Is Canva Magic Studio safe for work?
Medium risk · 25Canva Pty Ltd · Design · facts partly unverified, check sources
Canva Magic Studio is medium-risk for default at-work use (25/100): it trains on your data unless you opt out, and holds SOC 2 Type II.
25
Medium risk
Watch out: There is a genuine discrepancy between Canva's stated opt-in default and third-party reports of training toggles being on by default for Free/Pro accounts, so an at-work individual user should explicitly verify and disable both 'usage' and 'content' AI-training toggles in privacy settings.
Data and compliance facts
- Trains on consumer-tier data
- Opt-out
- Trains on business-tier data
- No
- Training opt-out available
- Yes
- SOC 2 Type II
- Yes
- ISO 27001
- Yes
- ISO 42001 (AI management)
- Unverified
- GDPR Data Processing Addendum
- Yes
- HIPAA BAA
- Unverified
- EU data residency
- Unverified
- SSO / SAML
- Yes
- Data retention
- Designs/content retained while the account is active; deletion follows standard account-deletion flow. Specific quantified retention windows not separately published for Magic Studio.
- Safer tier
- Canva Enterprise (also Teams/Business)
Why it scores 25 out of 100
- +14Trains on your data unless you opt out. Training is on by default on the consumer tier; you must find and toggle the opt-out.
- +6No EU data residency. Data cannot be guaranteed to stay in the EU.
- +5No HIPAA BAA. No Business Associate Agreement, so do not use it with protected health information.