When a Free-Text Box Becomes a Whistleblowing Channel: Course Feedback and the EU Directive You Didn't Design For
An anonymous open-text evaluation field is not a designated whistleblowing channel - but it can still receive a protected disclosure about fraud, safety, or a data breach. The EU Whistleblowing Directive then imposes obligations you never planned for. Quality teams need a routing rule, not silence.
Koji Education Team
Product ยท August 1, 2026
The short answer
An anonymous course-evaluation comment box is not designed to be a whistleblowing channel. But nothing stops a student typing "the lab supervisor falsified the safety sign-off" or "our placement employer is not paying the apprentices they claim to" into it. The moment that happens, the EU Whistleblowing Directive (Directive (EU) 2019/1937) becomes relevant - because the protection attaches to the disclosure and the discloser, not to whether they used the "correct" channel. Universities and large colleges are covered entities. Quality-assurance teams therefore need a deliberate routing rule for the rare feedback comment that crosses from teaching complaint into protected disclosure. Doing nothing is the one option that carries real risk.
This is distinct from two things we have written about before. It is not safeguarding disclosures, which concern a student's welfare and a duty of care. And it is not abusive comments directed at faculty, which concern harm to staff. This is about a student reporting a breach of law through the wrong door.
What the Directive actually requires
The Whistleblowing Directive entered into force on 16 December 2019, with transposition into national law required by 17 December 2021 (extended to 17 December 2023 for private entities of 50 to 249 workers). Its core requirements, drawn from the EUR-Lex summary of the Directive, matter here:
- Who is covered. Legal entities in the public and private sector with 50 or more workers must establish internal reporting channels. Public-sector bodies are covered, though member states could exempt municipalities under 10,000 inhabitants. Most universities and large VET providers are squarely inside scope.
- What is covered. The Directive protects reports of breaches of Union law across defined areas - public procurement, financial services and money laundering, product and transport safety, environmental protection, public health, consumer protection, protection of privacy and personal data and security of networks, and the protection of the EU's financial interests, among others. A student report about mishandled personal data or a falsified safety record can fall inside this scope.
- What the channel must do. Internal channels must be confidential and secure, protecting the identity of the reporter and any third party named. Organisations must acknowledge a report within seven days and provide feedback within three months.
- Anti-retaliation. Retaliation against a whistleblower is prohibited, and protection extends to facilitators and to third parties connected to the reporter, such as colleagues or relatives.
The obligation the Directive creates is specific and time-bound. The problem for quality teams is that a course-evaluation form meets almost none of those requirements: it is often anonymous by design (so you cannot acknowledge to the reporter), it is read weeks later in bulk, and it has no confidential follow-up workflow.
The trap: you cannot un-know a disclosure
Here is the mechanism that makes this a live risk rather than a hypothetical. Once your institution is aware of a potential breach - even through an unexpected channel like an evaluation comment - it cannot claim it never received the information. If the comment is ignored and the breach later surfaces, the institution has both a governance failure and, potentially, evidence that it sat on a protected disclosure. And if anyone identifiable is later disadvantaged in connection with that disclosure, the anti-retaliation provisions are in play.
An anonymous evaluation box makes this worse in a particular way. Because you often cannot contact the reporter, you cannot triage the report the way a proper channel would, and you cannot offer them the protections the Directive promises. The channel that felt safest - full anonymity - is the one that leaves both the student and the institution most exposed when a genuine disclosure lands in it.
"A course survey isn't a reporting channel, so the Directive doesn't apply"
This is the objection a general counsel might raise, and it is half right. A course-evaluation form is not a designated internal reporting channel, and the Directive does not require you to turn it into one. In the strict sense, the compliance obligation lives with your dedicated whistleblowing channel, not your evaluation tool.
But the protection does not depend on channel choice. The Directive protects a reporter who had reasonable grounds to believe the information was true and that it fell within scope - regardless of the route they picked. So the correct reading is not "the Directive is irrelevant to evaluation data" but "a protected disclosure can arrive through evaluation data, and you must route it to the compliant channel when it does." The risk is not that your survey is non-compliant as a whistleblowing channel; it is that you fail to recognise and hand off the one comment in ten thousand that is a protected disclosure.
There is an opposite failure mode worth guarding against: over-routing. If every sharp complaint about a lecturer gets escalated to the whistleblowing process, you trivialise a serious mechanism and bury your compliance team in ordinary teaching feedback. Most negative comments are exactly that - feedback. The skill is a calibrated filter, not a panic button.
Where Koji fits
This is a detection-and-routing problem, and it is precisely where structured analysis of open text helps. Koji for Education runs automatic thematic analysis over free-text feedback, which means comments that reference the Directive's subject areas - safety, fraud, data protection, procurement, environmental harm - can be surfaced and flagged for human review rather than lost in a bulk export read weeks later. That turns "we never saw it" into "we saw it, assessed it, and routed it," which is the difference the Directive cares about. Because the analysis is traceable to the exact quote, a reviewer sees the original wording, not a lossy summary - the same provenance principle that governs responsible AI summarisation.
Two honest limits. First, Koji is not a whistleblowing channel and does not replace one: its role is to detect a possible protected disclosure in evaluation data and route it to your compliant, confidential channel, not to discharge the Directive's requirements itself. Second, anonymity cuts both ways - if a student wants the Directive's protections, they may need a channel that can acknowledge and follow up with them, which an anonymous survey cannot. The right institutional design uses evaluation feedback as an early-warning surface and a signposting opportunity ("if you are reporting misconduct, here is the confidential channel"), not as the reporting mechanism of record. Handling the sensitive categories of content that show up in free text is a broader discipline we cover alongside special-category data under GDPR Article 9.
Most course feedback is about teaching, and should be treated as such. But the rare comment that reports a breach of law is a legal event the moment you receive it. Build the routing rule before you need it.
A simple routing rule you can adopt this term
You do not need a policy rewrite to close this gap - you need a rule. Four steps work. One: flag any free-text comment that names one of the Directive's subject areas - safety, fraud, procurement, data protection, environmental harm, financial irregularity. Two: have a named reviewer read the flagged comment in full, in its original wording, within days rather than weeks. Three: if it plausibly reports a breach of law, route it to your organisation's confidential whistleblowing channel of record and log that you did so. Four: wherever students submit feedback, signpost that confidential channel explicitly, so a student with a serious report can choose a route that can actually protect and update them. This costs almost nothing and converts your largest, most-used feedback surface from a liability into an early-warning system. Institutions that also run workforce or customer research on the main Koji platform can apply the same detect-and-route discipline to any open-text channel, not just course evaluation.
Frequently asked questions
Does the EU Whistleblowing Directive apply to universities? Generally yes. Public and private entities with 50 or more workers must have internal reporting channels, and public bodies are covered, so most universities and large VET providers fall within scope.
Can a course-evaluation comment count as a protected disclosure? It can. Protection under the Directive attaches to a reporter who reasonably believes the information is true and within scope, regardless of the channel used - so a qualifying report made through an evaluation form can be protected.
What kinds of report fall within the Directive's scope? Breaches of Union law in defined areas including public procurement, financial services and money laundering, product and transport safety, environmental protection, public health, consumer protection, data protection and network security, and the EU's financial interests.
Is a course-evaluation survey a compliant whistleblowing channel? No, and it does not need to be. The compliance obligation sits with your dedicated confidential channel. The risk is failing to recognise a protected disclosure that arrives via evaluation data and route it appropriately.
Why is an anonymous comment box a particular problem here? Because you often cannot contact the reporter to acknowledge the report within seven days or provide the three-month feedback the Directive expects, and you cannot extend the reporter the protections it promises. Full anonymity can leave both student and institution exposed.
How should quality teams handle this in practice? Detect comments that touch the Directive's subject areas, review them individually, route genuine disclosures to the confidential channel of record, and signpost students to that channel - while avoiding over-escalating ordinary teaching complaints.