Course Evaluation Data Retention: How Long to Keep Records for Audit and Accreditation
A practical, GDPR-aligned records-management guide for QA teams: how long to keep course evaluation data, how to reconcile storage limitation with the multi-year evidence accreditors expect, and a two-tier retention model with a worked schedule.
Koji Education Team
Product
Short answer: Keep course evaluation data in two tiers. Anonymised aggregate results and closing-the-loop action logs contain no personal data, fall outside the GDPR, and can be kept indefinitely as longitudinal accreditation evidence. Raw individual-level responses and verbatim free-text comments are personal data, are governed by the storage-limitation principle, and should be kept for a short, defined window — long enough to investigate and act, typically one to two academic years or one review cycle at most — then anonymised or deleted. This guide explains why, maps the GDPR mechanics, and gives you a retention schedule you can adopt.
The tension every QA office has to resolve
Two legitimate obligations pull in opposite directions.
On one side, data protection law demands you keep personal data no longer than necessary. Article 5(1)(e) of the GDPR — the storage limitation principle — states that personal data must be kept "for no longer than is necessary for the purposes for which the personal data are processed." Article 5(1)(c) (data minimisation) reinforces it. A retention period is not optional: under Article 30(1)(f) it must be documented in your Record of Processing Activities.
On the other side, quality assurance and accreditation reward longitudinal evidence. External review cycles under the Standards and Guidelines for Quality Assurance in the European Higher Education Area (ESG 2015) typically run on multi-year cycles, and ESG Standard 1.7, Information management, expects institutions to "collect, analyse and use relevant information for the effective management of their programmes." Programme review and revalidation panels want to see a trend across cohorts — a concern raised, an action taken, an outcome measured three years later. That is impossible if you deleted the evidence to satisfy storage limitation.
The resolution is not to choose one obligation over the other. It is to recognise that the two obligations apply to two different kinds of data, and to keep each accordingly.
What actually counts as personal data in course evaluation
"Anonymous survey" is doing a lot of work in most policies, and it is often wrong. Data can be personal even without a name attached:
- Re-identification in small cohorts. In a seminar of six students, "the only mature student" or a distinctive combination of demographic filters can single out a respondent. Small-N evaluation data is frequently personal data in practice.
- Free-text comments about the respondent. Students disclose disabilities, personal circumstances, and complaints in open-text boxes. That content is personal data about the author.
- Free-text comments about staff. A comment naming a lecturer is personal data about that lecturer, with employment-law and fairness implications entirely separate from the student's anonymity. You cannot keep an identifiable negative comment tied to a named individual indefinitely without a lawful basis and a defensible purpose.
Only once data is genuinely anonymised — aggregated so that no individual (student or staff) can be singled out, linked, or inferred — does it fall outside the GDPR. As regulators note, anonymisation lifts the restriction, but it must resist singling-out, linkability and inference. Weak "pseudonymisation" (dropping the name but keeping the free text and the module, date and cohort) is not anonymisation and stays in scope.
The GDPR mechanics that make long retention lawful
You do have a lawful route to keep evaluation evidence for years — provided you use it deliberately:
- Article 89(1) — archiving, research and statistics. Longer retention is permitted for archiving in the public interest, scientific/historical research, and statistical purposes, with the safeguards in Article 89(1) (data minimisation, and where possible pseudonymisation or anonymisation). Quality enhancement and accreditation evidence generally sit comfortably in the statistical/archiving frame — but the safeguards are the price of admission.
- Anonymisation as the clean exit. The most robust long-term store is anonymised aggregate data: it is outside the GDPR entirely, so no retention limit applies and it can back a decade of trend reporting.
- Article 17 — erasure. Retaining raw personal data past its defined window without an Article 89 basis exposes you to erasure requests you cannot lawfully refuse.
- Article 30(1)(f) — accountability. Whatever you decide, it must be written into your ROPA and your institutional retention schedule.
For sector-specific benchmarks, the JISC Business Classification Scheme and Records Retention Schedule for HE/FE is the widely adopted reference; many UK institutions base their own retention schedules on it, and it explicitly cross-references data-protection law. Use it — or your national equivalent — rather than inventing periods from scratch.
A two-tier retention model you can adopt
| Data type | Contains personal data? | Recommended retention | Basis / safeguard |
|---|---|---|---|
| Anonymised aggregate results (mean scores, response rates, theme frequencies) | No | Indefinite / life of the programme | Outside GDPR once genuinely anonymised |
| Closing-the-loop action logs (issue → action → outcome) | No, if de-identified | Indefinite / across review cycles | Core accreditation evidence; keep long-term |
| Raw individual quantitative responses | Yes (esp. small cohorts) | 1–2 academic years, or one review cycle max | Storage limitation; Art 89 safeguards if extended |
| Verbatim free-text comments (student-authored) | Yes | Short window for analysis, then anonymise/delete | Minimisation; redact before any archiving |
| Comments naming or identifying staff | Yes (staff personal data) | Shortest defensible window; restricted access | Employment-law + fairness; lawful basis required |
| Reports and SER extracts used in accreditation | Aggregated only | Length of accreditation cycle + one | Archiving; ensure no re-identifiable detail |
The operating principle: let the personal layer expire, keep the anonymised layer forever. You analyse raw responses and comments while they are fresh, extract the themes and actions, anonymise or delete the raw layer on schedule, and carry the aggregated evidence and action logs forward across cohorts.
Mapping the requirement to concrete outputs
Accreditation and audit reviewers ask specific questions. Here is how a well-run evaluation process answers each with retention-appropriate evidence:
| Reviewer expectation | Evidence to retain | Retention tier |
|---|---|---|
| "Show feedback collected over several cohorts" | Anonymised aggregate trend series | Long-term (outside GDPR) |
| "Show you acted on what students said" | Closing-the-loop action log | Long-term |
| "Show the qualitative substance, not just averages" | Anonymised, redacted theme summaries with representative (de-identified) quotes | Long-term after redaction |
| "Show you comply with data protection" | Retention schedule, ROPA entry, DPIA where required | Governance records |
| "Show individual-level rigour when queried" | Raw responses within the current window only | Short-term |
A platform such as Koji helps on the tiering itself: AI-moderated interviews are captured, automatically analysed into themes, and the actions recorded in a closing-the-loop log — so the durable, anonymisable evidence (themes + actions + trends) is separated by design from the transient raw layer. Koji is EU-hosted with GDPR-aligned handling, and shares its AI interview engine with the main Koji research platform. The tool does not absolve you of a retention policy — it makes the two-tier split operationally realistic instead of a manual annual purge.
A practical checklist
- Write it down. A course-evaluation retention schedule, referenced from your ROPA, benchmarked against JISC (or your national schedule).
- Define the window for raw responses and comments — pick a defensible period (commonly one to two academic years) and stick to it.
- Anonymise on a calendar, not on request. Automate the purge/anonymisation of the raw layer.
- Redact staff-identifying comments before anything is archived or shared beyond the immediate line-management purpose.
- Keep the aggregate and action layers as your permanent accreditation record.
- Treat small cohorts specially — apply minimum-N thresholds before any reporting or retention.
- Run a DPIA where evaluation processing is likely high-risk (Article 35), and document the outcome.
Retention periods vary by jurisdiction
The two-tier model is portable across Europe, but the specific periods and the regulator you answer to are not. In Poland, retention decisions sit under the 2018 Data Protection Act and the oversight of UODO (Urząd Ochrony Danych Osobowych), alongside the internal quality-assurance evidence that PKA expects. In Germany, federal BDSG rules interact with sixteen state data-protection acts and a strong self-hosting culture, so retention schedules are often stricter and locally hosted. In the UK, the ICO enforces UK GDPR and the JISC schedule is the de facto benchmark. The common thread: set your window against your national regulator and records schedule, not a generic default — and record the reasoning. A period that is defensible in one member state is not automatically defensible in another.
The bottom line
Storage limitation and accreditation evidence are not in conflict once you stop treating "course evaluation data" as one undifferentiated pile. Keep the personal layer briefly and purposefully; keep the anonymised aggregate and action layer indefinitely. Do that, and you can satisfy a data-protection audit and a programme review panel with the same, well-governed evidence base.
Frequently asked questions
How long should we keep course evaluation data? Use two tiers. Anonymised aggregate results and closing-the-loop action logs contain no personal data and can be kept indefinitely as accreditation evidence. Raw individual responses and verbatim comments are personal data and should be kept for a short defined window — commonly one to two academic years or one review cycle at most — then anonymised or deleted, unless an Article 89 archiving basis with safeguards applies.
Does GDPR storage limitation stop us keeping evidence for accreditation? No, as long as you separate the layers. Storage limitation (Article 5(1)(e)) governs personal data. Genuinely anonymised aggregate data falls outside the GDPR entirely, so it can back a decade of trend reporting for accreditation. Keep the personal layer briefly; keep the anonymised layer long-term.
Are anonymous course evaluations really personal data? Often, yes. In small cohorts a respondent can be singled out by role or demographic filters; free-text comments can identify the student who wrote them or name a staff member. Only genuine anonymisation — resistant to singling-out, linkability and inference — removes data from GDPR scope. Dropping the name while keeping the comment, module and cohort is not anonymisation.
How should we handle free-text comments that name a lecturer? Treat them as personal data about that staff member, with employment-law and fairness implications. Keep them for the shortest defensible window, restrict access to the relevant line-management purpose, and redact staff-identifying detail before any archiving or wider sharing. Do not retain identifiable negative comments indefinitely without a lawful basis.
What retention standard should a university benchmark against? The JISC Business Classification Scheme and Records Retention Schedule for HE/FE is a widely adopted reference that cross-references data-protection law; many institutions base their schedules on it. Use it or your national equivalent, document your periods in the Record of Processing Activities (Article 30(1)(f)), and confirm with your DPO and accreditation body.
Related Resources
- Institution-level evaluation reporting for QA audit evidence
- Student feedback as ESG accreditation evidence
- Programme review and revalidation evidence
- The self-evaluation report (SER) evidence guide
- EU AI Act and course evaluation software compliance
This guide is general information on records management and data protection, not legal advice. Confirm retention periods with your Data Protection Officer and against your national regulator (for example UODO, the ICO, or your local DPA) and accreditation body.
Related articles
Turning Student Feedback into ESG / ENQA Accreditation Evidence
A buyer's guide mapping the ESG 2015 internal quality assurance standards to concrete, accreditation-ready evidence you can generate from student feedback — and how AI-moderated evaluation closes the loop.
The EU AI Act and Course Evaluation Software: What European Universities Actually Have to Do
Course evaluation is usually not an Annex III high-risk use of AI. The obligations that genuinely bite are Article 50 transparency (2 August 2026, not deferred), Article 4 AI literacy, and the GDPR. A procurement-ready guide with a requirement-to-evidence mapping.
Institution-Level Evaluation Reporting for Quality Audits: Building Longitudinal, Cross-Programme Evidence
A buyer's guide to turning course-evaluation data into institution-level evidence for ESG-aligned quality audits and institutional review — mapping ESG Part 1 and Part 2 expectations to concrete, longitudinal, cross-programme outputs.
The Self-Evaluation Report (SER): Turning Course Evaluation Evidence into Accreditation-Ready Documentation
The self-evaluation report is the central document in almost every European programme accreditation and periodic review. This buyer's guide maps SER sections to ESG standards and shows how to turn student and course evaluation data into evidence that survives an external panel.