New

Now in Claude, ChatGPT, Cursor & more with our MCP server

Back to blog
Sector trends9 min read

Anonymity, Confidentiality, and GDPR in Course Evaluation: Honest Feedback Without Breaching Trust

Universities use anonymity and confidentiality as if they were the same word. Under GDPR they are not - and conflating them quietly undermines both honest feedback and lawful data handling. Here is the distinction that determines whether your evaluations are candid, compliant, and able to close the loop.

Koji for Education

Research & Editorial Team ·

Bottom line up front: Anonymity and confidentiality are different guarantees with different consequences. Anonymous feedback cannot be linked to an individual at all; confidential feedback can be linked but is protected from disclosure. The choice shapes everything downstream: candour, the risk of abusive comments, your ability to follow up or close the loop, and — critically — whether GDPR applies at all. Truly anonymised data falls outside GDPR; merely confidential or pseudonymised data does not. Most institutions promise "anonymity," deliver confidentiality, and govern it as if neither rule applied. Getting this right is simultaneously an ethics problem and a compliance problem.

Two words, two different promises

In everyday use the terms blur, but precision matters here:

  • Anonymity means the response carries no information that could identify the respondent — not a name, not an ID, not a combination of fields that could single someone out. Once truly anonymised, even the institution cannot re-link the response to a student.
  • Confidentiality means the response can be linked to a student (the system knows who said it) but the institution promises not to disclose the identity, and restricts who can access it.

These are not interchangeable. A "confidential" evaluation is still personal data; an "anonymous" one, properly done, is not. And students rarely understand which one they have been given — a 2023 scoping review of student motivations and perceptions found that assurances of confidentiality and anonymity are among the key factors shaping whether students participate at all and how candidly (Flodén-style evidence summarised here). If the promise is vague, so is the trust.

Why the distinction is a GDPR issue, not just an ethics one

Under the GDPR (and its national implementations such as the Dutch AVG), the regulation applies to personal data — information relating to an identified or identifiable person. Recital 26 is explicit that the principles of data protection do not apply to truly anonymous information, "namely information which does not relate to an identified or identifiable natural person." So the anonymity/confidentiality choice is the choice of whether GDPR is in scope.

This has concrete consequences most evaluation processes get wrong:

  • Free-text comments are a re-identification risk. A student who writes "as the only wheelchair user in the seminar…" has just identified themselves, regardless of how the system strips names. Open comments routinely contain identifying detail and references to third parties (other students, named staff) — which is personal data about people who never consented.
  • Small cohorts defeat anonymity. In a class of six, "the international student" or even a distinctive writing style re-identifies. This is why responsible institutions suppress results below a minimum response threshold (commonly around five responses) before releasing them — a practical safeguard against re-identification, not a bureaucratic nicety.
  • Demographic breakdowns collide with special-category data. Slicing results by gender, ethnicity, or disability — useful for detecting bias — can constitute processing of special-category data under Article 9, which carries stricter conditions. Anonymity and equity analysis are in tension: the more you can segment, the less anonymous the data.
  • AI analysis raises the automated-decision question. If evaluation data feeds decisions about staff, GDPR's provisions on profiling and automated decision-making (Article 22) and the broader EU AI Act conversation become relevant — a point we develop in our guide to AI in European higher-education quality assurance.

The candour-versus-accountability tension

Anonymity is usually defended on candour grounds, and the defence is real: when students trust that their identity is protected, they report problems they would otherwise soften. Confidentiality that students do not believe produces guarded, polite, low-value feedback. So far, so pro-anonymity.

But doesn't anonymity also enable abuse — and block follow-up?

Here is the strongest counterargument, and it cuts the other way. Full, irreversible anonymity has two serious costs.

First, it enables abusive comments. The same shield that frees candour also lets a minority post personalised, prejudicial, or cruel remarks "with impunity," with documented effects on the wellbeing of teaching staff — particularly women, minority-ethnic, and early-career academics. Anonymity is not a pure good; it is a trade-off that externalises a cost onto the people being evaluated.

Second, irreversible anonymity makes it impossible to close the loop or follow up. If you cannot link a response to a respondent, you cannot return to a student to probe an ambiguous comment, you cannot connect feedback to outcomes longitudinally, and you cannot tell a student "you said this, and here is what changed." The very feature that maximises candour destroys the relational responsiveness that rebuilds trust and lifts response rates over time.

This is why the binary — "anonymous good, identified bad" — is the wrong frame. The defensible target is usually confidential-by-design with strong technical and governance safeguards: responses are linkable for legitimate, narrow purposes (follow-up, longitudinal analysis, moderation of abuse) but access is tightly controlled, identities are never exposed to the evaluated staff member, results below a threshold are suppressed, and students are told precisely which guarantee they have. That honesty about the guarantee is itself what earns candour — vague promises of "anonymity" that students half-disbelieve produce worse data than a clearly-explained, well-governed confidentiality.

What good practice looks like

  • Say which one you mean. Tell students explicitly whether feedback is anonymous or confidential, who can see it, and what it will be used for. Precision builds the trust that drives candour.
  • Suppress small-cohort results. Apply a minimum-response threshold before any release to protect re-identification in small classes.
  • Govern free text deliberately. Open comments need moderation for both re-identification risk and abuse before they reach the evaluated staff member.
  • Separate equity analysis from open reporting. Demographic segmentation for bias detection should be handled under appropriate Article 9 conditions, not bolted onto routine reports.
  • Keep humans protected. Identities should never be exposed to the person being evaluated, and abusive content should be filtered, not forwarded.

This is where the platform's design does real work. Koji for Education is built for GDPR/AVG-compliant, EU-appropriate data handling, and its conversational model resolves the candour-versus-follow-up tension that breaks static surveys: AI-moderated interviews can probe an ambiguous comment in the moment — getting the clarification you would otherwise need to re-contact a student for — without exposing the student's identity to staff. The standardized, bias-aware AI moderation filters abusive content before it reaches a teacher, protecting wellbeing rather than relaying harm. Thematic analysis works on protected data so that equity insights surface without dumping raw, re-identifiable comments into a report. And because guarantees are stated clearly to students up front, the candour that anonymity is supposed to buy is earned through trust instead. (The same privacy-respecting conversational interview engine powers GDPR-compliant user and customer research on the main Koji platform.)

The lazy promise of "anonymous evaluations" tries to have candour without accountability and compliance without thinking. The honest path is to choose the guarantee deliberately, govern it properly, and tell students the truth about it.

One final caution: the guarantee you offer must match what your systems can actually deliver. Promising "fully anonymous" feedback while running it through a platform that logs IP addresses, device identifiers, or login timestamps is not anonymity — it is confidentiality with a misleading label, and the gap between the promise and the technical reality is precisely the kind of thing a data-protection authority, or a sceptical student, will notice. Audit what your tooling records before you make any promise about it, and align the wording with the architecture.

Key takeaways

  • Anonymity (cannot be linked to a person) and confidentiality (linkable but protected) are different guarantees with different consequences - and institutions routinely conflate them.
  • The distinction determines GDPR scope: truly anonymised data falls outside GDPR (Recital 26); confidential or pseudonymised data does not.
  • Free-text comments, small cohorts, and demographic breakdowns all create re-identification and special-category-data risks that naive "anonymisation" misses.
  • Full anonymity maximises candour but enables abusive comments and makes closing the loop impossible; the defensible target is usually confidential-by-design with strong safeguards.
  • Tell students exactly which guarantee they have, suppress small-cohort results, moderate free text, protect evaluated staff, and handle equity analysis under proper conditions.