New

Now in Claude, ChatGPT, Cursor & more with our MCP server

Back to blog
Sector trends9 min read

When a Student Discloses Harm in a Course Evaluation: The Safeguarding Duty Your Survey Was Never Designed For

Open-text feedback boxes occasionally receive things no evaluation form anticipated—disclosures of harassment, distress, or self-harm. Most survey processes have no plan for them. That is a duty-of-care and data-protection gap, not just an awkward edge case.

Koji for Education

Research & Editorial Team ·

Bottom line: Give students an anonymous free-text box and, sooner or later, someone will use it to disclose something serious: harassment by a staff member, sexual misconduct, acute distress, or thoughts of self-harm. Traditional course-evaluation pipelines are built to aggregate comments, not to notice one that needs a human response—and by the time an averaged thematic report reaches a committee weeks later, any window to help has closed. This is simultaneously a safeguarding obligation and a GDPR question about special-category data, and most universities have no defined pathway for it. Designing evaluation with disclosure in mind is now part of doing it responsibly.

The box that hears more than you asked

Course-evaluation forms ask about pace, clarity, and assessment. But an open comment field does not know its own topic. Students—especially when promised anonymity and given the first no-consequences channel they have encountered all term—sometimes write things that have nothing to do with pedagogy and everything to do with their safety: "the tutor made comments about my body," "I have not slept in a week and cannot cope," "something happened at the placement and I did not know who to tell."

These disclosures are rare per response but statistically inevitable at scale. A university collecting tens of thousands of evaluation comments a year will receive some. The question is not whether they arrive, but whether anyone is positioned to act when they do.

Why the standard pipeline fails exactly here

Conventional evaluation is optimised for the opposite of what a disclosure needs. It is:

  • Aggregated: individual comments are rolled into themes and counts, so a single urgent sentence is designed to be averaged away, not surfaced.
  • Delayed: reports are compiled after the collection window closes and reach committees weeks later—useless for an acute situation.
  • Deliberately de-identified: anonymity, the feature that makes honest disclosure possible, is also what can make follow-up support impossible if no safe re-contact route exists.
  • Unowned: it is nobody's explicit job to read raw comments for risk in real time. Analysts read for insight, not for safeguarding.

The result is a system that can receive a cry for help and file it under "qualitative feedback, Q7."

This is now a regulatory expectation, not just good manners

The clearest signal comes from the UK, where the Office for Students introduced Condition of Registration E6 on harassment and sexual misconduct, in force from 1 August 2025. E6 requires providers to maintain accessible ways for students to report and disclose harassment and sexual misconduct, and to have a fair, clear process for responding. A course-evaluation channel that routinely receives such disclosures but has no route to act on them sits uneasily beside that expectation.

While E6 is a UK instrument, the underlying principle is not UK-specific. Universities across Europe operate under a general duty of care to their students and, increasingly, under sector guidance and national frameworks that expect providers to take reasonable steps when they become aware of a risk of harm. "We collected it in a survey and did not read it in time" is not a defensible answer anywhere.

The GDPR dimension most teams miss

A disclosure of harassment, health, or distress is not ordinary feedback in data-protection terms—it is very likely special-category data under Article 9 of the GDPR (data concerning health, sex life, or, depending on content, other protected categories). That has three consequences:

  1. You are processing sensitive data whether you intended to or not. The lawful basis and safeguards you set for "course feedback" may not cover the health or safety information that lands in the box.
  2. Anonymity and duty of care can collide. Acting on a disclosure may require identifying or re-contacting a student, which an "anonymous" survey promised not to do. Resolving that tension needs to be designed in advance, not improvised.
  3. Retention and access matter more. Sensitive disclosures held in an evaluation dataset, readable by anyone with dashboard access and kept indefinitely, is a compounding risk under the storage-limitation and data-minimisation principles.

But won't screening comments for risk destroy the anonymity that makes feedback honest?

This is the central objection, and it is a real tension rather than a rhetorical one. Anonymity is what gives students the safety to be candid; anything that reads comments for identity or risk seems to threaten it.

The honest resolution is that these goals are reconcilable with careful design, not mutually exclusive. You can preserve response-level anonymity in reporting while still building a triage step that flags an at-risk comment and offers the student a route to support—for example, by surfacing signposting information ("if you need to talk to someone, here is how") at the point of disclosure, and by defining in advance who reviews flags and under what threshold. The alternative—choosing not to notice—does not protect students; it protects the institution's convenience at their expense. The goal is not surveillance of feedback; it is not being deaf to a disclosure you invited.

What responsible evaluation design looks like

  • Signpost at the point of collection. Tell students, before they write, where to go for wellbeing and reporting support, so the evaluation is not their only channel for a serious issue.
  • Define a triage pathway. Decide in advance who reviews flagged comments, how fast, and what the thresholds are—harm to self, allegations against staff, disclosure of misconduct.
  • Separate safeguarding from analytics. A disclosure should route to a named, trained human on a safeguarding path, not sit in the same queue as "the room was too cold."
  • Get the data-protection basis right. Treat potential special-category content explicitly in your privacy notice, retention schedule, and access controls—do not let it default to "general feedback."

The scale problem, and why it is getting worse

Two trends are enlarging this gap at once. First, universities are collecting more open-text feedback than ever, across more touchpoints—module surveys, mid-term pulses, placement reviews, micro-credential feedback—each an additional channel through which a disclosure can arrive. Second, the expectation to act is rising: regulators, students' unions, and the wider duty-of-care conversation increasingly treat "we didn't know" as a failure of system design rather than an excuse. The combination means the volume of potential disclosures is climbing while tolerance for missing them is falling. Manual review does not scale to this: no one can read every raw comment across every survey for risk, in time to matter, at a large institution. That is precisely why the triage question cannot be left to chance or goodwill. It has to be a designed capability—a defined threshold, a named owner, an agreed response time, and a technical layer that can distinguish "the seminar room was cold" from "I don't feel safe" and route the second to a human immediately. The institutions that get ahead of this will not be the ones with the strongest privacy disclaimers; they will be the ones who decided, in advance, what happens when the box hears something it was never designed to hear.

Where Koji fits

Koji for Education is a conversational, AI-moderated evaluation platform, and that architecture changes what is possible at the moment of disclosure. Because Koji interacts in real time rather than collecting a static form, it can respond at the point a concern is raised—surfacing appropriate signposting to institutional support and reporting routes rather than silently banking the comment for a report weeks later. Its automatic thematic analysis can distinguish a serious disclosure from routine feedback so it is not averaged into "Q7," making triage tractable at scale instead of dependent on an analyst happening to read the right row.

Koji is built for GDPR/AVG-compliant, EU-appropriate data handling, which is precisely the posture special-category disclosures demand—considered lawful basis, access control, and retention rather than sensitive content sitting indefinitely in an open dashboard. And because Koji's moderation is standardised, every student meets the same calibrated, supportive handling, not the luck of which staff member reads their comment first.

To be precise about the claim: Koji does not replace a university safeguarding team, and it should not. What it does is make sure a disclosure is noticed and routed rather than lost in aggregation—turning the evaluation channel from a liability into a safe first step toward the people who can actually help. Institutions that run wider research also use the same AI interview engine on the main Koji platform.

The uncomfortable truth is that if you invite students to write freely, you have already opened a disclosure channel—whether or not you meant to. The only real choice is whether you designed for what comes through it.

Building evaluation that handles disclosure responsibly? Talk to Koji for Education.