Help Center

GDPR in Canto – User Rights and Admin Actions

  • Updated

    ~ minute read

This article explains how GDPR data subject rights apply within Canto and what Administrators and users can do to exercise them.

For Canto's full legal documentation, see the Privacy Policy and the Trust Center.


What personal data does Canto store about users?

Canto stores the following data for each user account:

  • Inventory data (e.g. names, addresses) 

  • Contact data (e.g. e-mail, telephone numbers) 

  • Content data (e.g. text input, photographs, videos) 

  • Meta/communication data (e.g. device information, IP addresses) 


Your rights under GDPR

As a data subject, you have the following rights. The table below explains what each right means in the context of Canto.

Your right What it means in Canto
Right of access You can view the personal data Canto holds about your user account at any time via your profile page.
Right to rectification You can correct your name directly. Your Administrator can update your email address.
Right to data portability Administrators can export library metadata as a CSV file.
Right to erasure Deleting your user account removes your personal data from Canto. Assets you uploaded are anonymized (attributed to "Removed User"). See the deletion section below.
Right to object / restrict Contact privacy@canto.com to submit an objection or restriction request. Canto will respond in accordance with GDPR.
Right to complain You have the right to lodge a complaint with your national data protection supervisory authority.

If you are an Administrator

Administrators are responsible for managing user accounts and data within their Canto tenant. The following guidance covers the actions Administrators most commonly need to take in response to GDPR data subject requests.


How can a user find out what Canto holds about them?

Direct the user to their profile page. They can access it by clicking their profile icon in the top-right corner of the Canto interface and selecting Edit Profile. This page displays the personal data Canto has on record for their account, including their name, email address, and any optional profile fields they have completed.


How can a user change their personal data?

Users can update their name and optional profile fields directly on their Edit Profile page. Email addresses can only be changed by an Administrator. To update a user's email address:

  1. Go to Settings → Users & Groups → Users.
  2. Find the user in the list and click the pen icon to edit.
  3. Update the Email address field in the overlay that appears.
  4. Click Save.

See Edit Users for full instructions.

Please note:

Only Administrators can change a user's email address. Users cannot change it themselves.


How can a user export their personal data or library metadata?

For library metadata (asset metadata across the library, folder, or album), use the Metadata Export function:

  1. Go to Settings → Links & Connections → Metadata Export.
  2. Enter a name for the file and click Export as CSV.
  3. Canto will generate the file and send you an email with a download link when ready.

See How to: Export Metadata for full instructions, including how to export a specific folder or album.

Users can also access and download their own assets directly from the Main Library. Individual assets can be downloaded via the download icon on any thumbnail or preview page; multiple assets can be selected and downloaded as a ZIP archive. See Download Files and Advanced Options for Download for full instructions.


How do I delete a user account to fulfill a deletion request?

To permanently remove a user's personal data from Canto, you must delete their user account. Once deleted, the user's name, email address, and profile data are permanently removed from Canto's records.

Assets the user uploaded before deletion are not removed—they remain in the library but are anonymized: the attribution changes to "Removed User" rather than the user's name. Any shared Collections created by the user are deleted at the same time as the account.

To delete a user:

  1. Go to Settings → Users & Groups → Users.
  2. Find the user in the list and click the trash icon to the right of their name.
  3. Confirm deletion when prompted.

See Delete Users for full instructions.

Please note:

Deletion is immediate and cannot be undone. If the user should be temporarily deactivated rather than deleted, edit their account and change their expiration date instead.


How do I delete assets uploaded by a user?

If a data subject requests deletion of specific assets they uploaded, use the Filter panel to locate them:

  1. Open Main Library and display the Filter panel by clicking the filter icon in the top right.
  2. Expand the Uploaded By section and select the relevant user. The gallery will update to show only their assets.
  3. Select the assets and delete them. Deleted assets move to Trash Bin and are held for 30 days before permanent deletion.
  4. To permanently delete them immediately, open Trash Bin (at the bottom of the Folder Tree), locate the assets using the Deleted By filter if needed, then click the permanent delete icon in the Actions column.

See How to: Filters for full instructions on the Filter panel, and How to: Recover assets, folders, and albums from the Trash Bin for instructions on managing Trash Bin.


How do I permanently close a Canto tenant?

To close your organization's Canto tenant entirely—for example, on contract termination—contact Canto Customer Support or your Account Manager to initiate the cancellation process. Data deletion timelines upon contract termination are set out in your Data Processing Agreement. Contact your Customer Success Manager for details.


If you are a user

The following guidance covers how individual Canto users can exercise their own GDPR rights without needing to contact an Administrator.


How can I see the personal data Canto holds about me?

Click your profile icon in the top-right corner of the Canto interface and select Edit Profile. This page shows the personal data associated with your account, including your name, email address, and any profile fields you have filled in.


How can I change my personal data in Canto?

You can update your name and optional profile fields directly on your Edit Profile page. To change your email address, contact your Canto Administrator – email addresses can only be updated by an Administrator.


How can I request a copy of my personal data?

You can access and download your own assets directly from the Main Library at any time. To download individual assets, click the download icon on any thumbnail or in the preview. To download multiple assets at once, select them and click the download icon in the top right; Canto will package them into a ZIP file. See Download Files for full instructions.


How can I have my personal data permanently removed?

Personal data is removed when your user account is deleted. To request deletion, ask your Canto Administrator to delete your account from Settings → Users & Groups → Users.

Once your account is deleted, your name, email address, and profile data are permanently removed. Assets you uploaded before deletion remain in the library but are anonymized — they will be attributed to "Removed User" rather than your name. Shared Collections you created are deleted along with your account.

Please note:

Account deletion is permanent and cannot be undone. If you only want to remove specific assets you uploaded, ask your Administrator to use the Uploaded By filter in the Filter panel to locate and delete them. Depending on your user role, you may not have permission to delete assets yourself.


What deletion means in Canto

Understanding how deletion works in Canto is important for Administrators managing GDPR deletion requests.

  • User account deletion: Permanent and immediate. Personal data (name, email, profile fields) is removed from Canto's records. This action cannot be undone.
  • Asset deletion: Assets deleted from Main Library move to Trash Bin and are held for 30 days. They can be recovered during this period. After 30 days, they are permanently and automatically deleted. Administrators can also permanently delete items from Trash Bin at any time before the 30-day period expires.
  • Backup retention: Canto retains backups for 30 days after deletion or contract termination. After this period, backups are permanently deleted.
  • Contract termination: All customer data is deleted from Canto's systems 30 days after the contract end date.

Please note:

It is the customer's responsibility to secure their data before account or contract termination. Canto cannot recover data after permanent deletion.

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request