Provision record
Figma · Figma Terms of Service · View original document ↗

Figma Security Measures for Customer Content

High severity Explicit document language Common · 296 of 352 platforms
Stay ahead of the changes
Track Figma and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF

This analysis describes what Figma's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

Recent Activity

This document changed recently

Medium Mar 31, 2026

The removal of the Subprocessors list link makes it less convenient for users, particularly enterprise and EU-based customers who rely on this information for data protection compliance, to verify which third parties Figma engages to process their data. While the subprocessor information may still exist on Figma's website, removing the direct link from the Terms of Service reduces accessibility and transparency. Enterprise customers and those subject to GDPR may need to contact Figma directly to access current subprocessor information.

View change record →

Clause Stability Stable

0
Changes
5
Months Monitored
Jul 10, 2026
First Seen
Jul 10, 2026
Last Seen
This clause type exists across 4186 other provisions on other platforms.

How other platforms handle this

Baseten Medium

Category B: Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e))... bank account number, credit card number, debit card number, or any other financial information... Collected: Yes.

Apple App Store Medium

These technologies help us to better understand user behavior including for security and fraud prevention purposes, tell us which parts of our websites people have visited, and facilitate and measure the effecti...

ZipRecruiter Medium

You may give us your Identity Data, Contact Data, Financial Data, Profile Data, and other information by filling in forms or by corresponding with us by post, phone, e-mail or otherwise.

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
Figma implements and maintains physical, technical, and administrative security measures designed to protect the applications and materials that Customer (or Customer's Authorized Users) develop on or upload to the Services...

Excerpt from Figma's Terms of Service

Applicable regulations

EU AI Act
European Union
CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
ePrivacy Directive
European Union
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
UK GDPR
United Kingdom
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Figma Terms of Service
Entity
Figma
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-032106
Document ID
CA-D-00205
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
4106ee3ad0aa07e2637b5162e0bd4edf0940a8905d10a4f235130ed1e05cafcd
Analysis generated
July 9, 2026 06:02 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Figma
Document: Figma Terms of Service
Record ID: CA-P-032106
Captured: 2026-07-09 06:02:18 UTC
SHA-256: 4106ee3ad0aa07e2…
URL: https://conductatlas.com/platform/figma/figma-terms-of-service/provision/CA-P-032106/figma-security-measures-for-customer-content/
Accessed: Aug. 18, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Figma's Figma Security Measures for Customer Content clause do?

The clause states: “Figma implements and maintains physical, technical, and administrative security measures designed to protect the applications and materials that Customer (or Customer's Authorized Users) develop on or upload to the Services...”

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 296 platforms. See the full comparison.

Is ConductAtlas affiliated with Figma?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Figma.