New

Now in Claude, ChatGPT, Cursor & more with our MCP server

Back to blog
Sector trends8 min read

You Fixed Your GDPR Basis. Your Evaluation Tool Still Needs Cookie Consent.

Choosing public task over consent as your GDPR lawful basis was the right call. But it does nothing for the ePrivacy rule that governs the cookies your survey platform drops the moment a student loads the page — a separate regime, with its own regulator and nine-figure fines.

Koji Education Team

Product ·

Answer first: Getting your GDPR lawful basis right — running course evaluation on public task rather than consent — solves one legal question. It does not touch a second, entirely separate one. Under Article 5(3) of the ePrivacy Directive (2002/58/EC), storing or reading any information on a student's device that is not strictly necessary requires prior, informed consent — regardless of whether that information is personal data, and regardless of what GDPR basis you rely on for the survey itself. If your evaluation platform loads an analytics tag, an embedded video pixel, or a third-party font that sets a cookie before the student clicks anything, you likely have a compliance gap that your carefully-argued public-task assessment cannot close.

This is one of the most common and least-discussed mistakes in institutional evaluation procurement. Data-protection officers spend real effort deciding the GDPR lawful basis for processing student feedback — and rightly conclude, in most cases, that consent is the wrong basis for a mandatory quality-assurance process (we argued exactly that in our piece on why "we need your consent" is the wrong basis for course evaluation). Then the same platform quietly sets a Google Analytics cookie on page load, and a different law — with a different regulator and different penalties — has already been broken.

Two laws, not one

The GDPR governs the processing of personal data. The ePrivacy Directive governs access to the user's terminal equipment — the phone or laptop in the student's hand. These overlap but are not the same. Article 5(3) requires that storing information, or gaining access to information already stored, in a user's device is "only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information." The only carve-out is for storage that is strictly necessary to provide a service the user has explicitly requested.

Two consequences follow that catch institutions out:

1. It applies even when there is no personal data. A cookie that stores an anonymous, rotating analytics ID still triggers Article 5(3), because the trigger is access to the device, not processing of personal data. You cannot reason your way out of it by arguing the cookie is anonymous. As one plain-language summary of the rule puts it, Article 5(3) applies "regardless of whether it constitutes personal data."

2. Consent is the only available basis — you cannot borrow your GDPR basis. Under GDPR you can process on public task, legitimate interest, contract, and four other bases. Under ePrivacy, for anything non-essential, consent is the only lawful basis available. You cannot set an analytics or advertising cookie on the strength of "legitimate interest" or "public task." This is the crux: the very reasoning that correctly removes consent from your survey processing does nothing for the cookies, because the cookies were never on the GDPR menu in the first place.

This is enforced, and the numbers are not small

It is tempting to treat cookie rules as a paperwork formality. Regulators disagree. France's data-protection authority, the CNIL, enforces Article 5(3) through Article 82 of the French Data Protection Act, and it has used it aggressively:

  • In December 2020, the CNIL fined Google a total of €100 million and Amazon €35 million for placing advertising cookies on users' devices before obtaining consent (CNIL / Conseil d'État).
  • In December 2021, it fined Google €150 million and Facebook €60 million for making it harder to refuse cookies than to accept them (privacylaws.com).
  • In September 2025, it fined Google €325 million and Shein €150 million in a further cookie-enforcement action (France 24).

Universities are not Google, and no regulator is hunting for a modest analytics cookie on a Dutch or German evaluation portal. But the point is not the size of the fine you personally risk; it is that the regime is real, actively enforced, and structurally separate from GDPR. A university that has told its academic board "our evaluation processing is lawful" has answered only half the question if it has not also looked at what its evaluation tool loads onto the student's browser.

Where evaluation platforms actually trip

The gap is rarely a deliberate tracking strategy. It is almost always inherited plumbing:

  • Embedded analytics — Google Analytics, Hotjar, or a similar tag added "to see completion rates," firing on page load before any consent interaction.
  • Third-party fonts and CDNs that set cookies or expose IP addresses on load.
  • Embedded media — a welcome video from YouTube's standard (non-privacy) domain sets cookies the instant the page renders.
  • Marketing/session tools carried over from the vendor's commercial website into the survey subdomain.

None of these are "strictly necessary" to run a course evaluation. All of them, on a strict reading of Article 5(3), require prior consent — which a mandatory, public-task evaluation process is specifically trying to avoid having to collect.

The strongest counterargument

"Surely a functional survey needs cookies to work — aren't those exempt?" Some are, and this is the honest nuance. A session cookie that remembers a student's place in a multi-page questionnaire, or a security token that prevents double-submission, is a strong candidate for the strictly necessary exemption, because it is essential to a service the user explicitly requested. The ePrivacy consent requirement is not a demand for a banner on every page; it is a demand that non-essential storage be consented to. The correct response is therefore not panic but classification: inventory every cookie and tag your evaluation tool sets, separate the genuinely essential from the analytical and third-party, and either drop the non-essential ones or gate them behind real consent. The mistake is not "using cookies" — it is never having done the inventory because everyone assumed GDPR was the only law in play.

A second fair objection: "The ePrivacy Regulation was supposed to replace this — isn't the Directive obsolete?" The long-delayed ePrivacy Regulation has still not been adopted, and the 2002 Directive (as amended in 2009) remains the law in force across the EU. Planning compliance around a regulation that may never arrive is not a strategy.

What good looks like — and where Koji fits

The defensible posture is a platform that is clean by design: it sets only what is strictly necessary to run the evaluation, and it does not import commercial tracking into the space where students give feedback. When we built Koji for Education, the principle was that a mandatory, EU-appropriate evaluation process should not create a second legal problem the moment the page loads. That means no advertising or cross-site tracking cookies in the respondent experience, EU-appropriate data handling that keeps the ePrivacy and GDPR stories consistent rather than contradictory, and a data-processing posture your DPO can actually reconcile with the public-task basis you chose.

Koji's AI-moderated conversational interviews change what the evaluation is — probing beyond a Likert number, running automatic thematic analysis of open-text feedback, and surfacing themes with traceable provenance — but the relevant point here is narrower: the tool should not quietly undermine the legal basis you worked to establish. (The same conversational interview engine powers the main koji.so platform for teams doing general user and customer research, where the identical cookie-hygiene logic applies to respondents.)

Koji does not eliminate your compliance obligations — no vendor can, and any that claims to should be treated with suspicion. Your institution remains the controller; the DPIA, the record of processing, and the cookie inventory are still yours to own. What a well-designed platform does is reduce the surface area: fewer non-essential trackers to consent to, fewer contradictions between your two legal regimes, and fewer nasty surprises when someone finally opens the browser developer tools on your evaluation portal.

The one-paragraph version for your DPO

Your GDPR lawful-basis analysis and your ePrivacy cookie analysis are two different documents answering two different questions. Public task can be the correct basis for the survey and you can still be non-compliant on cookies. Before your next evaluation cycle, ask your vendor for a full list of every cookie and third-party tag their tool sets on page load, classify each as strictly-necessary or not, and drop or gate the rest. If the vendor cannot produce that list, that itself is the finding.

Frequently asked questions

Does choosing public task as our GDPR lawful basis cover our cookies? No. GDPR lawful basis governs the processing of personal data; the ePrivacy Directive (Article 5(3)) governs access to the user's device. Non-essential cookies require consent under ePrivacy regardless of your GDPR basis — consent is the only ePrivacy basis available for them.

Does ePrivacy apply even if the cookie holds no personal data? Yes. Article 5(3) is triggered by storing or accessing information on the user's terminal equipment, not by whether it is personal data. An anonymous analytics ID still requires prior consent unless it is strictly necessary.

Are any cookies exempt from the consent requirement? Yes — those strictly necessary to deliver the service the user requested, such as a session cookie remembering progress through a multi-page survey or a token preventing double submission. Analytics and most third-party tags are not.

How is the cookie rule actually enforced? By national regulators. France's CNIL has fined organisations for setting cookies without consent: €100m (Google) and €35m (Amazon) in 2020, €150m (Google) in 2021, and €325m (Google) plus €150m (Shein) in 2025.

What should we ask our evaluation vendor? For a complete list of every cookie and third-party tag their tool sets on page load, before any student interaction. Classify each as strictly necessary or not, and drop or consent-gate the rest. If they cannot produce that list, that is itself your finding.

Does the coming ePrivacy Regulation change this? Not yet — it is not in force. The 2002 Directive (amended 2009) remains the applicable law across the EU.


Running a course-evaluation cycle and want a platform whose respondent experience does not create a second compliance problem? See how Koji for Education handles feedback the EU-appropriate way.