Provision record
DocuSign · DocuSign Privacy Statement · View original document ↗

Consent Required for Sensitive Personal Information

High severity Explicit document language Common · 296 of 352 platforms
Stay ahead of the changes
Track DocuSign and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF

This analysis describes what DocuSign's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

Clause Stability Stable

0
Changes
5
Months Monitored
Jul 10, 2026
First Seen
Jul 10, 2026
Last Seen
This clause type exists across 4186 other provisions on other platforms.

How other platforms handle this

GitHub Medium

In some jurisdictions, we only use non-essential cookies after obtaining your consent.

Baseten Medium

Category A: Identifiers. Examples: A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, driver's license number, passport number... Collected: Yes.

Apple App Store Medium

to the extent that Internet Protocol (IP) addresses or similar identifiers are considered personal data by local law, we also treat these identifiers as personal data in those regions.

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
If we process sensitive personal information about you, as well as ensuring that one of the lawful bases referenced above applies, we will make sure that one or more of the grounds for processing sensitive personal information applies.

Excerpt from DocuSign's Privacy Statement

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
ePrivacy Directive
European Union
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
DocuSign Privacy Statement
Entity
DocuSign
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-031422
Document ID
CA-D-00198
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
db171ce667d98db1d8936fb125acc66e0d283cc7f0c00e08307fb68fd757092c
Analysis generated
July 9, 2026 06:43 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: DocuSign
Document: DocuSign Privacy Statement
Record ID: CA-P-031422
Captured: 2026-07-09 06:43:10 UTC
SHA-256: db171ce667d98db1…
URL: https://conductatlas.com/platform/docusign/docusign-privacy-statement/provision/CA-P-031422/consent-required-for-sensitive-personal-information/
Accessed: Aug. 18, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does DocuSign's Consent Required for Sensitive Personal Information clause do?

The clause states: “If we process sensitive personal information about you, as well as ensuring that one of the lawful bases referenced above applies, we will make sure that one or more of the grounds for processing sensitive personal information applies.”

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 296 platforms. See the full comparison.

Is ConductAtlas affiliated with DocuSign?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by DocuSign.