Download this document PDF.
Purpose
This policy establishes requirements for vendors requesting access to the University of Detroit Mercy’s Learning Management System (LMS) Blackboard. It ensures the protection of institutional data, compliance with security and accessibility standards, and adherence to FERPA regulations.
Scope
This policy applies to all third-party vendors requesting integration with the LMS, including cloud-based services, software applications, and external tools that require data exchange or authentication with the LMS.
Requirements for Vendor Integration
A. Security & Compliance Documentation
Vendors must provide the following documentation before access to the Blackboard server is considered:
-
Higher Education Community Vendor Assessment Toolkit (HECVAT) – A completed HECVAT Lite or Full version is required to assess the vendor’s security posture and compliance with industry best practices.
-
Voluntary Product Accessibility Template (VPAT) – Vendors must submit a VPAT to demonstrate compliance with accessibility standards, ensuring compatibility with the Americans with Disabilities Act (ADA) and Section 508 of the Rehabilitation Act.
-
Disclosure of Data Use and Security Practices – Vendors must disclose:
-
The type of data collected, stored, or transmitted.
-
How data is secured and encrypted in transit and at rest.
-
Data retention and deletion policies.
-
Any third-party data sharing agreements.
B. Data Security & Protection
C. Compliance with FERPA
All vendor integrations must comply with the Family Educational Rights and Privacy Act (FERPA) to protect student records. Vendors must:
D. Institutional Review & Approval Process
-
Vendors must submit all required documentation to CETL for review.
-
A review will be conducted to evaluate security, compliance, and accessibility risks.
-
Approval from CETL is required before integration. Depending on the scope of the product, additional approvals from ITS may be required as well.
-
Periodic re-evaluation of vendor compliance may be required to maintain access.
Enforcement, Violations, Sunsetting
-
Failure to comply with this policy may result in the suspension or termination of vendor access to Blackboard.
-
Non-compliance with security or FERPA regulations may lead to further institutional action or reporting to regulatory authorities.
-
CETL may terminate vendor access without notification for use that exceeds the scope of approved access or after two consecutive terms of non-use.
Contact Information
For questions regarding vendor access and compliance, please contact CETL