The policy states that when a user accesses Figma through an organizational account or has their account paid for by another party, Figma will disclose that user's information to the organization or paying party upon request and grant the organization certain control rights over the user's account information.
This analysis describes what Figma's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that organizational or employer accounts may request access to employee user data and certain control rights over those accounts, which is a common enterprise SaaS structure but creates data subject rights considerations for employees who may not be aware of this employer access mechanism.
The updated terms now restrict how Figma may use personal information from children. Children may only use the Services through a Figma for Education Enterprise agreement with their school, and Figma explicitly prohibits using children's personal information to train or improve AI services, serve targeted advertisements, or enable third-party tracking. Parents may contact Figma if they learn a child provided personal information without consent outside of an education agreement.
View change record →Under this provision, users whose Figma accounts are associated with an organization's domain or paid for by an employer or third party may have their account information disclosed to that organization upon the organization's request, and the organization may exercise certain control rights over the account.
Cross-platform context
See how other platforms handle Organizational Administrator Data Disclosure and Control and similar clauses.
Compare across platforms →"If you access the Services on behalf of an organization (such as with your organization's domain) or have your account paid for by another party, we will disclose your information to that organization or paying party at its request and give such organization certain rights over your information. For example, your organization may request that we provide extra security controls around your account to protect information about your organization or your organization may request that we link your Figma account with your organization's account to enhance collaboration.Excerpt from Figma's Privacy Policy (Superseded URL)
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes that organizational or employer accounts may request access to employee user data and certain control rights over those accounts, which is a common enterprise SaaS structure but creates data subject rights considerations for employees who may not be aware of this employer access mechanism.
Under this provision, users whose Figma accounts are associated with an organization's domain or paid for by an employer or third party may have their account information disclosed to that organization upon the organization's request, and the organization may exercise certain control rights over the account.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Figma.