New

Now in Claude, ChatGPT, Cursor & more with our MCP server

Back to blog
Sector trends9 min read

Are Your Course-Evaluation Results a Public Record? The Freedom-of-Information Question

At public universities, course-evaluation data can be requestable under freedom-of-information or public-access law. Aggregate results are often disclosable; individual scores and free-text comments usually protected — but the balance swings sharply from the UK's exemption regime to Sweden's radical openness. Design for both before a request lands.

Koji Education Team

Product · August 4, 2026

Bottom line up front: If you run a public university in Europe, your course-evaluation data may be a public record that outsiders — journalists, applicants, rival departments, disgruntled parties — can request. Whether they get it depends on your jurisdiction and on what, exactly, they ask for. Aggregate results ("the mean score for this programme") are frequently disclosable. Individual-instructor scores and, especially, free-text comments are usually protected as personal data — but "usually" hides a wide spread: the United Kingdom operates an exemption-based regime where personal data is withheld under a specific test, while Sweden's constitutional offentlighetsprincipen starts from radical openness and requires positive legal grounds for secrecy. The promise of confidentiality you make to a lecturer, and to a student, is only as good as the access law sitting underneath it.

This matters operationally, not just legally. If you promise staff that their scores are "confidential" and the law makes aggregate results disclosable, you have mis-set expectations. If you promise students their comments are "anonymous" and a small-cohort free-text response is both personal data and potentially re-identifiable, you have a problem. Access law should shape what you collect and how you report — before a request ever lands.

Two regimes, one spectrum

The UK Freedom of Information Act 2000 makes universities public authorities and their recorded information presumptively accessible on request — but subject to exemptions. The one that governs evaluation data is Section 40. Personal data of a third party is exempt where disclosure would breach the data-protection principles (Section 40(2)); the applicant's own personal data is handled instead under data-protection law (Section 40(1)). In practice, individual-instructor scores and identifiable free-text comments are typically withheld under Section 40(2), because releasing them to the world would be an unfair or unlawful processing of the staff member's (or a student's) personal data. Aggregate, non-identifying results generally are not protected by Section 40 and may have to be disclosed, subject to any other applicable exemption and — for qualified exemptions — a public-interest test.

Sweden sits at the other end. The principle of public access to official documents (offentlighetsprincipen), rooted in the Freedom of the Press Act, is a constitutional cornerstone: public universities are government authorities, their documents are presumptively official and accessible, and secrecy must find positive support in the Public Access to Information and Secrecy Act. The default is disclosure, the requester need give no reason, and the burden runs the other way. Documents held by a Swedish public university are far more exposed than their UK equivalents.

Between these poles sit a range of national regimes — Germany's federal and Länder information laws, for instance, with universities often governed at state level. The lesson is not a single rule but a discipline: know which regime you are in, and design to it.

Free text is the sharp edge

Numbers can be aggregated into safety; open text often cannot. A free-text comment can be personal data about the student (revealing their identity or, worse, special-category information) and about the lecturer it names. In a small cohort, even an "anonymous" comment can be re-identifiable from its content or style — a risk we have written about in the context of stylometric re-identification. That dual character is why free text is usually the hardest category to release and the easiest to get wrong: withhold too little and you breach data protection; withhold too much and you invite an appeal to the regulator.

The interaction with the promise you made to respondents is where institutions get burned. If your participation information told students their responses were "confidential and used only for course improvement," and you then disclose comments under an access request, you may have breached both the data-protection fairness principle and the trust the whole exercise depends on. Confidentiality promises and access-law reality must be reconciled in advance.

"Isn't transparency a good thing?" — the objection

The strongest objection is that public money buys public accountability: students and taxpayers fund these institutions, so evaluation results — evidence of teaching quality — should be open by default, and hedging about "personal data" looks like an establishment protecting itself.

There is real force in this, and it should be met honestly rather than deflected. Aggregate teaching-quality information is a legitimate object of public interest, and institutions that reflexively withhold everything are neither compliant nor defensible — the UK regime's public-interest test exists precisely to stop that. But the accountability argument applies to programmes and institutions, not to the surgical exposure of one named lecturer's scores or a student's identifiable comment. The principled position is: transparent at the aggregate level, protective at the individual level. That is not evasion; it is the same line that runs through most well-designed access regimes, and it is defensible to a regulator and to the public alike.

Where Koji fits

Access law rewards evaluation systems that can separate the disclosable from the protected cleanly — and punishes those that store everything in one undifferentiated pool.

  • Reporting engineered for aggregation. Koji's programme- and institution-level reporting produces the aggregate, non-identifying outputs that are both good practice and the natural unit of disclosure — so a legitimate transparency request can be met without exposing individuals.
  • Disclosure-aware handling of free text. Automatic thematic analysis lets you report themes from open-text feedback rather than verbatim, identifiable comments — reducing both the re-identification risk and the volume of raw personal data you hold and might have to assess against an access request. See our note on disclosure control and small-class reporting.
  • Honest confidentiality by design. Because Koji's data handling is GDPR/AVG-aligned and EU-appropriate, you can make participation promises that match the access law — rather than promising an anonymity the underlying regime cannot guarantee.
  • A clear record of what is held where. Standardized collection makes it far easier to answer the first question any access request forces: what recorded information do we actually hold, and in what form?

None of this decides a disclosure for you — that is a call for your information-governance team against your jurisdiction's law. What it does is make the boundary between "publish the aggregate" and "protect the individual" a design feature rather than a scramble. The same platform underpins general research at koji.so, where the public-record question recurs for any publicly funded body.

The practical takeaway

Find out which access regime governs you and how it treats aggregate versus individual evaluation data. Reconcile your confidentiality promises with that reality before you collect. Report at the aggregate level by default, theme your free text rather than storing a verbatim liability, and route any actual request through information governance, not the quality office. Transparency and confidentiality are not opposites here — but only if you design for both.

Frequently asked questions

Can someone request our course-evaluation results under freedom-of-information law? At a public university, often yes — the data is recorded information held by a public authority. Whether they receive it depends on the jurisdiction and the specific request. Aggregate results are frequently disclosable; individual-instructor scores and identifiable free-text comments are usually protected as personal data. Regimes vary widely.

Are individual lecturers' scores disclosable? Usually not in exemption-based regimes such as the UK's, where they are typically withheld under Section 40(2) FOIA as third-party personal data whose release would breach data-protection principles. But in very open regimes such as Sweden's offentlighetsprincipen, the default leans toward disclosure and secrecy must be positively justified. Check your regime.

What about free-text comments? Free text is the hardest category. A comment can be personal data about both the student who wrote it and the lecturer it names, and in small cohorts it can be re-identifiable even when "anonymous". It is usually the most protected category — and the easiest to mishandle in either direction.

Doesn't the public have a right to see how well courses are taught? There is a genuine public interest in aggregate teaching-quality information, and reflexively withholding everything is neither lawful nor defensible. The principled line is transparency at the programme and institution level, protection at the individual level — which most access regimes' balancing tests are designed to produce.

How does this affect what we promise respondents? Directly. If you promise "confidential, course-improvement only" and then disclose comments under an access request, you may breach the data-protection fairness principle and lose respondents' trust. Confidentiality promises must be written to match the access law that actually governs you.

Does reporting themes instead of verbatim comments help? Yes. Reporting aggregated themes rather than identifiable verbatim text reduces re-identification risk and shrinks the pool of raw personal data you hold and might have to assess against a request. It aligns good methodology with good information governance.


Koji for Education produces aggregate, disclosure-aware reporting and themed open-text analysis — so you can be transparent where the law wants openness and protective where it demands it. Book a demo.