Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that personal data transferred outside the EEA, Switzerland, and UK to non-adequate countries is safeguarded through Module 2 Standard Contractual Clauses under GDPR Article 46(2), with Swiss-law amendments and a UK Addendum for UK-originating transfers.
This analysis describes what Figma's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision documents the legal transfer mechanisms Figma relies upon for international data flows, specifying Module 2 SCCs (controller-to-processor) as the primary safeguard, which is operationally significant for enterprise customers conducting transfer impact assessments under GDPR.
The updated terms now restrict how Figma may use personal information from children. Children may only use the Services through a Figma for Education Enterprise agreement with their school, and Figma explicitly prohibits using children's personal information to train or improve AI services, serve targeted advertisements, or enable third-party tracking. Parents may contact Figma if they learn a child provided personal information without consent outside of an education agreement.
View change record →Under this provision, personal data transferred from the EEA, Switzerland, or UK to countries without an adequacy decision is protected through Module 2 Standard Contractual Clauses, with jurisdiction-specific modifications. The sub-processor list referenced at figma.com/sub-processors discloses the geographies where processing occurs.
Cross-platform context
See how other platforms handle International Data Transfers via Standard Contractual Clauses and similar clauses.
Compare across platforms →Monitoring
Figma has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Where we transfer your personal information to countries and territories outside of the European Economic Area ("EEA"), Switzerland and the UK which have been formally recognized as providing an adequate level of protection for personal information, we rely on the relevant "adequacy decisions" and "adequacy regulations" from the European Commission, Swiss and UK authorities. Where the transfer is not subject to an adequacy decision or derogation under the applicable law, we take appropriate safeguards to ensure that your personal information will remain protected in accordance with this Privacy Policy and applicable laws. These safeguards include implementing the Module 2 of European Commission's Standard Contractual Clauses as issued on 4 June 2021 under Article 46(2) GDPR for transfers originating in the EEA, Switzerland (with amendments required under the applicable Swiss law) and the UK Addendum permitted under Article 46(2) of the UK GDPR for the transfer of data originating in the UK.Excerpt from Figma's Privacy Policy (Superseded URL)
1. REGULATORY LANDSCAPE: This provision directly engages GDPR Article 46(2) and the European Commission's June 2021 SCCs, UK GDPR Article 46(2) and the ICO's UK Addendum, and Swiss data protection law transfer requirements. The EU-U.S. DPF serves as a parallel transfer mechanism as described in Section 7 of the policy. EDPB guidance on transfer impact assessments is operationally relevant to enterprise customers evaluating Figma as a data processor. 2. GOVERNANCE EXPOSURE: Low to Medium. Module 2 SCCs are a recognized GDPR-compliant transfer mechanism, and their use for controller-to-processor transfers is standard practice. However, enterprise customers remain responsible for conducting transfer impact assessments for their own use of Figma as a processor, particularly where Figma sub-processes data in jurisdictions that may be subject to government access risks. 3. JURISDICTION FLAGS: EEA, UK, and Swiss users have the most direct exposure to international transfer compliance requirements. Enterprise customers with operations in these jurisdictions must ensure their DPAs with Figma incorporate the applicable SCCs and that transfer impact assessments have been conducted and documented. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement teams should access the Customer DPA linked in the policy to confirm SCC incorporation. The sub-processor list at figma.com/sub-processors should be reviewed to identify all processing geographies. DPAs should include sub-processor change notification obligations and objection rights consistent with GDPR processor requirements. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should document their transfer impact assessment for Figma as a processor, using the sub-processor list to identify jurisdictions subject to assessment. The DPA should be reviewed to confirm Module 2 SCC language is current and reflects the 2021 SCCs. Any updates to the sub-processor list should trigger a review of whether existing transfer safeguards remain adequate.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision documents the legal transfer mechanisms Figma relies upon for international data flows, specifying Module 2 SCCs (controller-to-processor) as the primary safeguard, which is operationally significant for enterprise customers conducting transfer impact assessments under GDPR.
Under this provision, personal data transferred from the EEA, Switzerland, or UK to countries without an adequacy decision is protected through Module 2 Standard Contractual Clauses, with jurisdiction-specific modifications. The sub-processor list referenced at figma.com/sub-processors discloses the geographies where processing occurs.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Figma.