Figma
Last Reviewed: 04 Jun 2026
At a Glance
Figma's DPA addresses key GDPR, UK GDPR, Swiss FADP, Brazilian LGPD, and US data protection requirements, with SCCs in place for EEA, UK, Swiss, and Brazilian transfers plus US Data Privacy Framework certification. Processor-only restrictions and clear flowdown obligations apply throughout. Audit rights are structured: annual third-party reports are provided, with direct audit available once yearly on 45 days' notice.
Company & Product Details
HQ
United States
Products
Figma platform
Product description
Collaborative design, prototyping, whiteboarding and developer handoff platform.
What data is being processed?
Customer personal data relating mainly to authorised users of the Figma platform and any personal data included in collaboration content, comments or uploaded files.
Document Details
Date of DPA
30 Mar 2026
Additional date information
DPA last updated 30 March 2026.
What jurisdictions are covered?
EU (GDPR), UK (UK GDPR and Data Protection Act 2018), Switzerland (FADP), Brazil (LGPD), and multiple U.S. state privacy laws are expressly referenced and addressed by dedicated provisions. EU SCCs are governed by Irish law with disputes before the Irish courts. Schedule 2 contains region-specific obligations for each jurisdiction including transfer mechanisms. (Schedule 2, sections 1–5)
Is the DPA incorporated into service or customer agreements?
Link
Location & Transfers
Where is data held or processed?
Not explicitly stated The DPA does not state specific countries where data is held, as storage locations depend on which approved sub-processors are in use. Figma maintains a public sub-processor list at https://www.figma.com/sub-processors which includes sub-processor locations, and cross-border transfers are governed by the mechanisms in Schedule 2. (clause 3.3; Schedule 2)
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
Figma has implemented and will maintain appropriate technical and organisational measures designed to protect the security, confidentiality, integrity, and availability of Customer Content. Detailed TOMs are set out in Annex II of the DPA. Annual third-party audits are conducted and Figma holds certifications including SOC 2 Type 2, ISO 27001, ISO 27018 and EU Cloud Code of Conduct Level 2, available as compliance reports on request. (clause 2.1; Annex II; clause 6.1)
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
Figma must notify Customer without undue delay and, where feasible, within 72 hours after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Content processed by Figma and/or its sub-processors. Figma will use commercially reasonable efforts to investigate and take reasonable steps to mitigate and remediate the effects. (clause 2.2)
What happens to the data on termination?
At the customer's option, Figma will delete or return all Customer Content within 30 days after the end of the service. Figma may retain Customer Content only to the extent required by Data Protection Law, subject to the confidentiality and processing restrictions in the Addendum. (clause 5)