Your Course-Evaluation Archive Is a Research Asset — and the Data Governance Act Changed the Rules for Sharing It
Years of student feedback is a re-usable public-sector data asset. Since September 2023 the EU Data Governance Act sets conditions for re-using it and a framework for sharing it altruistically. Most universities have not noticed.
Koji Education Team
Product · August 8, 2026
Bottom line up front: A university sitting on a decade of course-evaluation responses is holding a research asset, not just a compliance liability. Since 24 September 2023 the EU Data Governance Act — Regulation (EU) 2022/868 — has set conditions for how public-sector bodies re-use protected data they hold, and created a formal framework for sharing data for altruistic (public-interest) research purposes. Universities are, for large parts of their activity, public-sector bodies. Most have GDPR-proofed their evaluation data for protection and never asked the adjacent question the DGA now forces: under what conditions may this data be re-used, by researchers or by the sector, at all?
What the Data Governance Act actually does
The DGA is not GDPR, and it is not the Data Act (Regulation (EU) 2023/2854, which governs switching and access to IoT and cloud data). As the European Commission and OECD summaries put it, the DGA establishes a Union framework to facilitate the re-use of certain public-sector data, to regulate data-intermediation services, and to enable data altruism — the voluntary sharing of data for the public good.
Three of its pillars matter for course evaluation:
Re-use of protected public-sector data (Chapter II). Public-sector bodies hold data that is protected — because it is personal, commercially confidential, or covered by IP. The DGA does not force disclosure, but where such data is made available for re-use, it sets conditions: they must be, in the regulation's own terms, non-discriminatory, transparent, proportionate and objectively justified. It also nudges bodies toward enabling re-use through privacy-preserving techniques (anonymisation, secure processing environments) rather than blanket refusal.
Data altruism (Chapter IV). The DGA creates a voluntary register of "recognised data altruism organisations" that collect and share data for public-interest purposes — including scientific research — under explicit, informed consent and a common EU consent form, with a designated competent authority in each Member State supervising them.
Data intermediation services (Chapter III). A notified, neutral class of intermediaries that broker data-sharing without themselves monetising the data, designed to build trust between data holders and users.
Why this lands on the evaluation office
Course-evaluation data is unusually valuable to researchers: it is longitudinal, structured, tied to programmes and cohorts, and speaks directly to teaching quality, student experience and — when linked to outcomes — the effectiveness of higher education itself. Education researchers, quality-assurance scholars and policy analysts would legitimately like access to it. The DGA changes the framing of that request in two ways.
First, it makes re-use a first-class governance question rather than an afterthought. The instinct of a GDPR-anxious institution is to lock everything down. The DGA's posture is different: for public-sector data, the presumption tilts toward enabling well-governed re-use through safeguards, not toward reflexive refusal. An institution that cannot articulate the conditions under which its evaluation data may be re-used is now out of step with the direction of EU data policy.
Second, it gives structure to something universities already flirt with — sharing feedback data for sector research, benchmarking consortia or public-good studies — and says: if you do this, do it through recognised, supervised, consent-based channels, not ad hoc data-sharing agreements drafted by whoever picked up the phone.
But doesn't GDPR already govern all of this? The counterargument
The obvious objection: student feedback is personal data, GDPR already governs its processing and sharing, the lawful basis is settled, and free text is riddled with special-category disclosures — so the DGA adds nothing but paperwork, and re-use of this data is a non-starter anyway.
This deserves a precise answer. GDPR and the DGA are complementary, and the DGA is explicit that it does not override data-protection law: the GDPR continues to apply in full, and where there is any conflict, data-protection rules prevail. So the objection is right that GDPR sets the floor. But it is wrong that this makes re-use impossible or the DGA irrelevant. The DGA supplies the governance scaffolding for the exact scenario GDPR leaves open-ended — how a public body should responsibly enable third parties to re-use protected data — and it points firmly at technical safeguards. And the special-category problem is a design problem, not a veto: raw free text may be unshareable, but structured, thematically-abstracted, aggregated signal derived from it can often be re-used safely. The honest position is not "we can never share" but "we can share only what we have properly de-risked, through the right channel." The DGA is what turns that sentence into a process.
What good looks like
An institution ready for this environment can, for its evaluation data: state clear, DGA-consistent conditions for re-use; distinguish raw personal free text (generally not shareable) from aggregated, de-identified, thematically-structured signal (often shareable); minimise special-category exposure at the point of collection and analysis; and route any altruistic sharing through recognised, consent-based channels rather than bilateral improvisation.
This is where the shape of your evaluation data determines your options. Koji for Education helps on both sides of the DGA question. Its automatic thematic analysis converts raw open-text into structured, aggregated themes — the de-risked, re-usable layer — so the sharable asset exists separately from the sensitive raw transcript. Its quality scoring and standardised, bias-aware AI moderation produce consistent, well-structured records that are far easier to govern and to anonymise than a pile of free-form comments. Its programme- and institution-level reporting is aggregation by design, and its EU-appropriate, GDPR/AVG-aware data handling keeps the protection floor intact. Koji reduces the friction and the risk of making evaluation data a governed, re-usable asset; it does not make you a recognised data altruism organisation, and it does not remove your obligation to run the DGA and GDPR analyses. Deciding whether and through which channel to share remains an institutional judgement.
The same conversational engine underlies the main Koji platform, where research teams handle wider stakeholder data under the same governance discipline.
Where this connects
This is the sharing-and-re-use counterpart to the corpus's protection-focused pieces — data residency and Schrems II, how long to retain evaluation data, and confidentiality and anonymity. Those ask how to guard the data. The DGA asks a newer question: on what terms should you let it work.
The takeaway
The Data Governance Act reframes your evaluation archive from a risk to be contained into an asset to be responsibly mobilised. That does not mean opening the floodgates; it means being able to say, clearly and defensibly, what may be re-used, in what de-identified form, and through which supervised channel. Build your evaluation so the shareable layer exists by design, and you are ready for the way EU data policy is actually moving.
Frequently asked questions
What is the Data Governance Act? The Data Governance Act, Regulation (EU) 2022/868, applicable since 24 September 2023, is an EU framework to facilitate the re-use of protected public-sector data, to regulate neutral data-intermediation services, and to enable data altruism — voluntary data-sharing for public-interest purposes such as research — under supervised, consent-based conditions.
Does the Data Governance Act override GDPR? No. The DGA is complementary to GDPR and explicitly does not override data-protection law; where the two conflict, GDPR prevails. GDPR remains the floor for how personal data is processed and shared, while the DGA adds governance scaffolding for responsibly enabling re-use of protected data.
Can course-evaluation data be shared for research? Raw personal free text generally cannot be shared safely, but structured, aggregated, de-identified and thematically-abstracted signal derived from it often can. The DGA points toward doing this through safeguards and recognised, consent-based channels rather than ad hoc bilateral agreements.
What is data altruism under the DGA? Data altruism is the voluntary sharing of data for the public good, such as scientific research, without seeking reward. The DGA creates a register of recognised data altruism organisations, a common EU consent form, and a supervising competent authority in each Member State to build trust in such sharing.
How does Koji help with DGA readiness? Koji's thematic analysis converts raw open-text into structured, aggregated themes that form a de-risked, re-usable layer separate from the sensitive transcript; its standardised moderation and quality scoring produce well-structured, easier-to-govern records; and its reporting is aggregated by design. It reduces the friction and risk of governed re-use without making you a data altruism organisation or removing your DGA and GDPR obligations.