Canva
Last Reviewed: 02 Jun 2026
At a Glance
Canva's DPA comprehensively covers GDPR processor requirements: instruction-only processing, explicit prohibition on selling or sharing customer data, SCCs (Module 2) under Irish law for restricted transfers, full sub-processor flowdown liability, and ISO 27001-backed structured audit rights. On termination, data is destroyed only — no return option. All key provisions are addressed.
Company & Product Details
HQ
Australia
Products
Canva design and collaboration platform
Product description
Cloud design, collaboration and content creation service for teams and enterprises.
What data is being processed?
Customer account data, user profile data, uploaded content and any personal data included in designs, brand assets, comments or related service content.
Document Details
Date of DPA
30 Oct 2025
Additional date information
DPA dated 30 October 2025 as stated at the foot of the document. The Addendum is incorporated into the Agreement (Canva's Terms of Use or other applicable agreement). (Introduction; last updated date at foot of document)
What jurisdictions are covered?
EU GDPR, UK GDPR (incorporated into UK domestic law via the EU Withdrawal Act 2018), Swiss Federal Data Protection Act, and applicable EU national laws are expressly named under 'European Privacy Laws'. US State Privacy Laws (including CCPA) and Brazilian data protection authority are also referenced for transfer safeguard purposes. (Sections 1, 2.2, 2.3)
Is the DPA incorporated into service or customer agreements?
Link
Location & Transfers
Where is data held or processed?
Not explicitly stated The DPA does not explicitly name the countries where Customer Personal Data is stored or processed. Processing locations depend on the Canva entity under the applicable Agreement and on engaged sub-processors; full sub-processor details are published at canva.com/policies/subprocessors. (Section 2.7, Annex 3)
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
Canva must implement appropriate technical and organisational measures (TOMs) to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. TOMs are described in full in Canva's Statement of Technical and Organisational Measures published at canva.com/policies/technical-and-organisational-measures/. TOMs may be updated provided the overall security level is not degraded. (Section 2.6, Annex 2)
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
Upon becoming aware of a Personal Data Breach, Canva must inform Customer without undue delay and provide timely information and cooperation needed to fulfil breach reporting obligations under applicable privacy laws. Canva must take measures to remedy or mitigate effects and keep Customer informed of material developments. No specific notice period (e.g. 72 hours) is stated. Customer must obtain Canva's prior approval before publishing any breach notice identifying Canva, unless compelled by law. (Section 2.10)
What happens to the data on termination?
Upon termination or expiry of the Agreement, Canva shall destroy all Customer Personal Data in its possession or control. There is no express option to return data to the Customer. Retention is permitted only to the extent necessary for the Permitted Purpose or required by applicable law; the same standard of protection applies until deletion is complete. (Section 2.11)