Is Covidence GDPR compliant? What universities should check
Covidence is the systematic review platform behind many Cochrane and university reviews, and a large number of European universities hold institutional licences. This page sets out what Covidence publicly documents about hosting, contracts, transfers, AI features and security, and what that means for a university.
Short answer
Covidence is run by Veritas Health Innovation Ltd in Melbourne, Australia, and owned by the not-for-profit Future Evidence Foundation. Its privacy policy describes Covidence as a GDPR controller relying mainly on consent, and says data may be stored outside the user's country without naming a hosting provider or region. The terms give Covidence a perpetual licence to use non-personal Review Data, including for machine learning. Its AI features are documented in unusual depth, and it says LLM providers do not train on or store uploaded PDFs. Covidence reports SOC 2 Type I, with Type II and ISO 27001 audits underway. For a university, the licence contract and transfer terms matter more than the tool itself.
Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers systematic review screening with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data
What Covidence documents publicly
Everything in this table comes from Covidence's own pages, read on 7 October 2026. Numbers in brackets refer to the sources at the end of the page.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and establishment | Veritas Health Innovation Ltd (ABN 41 600 366 274), Level 5, 485 Latrobe Street, Melbourne. The website footer says Covidence is owned by the Future Evidence Foundation, a non-profit. The terms (last updated August 2025) are governed by the law of Victoria, Australia. The privacy policy refers EU residents to an EU representative but gives no separate name or address. | [1] [2] |
| Where data is stored | Not found publicly The privacy policy says data "may be stored outside of your country of origin" and that data hosting providers are "located in various countries". The hosting provider and region were not found (checked 7 October 2026). | [1] |
| Controller role and DPA | Partly documented Covidence describes itself as a data controller and relies on consent as its lawful basis. It also refers to clients "where we act as a data processor" and to "customer data agreements". A standard customer DPA was not published (checked 7 October 2026). | [1] [3] |
| Subprocessors | Categories only The policy lists categories: web hosts, email, CRM and analytics providers, mailing houses, market research organisations and consultants. A named subprocessor list was not found (checked 7 October 2026). | [1] |
| International transfers | Stated in general terms For transfers outside the EU or EFTA, Covidence says it ensures protection "based on the adequacy of the receiving country's data protection laws". Australia does not appear on the European Commission's list of adequate countries. Standard Contractual Clauses were not mentioned in the policy. | [1] [4] |
| Use of review content | Licence granted Users keep ownership, but grant "a perpetual, royalty-free and worldwide license" to use Review Data (not personal information) for non-commercial purposes, including new data sets and "the development of machine learning models". | [2] |
| AI features | Documented Relevance sorting (active learning on the team's own decisions), RCT tagging and removal (EPPI-Centre classifier, recall above 99.5% per Covidence), and LLM extraction and intervention suggestions from PDFs. Extraction suggestions are on by default in review settings. Covidence says its LLMs "do not train on, store, or distribute" uploaded PDFs. The LLM provider is not named. | [5] [6] [7] |
| Retention and deletion | Trial Review Data is deleted seven days after the trial ends. For institutional and paid accounts, Review Data is retained indefinitely unless users delete it, which removes it permanently from the database. Personal data is kept "as long as it is needed". | [1] [2] |
| Security and certifications | In progress Covidence says it holds SOC 2 Type I, with SOC 2 Type II and ISO 27001 audits underway and certification expected in late 2026. The privacy policy describes industry-standard encryption for storage and transfer and a 72-hour breach reporting target for EU users. | [1] [3] |
| Institution controls | Plan-dependent Organisational subscriptions include unlimited reviews and users, and administrators see and manage all institutional reviews and authors. Individual plans cost USD 339 a year for one review and USD 907 for up to three. | [8] |
Covidence deserves real credit for how it handles AI. Each feature has public documentation of its model, training basis, evaluation results, known limitations and suggested reporting text aligned with the RAISE guidance, and Covidence says features that do not meet its decision matrix are not released [3] [5]. Its blog also gives procurement teams direct answers on training, storage and certification [3].
What this means for a university
Validemic's analysisMostly published literature, with exceptions. Screening records are bibliographic data about published studies. The personal data is mainly reviewers' accounts and decisions, plus author names. It becomes more sensitive when teams upload unpublished trial reports, correspondence with study authors or individual participant data, which Covidence can hold as Review Data.
Transfers need a documented basis. The policy's reliance on "adequacy of the receiving country's data protection laws" does not by itself explain how transfers to Australia, which has no EU adequacy decision [4], are covered. Under Chapter V GDPR [9] a university needs to know whether its licence includes Standard Contractual Clauses or another safeguard, and where hosting actually sits. This is the first question to settle.
Consent as lawful basis. Covidence relies mainly on consent for its own processing. When staff use Covidence under an institutional licence as part of their job, consent is a weak basis in an employment setting, and a processor arrangement under Article 28 [9] for institutional content is usually easier to defend.
The Review Data licence. The perpetual licence excludes personal information and is limited to non-commercial purposes, which fits Covidence's not-for-profit mission. Even so, research teams under confidentiality obligations to funders, industry partners or journals should know that non-personal review content can be reused, including for machine learning. The terms say the licence also covers Review Data that Covidence has removed from its database, and they do not say whether it ends when users delete their own reviews.
LLM extraction is on by default. Covidence's commitments on PDFs are clear, but the provider is not named. A university should know who processes full texts and where, especially for unpublished documents.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask Covidence before approving it
- Can you send the data processing terms used for European institutional licences, and does Covidence act as our processor for review content?
- Which hosting provider and region store our reviews, PDFs and backups?
- Which transfer mechanism covers EU personal data sent to Australia and to any other country?
- Can we have a named list of subprocessors, including the LLM provider used for extraction suggestions, and notice of changes?
- Who is your EU representative under Article 27 GDPR, and how can our DPO reach them?
- Can the Review Data licence for machine learning be excluded in our institutional agreement?
- Can administrators turn off extraction suggestions for all reviews, rather than review by review?
- When will the SOC 2 Type II report and ISO 27001 certificate be available, and can we see the SOC 2 Type I report now?
The EU AI Act angle
Screening and extracting data for a systematic review is research, not one of the education uses listed as high-risk in Annex III of the AI Act, Regulation (EU) 2024/1689 [10]. The obligation that applies to a university today is AI literacy: Article 4, as amended by Regulation (EU) 2026/1744, requires deployers to take measures to support the AI literacy of staff using AI systems [11]. Covidence's feature documentation and reporting templates are well suited to this, because they explain what each model does and where it can fail. Annex III obligations apply from 2 December 2027 [12], which matters only if review tools were used to assess students, for example in a graded review assignment.
Sources
- Covidence Privacy Policy, no date shown, retrieved 7 October 2026
- Covidence Terms of Use, last updated August 2025, retrieved 7 October 2026
- How to justify AI tools to institutions, Covidence, published 7 July 2026, retrieved 7 October 2026
- Adequacy decisions, European Commission, retrieved 7 October 2026
- Overview of all Automation (AI) features available in Covidence, Covidence Knowledge Base, updated 11 February 2026, retrieved 7 October 2026
- AI feature: Extraction suggestions, Covidence Knowledge Base, updated 28 September 2026, retrieved 7 October 2026
- Data privacy in Covidence: a guide to PDFs and LLM usage, Covidence Knowledge Base, updated 27 August 2026, retrieved 7 October 2026
- Covidence Pricing, retrieved 7 October 2026
- Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 27, 28 and 44 to 49, retrieved 7 October 2026
- AI Act Annex III: High-risk AI systems, AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 4: AI literacy (as amended), AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 113: Entry into force and application (as amended), AI Act Service Desk, retrieved 7 October 2026
About this page
We read Covidence's privacy policy, terms, pricing page, blog and knowledge base on 7 October 2026, together with the European Commission's adequacy page. Covidence is an Australian company, so the EU-US Data Privacy Framework does not apply to it. "Not found" means we could not find the information in public documentation; it does not mean the vendor lacks it. Covidence's institutional agreements may contain terms that are not public, so confirm the current position with Covidence before relying on this page.
This page describes public documentation and gives our own analysis. It is not legal advice and it is not a statement that the tool is or is not GDPR compliant, which depends on your contract, configuration and use. If you work for Covidence and see an error, please contact us and we will correct it.
Frequently asked questions
Is Covidence GDPR compliant?
No tool is GDPR compliant on its own. Covidence's privacy policy says it processes personal data in line with the GDPR and the Australian Privacy Principles and describes itself as a data controller. Whether a university's use complies depends on its licence agreement, any data processing terms it signs and what reviewers upload.
Where is Covidence data stored?
Covidence's privacy policy says data may be stored outside the user's country of origin and that hosting and IT providers are located in various countries. The hosting provider and storage region were not found in public documentation (checked 7 October 2026), so ask Covidence directly.
Does Covidence use AI on my review?
Covidence offers relevance sorting trained on the review team's own screening decisions, an RCT classifier developed by the EPPI-Centre, and LLM-based extraction suggestions from full-text PDFs. Extraction suggestions are enabled by default in review settings. Covidence says the LLMs it uses do not train on, store or distribute user-provided full-text PDFs.
Can Covidence reuse our review data?
Covidence's terms grant it a perpetual, worldwide licence to use Review Data, excluding personal information, for non-commercial purposes, including building new data sets and developing machine learning models. Personal information is governed by the privacy policy instead. Universities should read this clause before uploading unpublished work.
Does Covidence have SOC 2 or ISO 27001?
In a July 2026 article Covidence said it is SOC 2 Type I certified, and that external audits for SOC 2 Type II and ISO 27001 were underway, with certification expected in late 2026.