Guidelines for Data Disclosure Requests
PURPOSE AND SCOPE
Docusign operates its business with the highest ethical standards and is deeply committed to the integrity and protection of customer and company data. The following information provides operational guidance regarding Docusign’s principles, requirements, and procedures for receiving, evaluating, and responding to third-party requests for Docusign customer or company data. These guidelines are generally applicable to subpoenas, court orders, search warrants, and other legal requests or inquiries (“Data Disclosure Request”) from law enforcement, government agencies, or civil litigants (“Requesting Party”).
Before requesting customer data from Docusign, we encourage you to directly request it from the Docusign customer who used the services and will generally have access to the agreement contents and related account information. If you are unsuccessful in your attempt to request data from the customer directly, and you properly serve Docusign with a valid Data Disclosure Request as provided in these guidelines, Docusign will respond to your request accordingly.
Docusign will disclose the minimum amount of information permissible when responding to a Data Disclosure Request based on a reasonable interpretation of that request. Docusign recognizes the urgency of matters involving emergency situations, imminent harm, child safety, and valid judicial deadlines, though the time required for production will vary depending on the request's complexity and scope.
GOVERNANCE OF DATA DISCLOSURE REQUESTS
Governance oversight of a third-party Data Disclosure Request resides with Docusign’s Chief Legal Officer and Chief Privacy Officer. These functions coordinate with Trust & Security to ensure compliance with applicable law and Docusign’s internal policies.
Docusign will only disclose data in response to a valid Data Disclosure Request and in accordance with our Terms of Use, the applicable Master Services Agreement in effect between Docusign and its customers, Docusign’s Binding Corporate Rules (“BCRs”), Docusign’s Privacy Notice, and and other applicable laws, including the United States Federal Stored Communications Act, 18 U.S.C. §§ 2701 et seq. (the “SCA”).
Docusign’s Binding Corporate Rules require that Docusign ensure transfers of personal information in response to a Data Disclosure Request are not “massive, disproportionate and indiscriminate” in a manner that would go beyond what is necessary in a democratic society. Docusign has committed to preparing an Annual Transparency Report, which reflects to the extent permitted by applicable laws, the number and type of Data Disclosure Requests it has received for the preceding year and the Requesting Authorities who made those requests. Docusign shall make this report available upon request to competent data protection authorities.
SERVICE OF REQUEST WITHIN THE U.S.
Docusign's obligation to disclose data is contingent upon the proper service of a valid Data Disclosure Request, which must adhere to all applicable U.S. laws, codes, or statutes.
Service of process for Docusign, Inc. is accepted through its registered agent, United Agent Group, Inc., in any state where Docusign is registered to conduct business. The Requesting Party must confirm the correct service address by checking with their respective State’s Secretary of State website. The service address for United Agent Group, Inc. in California, where Docusign, Inc. is headquartered, is provided below:
Docusign, Inc.
c/o United Agent Group, Inc.
7801 Folsom Blvd., #202
Sacramento, CA 95826
process@unitedagentgroup.com
Docusign does not accept service of process at its physical office locations. Acceptance of legal process at Docusign’s offices or by any other means is for convenience only and does not waive any objections, including lack of jurisdiction or proper service.
SERVICE OF INTERNATIONAL REQUESTS
As a U.S. company, Docusign, Inc. stores all U.S.-based customer data within the United States. Consequently, a Requesting Party seeking access to U.S.-based customer data must serve Docusign, Inc., irrespective of the Party's country of origin. Requesting Authorities located outside the U.S. are required to formally domesticate their request through a U.S. court by working through the appropriate process for international cooperation, such as letters rogatory or the Mutual Legal Assistance Treaty (MLAT). Further information about this process can be obtained by contacting the Office of International Affairs at the U.S. Department of Justice.
Requesting Authorities outside the U.S. looking to obtain customer data stored in a non-U.S. geographical region may serve the appropriate Docusign subsidiary at its registered address, or as mandated by applicable local law, code, or statute. Serving a Data Disclosure Request to a specific Docusign global subsidiary only grants access to data governed by that subsidiary. For instance, a request served within the European Union will only entitle the Requesting Party to EU data. The Requesting Party is responsible for ensuring that legal process is directed to the correct Docusign entity.
As the Requesting Party may not know the location in which the data they are seeking resides, consider first directing a Preservation Request to Docusign. After documents responsive to Preservation Request have been identified and preserved, Docusign will advise the Requesting Party of the most appropriate location to serve a formal Data Disclosure Request. Docusign will preserve all responsive data until a proper Data Disclosure Request is served in the correct jurisdiction.
PRESERVATION REQUESTS
Docusign will comply with Preservation Requests in accordance with 18 U.S.C. § 2703(f) or other applicable global laws, codes, or statutes. Data will be preserved for a period of 90 days, extendable for an additional 90 days upon written request. After the preservation period expires, the data may no longer be available.
Preservation Requests must be submitted on an official company or agency letterhead, clearly state the legal basis for the request, and identify the specific underlying matter to which the data is relevant. Docusign reserves the right to object to overly broad "blanket requests", as such requests may interfere with Docusign's business operations or violate its obligations under the applicable Terms of Use or Master Services Agreement with its customers.
To obtain data that has been preserved, the Requesting Party must submit a valid Data Disclosure Request. This request should reference the original Preservation Request, as this will enable Docusign to locate the previously preserved data.
FORM OF REQUEST
Data Disclosure Requests must be submitted in the appropriate form, and must include required information which allow Docusign to authenticate the request and conduct an internal search for data. Docusign will only respond to requests that meet these requirements. This includes:
Case name
Case number or reference number
Identifiers required to conduct an internal search
Production date which allows sufficient time to respond
Legal authority supporting the request
Signature and contact information for the Requesting Party.
The Data Disclosure Request must specify the type of data sought, and include required identifying information pertaining to the target transaction, user, or account, including:
Envelope ID
User email address (must be associated with active Docusign account)
Account ID (must be active Docusign account)
Defined date range
Docusign cannot conduct an exhaustive search based on the following personal identifiers:
Individual or entity name
Date of birth
Identification number (SSN or other government ID)
Telephone number
Physical address
Partial User ID (15-digit code underneath signature image)
Docusign reviews each request for legal sufficiency, scope, specificity, and proportionality, and reserves its right to object to improper or overly-broad requests. Docusign will seek to limit disclosure to data which is relevant and is reasonably calculated to lead to the discovery of admissible evidence proportional to the needs of the case.
DATA SUBJECT TO DISCLOSURE
Docusign maintains customer data in its system for no longer than necessary for the purposes for which it is processed or as required by applicable law, per Docusign’s Data Protection Attachment (“DPA”). Parties should act expeditiously where short operational retention may affect availability of certain logs or data.
Docusign products have been specifically designed to restrict Docusign’s ability to access the contents of customer agreements stored in Docusign’s System in order to preserve the confidentiality of customer information uploaded to Docusign services. Consequently, Docusign's ability to provide data in response to a request is limited, depending on whether the targeted data is classified as "content" or "non-content" data.
Content (agreement contents): Docusign encrypts customer agreement contents at rest and cannot decrypt, access, or search their contents. As a result, Docusign cannot produce decrypted or plaintext versions of customer agreements. When seeking content data, Requesting Authorities should directly contact parties to the agreement with access rights to that data.
As a cloud-based service provider that facilitates and stores electronic documents and communications, Docusign is also subject to the Stored Communications Act (“SCA”), which governs compelled disclosure of "stored wire and electronic communications and transactional records". Under the SCA, Docusign is strictly prohibited from disclosing the contents of communications to any third party, even when served with a subpoena or court order.
Non-content (subscriber data / log data): Disclosable in response to a valid Data Disclosure Request. Requests must include required identifying information, specific data sought, and a valid date range. Account subscriber data and audit log data or metadata related to transactions is generally responsive to these requests.
The following categories of data are subject to disclosure:
Subscriber data:
Name
Address
Email address
Telephone number
Subscriber number or identity (User ID, Account ID)
Length and type of service utilized
Means and source of payment
Audit Log data / metadata:
Records of session times and durations
Temporarily assigned network address (IP address)
User or account activity data
Disclosable business records may include:
Certificate of Completion
Envelope History
Account Subscriber Records
Account Payment Data (excluding payment amount)
CUSTOMER NOTIFICATION POLICY
Pursuant to Docusign’s Master Services Agreement, Docusign is obligated to provide prompt written notification to customers whose data is the subject of a Data Disclosure Request to allow them an opportunity to review the proposed disclosure. Should a customer file a legal objection to the disclosure of their data, such as a Motion to Quash, Docusign will withhold producing data until the matter is resolved by a Court or through mutual agreement of the involved parties.
Requesting Authorities seeking to prohibit customer notification, as it would compromise a confidential investigation, must either:
Obtain a signed Non-Disclosure Order obtained under 18 U.S.C. § 2705(b); or
Identify a criminal statute that explicitly prohibits Docusign from providing notification.
Language in a Data Disclosure Request that merely "requests," "prefers," or "asks" Docusign not to disclose the request is not considered a prohibition on customer notification. Failure to provide customer notification without a valid legal basis constitutes a violation of Docusign's Master Services Agreement with its customers.
Non-Disclosure Orders issued under 18 U.S.C. § 2705(b) (“Delayed Notice”) are only valid for a specified period. Once this period expires, the Non-Disclosure Order is no longer binding. Because the underlying investigation may still be active, a renewal Order must be obtained to continue prohibiting customer notification.
Notification may also be delayed or withheld in urgent matters to prevent emergency situations, imminent harm, or child, with delayed notice provided where legally permissible and safe.
REQUESTS FOR TESTIMONY
Docusign does not provide testimony support. In most instances, testimony by a Docusign witness is unnecessary and burdensome, and Docusign’s policy is to object formally to requests for testimony, including filing a Motion to Quash when necessary.
Business records accompanied by a business records certification are generally admissible as evidence without the need for testimony. Certification forms should be included with Data Disclosure Requests, if required for the admissibility of evidence received from Docusign.
If explanation of documents produced by Docusign is required, refer to resources available on Docusign’s website before inquiring about testimony. Docusign will generally not provide expert testimony regarding topics which are duplicative of explanatory material available on Docusign’s website. In limited circumstances, Docusign may provide an explanatory declaration or affidavit for the purpose of describing product functionality and authenticating and defining data captured by Docusign's System.
Docusign will seek cost reimbursement for compliance with demands for testimony pursuant to applicable law, including statutory fees, travel, and accommodations.
PRODUCT RESOURCES
User Guides for eSIGNATURE, CLM, IAM, and other products provide detailed information about Docusign products, including product functionality, account settings, and available features for users.
eSignature Legality Guide provides a detailed summary, history, and guidance about laws governing electronic signatures globally.
Are Electronic Signatures Legal? is a Docusign whitepaper for legal professionals which provides detailed information and resources regarding the legality of eSignature, reference to local laws and enforceability, as well as reference to the Audit Trail, which establishes authenticity and can help resolve disputes over electronic signatures in court.
eSignature Signing Process provides an overview of Docusign eSignature for sending and signing documents electronically, including links to related topics.
Certificate of Completion overview. The Certificate provides identifying information about an envelope and complete details of all envelope events, categorized into general envelope details, recipient events, and envelope summary events.
Envelope History overview and definition of actions. The History provides a summary of the envelope and document details and a list of sender and recipient activities to date.
Recipient Identity Verification options available to customers for recipients of an envelope, requiring them to provide information to prove their identity, including phone authentication (SMS or phone call), knowledge-based ID check, and ID Verification.
Signature Adoption Configuration options, including the default mode for signature adoption and signature styles available for signers.
Electronic Record and Signature Disclosure (ERSD). If enabled, recipients must read and agree to the legal terms of this disclosure before they can access and take action within an envelope.
eSignature Certificates overview, confirming digital certificate cryptography uses Public Key Infrastructure (PKI) technology to issue certificates based on X.509 standards to represent the digital identity of a signer.
Data Management & Privacy. Docusign practices regarding data retention, deletion, access and residency for eSignature.
Document Retention options available to Docusign customers and summary of Docusign’s standard retention practices.
Data Residency. Confirmation of the storage location for customer’s uploaded and completed agreements for eSignature.
Docusign Safety Center. Customer resource for identifying and reporting suspicious activity, fraud, and other security concerns.
FREQUENTLY ASKED QUESTIONS
Who can I contact with questions about these guidelines?
Please contact Docusign’s Legal Department at legal@docusign.com.
How do I serve Docusign with a Data Disclosure Request, and does Docusign accept service by email?
Service of process for Data Disclosure Requests must comply with the laws governing U.S. corporations or global subsidiaries. Docusign does not accept service of process electronically or at its physical office locations, except where permitted by law.
In the U.S., requests must be addressed to Docusign, Inc. c/o United Agent Group, Inc. Please verify the current local address using the appropriate Secretary of State's website.
What business records does Docusign retain, and which are subject to disclosure?
Docusign may disclose retained account subscriber data and audit log data upon receipt of a valid Data Disclosure Request requiring the disclosure. Please refer to the DATA SUBJECT TO DISCLOSURE section for further details.
Can Docusign disclose the contents of customer agreements or provide copies of signed documents?
No, customer agreements are encrypted and Docusign is unable to decrypt or search the contents of customer agreements. The Stored Communications Act also imposes a strict prohibition on Docusign's ability to disclose the contents of communications to any third party.
Requesting Authorities should approach the parties to the agreement directly, as they generally have access to agreements via their Docusign account or the notification email received.
What identifying information is required to search for business records?
To locate data, Docusign requires the agreement's Envelope ID, the account holder's email address or Account ID, and a date range. Docusign is unable to search for data using personal identifiers such as individual or entity name, date of birth, SSN, address, phone number, or other IDs.
Does Docusign notify its customers about Data Disclosure Requests?
Yes, Docusign notifies customers when their data is subject to disclosure in response to a valid Data Disclosure Request, unless legally prohibited to do so (i.e., Non-Disclosure Order).
Where is Docusign customer data stored, and is user location recorded?
Docusign eSignature utilizes multiple secure data centers (see Data Residency). While Docusign records the IP address of users in the audit trail, it does not record physical location information or device information.
Is Docusign subject to the Clarifying Lawful Overseas Use of Data (CLOUD) Act?
Docusign complies with CLOUD Act Orders, adhering to all applicable laws and policies governing data disclosure. Requesting Authorities must obtain a warrant for CLOUD Act information requests.
While the Act addresses Requesting Authorities access to electronic communications content, all customer agreements are encrypted immediately upon upload, rendering them inaccessible to Docusign employees. Furthermore, customers retain full control over the storage and deletion settings for their agreements stored on Docusign’s System.
OPERATIONAL BEST PRACTICES
Start with the subscriber: Parties to an agreement generally have access to the agreement contents and all metadata associated with the agreement. Docusign’s access to agreement data is limited.
Be precise: Include account-holder information (email address, Account ID), agreement identification numbers (Envelope ID), and a valid date range. Specify the precise non-content records sought and avoid overly-broad language (“and and all documents”).
Use appropriate channels: Ensure compliance with service of process requirements under the law. Docusign will not respond to requests served improperly and is not required to advise Requesting Authorities regarding service.
Plan accordingly: Response time for Data Disclosure Requests is typically three weeks, including the required customer notification period. Ensure the production date is compliant with laws governing the request and allows Docusign sufficient time to comply.
Customers have a say: Docusign customers own their data and have a right to review potential disclosures of their data. Customers will be notified of a Data Disclosure Request unless legally prohibited.