Canva

Last Reviewed: 02 Jun 2026

GDPR Addressed

At a Glance

Canva's DPA comprehensively covers GDPR processor requirements: instruction-only processing, explicit prohibition on selling or sharing customer data, SCCs (Module 2) under Irish law for restricted transfers, full sub-processor flowdown liability, and ISO 27001-backed structured audit rights. On termination, data is destroyed only — no return option. All key provisions are addressed.

Company & Product Details

HQ

Australia

Products

Canva design and collaboration platform

Product description

Cloud design, collaboration and content creation service for teams and enterprises.

What data is being processed?

Customer account data, user profile data, uploaded content and any personal data included in designs, brand assets, comments or related service content.

Document Details

Date of DPA

30 Oct 2025

Additional date information

DPA dated 30 October 2025 as stated at the foot of the document. The Addendum is incorporated into the Agreement (Canva's Terms of Use or other applicable agreement). (Introduction; last updated date at foot of document)

What jurisdictions are covered?

EU GDPR, UK GDPR (incorporated into UK domestic law via the EU Withdrawal Act 2018), Swiss Federal Data Protection Act, and applicable EU national laws are expressly named under 'European Privacy Laws'. US State Privacy Laws (including CCPA) and Brazilian data protection authority are also referenced for transfer safeguard purposes. (Sections 1, 2.2, 2.3)

Is the DPA incorporated into service or customer agreements?

Yes
This Addendum is stated to be supplementary to, and forms part of, the Agreement between Canva and the Customer (Canva's Terms of Use or other applicable agreement). In the event of conflict, this Addendum prevails over the Agreement, and the SCCs prevail over both. (Introduction, Section 2.4(vii))

Location & Transfers

Where is data held or processed?

Not explicitly stated The DPA does not explicitly name the countries where Customer Personal Data is stored or processed. Processing locations depend on the Canva entity under the applicable Agreement and on engaged sub-processors; full sub-processor details are published at canva.com/policies/subprocessors. (Section 2.7, Annex 3)

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
Standard Contractual Clauses (Module 2, controller-to-processor) from EC Decision 2021/914 are incorporated by reference for any Restricted Transfer, with Customer as data exporter and Canva as data importer. Clause 9 Option 2 (general authorisation for sub-processors) applies and Irish law governs. A UK Addendum (IDTA v B1.0) applies for UK transfers; Swiss modifications apply for Swiss transfers. (Sections 2.4, 2.4.a, 2.4.b)

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

Canva must implement appropriate technical and organisational measures (TOMs) to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. TOMs are described in full in Canva's Statement of Technical and Organisational Measures published at canva.com/policies/technical-and-organisational-measures/. TOMs may be updated provided the overall security level is not degraded. (Section 2.6, Annex 2)

Non Processor Data Use

Does the company process data solely as a processor?

Yes
Canva must process Customer Personal Data only for the Permitted Purpose and not for any other purpose including its own commercial purposes. Canva must not 'sell', 'share' or 'process for targeted advertising' as defined under US State Privacy Laws, nor combine Customer Personal Data with data from other sources except as permitted. The parties acknowledge the transfer is not a 'sale' under applicable laws. No controller rights are claimed. (Section 2.2)

Subprocessing

General authorization

General
Customer grants general authorisation to engage sub-processors listed at canva.com/policies/subprocessors, with at least 30 days' prior notice of additions or replacements. Customer may object within 10 days on data protection grounds; if Canva cannot satisfy the objection, Customer may terminate the affected services. Canva imposes equivalent data protection obligations on all sub-processors and remains fully liable for sub-processor breaches. (Section 2.7)

Do all the DPA terms flow down to sub-processors?

Yes
Canva must impose data protection terms on any sub-processor it engages requiring substantially the same standard of protection as provided under this Addendum. Canva remains fully liable to the Customer for any breach caused by an act, error or omission of its sub-processors. (Section 2.7(b))

Is data only processed on the instruction of the controller?

Yes
Canva shall process Customer Personal Data only for the Permitted Purpose: providing and maintaining the Service, performing its obligations, and acting on Customer's documented instructions as set out in the Agreement, this Addendum, and/or submitted through the Service. Authorised Persons may only process data as necessary for the Permitted Purpose. (Sections 2.2, 2.5)

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
Canva must provide all reasonable and timely assistance to enable Customer to respond to any Data Subject request (access, correction, objection, erasure, portability) and any correspondence or complaints from Data Subjects, regulators or third parties. Where requests are made directly to Canva, Canva must promptly inform Customer with full details. (Section 2.8)

Does the contract include staff confidentiality clauses?

Yes
Canva must ensure that any Authorised Person (including staff, agents and subcontractors) authorised to process Customer Personal Data is subject to a strict duty of confidentiality (whether contractual or statutory), and processes data only as necessary for the Permitted Purpose. (Section 2.5)

Are there audit rights for the data?

Structured
Canva is regularly audited against ISO 27001 standards by independent third-party auditors and will, on request, provide Customer with a summary copy of its audit report(s), subject to the Agreement's confidentiality provisions. Customer may submit written audit questions no more than once per year. The parties agree that SCC Clause 8.9 audit rights are exercised exclusively through these mechanisms; no on-site inspection right exists. (Section 2.12)

Is there assistance with DPIA requests?

Yes
Canva shall provide all reasonable and timely assistance as required to enable Customer to comply with its obligations to conduct Data Protection Impact Assessments and, where necessary, to consult with the relevant data protection authority. (Section 2.9)

How much notice is provided for data breaches?

Upon becoming aware of a Personal Data Breach, Canva must inform Customer without undue delay and provide timely information and cooperation needed to fulfil breach reporting obligations under applicable privacy laws. Canva must take measures to remedy or mitigate effects and keep Customer informed of material developments. No specific notice period (e.g. 72 hours) is stated. Customer must obtain Canva's prior approval before publishing any breach notice identifying Canva, unless compelled by law. (Section 2.10)

What happens to the data on termination?

Upon termination or expiry of the Agreement, Canva shall destroy all Customer Personal Data in its possession or control. There is no express option to return data to the Customer. Retention is permitted only to the extent necessary for the Permitted Purpose or required by applicable law; the same standard of protection applies until deletion is complete. (Section 2.11)