Is REDCap GDPR compliant? What universities and researchers should check
REDCap is the research data capture platform developed at Vanderbilt University and licensed free of charge to non-profit institutions through the REDCap Consortium. Unlike most tools on this site, REDCap is normally installed and run by the university itself. This page explains what that means for the GDPR question, what the consortium documents publicly, and what a DPO or research office should check.
Short answer
REDCap is not a cloud service you sign up to. A non-profit institution signs a licence with Vanderbilt University and then installs, hosts and supports REDCap on its own infrastructure. Vanderbilt says it has no access to other institutions' REDCap systems. The GDPR position therefore depends almost entirely on your own installation: where the server runs, who administers it, how access is controlled, which optional integrations are switched on, and what your procedures say. That gives a university a high degree of control, and it also means the university carries the hosting and security responsibility that a vendor would carry for a SaaS tool.
Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers research surveys with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data
What the REDCap Consortium documents publicly
This summary reflects the consortium's pages at projectredcap.org and a Vanderbilt news article, read on 7 October 2026. Numbers in brackets refer to the sources at the end of the page.
| Topic | What the documentation states | Source |
|---|---|---|
| Who develops it | Documented REDCap was created at Vanderbilt University in 2004, and the site describes it as "powered by Vanderbilt"; the FAQ says the consortium handles all software development internally. The REDCap Consortium launched in 2006 as a community of non-profit partner organisations. The site lists over 8,400 institutions in 167 countries. | [1] [3] |
| Licence and cost | Documented A licence agreement between the non-profit institution and Vanderbilt is required. The FAQ says the licence, codebase and consortium support cost nothing for non-profit organisations. REDCap is not open source, because the licence is required to obtain the code. | [2] [3] |
| Where data is stored | Institution-dependent Each partner installs and maintains its own system. Licences are issued only to non-profits with enough internal IT infrastructure to self-host. The storage location is whatever the institution chooses for its servers. | [2] [3] |
| Vendor access to data | Documented The FAQ says each REDCap system is "independently maintained and supported" and that Vanderbilt staff have "no access to, familiarity with, or purview over" other REDCap systems worldwide. | [3] |
| Data processing agreement | Not applicable in the usual model In the self-hosted model Vanderbilt is a software licensor, not a host. A data processing agreement with Vanderbilt for self-hosted installations was not found in public documentation (checked 7 October 2026). The published licence terms state that no training, support, hosting or other services from Vanderbilt are provided under the agreement. | [2] [3] [11] |
| Hosted alternatives | Documented Vanderbilt's own system, redcap.vumc.org, can be used for a monthly fee, but only by groups in the United States aligned with the VUMC mission. REDCap Cloud is a separate commercial service for industry-sponsored trials needing 21 CFR Part 11 validation, outside the consortium licence. The licence terms also allow the institution to install REDCap on cloud servers from a hosting company it has hired, provided that company has no access to the software. | [2] [3] [11] |
| Support model | Documented Partners must provide their own internal IT support. The joining page says contracting for support, even with unpaid volunteers, is not permitted, and technical staff must be the institution's own employees. | [2] |
| Compliance statements | Institution-dependent The FAQ says no software alone is truly compliant with any standard; the environment in which it is installed, including server settings, backups, password controls and study team procedures, is what can be called compliant. It says REDCap has been used at sites meeting HIPAA, Part 11, FISMA and international rules such as the GDPR. | [3] [4] |
| AI features | Documented Three optional AI features (writing help, summaries of open-ended responses, and translation of forms) were released to the consortium in January 2025. They are off by default, can be activated only by each institution's REDCap administrators, and Vanderbilt advises connecting them to the institution's own managed AI service. | [5] |
Credit where it is due: the consortium is unusually clear that compliance is a property of the installation rather than the software, and it publishes that position in plain terms. For research data, the self-hosted model also means no third-party vendor sees participant data unless the institution chooses one, and features such as audit trails, export to statistics packages and branching logic are part of the standard software [4].
What this means for a university
Validemic's analysis
You are the host, so you carry the host's duties. With most cloud tools, a university relies on the vendor's data processing agreement, certifications and subprocessor list. With REDCap, those questions turn inward. Article 32 GDPR requires the controller to implement appropriate technical and organisational security measures [6], and for a self-hosted REDCap that means the university's own server hardening, patching, backups, encryption, logging and access reviews. Article 24 makes the controller responsible for being able to demonstrate compliance [6]. A short internal "REDCap service description" that records these measures is often the most useful document a DPO can have.
Roles are simpler, but check the edges. When the university runs REDCap for its own researchers, the university is normally the controller for study data and no processor agreement with Vanderbilt is needed. Processor relationships appear when the server runs on infrastructure provided by someone else, for example a public cloud or a national research network, and an Article 28 contract is then required with that provider [6]. Multi-site studies add another layer: when several institutions decide purposes and means together, they may be joint controllers under Article 26 and need an arrangement setting out who does what [6] [7].
Your installation decides the transfer picture. Because the institution chooses where servers run, a REDCap hosted on EU infrastructure can avoid international transfers entirely. Transfers can reappear through choices the institution makes, such as an external email relay, an SMS service for survey invitations, or a cloud AI service connected to the optional AI features. The FAQ does not list such integrations, so ask your REDCap administrators which are enabled.
Typical REDCap data is sensitive. REDCap is widely used for clinical and health research. Health data is special category data under Article 9 GDPR [6], and large-scale processing of it is one of the cases where Article 35 says a data protection impact assessment is required [6]. Many universities can write one DPIA for the REDCap service and then let individual studies refer to it, adding only study-specific risks. Our DPIA screening tool gives a first view.
Version and patch discipline matters. Since each partner maintains its own system [3], how quickly security updates are applied is an internal decision. A DPO should know who owns patching and how long the institution takes to install new releases.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask before approving REDCap for a study
For REDCap, most of these questions go to your own REDCap administrators and research office rather than to Vanderbilt.
- Where do our REDCap servers and backups physically run, and is any third party (cloud provider, data centre, research network) involved under a data processing agreement?
- Who in our organisation administers REDCap, and how are security updates and new versions tested and applied?
- How are user accounts created and removed? Is login through institutional single sign-on with multi-factor authentication?
- Which optional integrations are enabled: outgoing email, SMS, mobile app, external modules, AI features? Does any of them send data outside the EU/EEA?
- If the AI features are switched on, which AI service are they connected to, and is it covered by our own contracts and DPIA?
- Is there a service-level DPIA for REDCap that studies can refer to, and when was it last reviewed?
- For multi-site studies, who is the controller at each site, and is a joint controller or data sharing arrangement in place?
- What retention and deletion rules apply when a project is closed, and who carries them out?
The EU AI Act angle
The optional AI features described by Vanderbilt draft text, translate forms and summarise free-text responses, with a person reviewing the output before accepting it [5]. These are general research-support tasks and do not match the education uses listed as high-risk in Annex III, such as evaluating learning outcomes or monitoring students during tests [8]. The obligation that applies now is Article 4: a university deploying AI systems must take measures to support the AI literacy of staff using them [9]. If your institution enables the AI module, the provider of the underlying model and the institution's own contract with it become part of that assessment. High-risk obligations for Annex III systems apply from 2 December 2027 under the amended Article 113 [10].
Sources
- About REDCap, projectredcap.org, retrieved 7 October 2026
- Join & Get REDCap, projectredcap.org, retrieved 7 October 2026
- REDCap FAQ, projectredcap.org, retrieved 7 October 2026
- REDCap software features, projectredcap.org, retrieved 7 October 2026
- REDCap adds generative AI tools, with human oversight built in, Vanderbilt Health News, 7 September 2026, retrieved 7 October 2026
- Regulation (EU) 2016/679 (GDPR), Articles 9, 24, 26, 28, 32 and 35, text read from the Publications Office copy, retrieved 7 October 2026
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR, European Data Protection Board, retrieved 7 October 2026
- AI Act Annex III, AI Act Service Desk (consolidated text of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744), retrieved 7 October 2026
- AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026
- REDCap License Terms, projectredcap.org, retrieved 7 October 2026
About this page
We read the REDCap Consortium's about, joining, FAQ, licence terms and software pages, a Vanderbilt news article on REDCap's AI features, and the relevant EU legal texts and EDPB guidance on 7 October 2026. The licence terms are reproduced on the consortium's website; we read that published version, not any agreement signed by a particular institution. Statements about REDCap come from those pages; our own interpretation is labelled as Validemic's analysis. "Not found" means we could not find the information in public documentation; it does not mean it does not exist.
This page is not legal advice and does not say whether any particular REDCap installation complies with the GDPR, which depends on how it is hosted, configured and used. If you spot an error or the consortium has updated a document, please contact us and we will correct it.
Frequently asked questions
Is REDCap GDPR compliant?
No software is GDPR compliant on its own, and the REDCap FAQ makes the same point: it is the environment into which REDCap is installed that can be called compliant. Because each consortium partner installs and runs its own system, the answer depends on your institution's hosting, configuration, access control and procedures.
Does Vanderbilt have access to data in our REDCap?
The REDCap FAQ says each REDCap system is independently maintained and that Vanderbilt staff have no access to, familiarity with, or purview over the other REDCap systems worldwide. Vanderbilt runs its own system, redcap.vumc.org, which it offers only to certain groups in the United States.
Do we need a data processing agreement with Vanderbilt for REDCap?
In the usual self-hosted model, the university licenses the software and runs it on its own infrastructure, so Vanderbilt does not process the research data. A data processing agreement is then needed with any party that hosts or supports the installation for you, such as a cloud provider. Ask your DPO to confirm the roles for your set-up.
Can a company host REDCap for our university?
The consortium's joining page says licences go to non-profit organisations, that technical support must come from the organisation's own staff, and that contracting with third parties for support is not permitted. The published licence terms do allow installation on cloud servers from a hosting company the institution has hired, provided that company has no access to the software. A separate commercial service, REDCap Cloud, exists outside the consortium for industry-sponsored trials.
Does REDCap use AI?
Vanderbilt announced optional AI features for text generation, translation and summarising free-text responses. They are off by default, can be activated only by each institution's REDCap administrators, and Vanderbilt advises connecting them to the institution's own managed AI service.