New

Now in Claude, ChatGPT, Cursor & more with our MCP server

Back to blog
Sector trends9 min read

Where Does Your Course-Evaluation Data Actually Live? Schrems II, Data Sovereignty and the Question Your Survey Vendor Hopes You Won't Ask

Student feedback is personal data, and free text often holds special-category disclosures. Where it physically lives, and whose government can compel access, is a question most universities never ask, sitting on a transfer basis that has been struck down twice.

Koji Education Team

Product ยท July 13, 2026

The short answer

Student course-evaluation responses are personal data, and free-text comments frequently contain special-category data: a disclosed disability, a health crisis, a complaint that names someone. Where that data physically lives, and which country's government can lawfully compel access to it, is a question most universities never ask their survey vendor. It matters because a large share of evaluation and survey platforms are US-headquartered or run on US hyperscaler clouds, which turns every submission into an international data transfer governed by one of the most litigated corners of GDPR. Two successive EU-US transfer frameworks have already been struck down by the Court of Justice. The one in force today is under challenge. Building your quality-assurance infrastructure on that foundation is not illegal, but it is a governance risk worth naming.

How course evaluation became a data-transfer problem

Most institutions think of course evaluation as an internal process. Legally, it often is not. The moment student responses are stored or processed outside the EU/EEA, because the vendor is a US company, because the SaaS runs on a US-region cloud, or because "follow-the-sun" support means an engineer in another country can access the database, you have an international transfer of personal data under Chapter V of the GDPR.

That chapter is where the ground has repeatedly moved:

  • In Schrems II (Case C-311/18, 16 July 2020), the CJEU invalidated the EU-US Privacy Shield and held that standard contractual clauses remain valid only if the exporter assesses whether the destination country offers protection "essentially equivalent" to EU law, a transfer impact assessment (Schrems II guidance). US surveillance law was the specific problem.
  • The European Commission responded with the EU-US Data Privacy Framework (adequacy decision, 10 July 2023), which, following a US Executive Order adding safeguards on signals intelligence, restored a lawful basis for transfers to certified US organisations (Commission adequacy decision).
  • That framework was promptly challenged. In Latombe v Commission, the EU General Court dismissed the first challenge and upheld the DPF, but the ruling is narrow, and NOYB, the group behind the two successful earlier challenges, has signalled a broader case may follow (DPF survives first challenge).

The pattern is the thing to notice. Two frameworks invalidated; a third valid but contested. This is not settled law; it is a moving legal target that your student-feedback pipeline is sitting on.

Why the stakes are higher for evaluation data specifically

You might reasonably say: every SaaS tool a university uses faces this. Why single out course evaluation?

Because the data is unusually sensitive relative to how casually it is handled. Course-evaluation free text is a space where students disclose things they disclose nowhere else in the institution's systems: mental-health struggles, experiences of discrimination, safeguarding-relevant harm. It is often collected under an explicit promise of confidentiality and anonymity, which raises the reputational and ethical cost of a compelled-access or breach event far above that of, say, a room-booking system. And it is frequently held for years under vague retention practices, compounding the exposure we have written about under storage limitation.

Sensitivity, plus a promise of confidentiality, plus an unsettled transfer basis, is a combination that deserves deliberate governance, not a default.

"Isn't EU-only hosting just protectionism and privacy theatre?"

Here is the strongest counterargument, and it has real force.

The DPF is valid law today. A US-certified vendor transferring under it is on a lawful basis, and there is no GDPR rule that says student data must be hosted on EU soil. Demanding EU-only hosting can rule out excellent tools, raise costs, and, if done as a box-ticking reflex, deliver no real privacy gain while feeling virtuous. "Data sovereignty" is sometimes used as cover for industrial protectionism, and a research-literate reader should be sceptical of the term when it is waved around without specifics.

Two honest qualifications keep the argument grounded:

Vendor location is not the same as data location, and neither fully settles the question. A US-owned provider can host entirely in Frankfurt and still, in principle, face access requests under US law such as the CLOUD Act. Conversely, an EU vendor is not automatically more secure. The meaningful questions are specific: where is the data at rest, who are the sub-processors, under whose jurisdiction do they operate, and what happens on a lawful-access request?

This is risk management, not compliance absolutism. The case for EU-appropriate hosting of evaluation data is not "US transfer is illegal", it is not, right now. It is that critical, sensitive, confidentiality-promised infrastructure should not rest on a legal mechanism with a documented history of being struck down, when the data-minimising alternative is available. That is proportionality, the core GDPR principle, applied honestly.

The mechanisms, briefly

It helps to be precise about the legal plumbing, because "is it compliant?" has more than one answer. Transfers of personal data outside the EEA need a Chapter V basis, and for a US-based evaluation vendor there are really three live options. The first is the Data Privacy Framework: if the vendor is DPF-certified, transfers to it currently rest on the Commission's adequacy decision, with no further paperwork required, until and unless the decision is annulled. The second is standard contractual clauses backed by a transfer impact assessment: the fallback that survived Schrems II, but only where your assessment concludes the destination's law and practice give essentially equivalent protection, which for US surveillance access is precisely the contested question. The third is keeping the data in the EEA in the first place, which sidesteps Chapter V for that processing entirely.

Two facts complicate the picture. Hosting location does not neutralise jurisdiction: under the US CLOUD Act, a US-based provider can face a lawful demand for data it controls even when that data sits on EU servers, which is why "we host in Frankfurt" is a partial rather than a complete answer. And because course-evaluation free text routinely includes special-category and safeguarding content, processing it usually warrants a data protection impact assessment under Article 35 regardless of where it is hosted, which is the natural place to record the transfer analysis rather than discovering the question during a breach.

What to actually ask, and where Koji fits

The productive response is neither panic nor complacency. It is to ask any vendor, including us, a short list of specific questions and match the answer to the sensitivity of the data:

  1. Where is course-evaluation data stored at rest, and is EU/EEA residency available?
  2. Who are the sub-processors, and under what jurisdictions do they operate?
  3. Is there a transfer impact assessment, and what happens on a government access request?
  4. How long is data retained, and can free text be minimised or redacted at source?

Koji for Education is built for exactly this posture: GDPR/AVG-compliant, EU-appropriate data handling as a design default, not a bolt-on. Its AI-moderated conversational interviews and automatic thematic analysis can surface the themes an institution needs while reducing how much raw, identifying free text has to be retained and shipped around, data minimisation as an architectural choice. And because the platform is designed for European higher education, the residency and sub-processor questions above are ones it expects to answer, not deflect. The same EU-appropriate engine underpins the general Koji platform for teams running wider research, and it fits naturally into the ESG-aligned quality processes European institutions already operate.

None of this is a claim that Koji, or anyone, makes the Schrems saga disappear. It is a claim that you should know where your students' most candid disclosures live, and choose a vendor who treats that as a first-order question.

The bottom line

The legality of EU-US transfers has been invalidated twice and is contested a third time; your course-evaluation data may be riding on it without anyone in the quality office having decided that it should. You do not need to boycott US tools. You do need to ask where the data lives, insist the answer matches how sensitive that data is, and prefer EU-appropriate handling for the one dataset where students tell you the truth on the condition that you keep it safe.