New

Now in Claude, ChatGPT, Cursor & more with our MCP server

Back to blog
Sector trends9 min read

NIS2 and Course Evaluation: The Security Duty GDPR Doesn't Cover

GDPR governs whether you may hold student feedback. NIS2 governs whether you can keep it secure and available - and since October 2024 it makes senior management personally accountable. Why the platform holding your sensitive free-text comments is now a board-level question.

Koji Education Team

Product ยท August 2, 2026

Most universities treat the compliance status of their course-evaluation system as a settled question: it is GDPR-compliant, the data-protection officer has signed off, done. That answer is now incomplete. Since 18 October 2024, a second European regime applies to many higher-education institutions - the NIS2 Directive - and it asks a different question. GDPR asks whether you are allowed to hold student feedback. NIS2 asks whether you can keep the systems that hold it secure, available, and recoverable - and it puts that duty on senior management personally, not just on IT.

The short version: if your institution falls within NIS2 scope, the platform storing your students' free-text comments is part of the "network and information systems" you are now legally required to secure, monitor, and be able to report on when something goes wrong. A weak evaluation vendor is no longer only a privacy risk. It is a governance and supply-chain risk that a management board can be held accountable for.

What NIS2 actually is

The Network and Information Security Directive 2 - Directive (EU) 2022/2555 - replaced the original 2016 NIS Directive and set a transposition deadline of 17 October 2024, with national rules applying from 18 October 2024 (European Commission, Shaping Europe's Digital Future). It is worth being honest that transposition has been uneven: several member states missed the deadline and were still legislating well into 2025, so the exact rules that bind your institution depend on your national implementing law, not the Directive text alone.

NIS2 sorts in-scope organisations into essential entities (Annex I) and important entities (Annex II). Crucially for universities, research is named as a sector in Annex II. An organisation in an Annex II sector that meets the "medium enterprise" threshold - 50 or more staff, or annual turnover above EUR 10 million - is classified as an important entity (Legiscope, NIS2 essential vs important entities). Most public universities are an order of magnitude above that threshold, and several member states have used the Directive's discretion to bring the broader education sector into scope explicitly.

The honest caveat: NIS2 does not automatically capture every course you run or every small college. Whether a specific institution is in scope, and as which type of entity, is a function of national transposition and any national designation decisions. This is a question for your CISO and legal team, not a blog post. But the direction of travel is unambiguous - a large research-active university should assume it is in scope until told otherwise.

Why course evaluation is squarely inside this

It is tempting to file NIS2 under "critical infrastructure" and assume a feedback survey is beneath its notice. That misreads how the Directive works. The obligation attaches to the entity, not to individual systems. Once your institution is an important entity, Article 21 requires "appropriate and proportionate technical, operational and organisational measures" across all the network and information systems you use for your operations (NIS2 Directive, Article 21). Article 21 lists ten minimum measures, including risk-analysis policies, incident handling, business continuity and backup, cryptography and encryption, access control and multi-factor authentication - and, decisively, supply-chain security.

That supply-chain clause is why your evaluation vendor is now your concern. Course-evaluation platforms hold two categories of unusually sensitive content: free-text comments that frequently contain special-category data under GDPR Article 9 - disclosures about health, religion, sexuality - and occasional safeguarding disclosures about harm. A breach or an extended outage of that system is not a trivial IT ticket; it is exactly the kind of event NIS2 is designed to prevent and, failing that, to surface.

And it must be surfaced fast. Article 23 sets a tiered incident-reporting timeline for any incident with significant impact: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within one month (Advisera, NIS2 reporting obligations). If your feedback vendor is compromised, that clock can start ticking for you.

The part that changes behaviour: personal accountability

Under Article 20, management bodies must approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for failures - and they must undergo training. Penalties are structured to match: important entities face fines of up to EUR 7 million or 1.4% of global annual turnover, and essential entities up to EUR 10 million or 2% (Mayer Brown, implementation of NIS2). This is what moves evaluation-platform security from a procurement footnote to a board-level line item.

"But we already do GDPR - isn't this the same thing?"

This is the strongest and most common objection, and it deserves a straight answer: no, and the difference is the point. GDPR governs the lawfulness and confidentiality of personal data - it asks whether you have a lawful basis, whether processing is fair, whether the data subject's rights are honoured. Its Article 32 does require "security of processing," which overlaps with NIS2. But NIS2 is broader and differently aimed. It governs the security and resilience of the systems themselves - availability and integrity, not just confidentiality; non-personal data as well as personal; and it layers on a governance regime (management accountability), a supply-chain regime (you must assess your vendors), and a standardised incident-reporting regime that GDPR does not impose in the same form. A system can be perfectly GDPR-compliant on paper and still be a NIS2 failure waiting to happen: unpatched, unmonitored, with no tested backup and no incident runbook. You can satisfy one regime and breach the other.

A second objection: "our evaluation data is not mission-critical, so a proportionate approach means we can ignore it." Proportionality is real - NIS2 explicitly allows measures to be scaled to risk - but proportionality is a reason to right-size controls, not to exempt a system holding special-category disclosures. The blast radius of that particular dataset is higher than its transaction volume suggests.

Where Koji fits - and where it does not

To be clear about the limits first: no vendor makes your institution NIS2-compliant. Compliance is an institutional programme spanning far more than one SaaS tool, and Koji is one control among many. What a well-built evaluation platform can do is stop itself from being the weak link and make your supply-chain due diligence easier.

Koji for Education is built EU-side, with data handling designed for European hosting and residency expectations (the data-sovereignty and Schrems II question is a close cousin of this one), encryption, and role-based access control - the concrete Article 21 measures your risk assessment will look for. Because Koji's AI moderation collects only what the evaluation needs, data minimisation shrinks the blast radius of any incident. And when you run a procurement exercise, the security posture that NIS2's supply-chain clause obliges you to check is exactly what a serious RFP for evaluation software should interrogate - documented, not asserted. The same secure conversational-interview engine underpins general user research on the main Koji platform, so the security model is not a bolt-on for education.

The takeaway is not alarmism. It is that "GDPR-compliant" is no longer a complete answer to "is our course-evaluation system safe to run?" NIS2 has added a resilience-and-accountability question on top, and the sensitivity of student free-text makes the evaluation platform a natural place for an auditor to look.

If you want to see how Koji handles security, EU data residency, and vendor due-diligence documentation for course evaluation, talk to the Koji for Education team - and bring your CISO.

Frequently asked questions

Does NIS2 apply to all universities? Not automatically. NIS2 names "research" as an Annex II sector, and organisations above the medium-enterprise threshold (50+ staff or over EUR 10 million turnover) are typically classified as important entities - which covers most public universities. But actual scope depends on your national transposition law and any designation decisions, so confirm with your legal and information-security teams rather than assuming.

How is NIS2 different from GDPR for course evaluation? GDPR governs the lawfulness and confidentiality of personal data; NIS2 governs the security, availability, integrity and resilience of the systems that hold it, plus supply-chain assurance, management accountability and standardised incident reporting. A system can be GDPR-compliant yet fail NIS2, and vice versa.

Why would a course-evaluation platform be in scope? Because NIS2 obligations attach to the entity across all its systems, and evaluation platforms hold unusually sensitive content - special-category free-text and occasional safeguarding disclosures. Article 21's supply-chain security measure means you must assess the security of the vendors that process such data on your behalf.

What are the incident-reporting deadlines? For a significant incident, Article 23 requires an early warning within 24 hours, a notification within 72 hours, and a final report within one month. A breach at your evaluation vendor can start that clock for your institution.

What can Koji do to help? Koji reduces the chance of being the weak link: EU-appropriate data handling, encryption, access controls, and data minimisation that shrinks the impact of any incident, plus the documented security posture your NIS2 supply-chain due diligence needs. It does not, by itself, make your institution compliant - that is a wider institutional programme.