New

Now in Claude, ChatGPT, Cursor & more with our MCP server

Back to blog
Compliance12 min read

"The Algorithm Flagged You": GDPR Article 22 and Automated Course-Evaluation Decisions About Faculty

Most GDPR debate about course evaluation is about students. But the lecturers being scored are data subjects too — and when an evaluation platform's ranking or flag drives a personnel decision with only a nominal human sign-off, Article 22 and the CJEU's SCHUFA ruling may already apply.

Koji Education Team

Product · August 6, 2026

Bottom line up front: GDPR Article 22 gives individuals the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects them. In the course-evaluation context, the individual at risk is usually not the student — it is the lecturer whose contract renewal, probation, or promotion is shaped by an automated score or a system-generated "course of concern" flag. After the Court of Justice of the EU's 2023 SCHUFA judgment, the reassuring line that "a human always makes the final call" no longer settles the question. If a committee leans heavily on the number and does little to interrogate it, you may have built an unlawful automated decision about an employee.

This is a blind spot in most university deployments, because data-protection reviews of evaluation tools focus almost entirely on student respondents. The people being measured are data subjects with rights of their own.

What Article 22 requires

Article 22 GDPR sets a default prohibition: a person has the right not to be subject to a decision based solely on automated processing, including profiling, which produces "legal effects concerning him or her or similarly significantly affects him or her." Non-renewal of a teaching contract, denial of promotion, or a formal capability process clears the "significant effect" bar without difficulty.

The prohibition has three gateways: the decision is necessary for a contract, authorised by EU or member-state law, or based on the person's explicit consent. Even through a gateway, Article 22(3) mandates safeguards — at minimum the right to obtain human intervention, to express one's point of view, and to contest the decision. And Article 22(4) restricts decisions built on special-category data almost entirely. For faculty, that last point bites: free-text student comments routinely contain special-category data about the instructor — references to health, religion, or presumed sexual orientation.

The word doing all the work: "solely"

The obvious objection is that course-evaluation decisions are never purely automated — a head of department or a committee always signs off. This is exactly where the law is more demanding than institutions assume. The European Data Protection Board's guidance is clear that token human involvement does not rescue a process: to escape Article 22, the human must have genuine authority and competence to change the decision, and must actually weigh other factors, not merely rubber-stamp a system output. A dean who approves a list of "flagged" instructors generated by the dashboard, without independently examining the underlying evidence, has not meaningfully intervened. The decision is automated in substance even if a human name sits at the bottom.

Why SCHUFA changed the calculation

On 7 December 2023 the CJEU decided SCHUFA (Case C-634/21). A German credit agency argued it merely produced a score; the actual lending decision was made by the bank, so Article 22 did not apply to the agency. The Court disagreed. Where a third party "draws strongly" on an automated score to establish, implement, or terminate a contractual relationship, the generation of the score itself is an automated individual decision under Article 22 (IAPP analysis).

Read that across to a university. An evaluation platform computes an instructor-effectiveness score or auto-flags a "course of concern." A promotion or renewal committee "draws strongly" on it. Under SCHUFA's logic, the scoring step is not a neutral input sitting safely upstream of the real decision — it can be the decision, with the obligations that follow. The ruling deliberately closes the "we only provide a number, the human decides" defence that vendors and institutions have relied on.

This is the data-protection face of a problem we already knew

None of this is only a legal technicality. It is the compliance expression of a substantive measurement problem. We have argued that instructor averages are mostly noise, that raw means should never be used to rank instructors, and that one evaluation cannot serve both improvement and personnel decisions. Article 22 turns those methodological warnings into legal exposure: automating a high-stakes judgment about a person, on data known to be biased and noisy, is now both bad measurement and a regulatory risk — especially for the contingent faculty whose contracts turn on these numbers.

The counterarguments, taken seriously

"A committee makes the decision, so Article 22 does not apply." Only if the committee's involvement is real. If it routinely ratifies the dashboard's flags without independent scrutiny of the evidence, SCHUFA and the EDPB's rubber-stamp doctrine suggest the process is automated in substance. The test is whether a human with authority genuinely could, and sometimes does, reach a different conclusion.

"We only rank instructors; we do not make decisions." SCHUFA is precisely the answer to this. Producing the score that others rely on can itself be the regulated decision. You cannot outsource the decision to a committee and the accountability to the committee while keeping the influence.

"The score is one of several inputs." Then document how the other inputs are weighed and show that they can and do override the score. If in practice the number is decisive, "one of several inputs" is a description of the paperwork, not the decision.

"We have consent." Employee consent is a weak basis in an employment relationship because of the power imbalance, and consent to student processing is irrelevant to the lecturer's rights. This is why "we have consent" is usually the wrong basis for evaluation processing.

What a defensible process looks like

Compliance and good measurement point the same way: keep a substantive human in the loop, and give that human something worth interrogating. Three principles follow.

  1. Separate improvement from judgement. Use routine, formative evaluation to help teaching; reserve any personnel use for a distinct, evidence-rich process with explicit safeguards.
  2. Never let a single automated score be decisive. Provide human reviewers with the qualitative evidence, uncertainty, and context needed to genuinely weigh — and if necessary overturn — any flag.
  3. Guarantee the Article 22(3) rights in practice: a real route to human review, a channel for the instructor to give their side, and a way to contest.

This is where an evidence-first design matters. Koji for Education is built to surface the reasons behind a pattern, not just a headline number: AI-moderated conversational interviews probe beyond the rating, thematic analysis organises open-text feedback, and every theme is traceable to the quotes that generated it. That provenance is exactly what lets a human reviewer do the substantive weighing Article 22 demands, rather than deferring to an opaque score. Koji supports formative, mid-cycle collection kept separate from summative judgement, and programme-level reporting designed to inform decisions without automating them. (Teams doing broader people or customer research face the same "meaningful human involvement" standard, which is why the main Koji platform shares the interview engine.)

The uncomfortable synthesis is simple. If your evaluation number is good enough to decide a career on its own, the methodology says it almost certainly is not; and if it is not, letting it decide a career on its own is now a data-protection problem as well as an ethical one. Keep the human decision real — the law and the evidence agree on that.

Frequently asked questions

Does GDPR Article 22 apply to lecturers, not just students? Yes. The instructor being evaluated is a data subject. If an automated evaluation score or flag significantly affects them — for example, through renewal or promotion — Article 22 protections can apply to them.

Our committee signs off every decision. Are we automatically outside Article 22? Not necessarily. Human involvement must be genuine: the reviewer needs authority and competence to change the outcome and must actually weigh the evidence. Rubber-stamping a dashboard's flags does not take the decision outside Article 22.

What did the SCHUFA ruling change? In Case C-634/21 (2023) the CJEU held that generating a score can itself be an automated decision under Article 22 where others draw strongly on it — closing the argument that "we only produce a number, someone else decides."

What safeguards does Article 22 require? Where automated decision-making is permitted, data subjects must be able to obtain human intervention, express their point of view, and contest the decision. Decisions based on special-category data are additionally restricted.

Can we rely on consent to run automated evaluation decisions about staff? Rarely. Employee consent is generally weak because of the employment power imbalance, and student consent does not authorise processing that affects the lecturer.

How does Koji help keep decisions lawful? Koji surfaces the qualitative evidence and quote-level provenance behind any pattern, so a human reviewer can substantively weigh and, if needed, overturn a result — supporting the meaningful human involvement Article 22 requires, and keeping formative and summative uses separate.