New

Now in Claude, ChatGPT, Cursor & more with our MCP server

Back to docs
accreditation14 min

Course Evaluation Vendor Due Diligence: The GDPR Article 28 DPA & Sub-Processor Checklist

A procurement and DPO checklist for reviewing a course evaluation vendor as a data processor: the mandatory Article 28(3) data-processing-agreement clauses, sub-processor governance, international transfers, breach SLAs, deletion on exit, and audit rights — mapped to what to verify and to Koji outputs.

Koji Education Team

Product

When your university buys course evaluation software, the vendor becomes a processor of personal data about your students — and often your staff. Your institution stays the controller. Under Article 28(1) of the GDPR, a controller may only use a processor that provides "sufficient guarantees" of GDPR-compliant processing, and Article 28(3) makes a written contract — the data processing agreement (DPA) — mandatory. This is not a formality your legal team bolts on after selection. It is due diligence that should shape selection, and it is exactly the evidence an accreditation panel or a data-protection audit will expect you to hold under ESG 2015 Standard 1.7 (Information management).

This guide is a practical checklist for that review. It is deliberately narrow: it covers the processor contract and the sub-processor chain. Two related questions — where the data physically lives (international transfers) and whether you need a Data Protection Impact Assessment — are covered in their own guides and cross-linked below; this article points to them rather than repeating them.

Why the DPA is the centre of the review

A DPIA tells you whether the processing is risky. A DPA tells you whether the vendor is contractually bound to protect the data while they process it on your behalf. You need both, but the DPA is the one that creates enforceable obligations. If a vendor cannot produce a DPA that meets Article 28(3), the procurement should stop there — no certification, feature list, or price makes up for it, because without it your institution is in breach the moment data flows.

Note who is who. For end-of-module evaluation, the university is controller and the software vendor is processor. Do not accept a contract that describes the vendor as an independent controller of your student evaluation data, or as a "joint controller", unless you genuinely intend that — it changes who answers to your students and your supervisory authority.

The Article 28(3) mandatory clauses — what every DPA must contain

Article 28(3) lists eight things the contract must bind the processor to. Check each is present, specific, and not watered down.

Art 28(3) requirementWhat to verify in the DPAWhat to ask the vendor for
(a) Process only on documented instructionsProcessing is limited to delivering the evaluation service; no secondary use (no training generic models on your students' data without instruction, no marketing)A written scope of processing and a "no secondary use" statement
(b) Confidentiality of authorised staffEveryone with access is under a binding confidentiality obligationConfirmation staff and contractors are bound
(c) Article 32 security measuresEncryption in transit and at rest, access control, resilience, testingISO 27001 certificate and/or SOC 2 report, pen-test summary
(d) Sub-processor conditions respectedSub-processors only under Art 28(2)/(4) with flow-down termsCurrent sub-processor list (see next section)
(e) Assist with data-subject rightsVendor helps you answer access, erasure, objection requests (Chapter III)How they support a student or lecturer request technically
(f) Assist with Art 32–36Help with security, breach notification, DPIAs and prior consultationNamed support process and contacts
(g) Delete or return data at end of serviceAt your choice, all personal data deleted or returned, and copies deleted, unless law requires retentionDocumented off-boarding and deletion procedure
(h) Audits and information to demonstrate complianceYou can request evidence and audit/inspectAudit rights clause; how audits are accommodated

If any of these is missing or replaced with vague language ("commercially reasonable efforts", "industry-standard practices" with nothing behind them), treat it as a red flag and require the specific commitment.

Sub-processor governance — the part most reviews skip

Almost every SaaS course evaluation vendor uses sub-processors: a cloud host, an email/SMS delivery service, error monitoring, sometimes an AI model provider. Article 28(2) and 28(4) govern them, and this is where data quietly leaves the perimeter you thought you had contracted.

Check three things:

  1. Authorisation. The DPA must specify either specific prior authorisation or general written authorisation for sub-processors. General authorisation is standard, but it must come with a duty to notify you of changes so you can object.
  2. The list. Ask for the current sub-processor list — names, roles, and processing locations — and where it is published. A vendor that cannot produce one does not know its own data chain.
  3. Flow-down. Sub-processors must be bound by the same data-protection obligations as the main processor (Art 28(4)), and the main processor stays fully liable for its sub-processors' failures.

Pay attention to any sub-processor that introduces an AI model provider or a host outside the EEA — that is where the transfer question below is triggered.

International transfers — the short version (with a pointer)

If any sub-processor or the vendor itself processes your data outside the EEA, you are into Chapter V of the GDPR: you need a valid transfer mechanism (an adequacy decision, or the 2021 Standard Contractual Clauses, plus a transfer impact assessment after Schrems II). The EU–US Data Privacy Framework provides adequacy for certified US importers — it was adopted on 10 July 2023 and survived its first court challenge when the EU General Court dismissed the Latombe action on 3 September 2025 — but it remains under legal pressure (an appeal to the Court of Justice, Case C-703/25 P, is pending, and further "Schrems III" uncertainty continues into late 2026). The pragmatic conclusion for a European university is simple: the cleanest way to avoid the entire transfer question is to keep processing and hosting inside the EU/EEA. We work through the mechanics in Where does your course-evaluation data actually live? Schrems II and data sovereignty and in the GDPR data-residency buyer's guide. Confirm data residency in writing, in the DPA, not from a marketing page.

Breach notification — get the SLA in the contract

Under Article 33(2), a processor must notify the controller of a personal-data breach "without undue delay" after becoming aware of it. That is your trigger for your own 72-hour obligation to notify your supervisory authority under Article 33(1). "Without undue delay" is not a number, so pin it down: the DPA should state a concrete notification window (many institutions require notification within 24–48 hours), the information the vendor will provide, and a named contact. A vendor who will only commit to vague timing is handing you their risk.

Deletion and return on exit — before you ever sign

Article 28(3)(g) is the clause people remember only when they are switching vendors and discover their data is stranded. Confirm now: at the end of the contract, will the vendor delete or return all personal data and delete existing copies, on what timeline, in what export format, and with what certificate of deletion? This connects directly to your own retention rules — keep anonymised aggregate results and closing-the-loop action logs as long-term accreditation evidence, and delete raw individual responses on a defined schedule. See course evaluation data retention and records management.

Records and audit — the evidence you must be able to produce

Article 30 requires both controller and processor to keep records of processing activities (ROPA). Make sure the vendor maintains its Article 30(2) processor records and will share what you need for your own ROPA. Combined with the audit right in Article 28(3)(h) and the vendor's security certifications, this is the documentary trail that lets you demonstrate compliance — to a supervisory authority and to an accreditation reviewer under ESG Standard 1.7.

Requirement → Koji output

Due-diligence requirementKoji output
Article 28(3) DPAA GDPR Article 28-compliant data processing agreement offered as standard
Controller/processor clarityKoji acts as processor; the institution remains controller of its evaluation data
No secondary useStudent evaluation data processed only to deliver the service, on documented instructions
Sub-processor transparencyA maintained sub-processor list with roles and locations, and change notification
EU data residencyEU-hosted processing to keep data inside the EEA and avoid Chapter V transfers
Article 32 securityEncryption, access control, and security testing; certifications available for review
Breach notificationA contractual notification window and named contact to support your 72-hour duty
Deletion/return on exitDocumented off-boarding, export, and deletion process under Art 28(3)(g)
Audit and recordsAudit rights, processor ROPA, and evidence to support your own records

Red flags — when to walk away

  • No DPA, or a DPA that omits any Article 28(3) clause.
  • The vendor is described as an independent controller of your student evaluation data.
  • No sub-processor list, or refusal to notify you of sub-processor changes.
  • "We may use your data to improve our services/models" with no scope limit.
  • Data processed outside the EEA with no named transfer mechanism.
  • Breach notification promised only "as soon as reasonably practicable" with no window.
  • No deletion certificate or export path on exit.

Adjacent jurisdictions

The same logic applies with local overlays. In the UK, the UK GDPR and Data Protection Act 2018 mirror Article 28 (the ICO publishes processor-contract guidance), and EU→UK transfers rely on the UK adequacy decision. In Switzerland, the revised FADP imposes comparable processor-contract duties. In every case the DPA is required regardless of where the data sits — residency reduces transfer risk but never removes the need for the contract.

Related Resources

Frequently asked questions

Does buying course evaluation software require a data processing agreement?

Yes. The vendor processes personal data about your students (and often staff) on your behalf, which makes them a processor and your institution the controller. GDPR Article 28(1) only permits using a processor that offers sufficient guarantees, and Article 28(3) requires a written data processing agreement (DPA) containing eight mandatory clauses. If a vendor cannot provide a compliant DPA, the procurement should not proceed.

What must a GDPR Article 28 DPA contain?

Eight obligations on the processor: process only on your documented instructions; keep authorised staff under confidentiality; apply Article 32 security measures; use sub-processors only under Article 28(2)/(4); assist you with data-subject rights requests; assist with security, breach notification and DPIAs (Articles 32–36); delete or return all data at the end of the contract; and make available information and submit to audits to demonstrate compliance.

How should we handle a course evaluation vendor's sub-processors?

Confirm the DPA specifies either specific or general written authorisation for sub-processors, with a duty to notify you of changes so you can object. Obtain the current sub-processor list with names, roles and locations. Ensure sub-processors are bound by the same data-protection terms as the main processor (Article 28(4)), and remember the main processor stays liable for them. Watch for any sub-processor hosting or processing outside the EEA.

Is it safe to use a US-based course evaluation vendor after Schrems II?

It can be lawful if a valid transfer mechanism is in place — the EU–US Data Privacy Framework provides adequacy for certified US importers, or the 2021 Standard Contractual Clauses plus a transfer impact assessment apply. However, the Framework remains under legal challenge into late 2026, so the lowest-risk approach for a European university is to keep processing and hosting inside the EU/EEA, which avoids Chapter V transfers entirely. Confirm residency in the DPA.

How quickly must a course evaluation vendor report a data breach?

Under Article 33(2) a processor must notify the controller "without undue delay" after becoming aware of a breach, because that starts your own 72-hour clock to notify your supervisory authority. Since "without undue delay" is not a fixed number, require a concrete window in the DPA — many institutions specify 24 to 48 hours — along with the information the vendor will supply and a named contact.

What happens to our data when we switch course evaluation providers?

Article 28(3)(g) requires the processor, at your choice, to delete or return all personal data at the end of the service and delete existing copies, unless law requires retention. Before signing, confirm the export format, timeline, and whether a deletion certificate is provided. Plan this alongside your retention schedule so you keep anonymised aggregate results and action logs as accreditation evidence while raw individual responses are removed on schedule.