New

Now in Claude, ChatGPT, Cursor & more with our MCP server

Back to docs
accreditation11 min

Course Evaluation Data Retention: How Long to Keep Records for Audit and Accreditation

A practical, GDPR-aligned records-management guide for QA teams: how long to keep course evaluation data, how to reconcile storage limitation with the multi-year evidence accreditors expect, and a two-tier retention model with a worked schedule.

Koji Education Team

Product

Short answer: Keep course evaluation data in two tiers. Anonymised aggregate results and closing-the-loop action logs contain no personal data, fall outside the GDPR, and can be kept indefinitely as longitudinal accreditation evidence. Raw individual-level responses and verbatim free-text comments are personal data, are governed by the storage-limitation principle, and should be kept for a short, defined window — long enough to investigate and act, typically one to two academic years or one review cycle at most — then anonymised or deleted. This guide explains why, maps the GDPR mechanics, and gives you a retention schedule you can adopt.

The tension every QA office has to resolve

Two legitimate obligations pull in opposite directions.

On one side, data protection law demands you keep personal data no longer than necessary. Article 5(1)(e) of the GDPR — the storage limitation principle — states that personal data must be kept "for no longer than is necessary for the purposes for which the personal data are processed." Article 5(1)(c) (data minimisation) reinforces it. A retention period is not optional: under Article 30(1)(f) it must be documented in your Record of Processing Activities.

On the other side, quality assurance and accreditation reward longitudinal evidence. External review cycles under the Standards and Guidelines for Quality Assurance in the European Higher Education Area (ESG 2015) typically run on multi-year cycles, and ESG Standard 1.7, Information management, expects institutions to "collect, analyse and use relevant information for the effective management of their programmes." Programme review and revalidation panels want to see a trend across cohorts — a concern raised, an action taken, an outcome measured three years later. That is impossible if you deleted the evidence to satisfy storage limitation.

The resolution is not to choose one obligation over the other. It is to recognise that the two obligations apply to two different kinds of data, and to keep each accordingly.

What actually counts as personal data in course evaluation

"Anonymous survey" is doing a lot of work in most policies, and it is often wrong. Data can be personal even without a name attached:

  • Re-identification in small cohorts. In a seminar of six students, "the only mature student" or a distinctive combination of demographic filters can single out a respondent. Small-N evaluation data is frequently personal data in practice.
  • Free-text comments about the respondent. Students disclose disabilities, personal circumstances, and complaints in open-text boxes. That content is personal data about the author.
  • Free-text comments about staff. A comment naming a lecturer is personal data about that lecturer, with employment-law and fairness implications entirely separate from the student's anonymity. You cannot keep an identifiable negative comment tied to a named individual indefinitely without a lawful basis and a defensible purpose.

Only once data is genuinely anonymised — aggregated so that no individual (student or staff) can be singled out, linked, or inferred — does it fall outside the GDPR. As regulators note, anonymisation lifts the restriction, but it must resist singling-out, linkability and inference. Weak "pseudonymisation" (dropping the name but keeping the free text and the module, date and cohort) is not anonymisation and stays in scope.

The GDPR mechanics that make long retention lawful

You do have a lawful route to keep evaluation evidence for years — provided you use it deliberately:

  • Article 89(1) — archiving, research and statistics. Longer retention is permitted for archiving in the public interest, scientific/historical research, and statistical purposes, with the safeguards in Article 89(1) (data minimisation, and where possible pseudonymisation or anonymisation). Quality enhancement and accreditation evidence generally sit comfortably in the statistical/archiving frame — but the safeguards are the price of admission.
  • Anonymisation as the clean exit. The most robust long-term store is anonymised aggregate data: it is outside the GDPR entirely, so no retention limit applies and it can back a decade of trend reporting.
  • Article 17 — erasure. Retaining raw personal data past its defined window without an Article 89 basis exposes you to erasure requests you cannot lawfully refuse.
  • Article 30(1)(f) — accountability. Whatever you decide, it must be written into your ROPA and your institutional retention schedule.

For sector-specific benchmarks, the JISC Business Classification Scheme and Records Retention Schedule for HE/FE is the widely adopted reference; many UK institutions base their own retention schedules on it, and it explicitly cross-references data-protection law. Use it — or your national equivalent — rather than inventing periods from scratch.

A two-tier retention model you can adopt

Data typeContains personal data?Recommended retentionBasis / safeguard
Anonymised aggregate results (mean scores, response rates, theme frequencies)NoIndefinite / life of the programmeOutside GDPR once genuinely anonymised
Closing-the-loop action logs (issue → action → outcome)No, if de-identifiedIndefinite / across review cyclesCore accreditation evidence; keep long-term
Raw individual quantitative responsesYes (esp. small cohorts)1–2 academic years, or one review cycle maxStorage limitation; Art 89 safeguards if extended
Verbatim free-text comments (student-authored)YesShort window for analysis, then anonymise/deleteMinimisation; redact before any archiving
Comments naming or identifying staffYes (staff personal data)Shortest defensible window; restricted accessEmployment-law + fairness; lawful basis required
Reports and SER extracts used in accreditationAggregated onlyLength of accreditation cycle + oneArchiving; ensure no re-identifiable detail

The operating principle: let the personal layer expire, keep the anonymised layer forever. You analyse raw responses and comments while they are fresh, extract the themes and actions, anonymise or delete the raw layer on schedule, and carry the aggregated evidence and action logs forward across cohorts.

Mapping the requirement to concrete outputs

Accreditation and audit reviewers ask specific questions. Here is how a well-run evaluation process answers each with retention-appropriate evidence:

Reviewer expectationEvidence to retainRetention tier
"Show feedback collected over several cohorts"Anonymised aggregate trend seriesLong-term (outside GDPR)
"Show you acted on what students said"Closing-the-loop action logLong-term
"Show the qualitative substance, not just averages"Anonymised, redacted theme summaries with representative (de-identified) quotesLong-term after redaction
"Show you comply with data protection"Retention schedule, ROPA entry, DPIA where requiredGovernance records
"Show individual-level rigour when queried"Raw responses within the current window onlyShort-term

A platform such as Koji helps on the tiering itself: AI-moderated interviews are captured, automatically analysed into themes, and the actions recorded in a closing-the-loop log — so the durable, anonymisable evidence (themes + actions + trends) is separated by design from the transient raw layer. Koji is EU-hosted with GDPR-aligned handling, and shares its AI interview engine with the main Koji research platform. The tool does not absolve you of a retention policy — it makes the two-tier split operationally realistic instead of a manual annual purge.

A practical checklist

  1. Write it down. A course-evaluation retention schedule, referenced from your ROPA, benchmarked against JISC (or your national schedule).
  2. Define the window for raw responses and comments — pick a defensible period (commonly one to two academic years) and stick to it.
  3. Anonymise on a calendar, not on request. Automate the purge/anonymisation of the raw layer.
  4. Redact staff-identifying comments before anything is archived or shared beyond the immediate line-management purpose.
  5. Keep the aggregate and action layers as your permanent accreditation record.
  6. Treat small cohorts specially — apply minimum-N thresholds before any reporting or retention.
  7. Run a DPIA where evaluation processing is likely high-risk (Article 35), and document the outcome.

Retention periods vary by jurisdiction

The two-tier model is portable across Europe, but the specific periods and the regulator you answer to are not. In Poland, retention decisions sit under the 2018 Data Protection Act and the oversight of UODO (Urząd Ochrony Danych Osobowych), alongside the internal quality-assurance evidence that PKA expects. In Germany, federal BDSG rules interact with sixteen state data-protection acts and a strong self-hosting culture, so retention schedules are often stricter and locally hosted. In the UK, the ICO enforces UK GDPR and the JISC schedule is the de facto benchmark. The common thread: set your window against your national regulator and records schedule, not a generic default — and record the reasoning. A period that is defensible in one member state is not automatically defensible in another.

The bottom line

Storage limitation and accreditation evidence are not in conflict once you stop treating "course evaluation data" as one undifferentiated pile. Keep the personal layer briefly and purposefully; keep the anonymised aggregate and action layer indefinitely. Do that, and you can satisfy a data-protection audit and a programme review panel with the same, well-governed evidence base.

Frequently asked questions

How long should we keep course evaluation data? Use two tiers. Anonymised aggregate results and closing-the-loop action logs contain no personal data and can be kept indefinitely as accreditation evidence. Raw individual responses and verbatim comments are personal data and should be kept for a short defined window — commonly one to two academic years or one review cycle at most — then anonymised or deleted, unless an Article 89 archiving basis with safeguards applies.

Does GDPR storage limitation stop us keeping evidence for accreditation? No, as long as you separate the layers. Storage limitation (Article 5(1)(e)) governs personal data. Genuinely anonymised aggregate data falls outside the GDPR entirely, so it can back a decade of trend reporting for accreditation. Keep the personal layer briefly; keep the anonymised layer long-term.

Are anonymous course evaluations really personal data? Often, yes. In small cohorts a respondent can be singled out by role or demographic filters; free-text comments can identify the student who wrote them or name a staff member. Only genuine anonymisation — resistant to singling-out, linkability and inference — removes data from GDPR scope. Dropping the name while keeping the comment, module and cohort is not anonymisation.

How should we handle free-text comments that name a lecturer? Treat them as personal data about that staff member, with employment-law and fairness implications. Keep them for the shortest defensible window, restrict access to the relevant line-management purpose, and redact staff-identifying detail before any archiving or wider sharing. Do not retain identifiable negative comments indefinitely without a lawful basis.

What retention standard should a university benchmark against? The JISC Business Classification Scheme and Records Retention Schedule for HE/FE is a widely adopted reference that cross-references data-protection law; many institutions base their schedules on it. Use it or your national equivalent, document your periods in the Record of Processing Activities (Article 30(1)(f)), and confirm with your DPO and accreditation body.

Related Resources

This guide is general information on records management and data protection, not legal advice. Confirm retention periods with your Data Protection Officer and against your national regulator (for example UODO, the ICO, or your local DPA) and accreditation body.