The policy states that where a user accesses Figma through an organization's account or has their account paid for by a third party, Figma will disclose that user's information to the organization at the organization's request and grant the organization certain rights over that user's information.
This analysis describes what Figma's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that organizational account holders have rights to access and control over employee or member user data on Figma, and that individual users' information may be subject to their organization's privacy policies, for which Figma disclaims responsibility.
Interpretive note: The provision refers to 'certain rights' granted to organizations without enumerating them, and the full scope of organizational control is not defined in the quoted policy text, requiring reference to the Data Processing Addendum for complete understanding.
The updated terms establish specific restrictions on how Figma may use personal information collected from minors. Children under 13 in the US, under 16 in California and the EU, and under 18 in Japan may now use the Services only through agreements with educational institutions. Figma states it will not use children's personal information to train, fine-tune, or improve AI services, nor will it permit service providers to do so. The policy also prohibits using children's data for marketing purposes, targeted advertising, or enabling third-party tracking. If a parent learns their child provided personal information without consent outside an educational agreement, they may contact Figma to report the issue.
View change record →Under this clause, users accessing Figma through an employer or organizational account may have their information disclosed to that organization at the organization's request, and the organization is granted certain rights over that information. The agreement states that individual users' data may also be governed by their organization's privacy policy, and Figma does not accept responsibility for organizational privacy or security practices.
Cross-platform context
See how other platforms handle Organization and Administrator Data Access Rights and similar clauses.
Compare across platforms →"If you access the Services on behalf of an organization (such as with your organization's domain) or have your account paid for by another party, we will disclose your information to that organization or paying party at its request and give such organization certain rights over your information. For example, your organization may request that we provide extra security controls around your account to protect information about your organization or your organization may request that we link your Figma account with your organization's account to enhance collaboration. If you are the administrator of a team, organization or other account holder within the Services, we may disclose your contact information to current or past Service users related to you, for the purpose of facilitating Service-related requests. Please note that your information may also be subject to your organization's privacy policy, and we are not responsible for the privacy or security practices of our customers.Excerpt from Figma's Privacy Policy
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes that organizational account holders have rights to access and control over employee or member user data on Figma, and that individual users' information may be subject to their organization's privacy policies, for which Figma disclaims responsibility.
Under this clause, users accessing Figma through an employer or organizational account may have their information disclosed to that organization at the organization's request, and the organization is granted certain rights over that information. The agreement states that individual users' data may also be governed by their organization's privacy policy, and Figma does not accept responsibility for organizational privacy or …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Figma.