New

Now in Claude, ChatGPT, Cursor & more with our MCP server

Back to blog
Sector trends9 min read

The GDPR Blind Spot: Special-Category Data Hiding in Your Free-Text Course Feedback

Open-text student comments routinely contain health, religion, sexual-orientation and other Article 9 special-category data — often without anyone intending it. Why that is a compliance risk most evaluation systems ignore, and how to handle it responsibly.

Koji Education Team

Product ·

Bottom line up front: Every institution that collects open-text course feedback is almost certainly processing special-category personal data under Article 9 of the GDPR — health, religion, sexual orientation, ethnicity, disability, political opinion — without a deliberate decision to do so. It arrives incidentally, in a student sentence like "I have ADHD and the pace made it impossible" or "as a disabled student I could not access the labs." Most evaluation platforms treat all free text as ordinary data. That is a defensible-looking assumption that does not survive contact with either the regulation or the reality of what students write.

The mechanism: special-category data by content, not by field

Under Article 9 GDPR, processing of personal data "revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and… data concerning health or… a natural person's sex life or sexual orientation" is prohibited unless a specific condition applies. Crucially, the UK Information Commissioner's Office is explicit that this category is defined by content and inference, not by which box a form put the data in: as the ICO guidance on special category data sets out, if you can infer a special characteristic from the information, you are processing special-category data and need both a lawful basis under Article 6 and a separate condition under Article 9.

A free-text course-evaluation field is, in effect, an unstructured intake for exactly this material. Students disclose disability to explain an accessibility barrier, mention mental-health conditions to contextualise workload, reference religious observance to explain a scheduling clash, or reveal ethnicity or nationality when describing an experience of exclusion. None of this is pathological — it is often the most useful feedback a programme receives. But it converts an apparently mundane comments box into a repository of Article 9 data.

Why "they chose to write it" does not rescue you

The instinctive defence is that the student volunteered the information, so surely consent or the "manifestly made public" exemption covers it. Both routes are weaker than they look.

First, the exemption in Article 9(2)(e) for data "manifestly made public by the data subject" is narrowly construed. As legal scholarship on the provision notes, it requires a free, deliberate and informed act by which the person realised the data would be made public — and it explicitly excludes data shared unintentionally, inadvertently, or in a context the person believed to be confidential. A student typing a disability into an "anonymous" evaluation box has done the opposite of manifestly publishing it.

Second, consent under the GDPR must be specific, informed and freely given. A generic "your feedback helps us improve" notice does not constitute informed consent to process health or sexual-orientation data, and the power asymmetry between an institution and its students makes "freely given" consent contested terrain in any case. Relying on implied consent for Article 9 data is precisely the posture regulators warn against.

The anonymity illusion

Institutions often reassure themselves that evaluation is anonymous, so data-protection duties are light. Two problems. First, special-category data is protected regardless of identifiability where it can still be linked to an individual — and free-text comments are notoriously re-identifying. A single sentence naming a small seminar, a disability and a nationality can pick out one specific student in a cohort of twelve. Second, "anonymous" is a high legal bar the GDPR treats as data rendered irreversibly non-identifiable; most so-called anonymous evaluation is really pseudonymous or merely de-identified, which remains in scope. We have written before on the gap between anonymity and confidentiality in course evaluation — and Article 9 data is where that gap bites hardest.

But isn't this over-lawyering a comment box?

The strongest counterargument is pragmatic: universities have collected paper evaluation comments for decades without incident, so treating a free-text field as a compliance hazard is disproportionate — a lawyer's anxiety, not a real risk. This deserves engagement rather than dismissal.

It is true that the probability of harm from any single comment is low. But three things have changed. The scale is now different: digital evaluation aggregates thousands of comments into searchable, exportable, long-retained datasets, where paper forms were dispersed and ephemeral — and data-retention duties under the GDPR apply to every one of them. The processing is now different: institutions increasingly run these comments through AI summarisation and analytics, which is itself a form of Article 9 processing that a filing cabinet never performed. And the accountability standard is now different: the GDPR requires you to demonstrate compliance, not merely avoid incidents. "We never had a complaint" is not a defence the regulation recognises. So the point is not that comment boxes are dangerous; it is that unmanaged, indefinitely-retained, AI-processed special-category data is a liability that the paper era never created.

The overlooked chain: processors, transfers and profiling

Article 9 obligations do not stop at your own servers. If your evaluation platform acts as a data processor, the special-category status flows to it and to every sub-processor and hosting region it relies on — which is why the location of processing and any third-country transfer matters as much as the comment itself. And where sensitive disclosures are fed into automated analysis that scores, ranks or profiles individuals, you may also engage the GDPR's rules on automated decision-making. The practical test is blunt: can you name, today, every system that touches a student's disclosed disability, and justify each one? If not, the comments box has quietly extended your processing further than your compliance documentation reaches.

What responsible handling looks like

The goal is not to stop students disclosing — that feedback is valuable and sometimes the only route by which an accessibility failure surfaces. The goal is to process it lawfully and proportionately:

  • Recognise it exists. Map open-text evaluation as a potential Article 9 processing activity in your record of processing and your data-protection impact assessment, rather than pretending the comments box is ordinary data.
  • Establish a condition and safeguards. Identify a valid Article 9 condition (for many institutions, a substantial-public-interest or education-function basis, defined in national law) and document the appropriate policy and safeguards it requires.
  • Minimise and retain briefly. Apply storage limitation deliberately; special-category data should not sit in an evaluation archive for years by default.
  • Control secondary processing. Any AI analysis of comments must be inside your lawful basis, transparent to students, and covered by your impact assessment — not a quietly-added feature.
  • Be honest in the notice. Tell students their comments may contain sensitive information, how it is handled, and how long it is kept. Informed disclosure is both a legal requirement and a trust-builder.

How Koji handles it

Koji for Education is built for EU deployment, with GDPR- and AVG-appropriate data handling as a design premise rather than a bolt-on. Its AI-moderated interviews collect rich qualitative feedback while its automatic thematic analysis operates within a defined, documented processing basis — so the analytics that make open text useful are not an unmanaged secondary use. Because the moderation is standardised and configurable, institutions can shape how sensitive disclosures are prompted for, surfaced and retained, and apply storage limitation deliberately rather than hoarding comment archives indefinitely. Koji does not make the Article 9 question disappear — no tool can, because the obligation attaches to your processing — but it replaces an unaudited comments box with a system designed to be documented, minimised and defensible. The same engine underpins general research on the main Koji platform, where handling sensitive disclosures lawfully is an equally central concern.

The takeaway

The special-category data in your course feedback is not hypothetical; it is already there, written by students who trusted you with it. The regulatory failure is not that they disclosed — it is treating that disclosure as ordinary data, retaining it indefinitely, and running it through analytics no one mapped. Article 9 is not an obstacle to good evaluation. It is a prompt to handle your most sensitive, most useful feedback with the care it was given in.

Want course evaluation built for EU data protection from the ground up? Explore Koji for Education.