StackLégal

Collaboration

GDPR Figma

In an indie stack, Figma is used for Interface design and prototypes. Entity cited: Figma, Inc.. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.

Translation of the French sheet. The facts do not change. The date is the date the official pages were read.

DPA Figma

Yes. Public DPA.

Read the DPA

Stated role

As a processor, Figma processes the personal data in customer content only on documented instruction or to comply with the law. The policy also describes Figma's own collection (account, usage, data collected automatically).

Personal data

Name, email, personal site, image, phone for two-factor authentication, postal address, marketing preferences, customer content, usage data, support exchanges, IP address, settings, MAC address, cookie identifiers, device and browser details, location inferred from the IP, names and emails of connected authorized users, data of visitors to pages created on the platform.

Sub-processors of Figma

Public list.

List published by the vendor

Transfers outside the EU

Hosting / location

Any personal information processed by Figma is transferred, processed, and stored in the United States, where the headquarters and the primary servers are. Affiliates and providers also operate in the countries listed on the sub-processor page.

EU–United States Data Privacy Framework

Figma, Inc. is registered. EU-U.S. Data Privacy Framework status: Active. United Kingdom extension and Swiss-U.S. DPF: Active.

Data Privacy Framework sheet

Cookies

The site uses cookies, pixels, and local storage for performance, personalization, and marketing. Some cookies may be treated as a sale, advertising sharing, or targeted advertising.

Typical use, written by StackLégal and not by the vendor: Interface design and prototypes.

History

Last update: October 4, 2026.

  1. First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".

Clause to paste

Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.

Sub-processor clause

Add this vendor to your free sub-processors widget

Sources

Verified on October 4, 2026.

Frequently asked questions

Is Figma a processor within the meaning of the GDPR?

As a processor, Figma processes the personal data in customer content only on documented instruction or to comply with the law. The policy also describes Figma's own collection (account, usage, data collected automatically).

What DPA does Figma publish?

Yes. Public DPA. https://www.figma.com/legal/dpa/

Which further sub-processors does Figma publish?

Public list. https://www.figma.com/sub-processors/

Where does Figma state that it processes data, including outside the EU?

Any personal information processed by Figma is transferred, processed, and stored in the United States, where the headquarters and the primary servers are. Affiliates and providers also operate in the countries listed on the sub-processor page.

Is Figma registered under the EU–United States Data Privacy Framework?

Figma, Inc. is registered. EU-U.S. Data Privacy Framework status: Active. United Kingdom extension and Swiss-U.S. DPF: Active. https://www.dataprivacyframework.gov/participant/6132

Which personal data does Figma mention?

Name, email, personal site, image, phone for two-factor authentication, postal address, marketing preferences, customer content, usage data, support exchanges, IP address, settings, MAC address, cookie identifiers, device and browser details, location inferred from the IP, names and emails of connected authorized users, data of visitors to pages created on the platform.

Often in the same stack

These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.

Related tools

All the sheets collaboration

Full pack, from 39 € incl. VAT

The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.