Skip to main content
Newcomer
August 10, 2026
Solved

Questions before implementation of Docusign

  • August 10, 2026
  • 1 reply
  • 40 views

Hello, we are working on a project to make the DocuSign solution available to our Group Treasury.

We have some questions for you and need specific answers due to the confidentiality of our activities and clients. Could you please help us answer the questions below:

  • When data is collected by DocuSign, can they be anonymized? Where are they stored?
  • How long is the data collected by DocuSign (accounts, identity documents, photos, videos, etc.) retained?
  • After how long is the data (accounts, identity documents, photos, videos, etc.) deleted ? For example, for a user who leaves the group and therefore will no longer be able to access his account.
  • Can we have a RACI matrix of access to different types of data?
  • What are the different levels of access depending on the position/responsibility? For example: access to logs, signed documents, videos, identity documents. This is related to the previous question
  • Describe the steps in the procedure for signing a complete document with video verification
  • If I have a DocuSign account and I am a document signatory, is it possible to retain the initial verifications in my account (photos, video, etc) and only sign my name for subsequent signatures?
  • If identity verification fails during DocuSign, what is the procedure?
  • Who are DocuSign's subcontractors? We have identified IDVerse
  • Will non-EU employees be able to access to Docusign? If yes, Could they sign using the same workflow as EU employees?
  • Will it be possible to display an information notice to users during the workflow process? The location of this notice can be communicated to you if we decide to implement Docusign.
Best answer by Noralynn.Niduaza

Hi ​@Pauline M,

 

We appreciate you reaching out to the Docusign Community and are delighted to have you join us.

Thank you for your detailed questions regarding the use of Docusign for your Group Treasury project. I’m glad to help you with this and provide the necessary information. Some aspects, particularly retention, data residency, identity verification, and access controls, may depend on the Docusign agreement, account configuration, and the specific products being implemented. Please see the responses below:

  1. When data is collected by Docusign, can they be anonymized? Where are they stored?
  • Docusign applies security and privacy controls to personal data processed  through its services. Whether specific data can be anonymized depends on the type of data and the applicable service. 
  • Article: Data residency
  1. How long is the data collected by DocuSign (accounts, identity documents, photos, videos, etc.) retained?
  1. After how long is the data (accounts, identity documents, photos, videos, etc.) deleted ? For example, for a user who leaves the group and therefore will no longer be able to access his account.
  • Removing or deactivating a user’s account access does not necessarily mean that all data associated with that user’s account is immediately deleted. Envelope and audit may remain subject to the account’s retention policy and applicable legal requirements. Administrators can manage the user’s account access, while retention/deletion follows the applicable Docusign policies and configuration.
  • Article: What happens to a user's data once the user is closed?
  1. Can we have a RACI matrix of access to different types of data?
  • Docusign provides role-based and permission-based access controls. Access to envelopes and documents can be controlled through permissions, account roles, shared access/delegation, and other administrative access. The appropriate RACI should be defined based on the customer’s account structure and configurations.
  1. What are the different levels of access depending on the position/responsibility? For example: access to logs, signed documents, videos, identity documents. This is related to the previous question
  • Docusign supports different levels of access through administrative roles and permissions. Access can be restricted according to the user’s responsibilities, including administrative functions  and access to documents/envelopes. The exact permissions available depend on the account type, product configuration, and enabled features.
  • Article: Agreement Manager Permissions, Profiles, and Roles Permission Profiles
  1. Describe the steps in the procedure for signing a complete document with video verification
  • The exact workflow depends on the identity verification being implemented. Generally, the recipient will receive an email invitation to access the envelope, complete the configured identity verification steps, and, upon successful verification, proceed with the electronic signature. The resulting evidence/audit information is associated with the process, depending on the product and configuration.
  • Article: Docusign eSignature Signing Process
  1. If I have a Docusign account and I am a document signatory, is it possible to retain the initial verifications in my account (photos, video, etc) and only sign my name for subsequent signatures?
  • This depends on the identity verification method and configuration being used. Identity verification and electronic signature are separate concepts. A previously completed verification should not be assumed to be reusable for subsequent envelopes unless the specific Docusign verification workflow explicitly supports that behavior. The verification requirements configured by the sender apply to each envelope for security and audit purposes.
  1. If identity verification fails during DocuSign, what is the procedure?
  • If a recipient fails the identity verification process, they will generally be unable to proceed until they have passed it. Depending on the verification method, there maybe limited number of attempts, and the sender will be required to void the envelope and send a new one. This depends on the identity verification provider and configuration. 
  • Article/s: Access Your ID Verification Tasks Verify Your Identity
  1. Who are DocuSign's subcontractors? We have identified IDVerse
  • IDVerse acts as an identity verification subcontractor/partner for DocuSign, specifically powering local ID verification and compliance workflows (such as TDIF accreditation) for regions like Australia and New Zealand. DocuSign utilizes various third-party subprocessors and identity partners depending on geographic region and specific product features. The current list of Docusign subprocessors/partners and relevant processing information should be reviewed through the Docusign Trust Center
  • Article: Subprocessor list
  1. Will non-EU employees be able to access to Docusign? If yes, Could they sign using the same workflow as EU employees?
  • Non-EU employees may be able to use Docusign, subject to the organization’s account configuration, geographic availability, identity verification requirements, and applicable compliance restrictions. Whether they can follow the same identity verification workflow as EU employees depends on the verification method and the countries supported by the verification services. 
  • Article: List of Eligible Countries and Accepted IDs for ID Verification
  1. Will it be possible to display an information notice to users during the workflow process? The location of this notice can be communicated to you if we decide to implement Docusign
  • The implementation can provide users with appropriate information regarding the processing of their personal data. The exact location and presentation of such notices depend on the Docusign workflow and features being implemented. The organization’s privacy notice and relevant information language should be incorporated into the signing experience in accordance with the applicable legal requirements.
  • Article/s: Manage Notification Preferences 

We recommend validating the applicable Docusign agreement and the current documentation available through the Docusign Trust Center, as these requirements can vary depending on the products and services included in your Docusign account.

 

I hope the information provided is helpful to you. 😊

Feel free to click the “Best Answer ✅” button below the post. That helps others in the Community find trusted answers faster.

 

Best regards,

Noralynn | Docusign Community Moderator

 

1 reply

Community Moderator
August 11, 2026

Hi ​@Pauline M,

 

We appreciate you reaching out to the Docusign Community and are delighted to have you join us.

Thank you for your detailed questions regarding the use of Docusign for your Group Treasury project. I’m glad to help you with this and provide the necessary information. Some aspects, particularly retention, data residency, identity verification, and access controls, may depend on the Docusign agreement, account configuration, and the specific products being implemented. Please see the responses below:

  1. When data is collected by Docusign, can they be anonymized? Where are they stored?
  • Docusign applies security and privacy controls to personal data processed  through its services. Whether specific data can be anonymized depends on the type of data and the applicable service. 
  • Article: Data residency
  1. How long is the data collected by DocuSign (accounts, identity documents, photos, videos, etc.) retained?
  1. After how long is the data (accounts, identity documents, photos, videos, etc.) deleted ? For example, for a user who leaves the group and therefore will no longer be able to access his account.
  • Removing or deactivating a user’s account access does not necessarily mean that all data associated with that user’s account is immediately deleted. Envelope and audit may remain subject to the account’s retention policy and applicable legal requirements. Administrators can manage the user’s account access, while retention/deletion follows the applicable Docusign policies and configuration.
  • Article: What happens to a user's data once the user is closed?
  1. Can we have a RACI matrix of access to different types of data?
  • Docusign provides role-based and permission-based access controls. Access to envelopes and documents can be controlled through permissions, account roles, shared access/delegation, and other administrative access. The appropriate RACI should be defined based on the customer’s account structure and configurations.
  1. What are the different levels of access depending on the position/responsibility? For example: access to logs, signed documents, videos, identity documents. This is related to the previous question
  • Docusign supports different levels of access through administrative roles and permissions. Access can be restricted according to the user’s responsibilities, including administrative functions  and access to documents/envelopes. The exact permissions available depend on the account type, product configuration, and enabled features.
  • Article: Agreement Manager Permissions, Profiles, and Roles Permission Profiles
  1. Describe the steps in the procedure for signing a complete document with video verification
  • The exact workflow depends on the identity verification being implemented. Generally, the recipient will receive an email invitation to access the envelope, complete the configured identity verification steps, and, upon successful verification, proceed with the electronic signature. The resulting evidence/audit information is associated with the process, depending on the product and configuration.
  • Article: Docusign eSignature Signing Process
  1. If I have a Docusign account and I am a document signatory, is it possible to retain the initial verifications in my account (photos, video, etc) and only sign my name for subsequent signatures?
  • This depends on the identity verification method and configuration being used. Identity verification and electronic signature are separate concepts. A previously completed verification should not be assumed to be reusable for subsequent envelopes unless the specific Docusign verification workflow explicitly supports that behavior. The verification requirements configured by the sender apply to each envelope for security and audit purposes.
  1. If identity verification fails during DocuSign, what is the procedure?
  • If a recipient fails the identity verification process, they will generally be unable to proceed until they have passed it. Depending on the verification method, there maybe limited number of attempts, and the sender will be required to void the envelope and send a new one. This depends on the identity verification provider and configuration. 
  • Article/s: Access Your ID Verification Tasks Verify Your Identity
  1. Who are DocuSign's subcontractors? We have identified IDVerse
  • IDVerse acts as an identity verification subcontractor/partner for DocuSign, specifically powering local ID verification and compliance workflows (such as TDIF accreditation) for regions like Australia and New Zealand. DocuSign utilizes various third-party subprocessors and identity partners depending on geographic region and specific product features. The current list of Docusign subprocessors/partners and relevant processing information should be reviewed through the Docusign Trust Center
  • Article: Subprocessor list
  1. Will non-EU employees be able to access to Docusign? If yes, Could they sign using the same workflow as EU employees?
  • Non-EU employees may be able to use Docusign, subject to the organization’s account configuration, geographic availability, identity verification requirements, and applicable compliance restrictions. Whether they can follow the same identity verification workflow as EU employees depends on the verification method and the countries supported by the verification services. 
  • Article: List of Eligible Countries and Accepted IDs for ID Verification
  1. Will it be possible to display an information notice to users during the workflow process? The location of this notice can be communicated to you if we decide to implement Docusign
  • The implementation can provide users with appropriate information regarding the processing of their personal data. The exact location and presentation of such notices depend on the Docusign workflow and features being implemented. The organization’s privacy notice and relevant information language should be incorporated into the signing experience in accordance with the applicable legal requirements.
  • Article/s: Manage Notification Preferences 

We recommend validating the applicable Docusign agreement and the current documentation available through the Docusign Trust Center, as these requirements can vary depending on the products and services included in your Docusign account.

 

I hope the information provided is helpful to you. 😊

Feel free to click the “Best Answer ✅” button below the post. That helps others in the Community find trusted answers faster.

 

Best regards,

Noralynn | Docusign Community Moderator