Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that all personal information collected by Figma may be sold or transferred as part of a merger, acquisition, asset sale, bankruptcy, reorganization, or service transition, subject to applicable law and contract.
This analysis describes what Figma's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that personal information may be transferred to a different legal entity as part of a corporate transaction without requiring individual user consent, subject to the constraint that such transfer must be permitted by applicable law and contract.
The updated terms establish specific restrictions on how Figma may use personal information collected from minors. Children under 13 in the US, under 16 in California and the EU, and under 18 in Japan may now use the Services only through agreements with educational institutions. Figma states it will not use children's personal information to train, fine-tune, or improve AI services, nor will it permit service providers to do so. The policy also prohibits using children's data for marketing purposes, targeted advertising, or enabling third-party tracking. If a parent learns their child provided personal information without consent outside an educational agreement, they may contact Figma to report the issue.
View change record →Under this clause, personal information held by Figma may be transferred to a successor entity in the event of a corporate transaction including merger, acquisition, bankruptcy, or service transition. The agreement frames this transfer as occurring in accordance with Figma's legitimate interests and subject to applicable law and contractual constraints.
Cross-platform context
See how other platforms handle Disclosure in the Event of Merger, Sale, or Asset Transfer and similar clauses.
Compare across platforms →Monitoring
Figma has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Disclosure in the Event of Merger, Sale, or Other Asset Transfer. If we are involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, purchase or sale of assets, or transition of service to another provider, then your information may be sold or transferred in accordance with our legitimate interests in administering our business as part of such a transaction, as permitted by law and/or contract.Excerpt from Figma's Privacy Policy
1. REGULATORY LANDSCAPE: This provision implicates GDPR Article 6 regarding lawful basis for processing in the context of corporate transactions, CCPA disclosure requirements regarding data sales and transfers, and FTC Act Section 5 regarding representations about data use in acquisition contexts. The FTC has in prior actions required that acquirers in transactions not use personal data in ways inconsistent with original collection representations without consumer consent. The policy's reference to 'as permitted by law and/or contract' incorporates external legal constraints without enumerating them. 2. GOVERNANCE EXPOSURE: Low. Corporate transaction data transfer clauses are a commonly observed provision in privacy policies. The material governance consideration is whether the successor entity would be bound by the original privacy policy representations or could materially change data practices post-acquisition, which is not addressed in the quoted text. 3. JURISDICTION FLAGS: EU and UK users have GDPR-based rights regarding lawful basis for processing in corporate transactions. California users may have CCPA rights regarding notice of material changes to data use following an acquisition. The policy does not specify whether users will be notified of a transaction that results in data transfer. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers whose data processing agreements with Figma include data processing obligations should assess whether those agreements address successor entity obligations and whether DPA terms would bind an acquirer. Change of control provisions in enterprise agreements may be relevant in transaction scenarios. 5. COMPLIANCE CONSIDERATIONS: Organizations relying on Figma for processing sensitive business data should maintain awareness of corporate transaction news that may affect Figma's ownership and data governance. DPA terms should be reviewed for change-of-control provisions and successor entity obligations.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that personal information may be transferred to a different legal entity as part of a corporate transaction without requiring individual user consent, subject to the constraint that such transfer must be permitted by applicable law and contract.
Under this clause, personal information held by Figma may be transferred to a successor entity in the event of a corporate transaction including merger, acquisition, bankruptcy, or service transition. The agreement frames this transfer as occurring in accordance with Figma's legitimate interests and subject to applicable law and contractual constraints.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Figma.