GDPR-Compliant Course Evaluation Software: A 2026 Data-Residency Buyer's Guide
Which course evaluation tools actually keep student data in the EU — and why GDPR compliance and data residency are not the same question. An honest, verified comparison of EvaSys, Qualtrics, Microsoft Forms, Explorance Blue, and Koji.
Koji Education Team
Product ·
Short answer: Almost every serious course evaluation vendor can be operated in a GDPR-compliant way — with a Data Processing Agreement, Standard Contractual Clauses, and appropriate safeguards. But "GDPR-compliant" and "keeps my students' data physically in the EU" are two different questions, and procurement teams routinely conflate them. If your institution has a policy requirement for EU-only data residency, the shortlist narrows sharply: EvaSys (German-hosted, with an on-premise option), Koji (built around EU data handling), and Microsoft Forms (EU Data Boundary for EU/EFTA tenants) keep data in Europe by default; Qualtrics is US-headquartered and relies on transfer mechanisms; Explorance Blue is Canada-hosted with Azure regional options. This guide separates the two questions and gives you a procurement checklist that survives a DPO's scrutiny.
GDPR compliance vs data residency: the distinction that trips buyers up
A vendor can be fully GDPR-compliant while storing data outside the EU. GDPR does not mandate EU-only hosting; it permits international transfers where an appropriate mechanism is in place — an adequacy decision (the European Commission recognising a country's protection as equivalent), Standard Contractual Clauses (SCCs), or, for certified US firms, the EU–US Data Privacy Framework.
So why do so many universities insist on EU residency anyway? Three reasons that are entirely rational:
- Institutional policy and risk appetite. Many European universities have internal rules — often stricter than the law — requiring student personal data to remain in the EEA.
- Foreign-access risk. Data physically held by a US-headquartered provider can, in principle, be subject to foreign legal process such as the US CLOUD Act, regardless of SCCs. Some DPOs treat this as an unacceptable residual risk for student data.
- Special-category data in free text. Course-evaluation comments routinely contain health, religion, or other special-category data under GDPR Article 9, and identifying detail about named staff. That raises the stakes on where the data lives and who can reach it. (See our guide on the special-category data hiding in free-text feedback.)
The honest conclusion: GDPR compliance is achievable with most vendors; EU residency is a stricter, policy-driven bar that only some meet by default.
The comparison at a glance
| Vendor | Headquarters | Default data location | EU residency by default | Transfer mechanism if non-EU | Notable assurances |
|---|---|---|---|---|---|
| EvaSys | Germany | German / EU servers | Yes | Not required | ISO 27001; on-premise option |
| Koji | EU-oriented | EU data handling | Yes | Not required | GDPR-first design; EU processing |
| Microsoft Forms | USA | EU/EFTA (for EU/EFTA tenants) | Yes (EU Data Boundary) | Covered by M365 framework | EU Data Boundary completed 2025 |
| Explorance Blue | Canada | Canada (Azure regional for some products) | Partial / on request | Canada adequacy; SCCs | SOC 2 Type 2 |
| Qualtrics | USA | Vendor-defined; confirm contractually | On request, verify | SCCs / EU–US DPF | GDPR DPA; ISO-certified operations |
Verified against each vendor's public documentation as of publication. Data-centre options and contractual terms change and vary by plan — confirm the current position in writing with each vendor before you rely on it.
EvaSys: the EU-residency incumbent
EvaSys is the long-standing German course-evaluation platform, and data residency is one of its clearest strengths. EvaSys offers hosting on secure, exclusively EU-based (specifically German) servers with full GDPR compliance, is ISO 27001 certified, and — crucially for the most cautious institutions — supports on-premise deployment, so an institution can keep the data entirely within its own infrastructure.
Where EvaSys wins: if EU-only or on-premise residency is a hard procurement requirement, EvaSys is the safe, proven answer. Its German base and ISO 27001 certification make the DPO conversation short.
Its honest limitation: EvaSys's residency strength sits on top of a traditional, largely static Likert-survey methodology. You get strong data governance around a fundamentally conventional instrument — manual analysis, limited conversational depth. Residency is solved; feedback quality is not.
Microsoft Forms: EU residency by tenant, but a blunt instrument
If your institution runs Microsoft 365, Microsoft Forms inherits the EU Data Boundary, which Microsoft completed in 2025. For customers whose sign-up location is in the EU or EFTA, Forms data is stored and processed within the EU/EFTA region, and Forms is only deployed in the Americas and EU/EFTA geographies.
Where Microsoft Forms wins: it is already in your licence, EU residency is handled for EU/EFTA tenants, and there is no new vendor to procure.
Its honest limitation: Forms is a general-purpose survey tool, not a course-evaluation system. It has weak support for the things that matter in this domain — robust anonymity thresholds, hierarchical course/instructor structures, closing-the-loop workflows, and careful handling of special-category free text. Residency is fine; fitness for purpose is thin.
Explorance Blue: Canada-hosted, GDPR-workable
Explorance Blue is hosted in a Canadian data centre with a SOC 2 Type 2 attestation audited annually, while its companion products (MLY, Bluepulse, Forms, MTM) leverage Microsoft Azure regional data centres. Explorance processes data under contractual obligations that comply with GDPR, alongside FERPA, PIPEDA, and other regimes.
Here honesty matters: Canada is not a compliance problem for GDPR. The European Commission's adequacy decision covers data transferred to recipients subject to Canada's PIPEDA, so Canadian hosting is generally lawful without additional SCCs for commercial data. What Canadian hosting is not is EU residency — so it clears the legal bar but may not clear a policy that demands data stay in the EEA.
Where Blue wins: a mature, HE-specific platform with strong analytics (see our text-analytics comparison) and a defensible, adequacy-backed data position.
Its honest limitation: if your policy is strictly EU-only, Canadian default hosting will require an exception or a specific Azure-EU arrangement — worth confirming in writing.
Qualtrics: compliant, but confirm residency in the contract
Qualtrics is GDPR-compliant as a data processor, offering a comprehensive DPA with EU/UK Standard Contractual Clauses, and it appoints Qualtrics Ireland Limited as its EU data representative. What its public documentation does not clearly guarantee is default EU-only data residency: cross-border transfers are addressed primarily through SCCs (and, where applicable, the EU–US Data Privacy Framework) rather than a blanket EU-hosting commitment.
Where Qualtrics wins: it is a powerful, enterprise-grade experience-management platform, fully operable within GDPR, and the pragmatic choice for institutions already invested in it.
Its honest limitation: as a US-headquartered provider, it is the one on this list where a residency-focused DPO must do the most homework — confirming data-centre location, sub-processors, and transfer mechanisms contractually rather than assuming EU hosting. For institutions whose policy treats US-linked hosting of special-category student data as a residual risk, that is a real friction point.
Koji: GDPR-first, EU data handling, deeper feedback
Koji is built for European higher education, with EU data handling at the core rather than bolted on. Beyond residency, Koji is designed to reduce the volume of sensitive data risk in the first place: its AI-moderated interviews apply standardised, bias-aware moderation, and its analysis pipeline is oriented toward institutional reporting and closing-the-loop action tracking rather than sprawling raw exports.
The point is not that Koji is the only GDPR-compliant option — most tools here can be operated compliantly. It is that Koji pairs EU-oriented data handling with a modern methodology: conversational, AI-moderated collection and automatic thematic analysis, so you are not trading data governance against feedback quality. The same AI interview engine powers the main Koji platform (koji.so) for customer and user research under the same EU-first data posture.
Its honest limitation: Koji is a newer entrant than EvaSys or Qualtrics, so institutions with rigid "must be on-premise" mandates should confirm deployment specifics; the trade for that is a materially more modern feedback instrument.
A procurement checklist your DPO will actually use
Before signing, get written answers to:
- Where is student data physically stored and processed — by default, and can EU-only be guaranteed?
- What transfer mechanism applies if any processing occurs outside the EEA (SCCs, adequacy, EU–US DPF)?
- Who are the sub-processors, and where are they located?
- What is the DPA scope, and does it cover special-category data in free text (Article 9)?
- What are the anonymity thresholds and retention/deletion controls? (See data retention and storage limitation.)
- What certifications (ISO 27001, SOC 2 Type 2) back the security claims?
Answer those six, and "is it GDPR compliant?" resolves into the more useful question: does it meet our residency policy, for the kind of data course evaluations actually contain?