Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that domain capture is enabled by default for K-12 Enterprise education accounts, resulting in automatic disclosure of names, email addresses, and profile pictures to all users sharing the same organizational email domain.
This analysis describes what Figma's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a default-on data sharing configuration for education accounts that discloses student or staff identifying information across an organization without requiring affirmative action to enable the feature, which may engage FERPA and state student privacy obligations for U.S. educational institutions.
The updated terms now restrict how Figma may use personal information from children. Children may only use the Services through a Figma for Education Enterprise agreement with their school, and Figma explicitly prohibits using children's personal information to train or improve AI services, serve targeted advertisements, or enable third-party tracking. Parents may contact Figma if they learn a child provided personal information without consent outside of an education agreement.
View change record →Under this provision, users on Figma for Education Enterprise accounts have their name, email address, and profile picture automatically shared with others in their organization who share the same email domain, as this feature is enabled by default rather than requiring administrator activation.
Cross-platform context
See how other platforms handle K-12 Domain Capture Enabled by Default and similar clauses.
Compare across platforms →Monitoring
Figma has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Figma for Education's Enterprise accounts have domain capture functionality enabled by default in order to protect against unauthorized access from users with a different email domain. With domain capture enabled your name, email and profile picture (if you upload one) will be disclosed to other users across your Figma organization. This should be noted if email domains are shared across multiple educational institutions.Excerpt from Figma's Privacy Policy (Superseded URL)
1. REGULATORY LANDSCAPE: This provision implicates the Family Educational Rights and Privacy Act (FERPA) for U.S. K-12 institutions, as email addresses and names of students may qualify as education records or directory information subject to FERPA's disclosure requirements. State student privacy laws, including California's Student Online Personal Information Protection Act (SOPIPA), may also be engaged. The FTC holds general consumer protection jurisdiction, and state attorneys general may have jurisdiction under state student privacy statutes. 2. GOVERNANCE EXPOSURE: Medium. The default-on nature of domain capture for K-12 Enterprise accounts means that institutions must affirmatively take action to disable the feature if they determine it is inconsistent with their FERPA obligations or institutional policies. The policy's note that this should be considered when email domains are shared across multiple institutions suggests a recognized operational risk of cross-institutional disclosure. 3. JURISDICTION FLAGS: U.S. K-12 educational institutions have heightened exposure under FERPA and state student privacy laws. California institutions should evaluate SOPIPA applicability. Institutions in other jurisdictions should assess applicable student data protection requirements. The policy does not address how this provision interacts with GDPR for EU-based educational institutions. 4. CONTRACT AND VENDOR IMPLICATIONS: Educational institutions procuring Figma Enterprise for K-12 use should ensure their agreements with Figma address FERPA compliance, including whether Figma is designated as a school official under FERPA with legitimate educational interest, and whether the domain capture default is addressed in any applicable data processing agreements. Institutions sharing email domains with other schools should assess cross-institutional disclosure risks before deployment. 5. COMPLIANCE CONSIDERATIONS: K-12 compliance teams should verify whether domain capture has been disabled or reviewed in their Figma Enterprise accounts. Institutions should assess whether the automatic disclosure of student names and emails satisfies their FERPA directory information policies and whether parental or eligible student consent is required. Data processing agreements with Figma should be reviewed to confirm FERPA-compliant data handling obligations.
This provision establishes a default-on data sharing configuration for education accounts that discloses student or staff identifying information across an organization without requiring affirmative action to enable the feature, which may engage FERPA and state student privacy obligations for U.S. educational institutions.
Under this provision, users on Figma for Education Enterprise accounts have their name, email address, and profile picture automatically shared with others in their organization who share the same email domain, as this feature is enabled by default rather than requiring administrator activation.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Figma.