DocuSign

Last Reviewed: 01 Jun 2026

GDPR Addressed

At a Glance

DocuSign's DPA robustly restricts processing to customer instructions only, with BCRs as the primary transfer mechanism supplemented by EU SCCs and UK IDTA. The DPA explicitly prohibits selling, sharing, or independently using personal data and imposes full flowdown liability on sub-processors. All core GDPR provisions are addressed.

Company & Product Details

HQ

United States

Products

DocuSign eSignature / agreement workflow services

Product description

Electronic signature and agreement workflow SaaS services.

What data is being processed?

Agreement documents, signatory details, account data, contact information, audit trail information and related customer data processed through the DocuSign services.

Document Details

Date of DPA

04 Sept 2024

Additional date information

Document states "Version Date: September 4, 2024" in the opening text of the DPA. Fetched directly from https://www.docusign.com/legal/terms-and-conditions/data-protection-attachment.

What jurisdictions are covered?

Data Protection Laws generally, expressly including CCPA, GDPR, Swiss FADP, UK GDPR, Australian Privacy Act, PIPEDA, LGPD, Singapore PDPA and Japan APPI in the DPA definitions.

Is the DPA incorporated into service or customer agreements?

Yes
The DPA is incorporated into and forms part of the Agreement.

Location & Transfers

Where is data held or processed?

Not explicitly stated Not fixed to a single location in the DPA. DocuSign uses third-party data centre providers and may carry out cross-border processing subject to lawful transfer mechanisms.

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
Docusign's Binding Corporate Rules for Processors (BCRs) are the primary transfer mechanism and are incorporated by reference into the DPA (clause 8.2). As an additional safeguard, EU SCCs (2021/914) Module 2 (controller-to-processor) and Module 3 (processor-to-subprocessor) are deemed signed on execution of the DPA (clause 8.3). Governing law for the SCCs is Ireland. The UK International Data Transfer Addendum (UK IDTA) to the EU SCCs applies for UK transfers (clause 8.4). Swiss modifications to the EU SCCs apply for Swiss transfers (clause 8.5).

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

Appropriate administrative, technical, physical and organisational measures. Specific measures are described in the BCRs, Agreement and the Security Attachment for DocuSign Services (current version date 9 March 2026): https://www.docusign.com/legal/terms-and-conditions/security-attachment-docusign-services

Non Processor Data Use

Does the company process data solely as a processor?

Yes
Docusign commits to process Personal Data solely: (a) to fulfil its obligations to Customer under the Agreement, including this DPA; (b) on Customer's behalf pursuant to Customer's documented instructions; and (c) in compliance with Data Protection Laws. Docusign explicitly will not "sell" Personal Data, "share" or process it for "cross-context behavioural advertising" or "targeted advertising", or process it for any purpose outside the direct business relationship with Customer. Docusign also commits not to attempt to link, identify, or create a relationship between Personal Data and non-personal data without the express authorisation of Customer. No controller rights are claimed. (clause 2.3)

Subprocessing

General authorization

General
Customer acknowledges and agrees that Docusign may use Affiliates and other Subprocessors to process Personal Data in accordance with this DPA. Docusign publishes a Services Subprocessor List at https://www.docusign.com/trust/privacy/subprocessors-list and provides 30 days' prior notice of any new Subprocessor via a subscription mechanism. Where Customer has a commercially reasonable objection to a new Subprocessor, Docusign will use reasonable efforts to make available a change to the Services or recommend a workaround; Customer may terminate if Docusign cannot accommodate the objection. Docusign remains liable for all Subprocessor performance. (clauses 7.1, 7.2)

Do all the DPA terms flow down to sub-processors?

Yes
Docusign will take steps to select and retain Subprocessors capable of maintaining appropriate privacy and security measures consistent with Data Protection Laws and this DPA. Docusign remains fully liable for the performance of all its obligations under this DPA, whether performed by Docusign, its Affiliates, or Subprocessors. (clause 7.1)

Is data only processed on the instruction of the controller?

Yes
Docusign will process Personal Data solely to fulfil its Agreement obligations on Customer's behalf, pursuant to Customer's instructions, and in compliance with Data Protection Laws. Docusign must promptly notify Customer if, in its opinion, an instruction from Customer would infringe Data Protection Laws. (clause 2.3, clause 3(f))

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
Docusign will provide reasonable assistance to Customer in fulfilling its obligations to respond to Data Subject requests under Data Protection Laws. Where a Data Subject contacts Docusign directly, Docusign will promptly notify Customer (where the Data Subject has identified Customer as Controller) and may inform the Data Subject that it has done so. Customer remains solely responsible for responding to Data Subject requests. (clauses 4.1, 4.2)

Does the contract include staff confidentiality clauses?

Yes
Docusign will ensure that all persons it authorises to process Personal Data are subject to confidentiality obligations regarding such activity, or are under an appropriate statutory obligation of confidentiality. (clause 3(a))

Are there audit rights for the data?

Structured
Docusign must make available audit reports (SOC, ISO, NIST, PCI DSS or similar from a qualified third-party auditor) to confirm compliance with the DPA and Security Attachment. If Customer has reasonable basis to conclude the Audit Report is unsatisfactory, Customer may, at its sole expense and on 30 days' prior written notice, conduct an audit during normal business hours of relevant Docusign systems and records. Audit rights are limited to once per twelve-calendar-month period. (clause 9)

Is there assistance with DPIA requests?

Yes
Docusign will provide reasonable assistance and cooperation with Customer for Customer's performance of a data protection impact assessment of Processing or proposed Processing of Personal Data when required by Data Protection Laws (clause 3(c)). Docusign will also provide commercially reasonable assistance for Customer's consultation with regulatory authorities in relation to Processing or proposed Processing of Personal Data, and will comply with any applicable obligations on Docusign to consult with a supervisory authority (clause 3(d)).

How much notice is provided for data breaches?

Docusign will notify Customer without undue delay upon becoming aware of any Data Breach, and will assist Customer with its Data Breach-related compliance obligations by: (a) taking commercially reasonable steps to mitigate effects and reduce risk to affected Data Subjects; and (b) providing, to the extent known, information on the nature, potential categories and approximate number of Data Subjects affected, approximate number of Personal Data records affected, likely consequences, and measures taken or proposed. No specific hour count is stated. (clause 6)

What happens to the data on termination?

Prior to termination or expiry of the Agreement, Customer may retrieve Personal Data in accordance with the Agreement terms. On Customer's request, Docusign will promptly delete all Personal Data in its possession or control as soon as reasonably practicable, subject to: (a) any applicable legal retention obligation; and (b) Personal Data archived on back-up systems, which Docusign will securely isolate and protect from further processing until deletion is possible. (clause 10)