Cyberattack on Canvas

Canvas has been affected by a global cyberattack in which the personal data of students, lecturers and staff has been stolen. This includes users’ names, email addresses, student numbers and...

Updated on
May 5, 2026

Canvas

Update Xedule DPIA

Following the DPIA on Xedule in July 2025, it is time to provide an update. Xedule has indicated that it has now implemented most of the mitigating measures. The implementation...

Updated on
March 31, 2026

Xedule

TOPdesk implements privacy improvements following SURF DPIA 

Institutions can continue to use TOPdesk, according to SURF's DPIA. SURF identified 9 high risks and 3 low risks. TOPdesk has already mitigated 4 of the high risks and will mitigate the remaining high risks soon.  TOPdesk is a service management platform used by...

Updated on
January 15, 2026

Security assessment pilot on Xedule completed

SURF Vendor Compliance has completed a security assessment pilot on Xedule. This assessment was a joint initiative that provided both parties with a great deal of relevant knowledge. Xedule Xedule...

Updated on
January 12, 2026

Xedule