Canva
Technology & SaaS
Generic security commitment with basic measures mentioned (password verification) but lacks specific encryption details, certifications, or breach notification procedures, includes appropriate disclaimers about security limitations. Overall: Good with minor gaps.
10 dimensions · 93 claims · assessed 11 May 2026 · methodology · source policy ↗
Score Breakdown
Transparency
Excellent transparency
8.17/108.17/10
Transparency
Excellent transparency
Transparency & Clarity
9/10Comprehensive transparency with clear scope, plain language summaries, detailed section navigation, specific contact information including regional representatives, current version dating, and policy archives availability.
Purpose Limitation & Use
7/10Clear primary purposes stated with detailed secondary uses disclosed including AI training and machine learning, marketing opt-out available, and consent mechanisms for new purposes, though purpose limitation commitment could be more explicit.
Policy Maintenance & Accountability
8/10Strong maintenance framework with current update date, version archives, material change notifications via multiple methods, specific privacy contact details, regional representatives, and compliance certifications, though review frequency could be more specific.
Data Protection
Good with minor gaps
7.11/107.11/10
Data Protection
Good with minor gaps
Data Collection Disclosure
8/10Detailed enumeration of specific data types collected through multiple methods (direct, automatic, third-party, cookies, device identifiers, location) with clear purposes and collection necessity disclosures, though some sensitive data handling could be more explicit.
Third-Party Sharing & Disclosure
8/10Strong disclosure with named third parties (Facebook, Google, LiveRamp, etc.), specific categories of service providers, clear purposes, and contractual obligations mentioned, plus detailed Canva Education third-party processor list with deletion commitments.
Data Security
4/10Generic security commitment with basic measures mentioned (password verification) but lacks specific encryption details, certifications, or breach notification procedures, includes appropriate disclaimers about security limitations.
Cross-Border Data Flows
8/10Comprehensive cross-border disclosure with specific countries named, Data Privacy Framework compliance, EU Model Clauses for transfers, adequacy assessments acknowledged, and detailed third-party processor requirements with appropriate safeguards.
Your Rights
Good with minor gaps
7.8/107.8/10
Your Rights
Good with minor gaps
Consumer Rights & Control
8/10Comprehensive rights coverage including access, correction, deletion, marketing opt-out, consent withdrawal, privacy settings control, AI training opt-out, and complaint escalation to data protection authorities with multiple contact methods provided.
Automated Decision-Making
7/10Good disclosure of AI/ML use with specific examples (image analysis, audio translation, personalization), opt-out available for AI training, and automated profiling disclosed, but lacks human review rights and detailed algorithmic transparency.
Children's Data
9/10Excellent child protection with clear age thresholds, service restrictions, parental consent mechanisms, COPPA/FERPA certification, specific Canva Education protections, advertising restrictions, and detailed deletion policies for student accounts.
Sector Comparison
Technology & SaaS comparison