The DPA has been substantially restructured and simplified, notably replacing detailed sections on subprocessor objection, audit, and cross-border transfers with more high-level provisions, and updating the list of applicable regions and transfer mechanisms.
- Overall structure and scope: The previous DPA had a detailed structure with multiple exhibits and a complex treatment of SCCs for EEA, UK, Switzerland, and Brazil. The new version consolidates region-specific terms into a single Schedule 2 and general processing details into Schedule 1.
- Effective date added: The new DPA includes a "Last updated: March 30, 2026" date.
- Definitions changed:
- "Customer Personal Data" (pertaining to Customer's Authorized Users) is replaced by "Customer Content" (applications/materials developed or uploaded by Customer/Authorized Users). The new definition is broader and no longer explicitly limited to "logged-in" Authorized Users' personal data.
- "Data Protection Law" now includes all applicable laws generally, rather than listing specific US state laws, EU GDPR, UK GDPR, Swiss FADP, and LGPD. The specific US state laws (CCPA, CPRA, Colorado, Connecticut, Utah, Virginia) are no longer enumerated in the main body; they are referenced under United States region-specific terms.
- "Restricted Transfer" removed; instead, region-specific terms refer to transfers from the EEA, UK, Switzerland, and Brazil using SCCs.
- "Standard Contractual Clauses" definition now only mentions EU SCCs and UK Addendum (BR SCCs are mentioned only under Brazil section).
- Subprocessor objection: Previously, if resolution failed, Figma could proceed after 5 days and Customer could terminate within 30 days. Now, if no resolution within the Sub-processor Notice Period (15 days), the sole remedy is termination (notice is immediate upon failure to resolve). The previous version allowed Figma to proceed and Customer to terminate during a separate 30-day window.
- Audit rights narrowed: The previous version explicitly granted an audit right with 45 days' notice and annual limit; the new version first requires Figma to provide audit reports (SOC 2, ISO certs) and limits the audit right only if those reports are insufficient. The audit right also now requires advance written notice (45 days) and is limited to once per year. The previous version allowed audits for any of Figma's facilities, policies, procedures; the new version remains similar.
- Security Incident notification: The new version adds "where feasible, within 72 hours" after becoming aware of a breach, whereas the previous version said "without undue delay and within the time frame required under Data Protection Laws." The new version also adds language about investigating root cause and taking steps to mitigate.
- Data retention: Previous version allowed deletion/return within 30 days at Customer's option. New version identical.
- Removal of specific provisions: The previous DPA had detailed sections on Confidentiality (separate from security), Personal Data Inquiries and Requests, Data Protection Impact Assessment, Prior Consultation, Demonstrable Compliance, and CPRA-specific terms. The new version condenses these into broader assistance obligations (Sections 4.1, 4.2). The CPRA-specific language is replaced by more general US State Privacy Law obligations in Schedule 2.
- Cross-border transfers: The new DPA removes the separate sections on Data Transfer Impact Assessment, Supplemental Measures, and the Data Protection Framework (DPF) certification, instead integrating them per region in Schedule 2. The EU SCCs are updated to include Module Three (Processor to Processor) for customers acting as processor, and Clause 7 (docking clause) is removed (does not apply). The Swiss section now references "revised" Swiss FADP.
- Brazil: The new DPA includes Brazil-specific terms in Schedule 2 (previously was in the main body). The BR SCCs are now described in more detail with options selected.
- United States: New dedicated section in Schedule 2 addresses U.S. State Privacy Laws and the DP Framework (including U.S. DPF). The new version specifies that Figma certifies to the EU-U.S., UK Extension, and Swiss-U.S. DP Framework. It also lists specific obligations (e.g., not selling or sharing, not combining data outside business relationship, notifying if can't meet obligations).
- Exhibits restructured: The previous Exhibits A-D (including detailed TOMs) are replaced by Schedules 1, 2, and Annexes I-II. The detailed TOMs in previous Exhibit B (e.g., policies, background checks, logging, vulnerability management) are now summarized in a table in Annex II, with references to industry standards.
- Definition of "Figma Platform": Previously defined in the DPA as the offering in an Order, excluding community; now defined more broadly (all Figma offerings, products and services).
- Order of precedence: New version introduces an explicit order: Region-specific terms > main body > Agreement (previous had no such clause but said DPA controls where conflict).