data report card

Data Report Card · DocuSign

DocuSign Data Report Card

E-signature · Docusign, Inc.
Data
Practices
2Access1Portability2Friction2Deletion1Sells2Trains AI
=
B
10/12
Agent
Readiness
2Access 1Portability 2API access
=
B
5/6

Agent Readiness is a derived signal — a synthesis of two existing cells (Access, Portability) plus one sourced factor (API access), not an independently measured grade. API access scale: Best (2) consumer-grantable API · Moderate (1) partial / encumbered · Restrictive (0) manual export only. What is Agent Readiness?

Help me make a request →
Reviewed Jun 2026 · policies are checked weekly for changes  ·  stated — every cell is read from DocuSign's published policy; none has been tested (run by us) yet.
2Accessstated
DocuSign provides the right to access and receive a copy of the personal data it holds through the DocuSign Privacy Request Portal, satisfying the access right.
DocuSign — Data management and privacy practices · accessed Jun 2026 ↗
1Portabilitystated
Access and copies are delivered through the Privacy Request Portal, but the documentation does not confirm a structured multi-format machine-readable export, so portability is scored at the single-format level.
DocuSign — Privacy Notice · accessed Jun 2026 ↗
2Frictionstated
Rights are exercised through a self-serve DocuSign Privacy Request Portal rather than a manual email queue, placing friction at the low level.
DocuSign — Data management and privacy practices (Privacy Request Portal) · accessed Jun 2026 ↗
2Deletionstated
At a customer's request DocuSign deletes all personal data in its possession as soon as reasonably practicable, except where legally required to retain it or where archived on backup systems, so deletion is scored at the full level.
DocuSign — Data Protection Attachment (deletion) · accessed Jun 2026 ↗
1Sells / sharesstated
DocuSign does not describe selling personal data for money, but states it may aggregate or de-identify personal information for marketing, research, and product development, so data use is scored at the partial level.
DocuSign — Privacy Notice (aggregate / de-identify use) · accessed Jun 2026 ↗
2Trains AIstated
DocuSign states it intentionally designs its systems to avoid training models using the personal information customers enter into its services, except where the customer has given consent — an opt-in / avoid-by-default posture scored at the full level.
DocuSign — Privacy Notice (avoids training on customer data without consent) · accessed Jun 2026 ↗
2API access — feeds Agent Readiness, not the /12stated
DocuSign's eSignature REST API uses OAuth 2.0 Authorization Code Grant with refresh tokens (extended / offline scope) that a consumer grants to an app and can revoke, so agent access is scored at the full level.
DocuSign — Authorization Code Grant (OAuth 2.0) · accessed Jun 2026 ↗
Reviewed Jun 2026 from DocuSign's Privacy Notice and Data Management & Privacy pages. All cells "stated", not tested. DocuSign offers a self-serve Privacy Request Portal for access and deletion and takes a notably strong AI stance — it states it designs its systems to avoid training models on the personal information customers enter, except with consent. Weaknesses are format (portability not confirmed multi-format) and marketing use of aggregated / de-identified data.

How to request your data from DocuSign

  1. Go to https://www.docusign.com/privacy — DocuSign's data-request entry point.
  2. DocuSign Privacy Request Portal: access / copy / deletion of personal data.
  3. Expected wait: self-serve Privacy Request Portal for access / deletion; deletion honored except legal / backup retention; eSignature OAuth API — DocuSign's stated turnaround (we haven't independently timed a request yet).
  4. No self-serve option, or want a formal request? Contact DocuSign — Privacy Request Portal: https://www.docusign.com/privacy.

These steps reflect DocuSign's documented process as of Jun 2026. The wait time is the company's stated figure, not yet independently measured by us.