SURF Vendor Compliance
Together we ensure the best privacy and security terms for education and research

What is Vendor Compliance?
When personal data is breached, institutions face the risk of fines, reputational damage and liability claims. It is therefore necessary to check with suppliers how they process your data. Clear agreements must be made about this. Institutions often perform this compliance work individually: the same work for the same applications while expertise is scarce and expensive. To support institutions in these processes and take work off their hands, SURF Vendor Compliance carries out various compliance processes each year. Each year an average of eight projects are picked up. We determine which projects these are together with the members.
Latest news
Interim update memo on the Osiris DPIA | additions regarding vocational education
We would like to inform you that SURF Vendor Compliance has published an interim update memo regarding the expansion of the Osiris DPIA to include vocational education-specific scenarios. We have...
Update Xedule DPIA
Following the DPIA on Xedule in July 2025, it is...
SURF finalizes DPIA on Adobe Creative Cloud and Document Cloud for Education
SURF and Privacy Company have conducted a Data Protection Impact...
Latest compliance assessments

SURF provides (in collaboration with partners):
- The conducting risk analyses (including DPIAs and DTIAs);
- performing security and compliance checks, including data transfers outside the EEA, with legal and technical investigations;
- establishing, delivering and applying review frameworks against which suppliers are reviewed;
- making agreements with suppliers, such as processor agreements, that mitigate privacy risks and agree on security measures;
- providing information and support on how institutions can use the assessed applications/(cloud) software as securely as possible;
- monitoring suppliers' compliance with agreements made.
What are the benefits of Vendor Compliance?
By taking up assessments together, we have a strong negotiating position towards suppliers; we speak on behalf of the entire research and education sector.
By pooling expertise, institutions individually save costs and time.
Institutions get the building blocks they need to make their own trade-offs for the secure use of assessed applications/(cloud) software.
Do you have a question or want to communicate your desire about a compliance assessment
By talking to suppliers and staying in dialogue, we agree on the best privacy and security conditions for research and education.
If you have a question about a compliance program, please contact us or send us your requirements via the button below.