Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that Figma does not respond to Do Not Track signals but does recognize and process Global Privacy Control signals, treating them as opt-out requests from the sale or sharing of personal information for targeted advertising under CCPA definitions, with a secondary opt-out available via the 'Manage Cookies' footer link.
This analysis describes what Figma's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes Figma's treatment of browser-based privacy signals under CCPA, providing a mechanism through which California consumers may exercise opt-out rights without navigating a separate settings page, though the policy conditions recognition on the ability to 'reasonably associate' the GPC signal with an identifiable consumer.
Interpretive note: The policy conditions GPC recognition on the ability to 'reasonably associate' the signal with an identifiable consumer, and the operational threshold for this association is not defined in the document, creating uncertainty about GPC effectiveness in unauthenticated browsing contexts.
The updated terms establish specific restrictions on how Figma may use personal information collected from minors. Children under 13 in the US, under 16 in California and the EU, and under 18 in Japan may now use the Services only through agreements with educational institutions. Figma states it will not use children's personal information to train, fine-tune, or improve AI services, nor will it permit service providers to do so. The policy also prohibits using children's data for marketing purposes, targeted advertising, or enabling third-party tracking. If a parent learns their child provided personal information without consent outside an educational agreement, they may contact Figma to report the issue.
View change record →Under this clause, users with GPC-enabled browsers may have their opt-out of sale and sharing for targeted advertising recognized automatically, subject to Figma being able to reasonably associate the signal with an identifiable consumer. The agreement provides an alternative opt-out pathway through the 'Manage Cookies' link in the figma.com footer.
Cross-platform context
See how other platforms handle GPC Signal Processing and CCPA Opt-Out of Sale and Sharing and similar clauses.
Compare across platforms →Monitoring
Figma has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
""Do Not Track" and "Global Privacy Consent". Do Not Track ("DNT") and Global Privacy Consent ("GPC") signals are a privacy preferences that users can set in certain web browsers. We do not respond to DNT signals; however, we do recognize and process GPC signals by certain web browsers. If we are able to reasonably associate a GPC signal with an identifiable consumer, we will treat it as a request to opt-out of the "sale" or "sharing"/processing for targeted advertising of that consumer's personal information (as such terms are defined by the California Consumer Privacy Act). You can also opt out of the "sale" or "sharing" of your personal information by clicking on the "Manage Cookies" link in the footer of figma.com.Excerpt from Figma's Privacy Policy
1. REGULATORY LANDSCAPE: This provision directly engages CCPA and the California Privacy Rights Act (CPRA) requirements regarding opt-out of sale and sharing of personal information, including the requirement under California regulations to recognize GPC signals as opt-out requests. The California Privacy Protection Agency (CPPA) has enforcement authority over GPC compliance. The policy's condition that GPC signals are processed only where Figma can 'reasonably associate' the signal with an identifiable consumer may warrant evaluation against California regulatory guidance on GPC implementation, which has been an active area of enforcement focus. 2. GOVERNANCE EXPOSURE: Medium. The conditionality of GPC recognition (requiring reasonable association with an identifiable consumer) may create gaps in opt-out effectiveness for unauthenticated or unidentified browsing sessions, which California enforcement has scrutinized. The policy's explicit non-response to DNT signals is a commonly observed practice but is noted for documentation purposes. 3. JURISDICTION FLAGS: California residents have the most direct rights under this provision. Other U.S. states with comprehensive privacy laws, including Connecticut and Colorado, have adopted GPC recognition requirements that may apply to Figma's operations in those states. The provision does not address GPC recognition outside of the CCPA framework. 4. CONTRACT AND VENDOR IMPLICATIONS: Advertising technology vendors and analytics partners should be assessed for their ability to honor downstream opt-out signals passed through GPC recognition by Figma, as accountability for onward data use may require contractual provisions in advertising partner agreements. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should test the GPC signal recognition mechanism to verify it functions as described across authenticated and unauthenticated sessions. The 'Manage Cookies' footer opt-out should be verified to function correctly on figma.com and assessed for accessibility on mobile surfaces, given the policy's separate disclosure that cookie-based opt-outs are not effective on mobile applications.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes Figma's treatment of browser-based privacy signals under CCPA, providing a mechanism through which California consumers may exercise opt-out rights without navigating a separate settings page, though the policy conditions recognition on the ability to 'reasonably associate' the GPC signal with an identifiable consumer.
Under this clause, users with GPC-enabled browsers may have their opt-out of sale and sharing for targeted advertising recognized automatically, subject to Figma being able to reasonably associate the signal with an identifiable consumer. The agreement provides an alternative opt-out pathway through the 'Manage Cookies' link in the figma.com footer.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Figma.