Guide and template

HECVAT for European universities: what it covers and a GDPR-ready alternative

The HECVAT is the questionnaire many software vendors to higher education already have on file. This guide explains what the current version contains, why European universities usually need more on GDPR, international transfers and the EU AI Act, and offers an independent European questionnaire you can download and send to vendors.

Published 7 October 2026 · Sources checked 7 October 2026

The short version

Contents

  1. What the HECVAT is
  2. Versions: Full, Lite, On-Premise and HECVAT 4
  3. Licence and sharing
  4. Where European universities need more
  5. The European vendor questionnaire
  6. Using both together
  7. Reading the answers: red flags
  8. Sources
  9. About this page

1. What the HECVAT is

EDUCAUSE describes the HECVAT as a tool to help college and university professionals measure vendor risk. It was created by leaders in higher education in collaboration with EDUCAUSE, Internet2 and REN-ISAC, and it is a questionnaire that vendors complete to describe their cybersecurity, privacy, IT accessibility and compliance practices in one place. EDUCAUSE Review notes that the HECVAT has existed since 2016.

The questionnaire is a spreadsheet. Vendors answer the questions; institutions then use evaluation tabs to score the answers. According to EDUCAUSE's instructions for institutions:

EDUCAUSE also says vendors need to complete the HECVAT only once per year and can share it with any institution without changes. That is the main attraction for both sides: one answer set reused across many customers.

2. Versions: Full, Lite, On-Premise and HECVAT 4

Earlier HECVAT versions came as separate questionnaires, which EDUCAUSE refers to as the full, lite and on-prem versions. HECVAT 4 changed this:

TopicBefore HECVAT 4HECVAT 4 (current: 4.1.6)
StructureSeparate Full, Lite and On-Premise questionnairesOne file; vendors first answer scoping questions that determine which questions apply
"Lite" reviewSeparate shorter questionnaireReview only questions marked with an asterisk; a score is shown for the critical importance / lite questions
PrivacyA separate privacy question set created in 2022 by volunteers from the Chief Privacy Officers Community GroupThose questions pulled in, plus a privacy analyst evaluation tab
AINot described in the sources we readA set of AI-specific questions written by community volunteers

EDUCAUSE publishes a change log through an issue tracker, so it is worth checking which minor version a vendor has completed. A HECVAT completed on an older version may not include the privacy and AI questions.

3. Licence and sharing

EDUCAUSE owns the copyright in HECVAT 4 and the name is trademarked. EDUCAUSE makes HECVAT 4 available at no cost to colleges and universities, which may modify it for their non-profit needs, and to their vendors for use in those business relationships. Other parties, explicitly including third-party risk management platforms that want to integrate it, need permission and a licence from EDUCAUSE.

The Community Broker Index, a central place to find completed HECVATs, was retired on 31 July 2025. EDUCAUSE explains that many of the stored assessments had become outdated. Institutions now request a completed HECVAT directly from the vendor.

Validemic's analysis Because of these terms, the questionnaire we offer below is written from scratch. It does not reuse HECVAT questions, and it is organised around EU legal requirements rather than around the HECVAT's structure.

4. Where European universities need more

This is not a criticism of the HECVAT's quality. It is a broad, well-maintained questionnaire, and HECVAT 4 includes privacy and AI questions. We did not review every question in version 4.1.6 for this page, so check the current file yourself. The point is a structural one: EU law requires specific legal artefacts and decisions, and a questionnaire answer, however good, is a statement rather than the artefact itself.

EU requirementWhat it requiresWhat to ask the vendor for
GDPR roles (Art. 4(7), 4(8), 26, 28(10))Knowing whether the vendor is a processor, a controller for some purposes, or a joint controllerA purpose-by-purpose role statement, including analytics, product improvement and AI training
Art. 28(3) agreementA binding contract containing eight specific processor obligationsThe DPA itself, mapped clause by clause
Subprocessors (Art. 28(2), 28(4))Prior authorisation, notice of changes and a right to object; same obligations down the chainThe current list with locations, and the change and objection process
Transfers (Chapter V)A valid transfer tool for each non-EEA recipient; remote access counts as a transfer according to the EDPBDPF List entry, SCC module, transfer impact assessment, access locations
Public authority limits (Art. 49(3))Some derogations do not apply to public authorities exercising public powersA transfer tool other than consent or contract-necessity derogations
DPIA (Art. 35, 28(3)(f))The controller's assessment, with the processor's assistanceData flow, risk and mitigation information you can reuse
EU AI ActProhibitions (Art. 5), AI literacy (Art. 4), transparency (Art. 50), and from 2 December 2027 high-risk duties for Annex III systems, including education usesThe vendor's AI Act role, intended purpose and Annex III assessment for each AI feature
Web Accessibility Directive (EU) 2016/2102Accessible websites and apps for public sector bodies; EN 301 549 is the harmonised standard referenced for presumption of conformityA conformance report against EN 301 549 / WCAG

The AI Act timing deserves a note. The Digital Omnibus on AI (Regulation (EU) 2026/1744), in force since 27 July 2026, moved the application of the high-risk rules for Annex III systems to 2 December 2027. Annex III point 3 covers AI used to decide admission, evaluate learning outcomes, assess the appropriate level of education, or monitor prohibited behaviour during tests. Using AI to infer the emotions of people in education institutions has been prohibited since 2 February 2025, except for medical or safety reasons. See our AI Act guide for universities.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

5. The European vendor questionnaire

Our European Vendor Assessment Questionnaire for Higher Education is a Word document with 77 questions in 11 sections. Each section is a table with three columns: the question, the vendor's answer, and the evidence or document that supports it. The evidence column is the important one: it turns claims into references you can check.

SectionQuestionsMain legal anchor
A. Company and contracts7GDPR Art. 27 (EU representative), contract structure
B. Data processing and GDPR roles9GDPR Art. 4, 9, 26, 28, 35
C. Data location and transfers8GDPR Chapter V; Decision (EU) 2021/914; Decision (EU) 2023/1795
D. Subprocessors6GDPR Art. 28(2) and 28(4); EDPB Opinion 22/2024
E. Security controls10GDPR Art. 32
F. Identity and access6GDPR Art. 32; institutional identity requirements
G. Incident and breach6GDPR Art. 33(2)
H. Business continuity5GDPR Art. 32(1)(b) and (c)
I. AI features and the EU AI Act10AI Act Art. 4, 5, 50, Annex III point 3
J. Accessibility (EN 301 549 / WCAG)5Directive (EU) 2016/2102
K. Exit and data return5GDPR Art. 28(3)(g)

Examples of the questions

The document opens with instructions for both sides, a cover table to fill in, and a list of documents to attach. It ends with a short declaration for the vendor to sign. Delete sections that do not apply, and add your own institutional requirements.

Independence statement: this questionnaire is published by Validemic (Avidemic AB, Sweden). It is not affiliated with, endorsed by or derived from EDUCAUSE or the HECVAT. HECVAT is a trademark of EDUCAUSE.

6. Using both together

Many vendors to higher education will already have a completed HECVAT. Asking them to answer a completely different security questionnaire wastes their time and yours. A practical combination:

  1. Accept the HECVAT for general security. If the vendor sends a recent HECVAT 4, use it for most of sections E, F and H, and ask only follow-up questions.
  2. Ask the EU-specific sections directly. Sections B, C, D and I of our questionnaire cover the GDPR roles, transfers, subprocessors and AI Act points where European institutions need documents rather than answers.
  3. Collect the documents. Whatever questionnaire you use, the decision should rest on the DPA, subprocessor list, transfer documentation and independent security reports. Our vendor assessment guide lists the full evidence pack.
  4. Record the outcome. Add the processing to your record of processing activities, and run DPIA screening for higher-risk uses.

7. Reading the answers: red flags

Validemic's analysis These answer patterns deserve a follow-up question before approval. None of them is automatically disqualifying.

Answer patternWhy it mattersFollow-up
"We are GDPR compliant" with no document referenceCompliance depends on contract, configuration and use, not on a labelAsk for the DPA clause and the role statement
EU hosting stated, access locations not statedThe EDPB treats remote access from a third country as a transferAsk C2 and the transfer tool for each access location
DPF reliance without a List entryThe adequacy decision covers organisations on the Data Privacy Framework ListAsk for the exact entry and check it yourself
Subprocessor list "available on request"The EDPB expects controllers to have subprocessor identities readily available at all timesAsk for the list now and the change notification method
AI training "may" use customer data, or differs by planThe vendor may be a controller for training; plan differences change the riskAsk which plan you are buying and get the commitment in the contract
Certificate without scopeA certificate may not cover the product or hosting you buyAsk for the scope statement and certification body
Accessibility "WCAG compliant" without a reportConformance claims need testing evidence and a list of known issuesAsk for the conformance report

If you review many vendors, the free DPA checker and transfer mechanism tool help with the two most common follow-ups, and our AI Act checker for education helps with section I.

Sources

  1. EDUCAUSE: Higher Education Community Vendor Assessment Toolkit (current version, licence terms) (retrieved 7 October 2026).
  2. EDUCAUSE: HECVAT FAQs for Higher Education (HECVAT 4 structure, lite review, Community Broker Index) (retrieved 7 October 2026).
  3. EDUCAUSE: How to Use the HECVAT (evaluation tabs and scoring) (retrieved 7 October 2026).
  4. EDUCAUSE Review: HECVAT 4: Better than Ever, February 2025 (retrieved 7 October 2026).
  5. Regulation (EU) 2016/679 (GDPR) (retrieved 7 October 2026).
  6. Regulation (EU) 2024/1689 (AI Act), Articles 4, 5, 50, 113 and Annex III (retrieved 7 October 2026).
  7. Regulation (EU) 2026/1744 (Digital Omnibus on AI) (retrieved 7 October 2026).
  8. EDPB Recommendations 01/2020 on supplementary measures (retrieved 7 October 2026).
  9. EDPB Opinion 22/2024 on reliance on processors and sub-processors (retrieved 7 October 2026).
  10. Commission Implementing Decision (EU) 2023/1795 (EU-US Data Privacy Framework) (retrieved 7 October 2026).
  11. Commission Implementing Decision (EU) 2021/914 (SCCs) (retrieved 7 October 2026).
  12. Directive (EU) 2016/2102 (Web Accessibility Directive) and Commission Implementing Decision (EU) 2021/1339 referencing EN 301 549 v3.2.1 (retrieved 7 October 2026).

About this page

Sources checked on 7 October 2026. HECVAT facts come from EDUCAUSE's own pages and EDUCAUSE Review; we did not have access to the content of the HECVAT 4.1.6 spreadsheet for this page and make no claims about individual HECVAT questions. Legal texts were read in their Official Journal versions. The European questionnaire was written by Validemic and is not legal advice: adapt it to your institution and national law. If you spot an error, or you are from EDUCAUSE and would like us to correct something, please contact us.

Frequently asked questions

What does HECVAT stand for?

Higher Education Community Vendor Assessment Toolkit. It is a vendor questionnaire created by people in higher education with EDUCAUSE, Internet2 and REN-ISAC, and EDUCAUSE owns the copyright.

What is the current version of the HECVAT?

On 7 October 2026 the EDUCAUSE HECVAT page lists HECVAT 4 with current version 4.1.6.

Is there still a HECVAT Lite?

Not as a separate file. In HECVAT 4 the Full, Lite and On-Premise versions were rolled into one file. EDUCAUSE explains that a lite review means looking only at the questions marked with an asterisk.

Is the HECVAT free to use?

EDUCAUSE makes HECVAT 4 available at no cost to colleges and universities and to their vendors for those business relationships. Other parties, including third-party risk management platforms, need permission and a licence from EDUCAUSE.

Is a completed HECVAT enough for GDPR?

Usually not on its own. GDPR requires specific documents and decisions, such as an Article 28 agreement, a Chapter V transfer mechanism, and sometimes a DPIA. A questionnaire answer is evidence, but it does not replace these.

Is Validemic's European questionnaire an official HECVAT version?

No. It is an independent questionnaire written by Validemic. It is not affiliated with, endorsed by or derived from EDUCAUSE or the HECVAT.