Is Canvas LMS GDPR compliant? What universities should check
Canvas, made by the US company Instructure, is the learning management system at many European universities, which means it holds course work, grades, messages and enrolment data for most students. This page sets out what Instructure and its university customers publicly document about hosting, transfers, AI features and the 2026 security incident, and what that means for a university.
Short answer
Instructure, Inc. is a US company in Salt Lake City; its European customers contract with Instructure Global Ltd in London. Instructure says the institution decides how personal data in Canvas is used, states that it complies with the EU-US Data Privacy Framework and refers to standard contractual clauses for transfers. Its public notices do not name hosting regions, but university customers describe hosting on AWS in Ireland or Germany. Instructure says it does not use student data to train its AI models and that IgniteAI features can be switched on or off by administrators. In April and May 2026 an unauthorised actor accessed Canvas data, including names, email addresses, enrolment information and messages, at institutions worldwide, including in the EU. A university should read its own contract and the incident record together.
What Instructure documents publicly
The table below summarises Instructure's privacy notices, AI notice, trust centre, press releases and incident updates, plus privacy statements published by two university customers, all read on 7 October 2026. Many trust centre documents, including the third-party service provider guide, require approved access.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and establishment | Documented Instructure, Inc., Salt Lake City, Utah, and Instructure Global Ltd., London, United Kingdom. The product privacy notice was last updated on 10 July 2026. Its EU privacy addendum names a data protection officer reachable at privacy@instructure.com. | Product Privacy Notice [1], EU addendum [2] |
| Where data is stored and processed | Customer-documented Instructure's notices say personal information may be transferred to servers outside the user's country, without naming regions. The University of Twente's privacy statement (23 September 2026) says Canvas uses S3 in the AWS EU (Ireland) region. The University of St.Gallen's information sheet lists the EU (Ireland and/or Germany) for the service and the USA for customer support to its administrators. | [1], University of Twente [3], University of St.Gallen (PDF) [4] |
| Data processing agreement | Partly documented The EU addendum says customers act as data controllers and that Instructure processes the personal data on their behalf. St.Gallen states Instructure is bound as a processor through a DPA. A public DPA template was not found on Instructure's website (checked 7 October 2026). | [2], [4] |
| Subprocessors | Partly documented Instructure's trust centre says a subprocessor list is available through its third-party service provider guide, which requires approved access. St.Gallen's sheet names providers including AWS, Amazon CloudFront, Splunk, Salesforce and Instructure entities in the US, UK and Hungary. | Trust centre [5], [4] |
| International transfers (DPF, SCCs) | Documented The product privacy notice says Instructure complies with the EU-US DPF, the UK Extension and the Swiss-US DPF (DPF status read from the vendor's notice; the official list API returned no results for any query on the check date). The EU addendum refers to adequacy decisions and standard contractual clauses. The University of Twente has a data transfer agreement with Instructure based on the SCCs. | [1], [2], [3] |
| AI features and training on customer content | Documented The AI privacy notice (27 October 2025) says "Instructure does not use student data to train our AI models" and names third-party base models including Claude 3 Haiku, Meta M2M-100 and Cohere Embed Multilingual. The April 2026 tier announcement says customer data is not used to train external models and that administrators can enable or disable AI capabilities at institution, department or course level. Where AI processing runs was not found in public documentation (checked 7 October 2026). | AI Privacy Notice [6], Press release [7] |
| Retention and deletion | Not found The EU addendum covers data Instructure holds as a controller, kept while there is an ongoing legitimate need. Contractual deletion of institutional Canvas data at the end of a subscription was not found in public documentation (checked 7 October 2026). Universities set their own rules: Twente states up to three years after a user leaves. | [2], [3] |
| Security certifications | Documented The trust centre lists SOC 2 Type II, ISO 27001, SOC 3, CSA, Cyber Essentials Plus, a HECVAT with an AI section, a VPAT and the DPF. | [5] |
| Security incident in 2026 | Documented Instructure detected unauthorised access on 29 April 2026 and a second access through another vulnerability on 7 May, when it took Canvas offline. It lists usernames, email addresses, course names, enrolment information and messages as involved, and says course content, submissions and credentials were not. On 11 May it said the data was returned with confirmation of destruction. It traced the cause to Free-For-Teacher accounts and discontinued that offer. | Incident update [8] |
The incident reached Europe. The University of Amsterdam confirmed that names, email addresses and possibly Canvas IDs or student and staff numbers of its students and employees leaked, made a preliminary notification to the Autoriteit Persoonsgegevens and worked with other Dutch universities on a further report [9]. Spain's national cybersecurity institute INCIBE also published an analysis of the incident [10].
What this means for a university
Validemic's analysis
Scale and sensitivity. An LMS is not one more tool: it holds data about nearly every student, including grades, submissions, private messages to teachers and sometimes information about disability accommodations or illness. That breadth is why a DPIA under Article 35 GDPR is the normal expectation rather than the exception [11]. Dutch universities such as Twente publish detailed privacy statements and transfer arrangements for Canvas, which shows the work is feasible and gives a useful template [3].
Hosting is real but under-documented. Customer statements consistently describe EU hosting on AWS [3][4], but Instructure's own public notices do not commit to a region. The commitment should therefore be in your contract, not assumed from another university's statement. Support access from the US [4] and US-based forensic or e-discovery work after an incident [8] are transfers too, and belong in the transfer assessment.
The incident is part of due diligence now. Every software vendor can be breached, and Instructure's public timeline, forensic engagement and discontinuation of the account type that was abused are the kind of response a customer should expect [8]. Still, a university renewing Canvas should ask for the root cause analysis, check whether its own tenant was affected, confirm what was notified and when under Article 33 GDPR [11], and review whether its contract's breach notification terms worked in practice.
AI controls. Instructure's model of institutional, departmental and course-level switches [7] lets a university approve IgniteAI features one by one. That is a strength. The gap is information: which model processes which feature, and where.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask Instructure before approving or renewing Canvas
- Which Instructure entity signs our agreement and DPA, and does it commit to a named EU hosting region for all Canvas data, including backups, logs and Canvas Data exports?
- Can we receive the current third-party service provider guide, and how are we notified of new subprocessors?
- Was our tenant affected by the April and May 2026 incident, which data categories, and can we receive the root cause analysis and forensic summary?
- Where did post-incident forensic and e-discovery review of EU customer data take place, and under which transfer mechanism?
- For each IgniteAI feature, which model runs it, in which region, and with what retention at the model provider?
- Which AI features are on by default in our tier, and can we keep them off at institution level until reviewed?
- How long is institutional data kept after the end of our subscription, and how is deletion confirmed?
- Which LTI tools connected to our instance receive student data, and does Instructure treat them as its subprocessors or ours?
The EU AI Act angle
An LMS sits closer to the AI Act's high-risk list than most tools. Annex III covers AI systems intended to evaluate learning outcomes (including when those outcomes steer the learning process), to assess the appropriate level of education a person will receive, and to monitor prohibited behaviour during tests [12]. Features such as rubric generators or discussion summaries look like general assistance, but any IgniteAI feature used to grade, recommend learning paths or flag students would need a careful classification. Those high-risk obligations apply from 2 December 2027 under the amended Article 113 [13]. The obligation that applies now is Article 4: deployers must take measures to support the AI literacy of staff using AI systems on their behalf [14]. Article 5(1)(f) prohibits emotion recognition in education institutions except for medical or safety reasons [15]; we found no such feature in Instructure's documentation.
Sources
- Instructure Product Privacy Notice (last updated 10 July 2026), retrieved 7 October 2026
- Instructure EU Privacy Policy Addendum (effective 28 June 2022), retrieved 7 October 2026
- Canvas privacy statement, University of Twente (version 1.31.0, 23 September 2026), retrieved 7 October 2026
- Information about data processing and data transfer: Canvas, University of St.Gallen (PDF), retrieved 7 October 2026
- Instructure Trust Center, retrieved 7 October 2026
- Instructure AI Privacy Notice (last updated 27 October 2025), retrieved 7 October 2026
- Instructure Introduces Simplified Canvas Tiers and Ecosystem Updates, Instructure press release, 21 April 2026, retrieved 7 October 2026
- Instructure incident update, retrieved 7 October 2026
- Stand van zaken datalek bij leverancier Canvas, University of Amsterdam, May 2026, retrieved 7 October 2026
- Cybersecurity incident at Instructure and its impact on the Canvas platform, INCIBE-CERT, retrieved 7 October 2026
- Regulation (EU) 2016/679 (GDPR), Articles 33 and 35, text read from the Publications Office copy, retrieved 7 October 2026
- AI Act Annex III, AI Act Service Desk (consolidated text of Regulation (EU) 2024/1689 as at 27 July 2026), retrieved 7 October 2026
- AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 5: Prohibited AI practices, AI Act Service Desk, retrieved 7 October 2026
About this page
We read Instructure's product privacy notice, EU addendum, AI privacy notice, trust centre, April 2026 press release and incident updates, privacy statements from the University of Twente and the University of St.Gallen, the University of Amsterdam's incident updates, INCIBE's analysis and the relevant EU legal texts on 7 October 2026. Where Instructure's own public documents are silent, we say so and cite customer statements as such. Our own interpretation is labelled as Validemic's analysis. This page is not legal advice and does not say whether any particular use of Canvas complies with the GDPR. If you spot an error or Instructure has updated a document, please contact us and we will correct it.
Frequently asked questions
Is Canvas GDPR compliant?
No tool is GDPR compliant on its own. Instructure says institutions decide how personal data in Canvas is used and that it processes that data on their behalf, states that it participates in the EU-US Data Privacy Framework and relies on standard contractual clauses for transfers. Whether a university's use complies depends on its contract, configuration, retention rules and how it informs students and staff.
Where is Canvas data stored for European universities?
Instructure's public privacy notices do not name hosting regions. University customers describe EU hosting on Amazon Web Services: the University of Twente says Canvas uses S3 in the AWS EU (Ireland) region, and the University of St.Gallen lists the EU (Ireland and/or Germany) for the service, with customer support for administrators in the USA.
Was European data affected by the 2026 Canvas incident?
Instructure detected unauthorised access in late April 2026 and said usernames, email addresses, course names, enrolment information and messages were involved. The University of Amsterdam confirmed that basic data of its students and staff leaked and made a preliminary notification to the Dutch data protection authority.
Does Canvas use student data to train AI?
Instructure's AI privacy notice says it does not use student data to train its AI models. Its April 2026 announcement says customer data is not used to train external models and that administrators can enable or disable AI capabilities at institution, department or course level.
Do universities need a DPIA for Canvas?
Usually yes, or at least a documented screening. An LMS processes data about almost every student, including grades and sometimes health-related accommodations, and AI features add new processing. Several Dutch universities publish privacy statements and transfer assessments for Canvas that can help structure a university's own assessment.