Provision record
Figma · Figma Privacy Policy · View original document ↗

GPC Signal Processing and CCPA Opt-Out of Sale and Sharing

Low severity Medium confidence Explicit document language Unique · 0 of 352 platforms
Stay ahead of the changes
Track Figma and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

The policy states that Figma does not respond to Do Not Track signals but does recognize and process Global Privacy Control signals, treating them as opt-out requests from the sale or sharing of personal information for targeted advertising under CCPA definitions, with a secondary opt-out available via the 'Manage Cookies' footer link.

This analysis describes what Figma's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes Figma's treatment of browser-based privacy signals under CCPA, providing a mechanism through which California consumers may exercise opt-out rights without navigating a separate settings page, though the policy conditions recognition on the ability to 'reasonably associate' the GPC signal with an identifiable consumer.

Interpretive note: The policy conditions GPC recognition on the ability to 'reasonably associate' the signal with an identifiable consumer, and the operational threshold for this association is not defined in the document, creating uncertainty about GPC effectiveness in unauthenticated browsing contexts.

Recent Activity

This document changed recently

Medium May 28, 2026

The updated terms establish specific restrictions on how Figma may use personal information collected from minors. Children under 13 in the US, under 16 in California and the EU, and under 18 in Japan may now use the Services only through agreements with educational institutions. Figma states it will not use children's personal information to train, fine-tune, or improve AI services, nor will it permit service providers to do so. The policy also prohibits using children's data for marketing purposes, targeted advertising, or enabling third-party tracking. If a parent learns their child provided personal information without consent outside an educational agreement, they may contact Figma to report the issue.

View change record →

Clause Stability Stable

0
Changes
5
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this clause, users with GPC-enabled browsers may have their opt-out of sale and sharing for targeted advertising recognized automatically, subject to Figma being able to reasonably associate the signal with an identifiable consumer. The agreement provides an alternative opt-out pathway through the 'Manage Cookies' link in the figma.com footer.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Opt Out of Arbitration
    Navigate to figma.com, scroll to the footer, and click 'Manage Cookies' to opt out of the sale or sharing of your personal information for targeted advertising. You may need to log out of your account to access the footer link. Complete this step on each browser and device separately.

Cross-platform context

See how other platforms handle GPC Signal Processing and CCPA Opt-Out of Sale and Sharing and similar clauses.

Compare across platforms →
▸ View Original Clause Language DOCUMENT RECORD
"
"Do Not Track" and "Global Privacy Consent". Do Not Track ("DNT") and Global Privacy Consent ("GPC") signals are a privacy preferences that users can set in certain web browsers. We do not respond to DNT signals; however, we do recognize and process GPC signals by certain web browsers. If we are able to reasonably associate a GPC signal with an identifiable consumer, we will treat it as a request to opt-out of the "sale" or "sharing"/processing for targeted advertising of that consumer's personal information (as such terms are defined by the California Consumer Privacy Act). You can also opt out of the "sale" or "sharing" of your personal information by clicking on the "Manage Cookies" link in the footer of figma.com.

Excerpt from Figma's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • State Attorney General
    State AGs in California, New York, Texas, and other states can investigate violations of state consumer protection and privacy laws, including CCPA (California), SHIELD Act (New York), and equivalents.
    Who can file: Residents of states with comprehensive privacy laws — primarily California, Virginia, Colorado, Connecticut, and Utah
    What you need: Evidence of the violation, explanation of how your state rights were affected, and your account or contact information with the company
    What to expect: Outcomes vary by state. May result in investigation, enforcement action, or requirement for the company to change practices. No direct individual compensation in most cases.

    Search "[your state] attorney general consumer complaint" to find your state's direct complaint form

Provision details

Document information
Document
Figma Privacy Policy
Entity
Figma
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014691
Document ID
CA-D-00206
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
f7f03821eec4a58f9dc0198f7828ff49a980d5d548d3fa82093da85a7a1559da
Analysis generated
July 9, 2026 06:11 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Figma
Document: Figma Privacy Policy
Record ID: CA-P-014691
Captured: 2026-07-09 06:11:55 UTC
SHA-256: f7f03821eec4a58f…
URL: https://conductatlas.com/platform/figma/figma-privacy-policy/provision/CA-P-014691/gpc-signal-processing-and-ccpa-opt-out-of-sale-and-sharing/
Accessed: Sept. 8, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Figma's GPC Signal Processing and CCPA Opt-Out of Sale and Sharing clause do?

This provision establishes Figma's treatment of browser-based privacy signals under CCPA, providing a mechanism through which California consumers may exercise opt-out rights without navigating a separate settings page, though the policy conditions recognition on the ability to 'reasonably associate' the GPC signal with an identifiable consumer.

How does this clause affect you?

Under this clause, users with GPC-enabled browsers may have their opt-out of sale and sharing for targeted advertising recognized automatically, subject to Figma being able to reasonably associate the signal with an identifiable consumer. The agreement provides an alternative opt-out pathway through the 'Manage Cookies' link in the figma.com footer.

Is ConductAtlas affiliated with Figma?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Figma.