Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
If Figma is sold, merged, or acquired, your personal data may be transferred to the new owner as part of the business transaction.
This analysis describes what Figma's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
In the event of a corporate acquisition or merger, your Figma account data, design files, and personal information could be transferred to a new company whose privacy practices may differ from Figma's.
The updated terms now restrict how Figma may use personal information from children. Children may only use the Services through a Figma for Education Enterprise agreement with their school, and Figma explicitly prohibits using children's personal information to train or improve AI services, serve targeted advertisements, or enable third-party tracking. Parents may contact Figma if they learn a child provided personal information without consent outside of an education agreement.
View change record →If Figma undergoes a merger, acquisition, or asset sale, your personal data, including design files and account information, may be transferred to a new corporate entity without requiring your consent, subject to notice requirements that may apply under applicable law.
How other platforms handle this
If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.
When you are asked to provide information, you may decline to do so; but if you choose not to provide information that is necessary to provide some of our Services, you may not be able to use those Services.
Monitoring
Figma has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"We may share or transfer your personal information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business by another company. In such transactions, personal information is generally one of the business assets that is transferred.Excerpt from Figma's Privacy Policy (Superseded URL)
REGULATORY LANDSCAPE: Business transfer provisions in privacy policies are common and generally permissible under US law, but GDPR requires that personal data transferred in a corporate transaction continue to be processed in accordance with the original purposes and legal bases, or that data subjects are informed of material changes. The FTC has addressed privacy policy representations in corporate transactions, including through enforcement actions requiring that acquirers honor prior privacy commitments. GOVERNANCE EXPOSURE: Low to Medium. This is a standard clause in SaaS privacy policies, but the breadth of content data collected by Figma means that any corporate transaction could transfer significant volumes of proprietary user and organizational data to a new entity. Organizations with data sovereignty or confidentiality concerns should be aware of this provision. JURISDICTION FLAGS: EU and UK users' data transferred in a corporate transaction must continue to be processed in compliance with GDPR and UK GDPR, including transfer mechanism requirements if the acquirer is located outside adequate jurisdictions. California users retain CCPA rights following a business transfer. Data Protection Authorities may require notification of significant data transfers in corporate transactions. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers should consider whether their data processing agreements with Figma include provisions governing data handling in corporate transactions, including the right to terminate and retrieve data if the acquirer does not meet contractual privacy standards. Change of control clauses in enterprise contracts should be reviewed. COMPLIANCE CONSIDERATIONS: Legal teams should monitor Figma corporate transactions and assess whether any change of control triggers DPA review, renegotiation rights, or regulatory notification obligations. Internal procedures for assessing vendor corporate transactions and their privacy implications should be documented.
Regulatory citations, enforcement risk, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
In the event of a corporate acquisition or merger, your Figma account data, design files, and personal information could be transferred to a new company whose privacy practices may differ from Figma's.
If Figma undergoes a merger, acquisition, or asset sale, your personal data, including design files and account information, may be transferred to a new corporate entity without requiring your consent, subject to notice requirements that may apply under applicable law.
ConductAtlas has identified this type of provision across 295 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Figma.