DocuSign · DocuSign Privacy Statement · View original document ↗

Retention of Personal Information

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time DocuSign changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for DocuSign Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The notice states that personal information is retained no longer than necessary for processing purposes or as required by law, with specific periods governed by a data retention policy and information handling standards referenced but not reproduced in the notice. Where technical limitations prevent deletion, the notice states that access is limited and security measures are applied.

This analysis describes what DocuSign's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The notice references a separate data retention policy and information handling standards that govern specific retention periods but does not reproduce those periods in the notice itself. The acknowledgment that technical limitations may prevent deletion, with safeguards applied in lieu of deletion, is an operationally relevant disclosure for enterprise data governance purposes.

Interpretive note: The notice references a separate data retention policy and information handling standards that are not reproduced in the notice, creating interpretive uncertainty about the specific retention periods applied to each data category.

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this provision, DocuSign retains personal information for periods determined by its separate data retention policy and applicable legal requirements, which are not specified in the notice. Where deletion is technically infeasible, the agreement states that active use is limited and security measures are applied rather than full deletion occurring.

Cross-platform context

See how other platforms handle Retention of Personal Information and similar clauses.

Compare across platforms →

Monitoring

DocuSign has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We keep your personal information for no longer than necessary for the purposes for which it is processed. The length of time for which we retain personal information depends on the purposes for which we collected and use it and/or as required to comply with applicable laws as set out in our data retention policy and information handling standards. Generally, this means we retain your personal information to comply with any retention compliance obligations or statutory requirements or for purposes of performing a contract with you. Where there are technical limitations that prevent deletion or anonymization, we safeguard personal information and limit active use of it through implementing appropriate organizational technical and security measures.

Excerpt from DocuSign's Privacy Statement

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision engages GDPR Article 5(1)(e) storage limitation principle and Article 17 right to erasure, which require that personal information not be retained longer than necessary and that deletion be carried out upon valid request. The reference to a separate data retention policy creates an external document dependency for full GDPR Article 13/14 compliance assessment. CCPA does not impose specific retention limits but requires disclosure of retention practices. 2. GOVERNANCE EXPOSURE: Medium. The notice does not specify retention periods by data category, directing readers to a separate policy. This creates a documentation gap for GDPR compliance purposes, where data subjects are entitled to know retention periods or the criteria for determining them. The technical limitation exception is acknowledged but the specific safeguards are not described. 3. JURISDICTION FLAGS: EU/EEA and UK users have the strongest exposure given GDPR storage limitation requirements. California users should be aware that retention periods affect the practical exercise of deletion rights, as legal obligation retention may override deletion requests. Healthcare and financial services customers may have sector-specific retention requirements that interact with DocuSign's retention framework. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers should request access to DocuSign's referenced data retention policy and information handling standards to verify that retention periods for customer data processed through eSignature, CLM, and Identity products are consistent with the customer's own regulatory obligations. Data processing agreements should specify retention terms and deletion timelines. 5. COMPLIANCE CONSIDERATIONS: Legal teams should request the data retention policy referenced in the notice and evaluate whether it satisfies GDPR Article 13/14 disclosure requirements. The technical limitation carve-out should be assessed against applicable erasure obligations, and enterprise customers should confirm what safeguards are applied in lieu of deletion.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Applicable agencies

  • FTC
    The FTC has jurisdiction over data retention representations and practices under the FTC Act.
    File a complaint →

Provision details

Document information
Document
DocuSign Privacy Statement
Entity
DocuSign
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014917
Document ID
CA-D-00198
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
db171ce667d98db1d8936fb125acc66e0d283cc7f0c00e08307fb68fd757092c
Analysis generated
July 9, 2026 06:43 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: DocuSign
Document: DocuSign Privacy Statement
Record ID: CA-P-014917
Captured: 2026-07-09 06:43:10 UTC
SHA-256: db171ce667d98db1…
URL: https://conductatlas.com/platform/docusign/docusign-privacy-statement/provision/CA-P-014917/retention-of-personal-information/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Frequently Asked Questions

What does DocuSign's Retention of Personal Information clause do?

The notice references a separate data retention policy and information handling standards that govern specific retention periods but does not reproduce those periods in the notice itself. The acknowledgment that technical limitations may prevent deletion, with safeguards applied in lieu of deletion, is an operationally relevant disclosure for enterprise data governance purposes.

How does this clause affect you?

Under this provision, DocuSign retains personal information for periods determined by its separate data retention policy and applicable legal requirements, which are not specified in the notice. Where deletion is technically infeasible, the agreement states that active use is limited and security measures are applied rather than full deletion occurring.

Is ConductAtlas affiliated with DocuSign?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by DocuSign.