Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The notice states that personal information is retained no longer than necessary for processing purposes or as required by law, with specific periods governed by a data retention policy and information handling standards referenced but not reproduced in the notice. Where technical limitations prevent deletion, the notice states that access is limited and security measures are applied.
This analysis describes what DocuSign's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The notice references a separate data retention policy and information handling standards that govern specific retention periods but does not reproduce those periods in the notice itself. The acknowledgment that technical limitations may prevent deletion, with safeguards applied in lieu of deletion, is an operationally relevant disclosure for enterprise data governance purposes.
Interpretive note: The notice references a separate data retention policy and information handling standards that are not reproduced in the notice, creating interpretive uncertainty about the specific retention periods applied to each data category.
Under this provision, DocuSign retains personal information for periods determined by its separate data retention policy and applicable legal requirements, which are not specified in the notice. Where deletion is technically infeasible, the agreement states that active use is limited and security measures are applied rather than full deletion occurring.
Cross-platform context
See how other platforms handle Retention of Personal Information and similar clauses.
Compare across platforms →Monitoring
DocuSign has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"We keep your personal information for no longer than necessary for the purposes for which it is processed. The length of time for which we retain personal information depends on the purposes for which we collected and use it and/or as required to comply with applicable laws as set out in our data retention policy and information handling standards. Generally, this means we retain your personal information to comply with any retention compliance obligations or statutory requirements or for purposes of performing a contract with you. Where there are technical limitations that prevent deletion or anonymization, we safeguard personal information and limit active use of it through implementing appropriate organizational technical and security measures.Excerpt from DocuSign's Privacy Statement
1. REGULATORY LANDSCAPE: This provision engages GDPR Article 5(1)(e) storage limitation principle and Article 17 right to erasure, which require that personal information not be retained longer than necessary and that deletion be carried out upon valid request. The reference to a separate data retention policy creates an external document dependency for full GDPR Article 13/14 compliance assessment. CCPA does not impose specific retention limits but requires disclosure of retention practices. 2. GOVERNANCE EXPOSURE: Medium. The notice does not specify retention periods by data category, directing readers to a separate policy. This creates a documentation gap for GDPR compliance purposes, where data subjects are entitled to know retention periods or the criteria for determining them. The technical limitation exception is acknowledged but the specific safeguards are not described. 3. JURISDICTION FLAGS: EU/EEA and UK users have the strongest exposure given GDPR storage limitation requirements. California users should be aware that retention periods affect the practical exercise of deletion rights, as legal obligation retention may override deletion requests. Healthcare and financial services customers may have sector-specific retention requirements that interact with DocuSign's retention framework. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers should request access to DocuSign's referenced data retention policy and information handling standards to verify that retention periods for customer data processed through eSignature, CLM, and Identity products are consistent with the customer's own regulatory obligations. Data processing agreements should specify retention terms and deletion timelines. 5. COMPLIANCE CONSIDERATIONS: Legal teams should request the data retention policy referenced in the notice and evaluate whether it satisfies GDPR Article 13/14 disclosure requirements. The technical limitation carve-out should be assessed against applicable erasure obligations, and enterprise customers should confirm what safeguards are applied in lieu of deletion.
The notice references a separate data retention policy and information handling standards that govern specific retention periods but does not reproduce those periods in the notice itself. The acknowledgment that technical limitations may prevent deletion, with safeguards applied in lieu of deletion, is an operationally relevant disclosure for enterprise data governance purposes.
Under this provision, DocuSign retains personal information for periods determined by its separate data retention policy and applicable legal requirements, which are not specified in the notice. Where deletion is technically infeasible, the agreement states that active use is limited and security measures are applied rather than full deletion occurring.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by DocuSign.