Figma · Figma Privacy Policy (Superseded URL) · View original document ↗

K-12 Domain Capture Enabled by Default

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Figma changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Figma recorded 4 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Figma Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy states that domain capture is enabled by default for K-12 Enterprise education accounts, resulting in automatic disclosure of names, email addresses, and profile pictures to all users sharing the same organizational email domain.

This analysis describes what Figma's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes a default-on data sharing configuration for education accounts that discloses student or staff identifying information across an organization without requiring affirmative action to enable the feature, which may engage FERPA and state student privacy obligations for U.S. educational institutions.

Recent Activity

This document changed recently

Medium May 28, 2026

The updated terms now restrict how Figma may use personal information from children. Children may only use the Services through a Figma for Education Enterprise agreement with their school, and Figma explicitly prohibits using children's personal information to train or improve AI services, serve targeted advertisements, or enable third-party tracking. Parents may contact Figma if they learn a child provided personal information without consent outside of an education agreement.

View change record →

Consumer impact (what this means for users)

Under this provision, users on Figma for Education Enterprise accounts have their name, email address, and profile picture automatically shared with others in their organization who share the same email domain, as this feature is enabled by default rather than requiring administrator activation.

Cross-platform context

See how other platforms handle K-12 Domain Capture Enabled by Default and similar clauses.

Compare across platforms →

Monitoring

Figma has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Figma for Education's Enterprise accounts have domain capture functionality enabled by default in order to protect against unauthorized access from users with a different email domain. With domain capture enabled your name, email and profile picture (if you upload one) will be disclosed to other users across your Figma organization. This should be noted if email domains are shared across multiple educational institutions.

Excerpt from Figma's Privacy Policy (Superseded URL)

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision implicates the Family Educational Rights and Privacy Act (FERPA) for U.S. K-12 institutions, as email addresses and names of students may qualify as education records or directory information subject to FERPA's disclosure requirements. State student privacy laws, including California's Student Online Personal Information Protection Act (SOPIPA), may also be engaged. The FTC holds general consumer protection jurisdiction, and state attorneys general may have jurisdiction under state student privacy statutes. 2. GOVERNANCE EXPOSURE: Medium. The default-on nature of domain capture for K-12 Enterprise accounts means that institutions must affirmatively take action to disable the feature if they determine it is inconsistent with their FERPA obligations or institutional policies. The policy's note that this should be considered when email domains are shared across multiple institutions suggests a recognized operational risk of cross-institutional disclosure. 3. JURISDICTION FLAGS: U.S. K-12 educational institutions have heightened exposure under FERPA and state student privacy laws. California institutions should evaluate SOPIPA applicability. Institutions in other jurisdictions should assess applicable student data protection requirements. The policy does not address how this provision interacts with GDPR for EU-based educational institutions. 4. CONTRACT AND VENDOR IMPLICATIONS: Educational institutions procuring Figma Enterprise for K-12 use should ensure their agreements with Figma address FERPA compliance, including whether Figma is designated as a school official under FERPA with legitimate educational interest, and whether the domain capture default is addressed in any applicable data processing agreements. Institutions sharing email domains with other schools should assess cross-institutional disclosure risks before deployment. 5. COMPLIANCE CONSIDERATIONS: K-12 compliance teams should verify whether domain capture has been disabled or reviewed in their Figma Enterprise accounts. Institutions should assess whether the automatic disclosure of student names and emails satisfies their FERPA directory information policies and whether parental or eligible student consent is required. Data processing agreements with Figma should be reviewed to confirm FERPA-compliant data handling obligations.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • FTC
    The FTC has jurisdiction over unfair or deceptive practices affecting student users and educational data handling
    File a complaint →
  • State AG
    State attorneys general may have jurisdiction under state student privacy statutes including California SOPIPA and other state-level education privacy laws
    File a complaint →

Provision details

Document information
Document
Figma Privacy Policy (Superseded URL)
Entity
Figma
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015823
Document ID
CA-D-00544
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
f7f03821eec4a58f9dc0198f7828ff49a980d5d548d3fa82093da85a7a1559da
Analysis generated
July 9, 2026 08:53 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Figma
Document: Figma Privacy Policy (Superseded URL)
Record ID: CA-P-015823
Captured: 2026-07-09 08:53:35 UTC
SHA-256: f7f03821eec4a58f…
URL: https://conductatlas.com/platform/figma/figma-privacy-policy-superseded-url/provision/CA-P-015823/k-12-domain-capture-enabled-by-default/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Figma's K-12 Domain Capture Enabled by Default clause do?

This provision establishes a default-on data sharing configuration for education accounts that discloses student or staff identifying information across an organization without requiring affirmative action to enable the feature, which may engage FERPA and state student privacy obligations for U.S. educational institutions.

How does this clause affect you?

Under this provision, users on Figma for Education Enterprise accounts have their name, email address, and profile picture automatically shared with others in their organization who share the same email domain, as this feature is enabled by default rather than requiring administrator activation.

Is ConductAtlas affiliated with Figma?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Figma.