Figma

Last Reviewed: 04 Jun 2026

GDPR Addressed

At a Glance

Figma's DPA addresses key GDPR, UK GDPR, Swiss FADP, Brazilian LGPD, and US data protection requirements, with SCCs in place for EEA, UK, Swiss, and Brazilian transfers plus US Data Privacy Framework certification. Processor-only restrictions and clear flowdown obligations apply throughout. Audit rights are structured: annual third-party reports are provided, with direct audit available once yearly on 45 days' notice.

Company & Product Details

HQ

United States

Products

Figma platform

Product description

Collaborative design, prototyping, whiteboarding and developer handoff platform.

What data is being processed?

Customer personal data relating mainly to authorised users of the Figma platform and any personal data included in collaboration content, comments or uploaded files.

Document Details

Date of DPA

30 Mar 2026

Additional date information

DPA last updated 30 March 2026.

What jurisdictions are covered?

EU (GDPR), UK (UK GDPR and Data Protection Act 2018), Switzerland (FADP), Brazil (LGPD), and multiple U.S. state privacy laws are expressly referenced and addressed by dedicated provisions. EU SCCs are governed by Irish law with disputes before the Irish courts. Schedule 2 contains region-specific obligations for each jurisdiction including transfer mechanisms. (Schedule 2, sections 1–5)

Is the DPA incorporated into service or customer agreements?

Yes
The DPA at https://www.figma.com/dpa is incorporated by reference into Figma's Terms of Service (clause 1.2) and the Figma Software Services Agreement (SSA).

Location & Transfers

Where is data held or processed?

Not explicitly stated The DPA does not state specific countries where data is held, as storage locations depend on which approved sub-processors are in use. Figma maintains a public sub-processor list at https://www.figma.com/sub-processors which includes sub-processor locations, and cross-border transfers are governed by the mechanisms in Schedule 2. (clause 3.3; Schedule 2)

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
EU SCCs apply with Module 2 (Controller-to-Processor) and Module 3 (Processor-to-Processor), governed by Irish law; disputes before Irish courts. A UK International Data Transfer Addendum applies for UK transfers. Swiss FADP transfers are covered via the EU SCC mechanism with Swiss-specific modifications. Brazilian Standard Contractual Clauses are formally incorporated for transfers from Brazil. Figma is certified under the EU-US, UK Extension to EU-US, and Swiss-US Data Privacy Frameworks. Sub-processors are listed at https://www.figma.com/sub-processors. (Schedule 2, sections 2–5)

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

Figma has implemented and will maintain appropriate technical and organisational measures designed to protect the security, confidentiality, integrity, and availability of Customer Content. Detailed TOMs are set out in Annex II of the DPA. Annual third-party audits are conducted and Figma holds certifications including SOC 2 Type 2, ISO 27001, ISO 27018 and EU Cloud Code of Conduct Level 2, available as compliance reports on request. (clause 2.1; Annex II; clause 6.1)

Non Processor Data Use

Does the company process data solely as a processor?

Yes
Customer Content is used solely to provide the Figma Platform in accordance with the Agreement. The US section explicitly confirms Figma will not sell, share, or process personal data for commercial purposes beyond those specified, and will not combine it with data from other sources except as permitted by U.S. State Privacy Laws. No language was found granting Figma rights to act as an independent controller. (clauses 1.2, 9.3; Schedule 2, section 5.1)

Subprocessing

General authorization

General
Figma operates under a general authorisation to engage sub-processors listed at https://www.figma.com/sub-processors. At least 15 days before a new sub-processor begins processing, Figma updates the list and notifies subscribed customers. Customers may object within that period on data protection grounds; if no resolution is reached, termination of the affected Order is the customer's sole and exclusive remedy. (clauses 3.1, 3.3, 3.4, 3.5)

Do all the DPA terms flow down to sub-processors?

Yes
Figma must enter into written agreements with each sub-processor imposing data protection obligations consistent with this Addendum, and remains liable to Customer where a sub-processor fails to fulfil its obligations. Figma's affiliates may also be engaged as sub-processors under the same framework. (clauses 3.1, 3.2)

Is data only processed on the instruction of the controller?

Yes
Figma processes Customer Content only in accordance with documented Customer Instructions, defined as: (i) processing to provide the Figma Platform per the Agreement; (ii) investigating Security Incidents; and (iii) other reasonable documented instructions consistent with the Agreement and platform use. Figma must notify Customer if it determines an instruction infringes Data Protection Law. (clauses 1.2, 1.3, 9.3)

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
Figma will provide reasonable and timely assistance to Customer to respond to data subject rights requests, where Customer cannot fulfil them independently using the Figma Platform's self-service functionality. Assistance is limited to what Customer cannot reasonably do itself. (clause 4.1)

Does the contract include staff confidentiality clauses?

Yes
Figma must ensure that all persons authorised to process Customer Content are subject to written or statutory obligations of confidentiality, covering both Figma staff and sub-processor personnel. (clause 1.4)

Are there audit rights for the data?

Structured
Figma uses independent third-party auditors at least annually and provides summaries of certifications and audit reports on written request with appropriate confidentiality controls. Where audit requirements cannot be satisfied by reports, Customer may conduct a direct audit at its own expense with 45 days' advance notice, limited to once per year, during business hours, and subject to confidentiality controls. (clauses 6.1, 6.2)

Is there assistance with DPIA requests?

Yes
Figma will provide reasonable assistance to Customer in connection with data protection impact assessments and consultations with regulatory authorities required under Data Protection Law, taking into account the nature of the processing. (clause 4.2)

How much notice is provided for data breaches?

Figma must notify Customer without undue delay and, where feasible, within 72 hours after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Content processed by Figma and/or its sub-processors. Figma will use commercially reasonable efforts to investigate and take reasonable steps to mitigate and remediate the effects. (clause 2.2)

What happens to the data on termination?

At the customer's option, Figma will delete or return all Customer Content within 30 days after the end of the service. Figma may retain Customer Content only to the extent required by Data Protection Law, subject to the confidentiality and processing restrictions in the Addendum. (clause 5)