Provision record
Figma · Figma Privacy Policy · View original document ↗

Figma Liability for Third-Party Agent DPF Violations

High severity Explicitdocumentlanguage Common · 233 of 352 platforms
Get alerted the next time Figma changes these terms. Follow Figma →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Figma recorded 4 documented changes in the last 30 days.
Follow Figma →
Monitor governance changes for Figma Monitor emails you the same day this changes. The archive stays free.
Follow Figma →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

This analysis describes what Figma's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

Recent Activity

This document changed recently

Medium May 28, 2026

The updated terms establish specific restrictions on how Figma may use personal information collected from minors. Children under 13 in the US, under 16 in California and the EU, and under 18 in Japan may now use the Services only through agreements with educational institutions. Figma states it will not use children's personal information to train, fine-tune, or improve AI services, nor will it permit service providers to do so. The policy also prohibits using children's data for marketing purposes, targeted advertising, or enabling third-party tracking. If a parent learns their child provided personal information without consent outside an educational agreement, they may contact Figma to report the issue.

View change record →

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 10, 2026
First Seen
Jul 10, 2026
Last Seen
This clause type exists across 997 other provisions on other platforms.

How other platforms handle this

Instacart Medium

Any access to or use of the Services or goods through your account by others, including your spouse, dependents, Recipients, and any access by AI Agents you enable or that operate on your behalf...

Twilio Medium

Indemnifying Party will not settle any Claim for which it has an obligation to indemnify under this Section 6 admitting liability or fault on behalf of Indemnified Party, nor create any obligation on behalf of Indemnified Party without Indemnified Party's prior written consent...

DeepL Medium

DeepL shall not settle or recognise claims of third parties without Customer's consent which shall not be unreasonably withheld or delayed.

See all platforms with this clause type →

Monitoring

Figma has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow Figma → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
If we have received your personal information in the U.S. and subsequently transfer that information to a third party acting as an agent...we will remain liable unless we can prove we are not responsible...

Excerpt from Figma's Privacy Policy

Applicable regulations

FTC Act Section 5
United States Federal

Provision details

Document information
Document
Figma Privacy Policy
Entity
Figma
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-032316
Document ID
CA-D-00206
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
f7f03821eec4a58f9dc0198f7828ff49a980d5d548d3fa82093da85a7a1559da
Analysis generated
July 9, 2026 06:11 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Figma
Document: Figma Privacy Policy
Record ID: CA-P-032316
Captured: 2026-07-09 06:11:55 UTC
SHA-256: f7f03821eec4a58f…
URL: https://conductatlas.com/platform/figma/figma-privacy-policy/provision/CA-P-032316/figma-liability-for-third-party-agent-dpf-violations/
Accessed: July 25, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does Figma's Figma Liability for Third-Party Agent DPF Violations clause do?

The clause states: “If we have received your personal information in the U.S. and subsequently transfer that information to a third party acting as an agent...we will remain liable unless we can prove we are not responsible...”

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 233 platforms. See the full comparison.

Is ConductAtlas affiliated with Figma?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Figma.