Figma · Figma Privacy Policy (Superseded URL) · View original document ↗

International Data Transfers via Standard Contractual Clauses

Low severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Figma changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Figma recorded 4 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Figma Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy states that personal data transferred outside the EEA, Switzerland, and UK to non-adequate countries is safeguarded through Module 2 Standard Contractual Clauses under GDPR Article 46(2), with Swiss-law amendments and a UK Addendum for UK-originating transfers.

This analysis describes what Figma's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision documents the legal transfer mechanisms Figma relies upon for international data flows, specifying Module 2 SCCs (controller-to-processor) as the primary safeguard, which is operationally significant for enterprise customers conducting transfer impact assessments under GDPR.

Recent Activity

This document changed recently

Medium May 28, 2026

The updated terms now restrict how Figma may use personal information from children. Children may only use the Services through a Figma for Education Enterprise agreement with their school, and Figma explicitly prohibits using children's personal information to train or improve AI services, serve targeted advertisements, or enable third-party tracking. Parents may contact Figma if they learn a child provided personal information without consent outside of an education agreement.

View change record →

Consumer impact (what this means for users)

Under this provision, personal data transferred from the EEA, Switzerland, or UK to countries without an adequacy decision is protected through Module 2 Standard Contractual Clauses, with jurisdiction-specific modifications. The sub-processor list referenced at figma.com/sub-processors discloses the geographies where processing occurs.

Cross-platform context

See how other platforms handle International Data Transfers via Standard Contractual Clauses and similar clauses.

Compare across platforms →

Monitoring

Figma has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Where we transfer your personal information to countries and territories outside of the European Economic Area ("EEA"), Switzerland and the UK which have been formally recognized as providing an adequate level of protection for personal information, we rely on the relevant "adequacy decisions" and "adequacy regulations" from the European Commission, Swiss and UK authorities. Where the transfer is not subject to an adequacy decision or derogation under the applicable law, we take appropriate safeguards to ensure that your personal information will remain protected in accordance with this Privacy Policy and applicable laws. These safeguards include implementing the Module 2 of European Commission's Standard Contractual Clauses as issued on 4 June 2021 under Article 46(2) GDPR for transfers originating in the EEA, Switzerland (with amendments required under the applicable Swiss law) and the UK Addendum permitted under Article 46(2) of the UK GDPR for the transfer of data originating in the UK.

Excerpt from Figma's Privacy Policy (Superseded URL)

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision directly engages GDPR Article 46(2) and the European Commission's June 2021 SCCs, UK GDPR Article 46(2) and the ICO's UK Addendum, and Swiss data protection law transfer requirements. The EU-U.S. DPF serves as a parallel transfer mechanism as described in Section 7 of the policy. EDPB guidance on transfer impact assessments is operationally relevant to enterprise customers evaluating Figma as a data processor. 2. GOVERNANCE EXPOSURE: Low to Medium. Module 2 SCCs are a recognized GDPR-compliant transfer mechanism, and their use for controller-to-processor transfers is standard practice. However, enterprise customers remain responsible for conducting transfer impact assessments for their own use of Figma as a processor, particularly where Figma sub-processes data in jurisdictions that may be subject to government access risks. 3. JURISDICTION FLAGS: EEA, UK, and Swiss users have the most direct exposure to international transfer compliance requirements. Enterprise customers with operations in these jurisdictions must ensure their DPAs with Figma incorporate the applicable SCCs and that transfer impact assessments have been conducted and documented. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement teams should access the Customer DPA linked in the policy to confirm SCC incorporation. The sub-processor list at figma.com/sub-processors should be reviewed to identify all processing geographies. DPAs should include sub-processor change notification obligations and objection rights consistent with GDPR processor requirements. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should document their transfer impact assessment for Figma as a processor, using the sub-processor list to identify jurisdictions subject to assessment. The DPA should be reviewed to confirm Module 2 SCC language is current and reflects the 2021 SCCs. Any updates to the sub-processor list should trigger a review of whether existing transfer safeguards remain adequate.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC holds enforcement jurisdiction over Figma's DPF compliance as stated in the policy, which operates alongside SCCs as a transfer mechanism
    File a complaint →

Provision details

Document information
Document
Figma Privacy Policy (Superseded URL)
Entity
Figma
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015828
Document ID
CA-D-00544
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
f7f03821eec4a58f9dc0198f7828ff49a980d5d548d3fa82093da85a7a1559da
Analysis generated
July 9, 2026 08:53 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Figma
Document: Figma Privacy Policy (Superseded URL)
Record ID: CA-P-015828
Captured: 2026-07-09 08:53:35 UTC
SHA-256: f7f03821eec4a58f…
URL: https://conductatlas.com/platform/figma/figma-privacy-policy-superseded-url/provision/CA-P-015828/international-data-transfers-via-standard-contractual-clauses/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Figma's International Data Transfers via Standard Contractual Clauses clause do?

This provision documents the legal transfer mechanisms Figma relies upon for international data flows, specifying Module 2 SCCs (controller-to-processor) as the primary safeguard, which is operationally significant for enterprise customers conducting transfer impact assessments under GDPR.

How does this clause affect you?

Under this provision, personal data transferred from the EEA, Switzerland, or UK to countries without an adequacy decision is protected through Module 2 Standard Contractual Clauses, with jurisdiction-specific modifications. The sub-processor list referenced at figma.com/sub-processors discloses the geographies where processing occurs.

Is ConductAtlas affiliated with Figma?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Figma.