DocuSign
Last Reviewed: 01 Jun 2026
At a Glance
DocuSign's DPA robustly restricts processing to customer instructions only, with BCRs as the primary transfer mechanism supplemented by EU SCCs and UK IDTA. The DPA explicitly prohibits selling, sharing, or independently using personal data and imposes full flowdown liability on sub-processors. All core GDPR provisions are addressed.
Company & Product Details
HQ
United States
Products
DocuSign eSignature / agreement workflow services
Product description
Electronic signature and agreement workflow SaaS services.
What data is being processed?
Agreement documents, signatory details, account data, contact information, audit trail information and related customer data processed through the DocuSign services.
Document Details
Date of DPA
04 Sept 2024
Additional date information
Document states "Version Date: September 4, 2024" in the opening text of the DPA. Fetched directly from https://www.docusign.com/legal/terms-and-conditions/data-protection-attachment.
What jurisdictions are covered?
Data Protection Laws generally, expressly including CCPA, GDPR, Swiss FADP, UK GDPR, Australian Privacy Act, PIPEDA, LGPD, Singapore PDPA and Japan APPI in the DPA definitions.
Is the DPA incorporated into service or customer agreements?
Link
https://www.docusign.com/legal/terms-and-conditions/data-protection-attachment
Location & Transfers
Where is data held or processed?
Not explicitly stated Not fixed to a single location in the DPA. DocuSign uses third-party data centre providers and may carry out cross-border processing subject to lawful transfer mechanisms.
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
Appropriate administrative, technical, physical and organisational measures. Specific measures are described in the BCRs, Agreement and the Security Attachment for DocuSign Services (current version date 9 March 2026): https://www.docusign.com/legal/terms-and-conditions/security-attachment-docusign-services
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
Docusign will notify Customer without undue delay upon becoming aware of any Data Breach, and will assist Customer with its Data Breach-related compliance obligations by: (a) taking commercially reasonable steps to mitigate effects and reduce risk to affected Data Subjects; and (b) providing, to the extent known, information on the nature, potential categories and approximate number of Data Subjects affected, approximate number of Personal Data records affected, likely consequences, and measures taken or proposed. No specific hour count is stated. (clause 6)
What happens to the data on termination?
Prior to termination or expiry of the Agreement, Customer may retrieve Personal Data in accordance with the Agreement terms. On Customer's request, Docusign will promptly delete all Personal Data in its possession or control as soon as reasonably practicable, subject to: (a) any applicable legal retention obligation; and (b) Personal Data archived on back-up systems, which Docusign will securely isolate and protect from further processing until deletion is possible. (clause 10)