DocuSign · DocuSign Privacy Statement · View original document ↗

Data Subject Rights Request Process

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time DocuSign changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for DocuSign Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The notice establishes a Privacy Request Portal as the designated mechanism for submitting data subject rights requests including access, deletion, correction, and export, and states that identity verification is required for all requests, with account login accepted as verification for registered users.

This analysis describes what DocuSign's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes the operational procedure for exercising data subject rights under GDPR, UK GDPR, CCPA, and applicable state privacy laws, including the identity verification standard and authorized agent process. The requirement to provide additional verification for non-account holders may affect the ease of exercising rights for individuals who receive documents through DocuSign without having a registered account.

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this provision, individuals can submit rights requests including deletion, correction, access, and data export through the DocuSign Privacy Request Portal, with identity verification required as a condition of processing. Authorized agents may submit requests on behalf of individuals subject to verification of the agent's authority.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Visit the DocuSign Privacy Request Portal and submit a deletion or rights request. You will be required to verify your identity through your account login if you are a registered user, or by providing additional identifying information if you are not.
  • Export Your Data
    Submit a data export request through the DocuSign Privacy Request Portal with identity verification completed. The portal accepts requests from authorized agents with documentation of authorization.

Cross-platform context

See how other platforms handle Data Subject Rights Request Process and similar clauses.

Compare across platforms →

Monitoring

DocuSign has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
To exercise any of these rights, please contact us via the Docusign Privacy Request Portal. If you make a request to exercise the rights referenced above, we will require you to provide certain information for identity verification purposes. If you have an account with us, we may verify you through your login of your account. If you do not have an account with us, we may require you to provide additional information from which we can confirm your identity. You may authorize an agent to make a request to us on your behalf and we will verify the identity of your agent or authorized legal representative by either seeking confirmation from you or documents that establish the agent's authorization to act on your behalf.

Excerpt from DocuSign's Privacy Statement

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision engages GDPR Articles 15 through 22 data subject rights, UK GDPR equivalent provisions, and CCPA Sections 1798.100 through 1798.125. The authorized agent mechanism reflects CCPA requirements. GDPR imposes response time obligations (generally 30 days, extendable by two months) that are not specified in the notice text itself. 2. GOVERNANCE EXPOSURE: Medium. The notice directs all rights requests to the Privacy Request Portal, which is consistent with industry practice. However, the notice separately states that where DocuSign acts as a processor, rights requests will be forwarded to the relevant customer, which may extend response timelines and create accountability gaps if not addressed in data processing agreements. 3. JURISDICTION FLAGS: EU/EEA and UK users have mandatory rights under GDPR and UK GDPR with specific response time requirements. California residents have CCPA rights including the right to appeal a denied request, which the notice acknowledges. Other state privacy law jurisdictions may impose additional rights or response obligations. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers whose employees or transaction counterparties submit rights requests to DocuSign should ensure their data processing agreements specify how DocuSign will forward and coordinate processor-context rights requests. The notice states that DocuSign will forward processor-context requests to the relevant customer, but does not specify a timeline for doing so. 5. COMPLIANCE CONSIDERATIONS: Legal teams should review whether the Privacy Request Portal's identity verification process satisfies GDPR and CCPA requirements for verifiable consumer requests without being unduly burdensome. The appeal process referenced in the notice should be documented internally for California and other state privacy law compliance.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Applicable agencies

  • FTC
    The FTC has jurisdiction over representations about data subject rights processes and their implementation under the FTC Act.
    File a complaint →
  • State AG
    State attorneys general have enforcement authority over CCPA and state privacy law rights response obligations.
    File a complaint →

Provision details

Document information
Document
DocuSign Privacy Statement
Entity
DocuSign
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014913
Document ID
CA-D-00198
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
db171ce667d98db1d8936fb125acc66e0d283cc7f0c00e08307fb68fd757092c
Analysis generated
July 9, 2026 06:43 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: DocuSign
Document: DocuSign Privacy Statement
Record ID: CA-P-014913
Captured: 2026-07-09 06:43:10 UTC
SHA-256: db171ce667d98db1…
URL: https://conductatlas.com/platform/docusign/docusign-privacy-statement/provision/CA-P-014913/data-subject-rights-request-process/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Frequently Asked Questions

What does DocuSign's Data Subject Rights Request Process clause do?

This provision establishes the operational procedure for exercising data subject rights under GDPR, UK GDPR, CCPA, and applicable state privacy laws, including the identity verification standard and authorized agent process. The requirement to provide additional verification for non-account holders may affect the ease of exercising rights for individuals who receive documents through DocuSign without having a registered account.

How does this clause affect you?

Under this provision, individuals can submit rights requests including deletion, correction, access, and data export through the DocuSign Privacy Request Portal, with identity verification required as a condition of processing. Authorized agents may submit requests on behalf of individuals subject to verification of the agent's authority.

Is ConductAtlas affiliated with DocuSign?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by DocuSign.