This analysis describes what Figma's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The removal of the Subprocessors list link makes it less convenient for users, particularly enterprise and EU-based customers who rely on this information for data protection compliance, to verify which third parties Figma engages to process their data. While the subprocessor information may still exist on Figma's website, removing the direct link from the Terms of Service reduces accessibility and transparency. Enterprise customers and those subject to GDPR may need to contact Figma directly to access current subprocessor information.
View change record →How other platforms handle this
Category B: Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e))... bank account number, credit card number, debit card number, or any other financial information... Collected: Yes.
These technologies help us to better understand user behavior including for security and fraud prevention purposes, tell us which parts of our websites people have visited, and facilitate and measure the effecti...
You may give us your Identity Data, Contact Data, Financial Data, Profile Data, and other information by filling in forms or by corresponding with us by post, phone, e-mail or otherwise.
"Figma implements and maintains physical, technical, and administrative security measures designed to protect the applications and materials that Customer (or Customer's Authorized Users) develop on or upload to the Services...Excerpt from Figma's Terms of Service
Netflix updated its Privacy Statement on April 18, 2026, disclosing voice recording collection and expanded household ad profiling for the first time.
Google's Privacy Policy covers Search, Gmail, YouTube, Maps, and every site running Google Analytics. Here is what it actually authorizes.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The clause states: “Figma implements and maintains physical, technical, and administrative security measures designed to protect the applications and materials that Customer (or Customer's Authorized Users) develop on or upload to the Services...”
ConductAtlas has identified this type of provision across 296 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Figma.