Figma · Figma Privacy Policy · View original document ↗

Organization and Administrator Data Access Rights

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Figma changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Figma recorded 4 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Figma Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy states that where a user accesses Figma through an organization's account or has their account paid for by a third party, Figma will disclose that user's information to the organization at the organization's request and grant the organization certain rights over that user's information.

This analysis describes what Figma's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that organizational account holders have rights to access and control over employee or member user data on Figma, and that individual users' information may be subject to their organization's privacy policies, for which Figma disclaims responsibility.

Interpretive note: The provision refers to 'certain rights' granted to organizations without enumerating them, and the full scope of organizational control is not defined in the quoted policy text, requiring reference to the Data Processing Addendum for complete understanding.

Recent Activity

This document changed recently

Medium May 28, 2026

The updated terms establish specific restrictions on how Figma may use personal information collected from minors. Children under 13 in the US, under 16 in California and the EU, and under 18 in Japan may now use the Services only through agreements with educational institutions. Figma states it will not use children's personal information to train, fine-tune, or improve AI services, nor will it permit service providers to do so. The policy also prohibits using children's data for marketing purposes, targeted advertising, or enabling third-party tracking. If a parent learns their child provided personal information without consent outside an educational agreement, they may contact Figma to report the issue.

View change record →

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this clause, users accessing Figma through an employer or organizational account may have their information disclosed to that organization at the organization's request, and the organization is granted certain rights over that information. The agreement states that individual users' data may also be governed by their organization's privacy policy, and Figma does not accept responsibility for organizational privacy or security practices.

Cross-platform context

See how other platforms handle Organization and Administrator Data Access Rights and similar clauses.

Compare across platforms →

Monitoring

Figma has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
If you access the Services on behalf of an organization (such as with your organization's domain) or have your account paid for by another party, we will disclose your information to that organization or paying party at its request and give such organization certain rights over your information. For example, your organization may request that we provide extra security controls around your account to protect information about your organization or your organization may request that we link your Figma account with your organization's account to enhance collaboration. If you are the administrator of a team, organization or other account holder within the Services, we may disclose your contact information to current or past Service users related to you, for the purpose of facilitating Service-related requests. Please note that your information may also be subject to your organization's privacy policy, and we are not responsible for the privacy or security practices of our customers.

Excerpt from Figma's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision implicates GDPR in contexts where the organization is a data controller and Figma acts as a processor, requiring that the relationship be governed by a Data Processing Agreement meeting GDPR Article 28 requirements. Under CCPA, employer-employee data relationships have specific treatment that compliance teams should evaluate. The policy's disclaimer of responsibility for organizational privacy practices does not extinguish Figma's processor obligations under applicable data protection law, which may impose independent obligations regardless of contractual disclaimers. 2. GOVERNANCE EXPOSURE: Medium. The provision that organizations are granted 'certain rights' over user information is not specifically enumerated in the quoted text, creating ambiguity about the scope of organizational access and control. Enterprise customers should review the Data Processing Addendum to understand the specific rights and access controls available to organizational administrators. Individual employees using Figma through an employer account should be aware that their usage data, content, and interactions may be accessible to their employer. 3. JURISDICTION FLAGS: EU employees have rights under GDPR regarding employer processing of their personal data, including rights to information about the processing, which may require employers using Figma to update their employee privacy notices. California employees have CCPA rights, though employer-employee data under CCPA was subject to transitional provisions that have since expired, meaning full CCPA protections now apply. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement teams should review the scope of administrator access rights granted under Figma's terms, particularly regarding access to individual user content, file interaction history, and IP address data disclosed to file administrators. The disclaimer of responsibility for organizational privacy practices is a standard but material vendor contract consideration that should be addressed in the customer's own data governance frameworks. 5. COMPLIANCE CONSIDERATIONS: Organizations deploying Figma for employee use should ensure their employee privacy notices or acceptable use policies disclose that organizational administrators may access employee Figma account data and content as described in Figma's terms. HR and legal teams should assess whether the organizational access rights described require updates to employment agreements or internal data governance policies.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Applicable agencies

  • FTC
    The FTC has consumer protection jurisdiction over data sharing practices between platform providers and organizational third parties, including representations about organizational access to user data.
    File a complaint →

Provision details

Document information
Document
Figma Privacy Policy
Entity
Figma
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014690
Document ID
CA-D-00206
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
f7f03821eec4a58f9dc0198f7828ff49a980d5d548d3fa82093da85a7a1559da
Analysis generated
July 9, 2026 06:11 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Figma
Document: Figma Privacy Policy
Record ID: CA-P-014690
Captured: 2026-07-09 06:11:55 UTC
SHA-256: f7f03821eec4a58f…
URL: https://conductatlas.com/platform/figma/figma-privacy-policy/provision/CA-P-014690/organization-and-administrator-data-access-rights/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Frequently Asked Questions

What does Figma's Organization and Administrator Data Access Rights clause do?

This provision establishes that organizational account holders have rights to access and control over employee or member user data on Figma, and that individual users' information may be subject to their organization's privacy policies, for which Figma disclaims responsibility.

How does this clause affect you?

Under this clause, users accessing Figma through an employer or organizational account may have their information disclosed to that organization at the organization's request, and the organization is granted certain rights over that information. The agreement states that individual users' data may also be governed by their organization's privacy policy, and Figma does not accept responsibility for organizational privacy or …

Is ConductAtlas affiliated with Figma?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Figma.