Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Canva is an online graphic design platform operated by Canva Pty Ltd in Australia. On third party websites Canva appears as design embeds, the Canva Button or shared design links that load code, fonts and assets from Canva servers, set cookies and process usage and account data. Because these embeds are not strictly necessary to deliver the page and they read and write identifiers on the visitor device, Canva performs non essential tracking that must load only after the visitor has given consent.
Canva is an online graphic design platform operated by Canva Pty Ltd, a company based in Sydney, Australia, that runs global infrastructure. On other organisations websites Canva usually appears in three ways: as a design embed shown inside an iframe, as the Canva Button that opens the Canva editor, and as shared design links that open a hosted view. In each case the browser loads code, fonts and assets from Canva servers such as canva.com and static.canva.com and renders them inside or alongside the host page.
When a Canva element loads, Canva sets cookies including a persistent identifier such as CID that recognises the browser across pages and visits, along with security and session cookies. It processes usage data such as which design was viewed, interactions with the embed and the referring page, and it can read and write entries in browser local storage. For visitors who are signed in to a Canva account, the activity can be associated with that account and combined with Canva own analytics and, where enabled, advertising cookies.
The identifiers and usage data that Canva processes are personal data under the GDPR, because they relate to an identifiable visitor. Storing and reading cookies and local storage on the visitor device also falls within Article 5(3) of the ePrivacy Directive, which the CNIL in France, the German authorities under the TDDDG and the AEPD in Spain all enforce as a strict prior consent obligation for non essential trackers. Because a Canva embed is not needed to deliver the core content of the host page, it does not qualify for the strictly necessary exemption.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Consent is required before the Canva embed, button or shared link loads, because it sets non essential cookies and processes usage data. That consent must be freely given, specific, informed and unambiguous, and refusing must be as easy as accepting. Until the visitor accepts, the Canva element should not load, no request should be sent to Canva servers and no cookies or local storage entries should be written. A static preview image with a click to load control is a common way to hold the embed back.
Canva Pty Ltd is established in Australia, which is not covered by a European Commission adequacy decision, and it relies on United States based subprocessors. European visitor data is therefore transferred outside the European Economic Area to both Australia and the United States. Such transfers require the EU Standard Contractual Clauses 2021/914 within the Canva Data Processing Addendum and a documented Transfer Impact Assessment that considers third country surveillance law, in line with the Schrems II ruling and the guidance of the European Data Protection Board.
Gate every Canva element behind your consent management platform so it fires only after the relevant category is accepted. Provide clear information about Canva in your cookie policy, including the identifiers it sets and their lifetime. Sign the Canva Data Processing Addendum, complete a Transfer Impact Assessment for the Australia and United States transfers and apply the shortest workable retention. Where a design can be exported as a static image or PDF and hosted on your own domain, prefer that option on pages where an interactive embed is not necessary.
Websites using Canva must obtain user consent under GDPR regulations.
DPIA considerations
A Data Protection Impact Assessment is advisable when Canva embeds are used across many pages or combined with account level tracking. Document the usage data captured by the embed, the persistent Canva identifier stored in cookies and local storage, the association with a Canva account for signed in users, the transfer of data to Australia and the United States and the retention applied to the records. Configure the embed so that it loads only after consent and avoid Canva elements on pages where they are not necessary.
Sample consent text
We use Canva, a design service operated by Canva Pty Ltd (Australia), to show you embedded designs. Canva loads content from its own servers, records how you interact with it and stores identifiers in cookies and local storage on your device. This data may be transferred to Australia and the United States under the EU Standard Contractual Clauses. Canva will only load if you click Accept.
Third-party domains contacted
canva.comwww.canva.comstatic.canva.comcanva-user-content.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| CID | HTTP cookie (first party to canva.com) | 1 year | Stores a persistent Canva identifier for the browser so that Canva can recognise the same device across pages and visits and attribute usage to a single profile, whether or not the visitor is signed in. |
| CAZ | HTTP cookie (first party to canva.com) | Session | Security and request validation cookie used by Canva to protect the session and mitigate cross site request forgery when the embed or editor communicates with Canva servers. |
| CDI | HTTP cookie (first party to canva.com) | 1 year | Holds a device level identifier that Canva uses to distinguish browsers and support analytics and abuse prevention across the service. |
| canva embed state | localStorage | Persistent (until cleared) | Stores state for the embedded design or button, such as view preferences and buffered interaction data, so the Canva element can render and function inside the host page. |
Canva collects user analytics data — you legally need a consent banner. Try FlowConsent free.
Canva sets a persistent identifier such as CID that recognises the browser across pages and visits, along with security and session cookies, and it can read and write entries in browser local storage to hold state for the embed. For signed in users additional account and, where enabled, advertising cookies may be set.
Yes. A Canva embed, button or shared link sets non essential cookies and processes usage data, so under the ePrivacy rules you must obtain prior consent before it loads. The Canva element should stay blocked until the visitor accepts, with no request sent to Canva servers in the meantime.
The only valid legal basis is consent under Article 6(1)(a) GDPR, combined with the prior consent requirement of Article 5(3) of the ePrivacy Directive. Legitimate interest cannot be used, because the embed cookies and usage tracking are not strictly necessary to deliver the page.
Yes. Canva Pty Ltd is based in Australia, which has no EU adequacy decision, and it relies on United States based subprocessors, so European visitor data is transferred to both countries. You need the EU Standard Contractual Clauses 2021/914 in the Canva Data Processing Addendum and a Transfer Impact Assessment to cover these transfers.
A Data Protection Impact Assessment is recommended when Canva embeds appear across many pages or are combined with account level tracking. Assess the usage data collected, the persistent identifier stored on the device, the link to a Canva account and the transfers to Australia and the United States.
Load every Canva element only through your consent management platform after the relevant category is accepted, describe Canva in your cookie policy, sign the Data Processing Addendum and complete a Transfer Impact Assessment. Where possible, use a static export hosted on your own domain on pages that do not need an interactive embed.
Alternatives for embedded design and graphics include Figma, Adobe Express, Visme and PicMonkey, and for static delivery you can export a design as an image or PDF and host it yourself. Each hosted option raises similar consent, cookie and transfer questions, so check the hosting location and data processing terms before assuming any is lighter on privacy.
Add a dedicated entry that names Canva Pty Ltd as the provider, lists the identifiers such as CID with their lifetimes, explains the usage data collected by the embed, and discloses the transfers to Australia and the United States and their safeguard under the Standard Contractual Clauses. Keep the entry in step with your consent categories.