Is Canva GDPR compliant? What universities should check
Canva is used across universities for posters, slides and student projects, often on free accounts long before any procurement review. It is run by an Australian company and now includes AI features built on several third-party models. This page sets out what Canva documents and what a university should settle before standardising on it.
Short answer
Canva Pty Ltd, an Australian company, is the controller for its consumer service and has an EU representative in Dublin. For multi-seat subscriptions such as Teams and Canva for Campus, Canva's Data Processing Addendum applies with Canva as processor, 30 days' notice of subprocessors and the Standard Contractual Clauses for transfers. Canva says it will not use Canva Education content for AI training; for other plans, privacy settings decide. Its AI features rely on subprocessors including OpenAI, Anthropic and Google in the United States. A university should make sure staff and students use institutional accounts, check its plan's AI settings and record transfers to Australia, which has no EU adequacy decision.
What Canva documents publicly
Everything in this table comes from Canva's own pages, read on 7 October 2026. Numbers in brackets refer to the sources at the end.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and establishment | Documented Canva Pty Ltd, Surry Hills, Australia, is the controller and the contracting party for users billed outside the US and UK. Its EU representative is the European Data Protection Office (EDPO) in Dublin. | [1], [2] |
| Plans | Plan-dependent Children may not use Canva other than through Canva Education. Canva markets a separate higher education offer, Canva for Campus, with SSO, domain capture and AI controls. | [2], [7] |
| Data processing agreement | Plan-dependent The DPA (last updated 30 October 2025) applies where Canva is processor. The Terms of Use say Canva acts as processor for subscriptions with multiple seats, and for Pro users collecting personal data through Canva Sites or forms. Data outside the DPA is processed by Canva as controller under its privacy policy. | [3], [2] |
| Where data is stored | Multiple countries The privacy policy lists the United States, Australia, Singapore, the EU, the UK, the Philippines and New Zealand. No EU-only storage option was found in public documentation (checked 7 October 2026). | [1] |
| Subprocessors | Documented The list (last updated 17 April 2026) names Amazon Web Services (US and EU), Google, MongoDB and Snowflake for hosting, and Anthropic, OpenAI, ElevenLabs and others for Canva AI services, mostly in the United States. One AI provider is marked as not processing data for Canva Education, Canva Enterprise or customers with a signed order form. Support providers include teams in the Philippines and the EU. The DPA promises at least 30 days' notice of changes. | [4], [3] |
| International transfers | Documented The privacy policy says third-party service providers in countries without an adequacy decision must agree safeguards such as the EU Standard Contractual Clauses and the UK addendum. The DPA incorporates the 2021 SCCs (module two) for restricted transfers from the customer to Canva. Its security page lists the Data Privacy Framework among its certifications without naming the certified entity; the official DPF List search service returned errors on the check date. | [1], [3], [6] |
| AI training on user content | Plan-dependent "We will not use User Content of Canva Education for AI training." For other users, privacy settings control whether Canva and its technology partners may use data to improve AI services, and inputs to AI features may be shared with technology partners to provide the feature. The default for Canva for Campus was not found in public documentation (checked 7 October 2026). | [2], [5] |
| Retention and deletion | Partly documented Under the DPA, Canva destroys customer personal data on termination except where needed for the permitted purpose or required by law. The privacy policy says that, around the end of each school year, Canva Education student accounts not logged into for more than 12 months receive a deletion notice and are deleted if the student does not log in within 3 months. | [3], [1] |
| Security certifications | Documented Canva states ISO 27001 certification and SOC 2 Type II, with SOC 3 and PCI DSS also listed. Designs are encrypted with AES-256 at rest and TLS in transit. | [6], [7] |
Canva deserves credit for naming its AI subprocessors individually with locations, for a flat commitment not to train on Canva Education content, and for giving higher education administrators a switch for AI features.
What this means for a university
Validemic's analysisFree accounts are the main risk. A lecturer using a free personal account is Canva's customer, and Canva is controller [2]. If that lecturer uploads student photos or names, the university has no processor agreement for that data. Article 28 GDPR requires one for processing on the university's behalf [9]. The DPA applies to multi-seat subscriptions [2], so the practical step is an institutional plan with SSO and domain capture [7], and guidance telling staff to use it.
Domain capture changes existing accounts. When someone signs up with an employer email address, Canva treats it as an administered account and may share the user's name, email address and account activity with the organisation [1]. Bringing staff who already use Canva under a Campus subscription is therefore also a change for them: tell them in advance what administrators will see, and give them a way to move private designs to a personal account before consolidation.
Teacher education is a special case. Faculties that train school teachers may use Canva Education with pupils on placement. That plan is the only route through which children may use Canva [2], and the school, not the university, may be the party that manages those accounts. Clarify who signs for what before students use Canva in a school setting.
Mixed roles need mapping. Even under the DPA, Canva says personal data outside the DPA's scope is processed by Canva as controller [2]. Ask Canva which data that covers for your plan (for example account and usage data) and describe it in your privacy notice.
AI features rely on US providers. Canva AI services use OpenAI, Anthropic, Google and others located in the United States [4], and inputs may be shared with them to provide the feature [5]. The education training commitment is clear [2]; for Campus or Teams plans, check the privacy setting at organisation level, not only for individual users.
Australia is not adequate. The European Commission's adequacy list does not include Australia [8]. Canva relies on SCCs for transfers [1], and support and administration involve Canva entities and providers in Australia, the Philippines and the United States [4]. These belong in the transfer impact assessment. Our transfer mechanism tool helps with the first step.
Use the 30-day notice. The DPA gives at least 30 days' notice of subprocessor changes, posted on the subprocessor page [3]. Sign a shared mailbox up for updates so that a change, for example a new AI provider, reaches the DPO in time to object.
DPIA. Design work is usually low risk, but Canva forms and Sites can collect personal data from others, and student portfolios can include images of identifiable people. Article 35 GDPR applies where high risk is likely [9].
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask Canva before approving it
- Does the DPA apply to our whole Canva for Campus subscription, including students, and which personal data do you process as controller?
- What is the default AI training privacy setting for Campus users, and can our administrators lock it off for the organisation?
- Can AI features be disabled entirely, or only some of them, and does that stop data reaching the AI subprocessors?
- Which Canva entity holds the Data Privacy Framework certification, and which transfers rely on it rather than the SCCs?
- Can our designs and account data be stored only in the EU?
- What is the deletion period for students who leave, and can we trigger bulk deletion?
- Can we obtain the SOC 2 Type II report and the ISO 27001 certificate with its scope?
The EU AI Act angle
Canva's AI features are generative tools, and a university that enables them is a deployer under Regulation (EU) 2024/1689 [10]. Article 4 on AI literacy has applied since 2 February 2025; the Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026, reworded it as a duty to take measures to support staff AI literacy [11]. Generating images or text for teaching materials is not an Annex III high-risk use; those rules, applying from 2 December 2027 under the Omnibus, cover uses such as evaluating learning outcomes or admissions [10], [11]. Guidance on labelling AI-generated material in student work is a sensible addition.
Sources
- Canva Privacy Policy (last updated 25 August 2026), retrieved 7 October 2026.
- Canva Terms of Use (effective 19 August 2026), retrieved 7 October 2026.
- Canva Data Processing Addendum (last updated 30 October 2025), retrieved 7 October 2026.
- Canva List of Subprocessors (last updated 17 April 2026), linked from canva.com/policies/subprocessors, retrieved 7 October 2026.
- Canva AI Product Terms (effective 26 June 2026), retrieved 7 October 2026.
- Canva Security, retrieved 7 October 2026.
- Canva for higher education, Security and SSO, retrieved 7 October 2026.
- European Commission, Adequacy decisions, retrieved 7 October 2026.
- Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 28 and 35, retrieved 7 October 2026.
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Article 4 and Annex III, retrieved 7 October 2026.
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), retrieved 7 October 2026.
About this page
We read Canva's privacy policy, Terms of Use, Data Processing Addendum, subprocessor list, AI Product Terms, security page and higher education security page on 7 October 2026. The official Data Privacy Framework List could not be queried on that date. We did not test a Canva for Campus account or review a customer-specific agreement. "Not found" means we could not find information in public documentation; it does not mean it does not exist.
This page is not legal advice and is not a statement that Canva is or is not GDPR compliant, which depends on your contract, configuration and use. If you work at Canva or spot an error, please contact us and we will correct it.
Frequently asked questions
Does Canva have a GDPR data processing agreement?
Yes. Canva's Data Processing Addendum (last updated 30 October 2025) applies where Canva acts as processor. Its Terms of Use say this covers subscriptions with multiple seats, such as Teams, and Pro users collecting personal data through Canva Sites or forms. Personal data not covered by the DPA is handled by Canva as controller under its privacy policy.
Does Canva use our designs to train AI?
Canva's terms say it will not use User Content of Canva Education for AI training. For other plans, Canva says users' privacy settings control whether Canva and its technology partners may use their data to improve AI services. We did not find a public statement on the default setting for Canva for Campus (checked 7 October 2026).
Where does Canva store data?
Canva's privacy policy lists the United States, Australia, Singapore, the European Union, the United Kingdom, the Philippines and New Zealand. Its subprocessor list names Amazon Web Services in the United States and EU and several AI providers in the United States.
Is Australia an adequate country under the GDPR?
No. The European Commission's list of adequacy decisions does not include Australia. Canva says that third-party service providers in countries without an adequacy decision must agree safeguards such as the EU Standard Contractual Clauses and the UK addendum, and its DPA incorporates the SCCs for restricted transfers.
Can a university turn off Canva's AI features?
Canva's higher education security page says Canva for Campus gives administrators control over AI usage, alongside SSO and domain capture. Check which features the control covers for your plan.