLM) and Identity products, we may act as a processor and as a controller in certain circumstances (e.g., retention of transactional data to comply with Docusign's legal obligations).Excerpt from DocuSign's Privacy Statement
1. REGULATORY LANDSCAPE: This provision directly engages GDPR Article 4 definitions of controller and processor, Article 28 data processing agreement requirements, and Article 82 liability allocation between controllers and processors. UK GDPR applies equivalent obligations. The characterization of DocuSign as a controller for certain CLM and Identity processing activities creates independent GDPR accountability obligations for DocuSign beyond those applicable in a pure processor context. 2. GOVERNANCE EXPOSURE: High. The dual role assertion across product lines means that enterprise customers cannot apply a uniform data processing agreement framework across all DocuSign products. Customers must map each product's data flows to the correct controller/processor characterization and ensure their DPAs reflect the specific role DocuSign asserts for each product. Failure to do so may create gaps in regulatory accountability and data subject rights coverage. 3. JURISDICTION FLAGS: EU/EEA and UK customers face the highest exposure given mandatory DPA requirements under GDPR Article 28. California customers should assess whether the controller characterization for CLM and Identity products affects their own CCPA service provider exception claims. Healthcare and financial services customers should evaluate whether DocuSign's independent controller role for certain processing activities engages sector-specific data governance obligations. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement and legal teams should ensure that data processing agreements with DocuSign specifically address the product-by-product controller/processor characterization described in this notice. Agreements should specify DocuSign's obligations as an independent controller for CLM and Identity-related processing, including lawful basis, retention, and data subject rights handling. Standard DPA templates may not adequately address the dual-role structure. 5. COMPLIANCE CONSIDERATIONS: Legal teams should conduct a product-level data mapping exercise to identify which DocuSign products are in use and which controller/processor characterization applies to each. Where DocuSign acts as a controller, enterprise customers should evaluate whether their own privacy notices accurately describe DocuSign as a third-party data controller rather than a service provider.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes the structural data governance relationship between DocuSign and its enterprise customers, determining which party bears primary responsibility for data subject rights responses, lawful basis determinations, and regulatory obligations depending on the product in use. The assertion of a dual controller/processor role for CLM and Identity products creates compliance dependencies that enterprise customers should reflect in their data …
Under this provision, individuals whose personal information is processed through DocuSign eSignature should direct data subject rights requests to the DocuSign customer (employer or requesting organization) rather than to DocuSign directly. For CLM and Identity products, DocuSign may independently determine processing purposes in certain circumstances, which affects the applicable rights framework.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by DocuSign.