HECVAT for European universities: what it covers and a GDPR-ready alternative
The HECVAT is the questionnaire many software vendors to higher education already have on file. This guide explains what the current version contains, why European universities usually need more on GDPR, international transfers and the EU AI Act, and offers an independent European questionnaire you can download and send to vendors.
The short version
- The HECVAT (Higher Education Community Vendor Assessment Toolkit) is a vendor questionnaire created with EDUCAUSE, Internet2 and REN-ISAC. The current version listed by EDUCAUSE on 7 October 2026 is 4.1.6.
- HECVAT 4 merged the former Full, Lite and On-Premise versions into one file and added questions on privacy and AI.
- For European universities, a completed HECVAT is useful security evidence. GDPR and the EU AI Act, however, ask for specific legal documents and decisions that a questionnaire answer does not replace.
- We publish a free, independent European vendor questionnaire (Word, 77 questions in 11 sections) built around those EU requirements. It is not affiliated with EDUCAUSE.
Contents
1. What the HECVAT is
EDUCAUSE describes the HECVAT as a tool to help college and university professionals measure vendor risk. It was created by leaders in higher education in collaboration with EDUCAUSE, Internet2 and REN-ISAC, and it is a questionnaire that vendors complete to describe their cybersecurity, privacy, IT accessibility and compliance practices in one place. EDUCAUSE Review notes that the HECVAT has existed since 2016.
The questionnaire is a spreadsheet. Vendors answer the questions; institutions then use evaluation tabs to score the answers. According to EDUCAUSE's instructions for institutions:
- There are evaluation tabs for institutional evaluation, high-risk evaluation and privacy analyst evaluation.
- Each question has a "compliant response" decided by the volunteers who wrote the questions, and a default importance level. Institutions can override both.
- Institutions can exclude whole categories from the score, for example card payment questions for a product where that feature will not be used.
- Questions can be marked "non-negotiable", which pulls them into the high-risk evaluation tab.
EDUCAUSE also says vendors need to complete the HECVAT only once per year and can share it with any institution without changes. That is the main attraction for both sides: one answer set reused across many customers.
2. Versions: Full, Lite, On-Premise and HECVAT 4
Earlier HECVAT versions came as separate questionnaires, which EDUCAUSE refers to as the full, lite and on-prem versions. HECVAT 4 changed this:
| Topic | Before HECVAT 4 | HECVAT 4 (current: 4.1.6) |
|---|---|---|
| Structure | Separate Full, Lite and On-Premise questionnaires | One file; vendors first answer scoping questions that determine which questions apply |
| "Lite" review | Separate shorter questionnaire | Review only questions marked with an asterisk; a score is shown for the critical importance / lite questions |
| Privacy | A separate privacy question set created in 2022 by volunteers from the Chief Privacy Officers Community Group | Those questions pulled in, plus a privacy analyst evaluation tab |
| AI | Not described in the sources we read | A set of AI-specific questions written by community volunteers |
EDUCAUSE publishes a change log through an issue tracker, so it is worth checking which minor version a vendor has completed. A HECVAT completed on an older version may not include the privacy and AI questions.
3. Licence and sharing
EDUCAUSE owns the copyright in HECVAT 4 and the name is trademarked. EDUCAUSE makes HECVAT 4 available at no cost to colleges and universities, which may modify it for their non-profit needs, and to their vendors for use in those business relationships. Other parties, explicitly including third-party risk management platforms that want to integrate it, need permission and a licence from EDUCAUSE.
The Community Broker Index, a central place to find completed HECVATs, was retired on 31 July 2025. EDUCAUSE explains that many of the stored assessments had become outdated. Institutions now request a completed HECVAT directly from the vendor.
Validemic's analysis Because of these terms, the questionnaire we offer below is written from scratch. It does not reuse HECVAT questions, and it is organised around EU legal requirements rather than around the HECVAT's structure.
4. Where European universities need more
This is not a criticism of the HECVAT's quality. It is a broad, well-maintained questionnaire, and HECVAT 4 includes privacy and AI questions. We did not review every question in version 4.1.6 for this page, so check the current file yourself. The point is a structural one: EU law requires specific legal artefacts and decisions, and a questionnaire answer, however good, is a statement rather than the artefact itself.
| EU requirement | What it requires | What to ask the vendor for |
|---|---|---|
| GDPR roles (Art. 4(7), 4(8), 26, 28(10)) | Knowing whether the vendor is a processor, a controller for some purposes, or a joint controller | A purpose-by-purpose role statement, including analytics, product improvement and AI training |
| Art. 28(3) agreement | A binding contract containing eight specific processor obligations | The DPA itself, mapped clause by clause |
| Subprocessors (Art. 28(2), 28(4)) | Prior authorisation, notice of changes and a right to object; same obligations down the chain | The current list with locations, and the change and objection process |
| Transfers (Chapter V) | A valid transfer tool for each non-EEA recipient; remote access counts as a transfer according to the EDPB | DPF List entry, SCC module, transfer impact assessment, access locations |
| Public authority limits (Art. 49(3)) | Some derogations do not apply to public authorities exercising public powers | A transfer tool other than consent or contract-necessity derogations |
| DPIA (Art. 35, 28(3)(f)) | The controller's assessment, with the processor's assistance | Data flow, risk and mitigation information you can reuse |
| EU AI Act | Prohibitions (Art. 5), AI literacy (Art. 4), transparency (Art. 50), and from 2 December 2027 high-risk duties for Annex III systems, including education uses | The vendor's AI Act role, intended purpose and Annex III assessment for each AI feature |
| Web Accessibility Directive (EU) 2016/2102 | Accessible websites and apps for public sector bodies; EN 301 549 is the harmonised standard referenced for presumption of conformity | A conformance report against EN 301 549 / WCAG |
The AI Act timing deserves a note. The Digital Omnibus on AI (Regulation (EU) 2026/1744), in force since 27 July 2026, moved the application of the high-risk rules for Annex III systems to 2 December 2027. Annex III point 3 covers AI used to decide admission, evaluate learning outcomes, assess the appropriate level of education, or monitor prohibited behaviour during tests. Using AI to infer the emotions of people in education institutions has been prohibited since 2 February 2025, except for medical or safety reasons. See our AI Act guide for universities.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
5. The European vendor questionnaire
Our European Vendor Assessment Questionnaire for Higher Education is a Word document with 77 questions in 11 sections. Each section is a table with three columns: the question, the vendor's answer, and the evidence or document that supports it. The evidence column is the important one: it turns claims into references you can check.
| Section | Questions | Main legal anchor |
|---|---|---|
| A. Company and contracts | 7 | GDPR Art. 27 (EU representative), contract structure |
| B. Data processing and GDPR roles | 9 | GDPR Art. 4, 9, 26, 28, 35 |
| C. Data location and transfers | 8 | GDPR Chapter V; Decision (EU) 2021/914; Decision (EU) 2023/1795 |
| D. Subprocessors | 6 | GDPR Art. 28(2) and 28(4); EDPB Opinion 22/2024 |
| E. Security controls | 10 | GDPR Art. 32 |
| F. Identity and access | 6 | GDPR Art. 32; institutional identity requirements |
| G. Incident and breach | 6 | GDPR Art. 33(2) |
| H. Business continuity | 5 | GDPR Art. 32(1)(b) and (c) |
| I. AI features and the EU AI Act | 10 | AI Act Art. 4, 5, 50, Annex III point 3 |
| J. Accessibility (EN 301 549 / WCAG) | 5 | Directive (EU) 2016/2102 |
| K. Exit and data return | 5 | GDPR Art. 28(3)(g) |
Examples of the questions
- "For each processing activity in the service, state whether you act as processor for the university, as an independent controller, or as joint controller." (B1)
- "From which countries can your staff or subprocessors access customer data, including for support, maintenance and incident response?" (C2)
- "If you rely on the EU-US Data Privacy Framework, give the exact name under which your organisation appears on the Data Privacy Framework List and confirm its status is active." (C4)
- "Is university data (inputs, outputs, files, usage data) used to train, fine-tune or evaluate any AI model, yours or a third party's? Does this differ by plan?" (I3)
- "Do you consider any feature a high-risk AI system under Annex III, in particular point 3 (education)? Explain your assessment." (I6)
The document opens with instructions for both sides, a cover table to fill in, and a list of documents to attach. It ends with a short declaration for the vendor to sign. Delete sections that do not apply, and add your own institutional requirements.
Independence statement: this questionnaire is published by Validemic (Avidemic AB, Sweden). It is not affiliated with, endorsed by or derived from EDUCAUSE or the HECVAT. HECVAT is a trademark of EDUCAUSE.
6. Using both together
Many vendors to higher education will already have a completed HECVAT. Asking them to answer a completely different security questionnaire wastes their time and yours. A practical combination:
- Accept the HECVAT for general security. If the vendor sends a recent HECVAT 4, use it for most of sections E, F and H, and ask only follow-up questions.
- Ask the EU-specific sections directly. Sections B, C, D and I of our questionnaire cover the GDPR roles, transfers, subprocessors and AI Act points where European institutions need documents rather than answers.
- Collect the documents. Whatever questionnaire you use, the decision should rest on the DPA, subprocessor list, transfer documentation and independent security reports. Our vendor assessment guide lists the full evidence pack.
- Record the outcome. Add the processing to your record of processing activities, and run DPIA screening for higher-risk uses.
7. Reading the answers: red flags
Validemic's analysis These answer patterns deserve a follow-up question before approval. None of them is automatically disqualifying.
| Answer pattern | Why it matters | Follow-up |
|---|---|---|
| "We are GDPR compliant" with no document reference | Compliance depends on contract, configuration and use, not on a label | Ask for the DPA clause and the role statement |
| EU hosting stated, access locations not stated | The EDPB treats remote access from a third country as a transfer | Ask C2 and the transfer tool for each access location |
| DPF reliance without a List entry | The adequacy decision covers organisations on the Data Privacy Framework List | Ask for the exact entry and check it yourself |
| Subprocessor list "available on request" | The EDPB expects controllers to have subprocessor identities readily available at all times | Ask for the list now and the change notification method |
| AI training "may" use customer data, or differs by plan | The vendor may be a controller for training; plan differences change the risk | Ask which plan you are buying and get the commitment in the contract |
| Certificate without scope | A certificate may not cover the product or hosting you buy | Ask for the scope statement and certification body |
| Accessibility "WCAG compliant" without a report | Conformance claims need testing evidence and a list of known issues | Ask for the conformance report |
If you review many vendors, the free DPA checker and transfer mechanism tool help with the two most common follow-ups, and our AI Act checker for education helps with section I.
Sources
- EDUCAUSE: Higher Education Community Vendor Assessment Toolkit (current version, licence terms) (retrieved 7 October 2026).
- EDUCAUSE: HECVAT FAQs for Higher Education (HECVAT 4 structure, lite review, Community Broker Index) (retrieved 7 October 2026).
- EDUCAUSE: How to Use the HECVAT (evaluation tabs and scoring) (retrieved 7 October 2026).
- EDUCAUSE Review: HECVAT 4: Better than Ever, February 2025 (retrieved 7 October 2026).
- Regulation (EU) 2016/679 (GDPR) (retrieved 7 October 2026).
- Regulation (EU) 2024/1689 (AI Act), Articles 4, 5, 50, 113 and Annex III (retrieved 7 October 2026).
- Regulation (EU) 2026/1744 (Digital Omnibus on AI) (retrieved 7 October 2026).
- EDPB Recommendations 01/2020 on supplementary measures (retrieved 7 October 2026).
- EDPB Opinion 22/2024 on reliance on processors and sub-processors (retrieved 7 October 2026).
- Commission Implementing Decision (EU) 2023/1795 (EU-US Data Privacy Framework) (retrieved 7 October 2026).
- Commission Implementing Decision (EU) 2021/914 (SCCs) (retrieved 7 October 2026).
- Directive (EU) 2016/2102 (Web Accessibility Directive) and Commission Implementing Decision (EU) 2021/1339 referencing EN 301 549 v3.2.1 (retrieved 7 October 2026).
About this page
Sources checked on 7 October 2026. HECVAT facts come from EDUCAUSE's own pages and EDUCAUSE Review; we did not have access to the content of the HECVAT 4.1.6 spreadsheet for this page and make no claims about individual HECVAT questions. Legal texts were read in their Official Journal versions. The European questionnaire was written by Validemic and is not legal advice: adapt it to your institution and national law. If you spot an error, or you are from EDUCAUSE and would like us to correct something, please contact us.
Frequently asked questions
What does HECVAT stand for?
Higher Education Community Vendor Assessment Toolkit. It is a vendor questionnaire created by people in higher education with EDUCAUSE, Internet2 and REN-ISAC, and EDUCAUSE owns the copyright.
What is the current version of the HECVAT?
On 7 October 2026 the EDUCAUSE HECVAT page lists HECVAT 4 with current version 4.1.6.
Is there still a HECVAT Lite?
Not as a separate file. In HECVAT 4 the Full, Lite and On-Premise versions were rolled into one file. EDUCAUSE explains that a lite review means looking only at the questions marked with an asterisk.
Is the HECVAT free to use?
EDUCAUSE makes HECVAT 4 available at no cost to colleges and universities and to their vendors for those business relationships. Other parties, including third-party risk management platforms, need permission and a licence from EDUCAUSE.
Is a completed HECVAT enough for GDPR?
Usually not on its own. GDPR requires specific documents and decisions, such as an Article 28 agreement, a Chapter V transfer mechanism, and sometimes a DPIA. A questionnaire answer is evidence, but it does not replace these.
Is Validemic's European questionnaire an official HECVAT version?
No. It is an independent questionnaire written by Validemic. It is not affiliated with, endorsed by or derived from EDUCAUSE or the HECVAT.