Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that when a user accesses Figma through an organizational account or has their account paid for by another party, Figma will disclose that user's information to the organization or paying party upon request and grant the organization certain control rights over the user's account information.
This analysis describes what Figma's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that organizational or employer accounts may request access to employee user data and certain control rights over those accounts, which is a common enterprise SaaS structure but creates data subject rights considerations for employees who may not be aware of this employer access mechanism.
The updated terms now restrict how Figma may use personal information from children. Children may only use the Services through a Figma for Education Enterprise agreement with their school, and Figma explicitly prohibits using children's personal information to train or improve AI services, serve targeted advertisements, or enable third-party tracking. Parents may contact Figma if they learn a child provided personal information without consent outside of an education agreement.
View change record →Under this provision, users whose Figma accounts are associated with an organization's domain or paid for by an employer or third party may have their account information disclosed to that organization upon the organization's request, and the organization may exercise certain control rights over the account.
Cross-platform context
See how other platforms handle Organizational Administrator Data Disclosure and Control and similar clauses.
Compare across platforms →Monitoring
Figma has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"If you access the Services on behalf of an organization (such as with your organization's domain) or have your account paid for by another party, we will disclose your information to that organization or paying party at its request and give such organization certain rights over your information. For example, your organization may request that we provide extra security controls around your account to protect information about your organization or your organization may request that we link your Figma account with your organization's account to enhance collaboration.Excerpt from Figma's Privacy Policy (Superseded URL)
1. REGULATORY LANDSCAPE: This provision engages GDPR requirements around transparency and purpose limitation, as employees using employer-provided Figma accounts may not have been separately informed that their account data is accessible to the employer through Figma's disclosure mechanism. CCPA's employee data provisions are also relevant for California-based organizations. The policy notes that user information may also be subject to the organization's own privacy policy, which creates a layered processing framework. 2. GOVERNANCE EXPOSURE: Medium. Enterprise customers that exercise control rights over employee Figma accounts become data controllers with respect to that disclosed data and must ensure their own privacy notices to employees reflect this data access. HR and IT teams in regulated sectors should assess whether employee monitoring laws or works council notification requirements apply to the use of this provision. 3. JURISDICTION FLAGS: EU and UK employees have heightened exposure, as GDPR requires a documented legal basis for employer access to employee personal data and transparency obligations must be met through employee-facing privacy notices. German, French, and Dutch employment law may require works council consultation before activating organizational data access controls. California employees retain CCPA rights over personal information even in employment contexts. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement teams should ensure their Figma agreements and DPAs clearly define the data controller and processor relationships for organizational account data. Internal policies governing IT administrator access to employee Figma data should be reviewed and documented. The policy's statement that Figma is not responsible for the organization's privacy practices means enterprise customers bear independent compliance responsibility for their use of disclosed employee data. 5. COMPLIANCE CONSIDERATIONS: HR and legal teams at organizations deploying Figma should review whether employee-facing privacy notices disclose that Figma account data may be accessed by the employer. Data mapping exercises should capture the organizational data access pathway as a distinct processing activity. In jurisdictions with employee monitoring notification requirements, activation of organizational control rights may trigger notification obligations.
This provision establishes that organizational or employer accounts may request access to employee user data and certain control rights over those accounts, which is a common enterprise SaaS structure but creates data subject rights considerations for employees who may not be aware of this employer access mechanism.
Under this provision, users whose Figma accounts are associated with an organization's domain or paid for by an employer or third party may have their account information disclosed to that organization upon the organization's request, and the organization may exercise certain control rights over the account.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Figma.