Is Figma AI GDPR compliant?
YesFigma · Design
Yes. Figma offers a Data Processing Agreement (DPA) for Figma AI, the baseline GDPR control when a vendor processes personal data on your behalf.
What we checked
This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.
- Data Processing Agreement
- Confirmed
- Figma publishes a DPA. A DPA is necessary but does not replace your own lawful-basis, DPIA and transfer assessment.
- EU data residency
- Confirmed
- Figma documents an EU data-residency option; confirm it is enabled for the account and workload in scope.
- Default data training
- Opt-out required
- Content training is on by default for Starter and Professional teams; admins can toggle 'Content training' in Settings. Content is de-identified and Education and Government data is excluded.
- Business-tier training
- No by default
- Content training is off by default on Organization and Enterprise plans.
Practical risk: Figma holds SOC 2 Type II and ISO 27001, and content training defaults off on Organization and Enterprise (on for Starter and Professional unless an admin turns it off). The gap is HIPAA: the AUP bars PHI and no BAA is offered.
How to make a decision
Check the precise account tier, written contract and intended data before approving Figma AI. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.
More on Figma AI
Is Figma AI HIPAA compliant?Is Figma AI SOC 2 compliant?Is Figma AI ISO 27001 certified?Does Figma AI train on your data?
See the full Figma AI risk profile, with every data-handling fact and its source, or browse all rated AI tools.