The notice states that personal information is retained no longer than necessary for processing purposes or as required by law, with specific periods governed by a data retention policy and information handling standards referenced but not reproduced in the notice. Where technical limitations prevent deletion, the notice states that access is limited and security measures are applied.
This analysis describes what DocuSign's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The notice references a separate data retention policy and information handling standards that govern specific retention periods but does not reproduce those periods in the notice itself. The acknowledgment that technical limitations may prevent deletion, with safeguards applied in lieu of deletion, is an operationally relevant disclosure for enterprise data governance purposes.
Interpretive note: The notice references a separate data retention policy and information handling standards that are not reproduced in the notice, creating interpretive uncertainty about the specific retention periods applied to each data category.
Under this provision, DocuSign retains personal information for periods determined by its separate data retention policy and applicable legal requirements, which are not specified in the notice. Where deletion is technically infeasible, the agreement states that active use is limited and security measures are applied rather than full deletion occurring.
Cross-platform context
See how other platforms handle Retention of Personal Information and similar clauses.
Compare across platforms →"We keep your personal information for no longer than necessary for the purposes for which it is processed. The length of time for which we retain personal information depends on the purposes for which we collected and use it and/or as required to comply with applicable laws as set out in our data retention policy and information handling standards. Generally, this means we retain your personal information to comply with any retention compliance obligations or statutory requirements or for purposes of performing a contract with you. Where there are technical limitations that prevent deletion or anonymization, we safeguard personal information and limit active use of it through implementing appropriate organizational technical and security measures.Excerpt from DocuSign's Privacy Statement
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The notice references a separate data retention policy and information handling standards that govern specific retention periods but does not reproduce those periods in the notice itself. The acknowledgment that technical limitations may prevent deletion, with safeguards applied in lieu of deletion, is an operationally relevant disclosure for enterprise data governance purposes.
Under this provision, DocuSign retains personal information for periods determined by its separate data retention policy and applicable legal requirements, which are not specified in the notice. Where deletion is technically infeasible, the agreement states that active use is limited and security measures are applied rather than full deletion occurring.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by DocuSign.