Figma · Figma Privacy Policy (Superseded URL) · View original document ↗

Organizational Administrator Data Disclosure and Control

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Figma changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Figma recorded 4 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Figma Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy states that when a user accesses Figma through an organizational account or has their account paid for by another party, Figma will disclose that user's information to the organization or paying party upon request and grant the organization certain control rights over the user's account information.

This analysis describes what Figma's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that organizational or employer accounts may request access to employee user data and certain control rights over those accounts, which is a common enterprise SaaS structure but creates data subject rights considerations for employees who may not be aware of this employer access mechanism.

Recent Activity

This document changed recently

Medium May 28, 2026

The updated terms now restrict how Figma may use personal information from children. Children may only use the Services through a Figma for Education Enterprise agreement with their school, and Figma explicitly prohibits using children's personal information to train or improve AI services, serve targeted advertisements, or enable third-party tracking. Parents may contact Figma if they learn a child provided personal information without consent outside of an education agreement.

View change record →

Consumer impact (what this means for users)

Under this provision, users whose Figma accounts are associated with an organization's domain or paid for by an employer or third party may have their account information disclosed to that organization upon the organization's request, and the organization may exercise certain control rights over the account.

Cross-platform context

See how other platforms handle Organizational Administrator Data Disclosure and Control and similar clauses.

Compare across platforms →

Monitoring

Figma has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
If you access the Services on behalf of an organization (such as with your organization's domain) or have your account paid for by another party, we will disclose your information to that organization or paying party at its request and give such organization certain rights over your information. For example, your organization may request that we provide extra security controls around your account to protect information about your organization or your organization may request that we link your Figma account with your organization's account to enhance collaboration.

Excerpt from Figma's Privacy Policy (Superseded URL)

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision engages GDPR requirements around transparency and purpose limitation, as employees using employer-provided Figma accounts may not have been separately informed that their account data is accessible to the employer through Figma's disclosure mechanism. CCPA's employee data provisions are also relevant for California-based organizations. The policy notes that user information may also be subject to the organization's own privacy policy, which creates a layered processing framework. 2. GOVERNANCE EXPOSURE: Medium. Enterprise customers that exercise control rights over employee Figma accounts become data controllers with respect to that disclosed data and must ensure their own privacy notices to employees reflect this data access. HR and IT teams in regulated sectors should assess whether employee monitoring laws or works council notification requirements apply to the use of this provision. 3. JURISDICTION FLAGS: EU and UK employees have heightened exposure, as GDPR requires a documented legal basis for employer access to employee personal data and transparency obligations must be met through employee-facing privacy notices. German, French, and Dutch employment law may require works council consultation before activating organizational data access controls. California employees retain CCPA rights over personal information even in employment contexts. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement teams should ensure their Figma agreements and DPAs clearly define the data controller and processor relationships for organizational account data. Internal policies governing IT administrator access to employee Figma data should be reviewed and documented. The policy's statement that Figma is not responsible for the organization's privacy practices means enterprise customers bear independent compliance responsibility for their use of disclosed employee data. 5. COMPLIANCE CONSIDERATIONS: HR and legal teams at organizations deploying Figma should review whether employee-facing privacy notices disclose that Figma account data may be accessed by the employer. Data mapping exercises should capture the organizational data access pathway as a distinct processing activity. In jurisdictions with employee monitoring notification requirements, activation of organizational control rights may trigger notification obligations.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • FTC
    The FTC has jurisdiction over consumer and employee privacy practices and the adequacy of notice regarding employer data access mechanisms
    File a complaint →

Provision details

Document information
Document
Figma Privacy Policy (Superseded URL)
Entity
Figma
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015826
Document ID
CA-D-00544
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
f7f03821eec4a58f9dc0198f7828ff49a980d5d548d3fa82093da85a7a1559da
Analysis generated
July 9, 2026 08:53 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Figma
Document: Figma Privacy Policy (Superseded URL)
Record ID: CA-P-015826
Captured: 2026-07-09 08:53:35 UTC
SHA-256: f7f03821eec4a58f…
URL: https://conductatlas.com/platform/figma/figma-privacy-policy-superseded-url/provision/CA-P-015826/organizational-administrator-data-disclosure-and-control/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Figma's Organizational Administrator Data Disclosure and Control clause do?

This provision establishes that organizational or employer accounts may request access to employee user data and certain control rights over those accounts, which is a common enterprise SaaS structure but creates data subject rights considerations for employees who may not be aware of this employer access mechanism.

How does this clause affect you?

Under this provision, users whose Figma accounts are associated with an organization's domain or paid for by an employer or third party may have their account information disclosed to that organization upon the organization's request, and the organization may exercise certain control rights over the account.

Is ConductAtlas affiliated with Figma?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Figma.