Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Figma certifies compliance with the EU-U.S. DPF, UK Extension, and Swiss-U.S. DPF, providing EU, UK, and Swiss users with an independent dispute resolution pathway through JAMS at no cost, with binding arbitration available as a final escalation mechanism under DPF rules.
This analysis describes what Figma's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a structured complaint resolution pathway for EU, UK, and Swiss users, including a 45-day initial response commitment, free referral to JAMS for unresolved complaints, and access to binding arbitration under DPF conditions, with the FTC holding enforcement jurisdiction over Figma's DPF obligations.
The updated terms now restrict how Figma may use personal information from children. Children may only use the Services through a Figma for Education Enterprise agreement with their school, and Figma explicitly prohibits using children's personal information to train or improve AI services, serve targeted advertisements, or enable third-party tracking. Parents may contact Figma if they learn a child provided personal information without consent outside of an education agreement.
View change record →Under this provision, EU, UK, and Swiss users who have unresolved data privacy complaints have access to JAMS dispute resolution at no charge, and may invoke binding arbitration as a final recourse under DPF framework conditions. The policy states that DPF Principles govern over the privacy policy terms in the event of conflict.
Cross-platform context
See how other platforms handle EU-U.S. Data Privacy Framework and Binding Arbitration Fallback and similar clauses.
Compare across platforms →Monitoring
Figma has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Figma, Inc. (for the purposes of this section, "Figma", "we", or "us") complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce... If you have an unresolved DPF complaint that we have not addressed satisfactorily, we have further committed to refer unresolved complaints to JAMS Data Privacy Dispute Resolution Program, an independent dispute resolution provider located in the U.S. made available free of charge. For more information or to submit a complaint please visit: https://www.jamsadr.com/DPF-Dispute-Resolution . Under certain conditions, more fully described on the Data Privacy Framework website, you may be entitled to invoke binding arbitration when other dispute resolution options do not satisfactorily resolve your concerns.Excerpt from Figma's Privacy Policy (Superseded URL)
1. REGULATORY LANDSCAPE: This provision directly engages the EU-U.S. Data Privacy Framework administered by the U.S. Department of Commerce, with FTC enforcement jurisdiction explicitly stated. The provision also engages UK GDPR and Swiss data protection law through their respective DPF extensions. EU data subjects retain rights under GDPR that may be asserted independently of the DPF mechanism. 2. GOVERNANCE EXPOSURE: Low to Medium. DPF certification provides a recognized adequacy mechanism for EU-U.S. data transfers, reducing exposure relative to relying solely on Standard Contractual Clauses. However, the DPF has previously faced legal challenge (Safe Harbor and Privacy Shield were invalidated by the Court of Justice of the EU), and future legal challenges to the DPF framework itself represent a structural risk that is not addressed in the policy. Compliance teams should monitor DPF validity. 3. JURISDICTION FLAGS: EU/EEA users have the most significant exposure to DPF-related risk in the event the framework is legally challenged. UK users benefit from the UK Extension. Swiss users are covered by the Swiss-U.S. DPF. U.S. users are not covered by this section's protections. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers with EEA, UK, or Swiss operations should confirm that Figma's DPF certification is current via the dataprivacyframework.gov registry. DPAs should be reviewed to confirm that transfer mechanisms are documented, noting that the policy also references SCCs as a parallel safeguard. Customers should assess whether DPF coverage extends to all data processing activities or only to specific data flows. 5. COMPLIANCE CONSIDERATIONS: Legal teams should monitor DPF legal status at the EU level and maintain SCCs as a fallback transfer mechanism given the policy's reference to both mechanisms. The 45-day complaint response commitment should be operationalized in Figma's customer-facing processes. Organizations acting as data controllers using Figma as a processor should assess whether their own transfer impact assessments are satisfied by Figma's DPF certification.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes a structured complaint resolution pathway for EU, UK, and Swiss users, including a 45-day initial response commitment, free referral to JAMS for unresolved complaints, and access to binding arbitration under DPF conditions, with the FTC holding enforcement jurisdiction over Figma's DPF obligations.
Under this provision, EU, UK, and Swiss users who have unresolved data privacy complaints have access to JAMS dispute resolution at no charge, and may invoke binding arbitration as a final recourse under DPF framework conditions. The policy states that DPF Principles govern over the privacy policy terms in the event of conflict.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Figma.