Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that where a user accesses Figma through an organization's account or has their account paid for by a third party, Figma will disclose that user's information to the organization at the organization's request and grant the organization certain rights over that user's information.
This analysis describes what Figma's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that organizational account holders have rights to access and control over employee or member user data on Figma, and that individual users' information may be subject to their organization's privacy policies, for which Figma disclaims responsibility.
Interpretive note: The provision refers to 'certain rights' granted to organizations without enumerating them, and the full scope of organizational control is not defined in the quoted policy text, requiring reference to the Data Processing Addendum for complete understanding.
The updated terms establish specific restrictions on how Figma may use personal information collected from minors. Children under 13 in the US, under 16 in California and the EU, and under 18 in Japan may now use the Services only through agreements with educational institutions. Figma states it will not use children's personal information to train, fine-tune, or improve AI services, nor will it permit service providers to do so. The policy also prohibits using children's data for marketing purposes, targeted advertising, or enabling third-party tracking. If a parent learns their child provided personal information without consent outside an educational agreement, they may contact Figma to report the issue.
View change record →Under this clause, users accessing Figma through an employer or organizational account may have their information disclosed to that organization at the organization's request, and the organization is granted certain rights over that information. The agreement states that individual users' data may also be governed by their organization's privacy policy, and Figma does not accept responsibility for organizational privacy or security practices.
Cross-platform context
See how other platforms handle Organization and Administrator Data Access Rights and similar clauses.
Compare across platforms →Monitoring
Figma has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"If you access the Services on behalf of an organization (such as with your organization's domain) or have your account paid for by another party, we will disclose your information to that organization or paying party at its request and give such organization certain rights over your information. For example, your organization may request that we provide extra security controls around your account to protect information about your organization or your organization may request that we link your Figma account with your organization's account to enhance collaboration. If you are the administrator of a team, organization or other account holder within the Services, we may disclose your contact information to current or past Service users related to you, for the purpose of facilitating Service-related requests. Please note that your information may also be subject to your organization's privacy policy, and we are not responsible for the privacy or security practices of our customers.Excerpt from Figma's Privacy Policy
1. REGULATORY LANDSCAPE: This provision implicates GDPR in contexts where the organization is a data controller and Figma acts as a processor, requiring that the relationship be governed by a Data Processing Agreement meeting GDPR Article 28 requirements. Under CCPA, employer-employee data relationships have specific treatment that compliance teams should evaluate. The policy's disclaimer of responsibility for organizational privacy practices does not extinguish Figma's processor obligations under applicable data protection law, which may impose independent obligations regardless of contractual disclaimers. 2. GOVERNANCE EXPOSURE: Medium. The provision that organizations are granted 'certain rights' over user information is not specifically enumerated in the quoted text, creating ambiguity about the scope of organizational access and control. Enterprise customers should review the Data Processing Addendum to understand the specific rights and access controls available to organizational administrators. Individual employees using Figma through an employer account should be aware that their usage data, content, and interactions may be accessible to their employer. 3. JURISDICTION FLAGS: EU employees have rights under GDPR regarding employer processing of their personal data, including rights to information about the processing, which may require employers using Figma to update their employee privacy notices. California employees have CCPA rights, though employer-employee data under CCPA was subject to transitional provisions that have since expired, meaning full CCPA protections now apply. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement teams should review the scope of administrator access rights granted under Figma's terms, particularly regarding access to individual user content, file interaction history, and IP address data disclosed to file administrators. The disclaimer of responsibility for organizational privacy practices is a standard but material vendor contract consideration that should be addressed in the customer's own data governance frameworks. 5. COMPLIANCE CONSIDERATIONS: Organizations deploying Figma for employee use should ensure their employee privacy notices or acceptable use policies disclose that organizational administrators may access employee Figma account data and content as described in Figma's terms. HR and legal teams should assess whether the organizational access rights described require updates to employment agreements or internal data governance policies.
This provision establishes that organizational account holders have rights to access and control over employee or member user data on Figma, and that individual users' information may be subject to their organization's privacy policies, for which Figma disclaims responsibility.
Under this clause, users accessing Figma through an employer or organizational account may have their information disclosed to that organization at the organization's request, and the organization is granted certain rights over that information. The agreement states that individual users' data may also be governed by their organization's privacy policy, and Figma does not accept responsibility for organizational privacy or …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Figma.