Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Upon termination for breach of the export control provisions, the agreement states that the Customer loses all right, title, and interest to Customer Content, and Figma may immediately quarantine, delete, or remove that content and suspend platform access, without the 30-day retrieval window that applies to other terminations.
This analysis describes what Figma's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision asserts that export control breaches result in permanent forfeiture of Customer Content ownership and immediate deletion rights, which is a distinct and more severe consequence than the standard termination pathway that includes a 30-day content retrieval period.
The removal of the Subprocessors list link makes it less convenient for users, particularly enterprise and EU-based customers who rely on this information for data protection compliance, to verify which third parties Figma engages to process their data. While the subprocessor information may still exist on Figma's website, removing the direct link from the Terms of Service reduces accessibility and transparency. Enterprise customers and those subject to GDPR may need to contact Figma directly to access current subprocessor information.
View change record →Under this clause, a termination triggered by breach of the export control section results in the Customer losing all rights to Customer Content, with Figma authorized to immediately quarantine or delete it. The standard 30-day post-termination content retrieval period does not apply in this scenario.
Cross-platform context
See how other platforms handle Customer Content Forfeiture Upon Export Control Breach and similar clauses.
Compare across platforms →Monitoring
Figma has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Notwithstanding the foregoing, upon termination of this Agreement for breach of Section 9.12 (Export Control), you lose all right, title, and interest to Customer Content, and Figma may immediately quarantine, delete, or remove Customer Content, and immediately suspend your use of and access to the Figma Platform.Excerpt from Figma's Terms of Service
(1) REGULATORY LANDSCAPE: The export control clause engages the U.S. Export Administration Regulations administered by the Bureau of Industry and Security and OFAC sanctions regulations administered by the U.S. Department of the Treasury. The forfeiture of Customer Content upon export control breach is consistent with regulatory requirements that may prohibit return of controlled items to sanctioned parties. The FTC and State AGs generally do not have primary jurisdiction over export control matters. (2) GOVERNANCE EXPOSURE: Medium. The immediate content deletion right without a retrieval period creates a material data loss risk for customers who may inadvertently trigger export control provisions, particularly organizations with international user bases or operations in jurisdictions subject to U.S. sanctions. The scope of what constitutes a breach is defined by reference to external Export Control regulations, which are complex and subject to change. (3) JURISDICTION FLAGS: This provision applies most directly to customers with operations or users in OFAC-sanctioned jurisdictions or involving parties on the OFAC Specially Designated Nationals list. Organizations operating in the EU with U.S.-origin technology should review their compliance with both U.S. Export Administration Regulations and applicable EU export control frameworks. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should assess whether their organization's international operations create any potential exposure under U.S. export control laws when using Figma. The permanent forfeiture of Customer Content upon export control breach is an unusual provision that should be flagged in vendor risk assessments and data governance planning. (5) COMPLIANCE CONSIDERATIONS: Legal and compliance teams should conduct an export control screening process to confirm that authorized users and customer entities do not appear on OFAC watchlists or operate in embargoed jurisdictions. Incident response plans should account for the possibility of immediate content deletion and access suspension without prior notice in the event of an export control determination by Figma.
This provision asserts that export control breaches result in permanent forfeiture of Customer Content ownership and immediate deletion rights, which is a distinct and more severe consequence than the standard termination pathway that includes a 30-day content retrieval period.
Under this clause, a termination triggered by breach of the export control section results in the Customer losing all rights to Customer Content, with Figma authorized to immediately quarantine or delete it. The standard 30-day post-termination content retrieval period does not apply in this scenario.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Figma.