When a Lecturer Files a Subject Access Request for the 'Anonymous' Comments About Them
You promised students their comments were anonymous. Then the lecturer they were about files a GDPR Article 15 request to see them. That collision is where most evaluation privacy promises quietly break.
Koji Education Team
Product · August 8, 2026
Bottom line up front: Free-text course-evaluation comments are personal data about two people at once — the student who wrote them and the lecturer they describe. When that lecturer submits a GDPR Article 15 subject access request, the institution must give them a copy of their personal data, and the comments about their teaching are their personal data. The promise you made to students — "your feedback is anonymous" — now collides head-on with a legal right, and the outcome is governed by Article 15(4), the rule that access must not adversely affect the rights and freedoms of others. Most institutions have never worked out where that line falls, and discover it during a dispute.
The collision, precisely
Two GDPR facts sit in tension.
Under Article 15, a data subject has the right to obtain confirmation that their data is processed and a copy of that data. The Court of Justice confirmed in Case C-487/21 (Österreichische Datenschutzbehörde, 4 May 2023) that the "copy" must be a faithful and intelligible reproduction — the right is substantive, not a formality. A lecturer asking to see what students wrote about them is squarely exercising this right.
But Article 15(4) provides that the right to obtain a copy "shall not adversely affect the rights and freedoms of others," and Recital 63 adds that the right of access should not adversely affect the rights of others, including trade secrets or intellectual property. The student who wrote the comment is one of those "others." Their identity — and often their words, which can identify them by content or writing style — is protected.
The result is not a clean win for either side. As data-protection authorities and commentators consistently note, Recital 63 and Article 15(4) are not a blanket exemption. In its opinion in Case C-634/21, the Advocate General stressed that the rights of others cannot be used to refuse all information; a minimum must still be delivered. So an institution cannot simply say "it is anonymous, request denied." It has to do the hard thing: disclose the substance of the personal data about the requester while protecting the identity and rights of the students who authored it.
Why "anonymous" was usually a promise you could not keep
The deeper problem is that most evaluation "anonymity" is really confidentiality, and often not even that. If your system can, in principle, connect a comment to a student — through login, timestamp, small cohort size, or the sheer specificity of the text — it is not anonymous in the GDPR sense; it is pseudonymous personal data. We have written before about how true anonymity is a high and often unmet bar, and how free text can re-identify its author stylometrically even when names are stripped. A subject access request is the moment that gap becomes concrete: the "rights of others" you must protect are only genuinely protectable if the comment cannot be traced back to a specific student — and in a seminar of nine, a comment naming a specific incident traces itself.
This is compounded when free text carries special-category data under Article 9 — a student disclosing a disability or religious observance while critiquing a scheduling decision — which raises the protection owed to the author even further.
But surely the lecturer just gets the comments? The counterargument
The strongest objection runs the other way: the lecturer has an unambiguous statutory right, teaching feedback is manifestly their personal data, transparency in employment matters is important, and over-redacting to protect students amounts to the institution unlawfully withholding data the requester is entitled to. Refusing access, on this view, is the real breach.
This is a serious argument and it is partly correct — which is exactly why the situation is hard rather than one-sided. The lecturer is entitled to the substance: what was said about their teaching, so they can understand and if necessary contest how they are being evaluated (a concern that sharpens when those comments feed automated or scored decisions about faculty). What they are not automatically entitled to is the identity of the student author, where disclosing it would adversely affect that student's rights. The lawful path is neither "disclose everything" nor "disclose nothing"; it is a documented, case-by-case balancing that releases the content while protecting the source — redacting identifying detail, aggregating where a single comment is too identifying, and recording the reasoning. Guidance from authorities such as the ICO on requests involving other people's data is consistent: you cannot use third-party rights as a reason to refuse outright, but you must weigh them, and you should apply a consistent, reasoned policy.
What defensible evaluation looks like
To survive a subject access request without breaking either the law or your word to students, an institution needs to: stop promising "anonymity" it cannot deliver and describe the real position honestly (confidential, access-limited, with disclosure caveats); design free-text collection so comments are less inherently identifying; be able to separate the substance of feedback from identifying detail; and have a documented Article 15(4) balancing process ready before the first request lands, not improvised during a grievance.
Koji for Education helps mainly by changing the shape of the data you would have to hand over. Its automatic thematic analysis produces an aggregated, theme-level layer — "several students raised pacing concerns" — that conveys the substance of feedback about a lecturer without exposing any single student's verbatim, identifying words, which is often the more disclosable form under an Article 15(4) balance. Its structured question types and standardised, bias-aware AI moderation steer feedback toward specific, behaviour-focused observations and away from the identifying, incident-specific detail that makes redaction impossible. Quality scoring helps surface and manage the low-signal, high-risk comments that cause the worst disputes. And honest, GDPR/AVG-aware framing lets you tell students the truth about confidentiality rather than an over-promise. Koji reduces the collision risk and gives you a more disclosable evidence layer; it does not make comments legally anonymous, does not decide the balancing test for you, and does not remove your obligation to respond to a valid access request. Where genuine anonymity is required, that remains a deliberate design and legal decision.
The same conversational engine powers the main Koji platform, where research teams manage participant data under the same access-rights discipline.
The takeaway
The subject access request is the stress test every evaluation privacy promise eventually faces. "Anonymous" is the wrong promise if your system cannot keep it; the right posture is honest confidentiality plus a designed-in ability to release the substance of feedback while protecting the student who gave it. Decide how you will run the Article 15(4) balance before a lecturer forces the question — because one of them eventually will.
Frequently asked questions
Can a lecturer request to see anonymous student comments about them under GDPR? Yes. Comments about a lecturer's teaching are that lecturer's personal data, so an Article 15 subject access request generally entitles them to the substance of those comments. It does not automatically entitle them to the identity of the student author, which is protected under Article 15(4) where disclosure would adversely affect the student's rights.
Does Article 15(4) let an institution refuse the request outright? No. Article 15(4) and Recital 63 protect the rights and freedoms of others but are not a blanket exemption. Authorities and CJEU opinions are clear that a minimum of information must still be provided; the institution must disclose the substance while protecting third-party identity, through a documented balancing exercise.
Is course-evaluation free text really personal data about two people? Usually yes. The text is personal data about the lecturer it describes and about the student who wrote it — especially where login, timestamp, small cohort size or distinctive content makes the author identifiable. That dual character is what creates the access-versus-anonymity tension.
Why is promising anonymity risky? Because most evaluation systems deliver confidentiality, not true anonymity: if a comment can in principle be linked to a student, it is pseudonymous personal data. A subject access request exposes the gap, and an over-promise of anonymity can become a broken promise or an unlawful refusal.
How does Koji reduce the risk? Koji's thematic analysis produces an aggregated, theme-level layer that conveys feedback substance without a student's identifying verbatim, and its structured, bias-aware moderation steers comments toward behaviour-focused observations that are easier to disclose safely. It reduces collision risk and improves disclosability, but does not make comments legally anonymous, decide the balancing test, or remove the duty to answer a valid request.