#1
proctoring tool for ease of use

Resource Center

Research, guides, and real-world insights on online proctoring; helping your program deliver results that are fair, trustworthy, and defensible.

10M+

Assessments secured

Zero

Data breaches in 12+ years

98%

Client retention rate

120+

Resources published

All resources

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Tag value
News
All Industries

Integrity Advocate Announces Integration with Open LMS

April 4, 2023

|

5 min read

Integrity Advocate has announced a strategic integration with Open LMS, combining identity verification and human-reviewed proctoring with Open LMS's learning management platform. The integration allows educators to deploy proctored assessments directly within Open LMS without additional technical overhead.

Integrity Advocate has announced a strategic partnership with Open LMS, a leading provider of open-source learning management systems used by educational institutions worldwide.

What the Partnership Delivers

The integration combines Integrity Advocate's identity verification and human-reviewed online proctoring with Open LMS's cloud-based learning management platform, giving institutions and educators a comprehensive solution for securing online assessments directly within their existing LMS environment.

Open LMS provides a robust suite of features including course management, student engagement tools, and analytics. Integrity Advocate adds identity verification, participation monitoring, and human review of flagged sessions, so every assessment result issued through the platform is fair, trustworthy, and defensible.

The partnership streamlines how online proctoring is deployed within Open LMS, allowing educators to create and manage proctored assessments without additional technical overhead or separate systems.

Integrity Advocate's CEO, said: "We are thrilled to collaborate with Open LMS. Together, we can offer a comprehensive solution to uphold academic integrity in online education. Our partnership will benefit educators and institutions. It will help maintain academic rigor, guarantee the accuracy of assessments, and safeguard the value of their academic programs."

This integration enables educational institutions to deliver secure and impartial online assessments regardless of where students are located, with the confidence that every flagged session is reviewed by a trained person before any outcome is recorded.

For more information on proctoring for Open LMS visit our integrations page

{{post-cta}}

LMS Integration
Online Proctoring
No items found.
An Australian flag with a gavel representing the legal privacy obligations Victorian public sector organizations must meet when selecting an online proctoring provider.
Compliance briefs
All Industries

Is Your Online Proctoring Platform Compliant with Victoria's PDP Act? What Australian Organizations Need to Know

December 4, 2023

|

5 min read

Victoria's Privacy and Data Protection Act 2014 sets 10 Information Privacy Principles that govern how public sector organizations and their vendors must handle personal information, and online proctoring platforms fall squarely within their scope. This guide walks through each principle and explains how Integrity Advocate meets it, from collection limitation and data minimization to human review, proactive learner transparency, and transborder data protections.

If your organization is a Victorian public sector body, or works with one, the Privacy and Data Protection Act 2014 governs how personal information must be handled. For online proctoring platforms that collect identity data, session recordings, and behavioral information from learners, compliance with the PDP Act is not optional. It is a condition of operating within Victoria's public sector ecosystem.

The PDP Act's 10 Information Privacy Principles set the minimum standard for how Victorian public sector organizations must manage personal information. This guide walks through each principle and explains how Integrity Advocate meets it.

What Is the PDP Act and Who Does It Apply To?

The Privacy and Data Protection Act 2014 is Victoria's primary privacy legislation for the public sector. Schedule 1 of the Act contains the Information Privacy Principles, which set out the minimum standards for how Victorian public sector organizations collect, use, disclose, store, and manage personal information.

The PDP Act applies to Victorian government departments, agencies, statutory authorities, and other public sector bodies. When a Victorian public sector organization uses an online proctoring platform, the vendor handling learner data becomes accountable to PDP Act standards. Choosing a vendor that does not meet those standards creates compliance risk for your organization.

The 10 Information Privacy Principles and How Integrity Advocate Meets Each One

1. Collection

Organizations can only collect personal information if it is necessary to fulfill one or more of their functions. Collection must be by lawful and fair means, not in an unreasonably intrusive way, and individuals must be notified of the collection through a Collection Notice consistent with the organization's Privacy Policy.

Integrity Advocate collects only the data required to verify a learner's identity and confirm their participation in an assessment session. Data minimization options eliminate the need for ID resubmissions where a learner's image has already been validated. Government-issued ID images are deleted within 24 hours of submission where used.

2. Use and Disclosure

Personal information can only be used and disclosed for the primary purpose for which it was collected, or for a secondary purpose that would be reasonably expected. Disclosure is also permitted in limited circumstances such as with individual consent or for law enforcement purposes.

Integrity Advocate restricts the processing of learner information to its stated purpose of verifying identity and confirming participation. It acts as an intermediary between the organization and the learner's personal data, protecting against the redistribution of personal information where it is not necessary to support a documented rule violation.

3. Data Quality

Organizations must keep personal information accurate, complete, and up to date, verifying accuracy at the time of collection and checking it periodically while it is in use.

Integrity Advocate provides every user with a copy of their retained data, review findings, and reviewer notes after their session is completed. This allows learners to verify the accuracy of the information held about them and the conclusions drawn from it.

4. Data Security

Organizations must protect personal information from misuse, loss, unauthorized access, modification, or disclosure, and must take reasonable steps to destroy or permanently de-identify personal information when it is no longer needed.

Integrity Advocate encrypts all user data in transit and at rest and completes as much data processing as possible on the user's device, minimizing online data transmission. Unnecessary data is deleted promptly after session completion. Any data retained beyond the immediate session is deleted after 24 months unless a specific client or regulatory requirement necessitates a different retention period.

5. Openness

Organizations must have clearly expressed policies on how they manage personal information, and individuals must be able to request access to those policies.

Integrity Advocate requires informed consent from every user before any personal information is collected. The privacy policy explains why information is being requested, how it will be used, and how it will be destroyed. It is available in over 70 languages to ensure genuine informed consent across diverse learner populations.

6. Access and Correction

Individuals have the right to seek access to their own personal information and to request corrections where necessary. Organizations may only refuse in limited circumstances defined by the PDP Act.

Integrity Advocate provides full access capabilities to authorized administrators and users through its secure API and LMS integrations. Users can review all data retained about them immediately after initial processing, as well as the findings of that processing, without needing to submit a formal access request.

7. Unique Identifiers

The use of unique identifiers is only permitted where an organization can demonstrate it is necessary to carry out functions efficiently. There are also restrictions on adopting unique identifiers assigned by other organizations.

Integrity Advocate uses unique identifiers specifically to reliably segregate learner data and to minimize the transmission of personally identifiable information. Identifiers are not used beyond this operational purpose.

8. Anonymity

Where lawful and practicable, individuals should have the option of transacting with an organization without identifying themselves.

Identity verification is a core function of online proctoring and anonymity is therefore not practicable at the point of use. However, once collected information is no longer required for its stated purpose, all data is either deleted or anonymized. The system is designed to minimize the period during which identifiable information is retained.

9. Transborder Data Flows

If personal information travels outside Victoria, privacy protection must travel with it. Organizations can only transfer personal information outside Victoria if the individual consents or the recipient is subject to a law substantially similar to the Victorian IPPs.

Integrity Advocate's default servers are located in Canada, a jurisdiction recognized for its strong privacy laws and substantially equivalent privacy protections. Storage in numerous other jurisdictions is also available and determined based on client preference and jurisdictional requirements.

10. Sensitive Information

The PDP Act places special restrictions on the collection of sensitive information, including racial or ethnic origin, political opinions, religious beliefs, trade union membership, sexual preferences, and criminal record. Organizations can only collect sensitive information in defined circumstances.

Integrity Advocate does not request, collect, retain, or transmit sensitive information as defined under the PDP Act as part of its services.

Why Human Review Matters for PDP Act Compliance

The Data Quality principle requires that personal information used to make decisions about individuals be accurate and complete. For online proctoring, this requirement has direct implications for how session flags are handled.

Automated proctoring systems generate flags based on algorithmic pattern detection. If an automated flag is inaccurate, the decision made on the basis of it is inaccurate, and the organization is exposed to a data quality challenge under the PDP Act. Integrity Advocate addresses this through human review. Every flagged session is assessed by a trained reviewer before any outcome is recorded, ensuring that the information your organization acts on is accurate and defensible.

Built for Australian Organizations

The PDP Act is one of several privacy frameworks relevant to Australian organizations using online proctoring. Depending on the nature of your program and the location of your learners, the Australian Privacy Act 1988, GDPR for international learners, and other state-level legislation may also apply. Integrity Advocate is designed to support compliance across multiple frameworks simultaneously.

{{post-cta}}

Privacy & Data Protection
Compliance
No items found.
A university administrator reviews student privacy compliance documentation at her desk in an academic office, representing the FERPA obligations US institutions must meet when selecting an online proctoring provider.
Compliance briefs
Education

Is Your Online Proctoring Platform FERPA Compliant? What US Educational Institutions Need to Know

February 10, 2021

|

5 min read

FERPA governs how US educational institutions and their vendors handle student education records, and online proctoring data tied to specific students falls squarely within its scope. This guide explains how FERPA applies to proctoring vendors, what institutions must look for to maintain compliance, and how Integrity Advocate's data minimization, human review, and 24-hour deletion practices support your FERPA obligations.

The Family Educational Rights and Privacy Act has governed student education records in the United States since 1974. For most of its history, compliance meant controlling access to paper files and transcripts. Today, it means carefully evaluating every technology platform that touches student data, including online proctoring.

If your institution is subject to FERPA and you use online proctoring, the data your proctoring vendor collects may constitute part of a student's education record. That makes vendor selection a FERPA decision, not just a technology decision.

This guide explains what FERPA requires, how it applies to online proctoring, and how Integrity Advocate is built to support your institution's compliance obligations.

What Is FERPA and Who Does It Apply To?

The Family Educational Rights and Privacy Act is a United States federal law that protects the privacy of personally identifiable information in students' education records. It applies to any educational institution that receives funding from the US Department of Education, which includes virtually all public schools, colleges, and universities.

FERPA gives students two primary rights. First, the right to access their own education records. Second, the right to control the disclosure of those records to third parties. Institutions that violate FERPA risk losing federal funding.

Under FERPA, an education record includes any record directly related to a student that is maintained by an institution or a party acting on its behalf. When a proctoring platform collects session data, identity images, and behavioral flags tied to a specific student, that data can fall within the definition of an education record.

How FERPA Applies to Online Proctoring

FERPA addresses proctoring vendors through the concept of a school official with legitimate educational interest. Institutions can share student education records with third-party vendors without explicit student consent if the vendor meets specific criteria:

  • The vendor performs a service or function that the institution would otherwise perform itself
  • The vendor is under the direct control of the institution with respect to the use and maintenance of education records
  • The vendor uses the data only for the purposes for which the disclosure was made
  • The vendor does not re-disclose the data without authorization

This means your proctoring vendor must operate as a legitimate school official under your institution's direction, not as an independent party free to use student data for its own purposes.

Proctoring vendors that use student session data for product development, algorithmic training, secondary research, or any purpose beyond delivering the proctoring service are operating outside what FERPA permits.

What FERPA Requires of Proctoring Vendors

For a proctoring vendor to support rather than undermine your FERPA compliance, they must be able to demonstrate the following:

Data Use Limitation

Student data collected during proctoring sessions must be used only for the purpose of delivering the proctoring service. It cannot be sold, transferred, or used for any secondary purpose without explicit institutional authorization.

Integrity Advocate uses session data exclusively for assessment integrity purposes. Student data is not sold, leased, repurposed for research, or used to train algorithms beyond the scope of the specific session it was collected for.

No Unauthorized Re-disclosure

FERPA prohibits vendors from re-disclosing student education records to third parties without authorization from the institution.

Integrity Advocate does not disclose session data to any third party beyond the institution that deployed the assessment. When a session is flagged, only the minimum information required to document the specific concern is shared. Data from sessions with no violations is not shared at all.

Collection Limitation

While FERPA does not specify collection limits as precisely as some privacy laws, the requirement that vendors act under institutional direction and use data only for authorized purposes creates an implicit obligation to collect only what is necessary.

Integrity Advocate collects only the data required to verify a student's identity and monitor their session. Browser history, desktop file contents, and program inventories are not collected. If a student is not permitted to access other tabs during their exam, Integrity Advocate monitors that and nothing more.

Data Security

Institutions are responsible for ensuring that the vendors they work with protect student data with appropriate security measures.

Integrity Advocate uses 256-bit encryption in transit and at rest, stores data on AWS infrastructure in Montreal by default, and has maintained zero data breaches across 12 or more years of operation. The platform holds SOC 2 certification, providing independent verification of security controls. Student identity images and session recordings are deleted within 24 hours of session completion for sessions with no violations.

Student Notification

FERPA gives students the right to know what information is maintained about them. Integrity Advocate proactively addresses this by sending every student an email after their completed and reviewed session, detailing what data was retained and what conclusions were drawn.

FERPA and the Annual Notification Requirement

FERPA requires institutions to notify students annually of their rights under the Act. If your institution uses online proctoring, that notification should include information about how proctoring session data is handled, how long it is retained, and what rights students have to access it.

Working with a proctoring vendor that provides clear, documented data practices makes this notification straightforward. Working with a vendor whose data practices are opaque or poorly documented creates a disclosure problem your institution has to solve on its own.

FERPA in the Context of AI-Based Proctoring

One area where FERPA compliance is increasingly relevant is the use of automated AI systems to make decisions about students based on session data. When an algorithm flags a student for suspected misconduct and that flag becomes part of the student's record, the accuracy of that flag matters under FERPA.

Integrity Advocate's human review process directly addresses this concern. Every automated finding is reviewed by a trained person before any conclusion is recorded. Students are not penalized based on an algorithm alone, and the information that enters any record reflects a reviewed, documented judgment rather than an automated output.

FERPA Is a Floor, Not a Ceiling

FERPA sets minimum standards for the protection of student education records. Institutions in states with stronger privacy laws, or those serving students subject to GDPR, PIPEDA, or other frameworks, need to meet the higher standard where applicable.

Integrity Advocate is built to support compliance across multiple frameworks simultaneously. The same Privacy by Design architecture that meets FERPA's requirements also supports PIPEDA, FIPPA, PIPA, POPIA, and GDPR, making it a consistent choice for institutions with a geographically diverse student population.

{{post-cta}}

Privacy & Data Protection
Compliance
No items found.
Wooden compliance blocks held by a professional, representing the regulatory standards that online proctoring platforms must meet under South Africa's POPIA legislation.
Compliance briefs
Corporations
Credentialing
Education
Government
Regulated industries

Is Your Online Proctoring Platform POPIA Compliant? What South African Organizations Need to Know

February 9, 2021

|

5 min read

POPIA has been fully enforceable in South Africa since July 2021, and online proctoring platforms that collect identity and biometric data from South African test takers must meet its eight conditions for lawful processing. This guide walks through each condition and explains how Integrity Advocate is built to meet them, from collection limitation and informed consent to 24-hour biometric deletion, human review, and proactive learner transparency.

If your organization operates in South Africa or processes the personal information of South African data subjects, the Protection of Personal Information Act applies to you. POPIA is South Africa's comprehensive data privacy law, and since the Information Regulator began enforcement on July 1, 2021, non-compliance carries real consequences including fines of up to R10 million and potential criminal liability.

For organizations using online proctoring, POPIA is directly relevant. Proctoring platforms collect identity information, facial images, session recordings, and behavioral data from every test taker. That is personal information under POPIA's definition, and how it is collected, used, stored, and deleted must meet the Act's requirements.

This guide explains what POPIA requires, how it applies to online proctoring, and how Integrity Advocate is built to support your compliance obligations.

What Is POPIA and Who Does It Apply To?

The Protection of Personal Information Act was signed into law in 2013 and came into full effect on July 1, 2021. It governs how both public and private bodies process personal information in the course of their activities. POPIA applies to any organization that processes personal information of South African data subjects, regardless of whether the organization is based in South Africa.

For online proctoring specifically, POPIA applies to any personal information collected from South African test takers, including:

  • Names and identity verification data
  • Facial images and biometric confirmation
  • Session recordings and behavioral monitoring data
  • Device and browser activity during an assessment

The Act places accountability on both the organization deploying the proctoring platform and the platform itself. If your vendor does not meet POPIA standards, your organization shares the compliance exposure.

POPIA's Eight Conditions for Lawful Processing and How Integrity Advocate Meets Each One

POPIA organizes its requirements around eight conditions for lawful processing of personal information.

1. Accountability

The responsible party must ensure that the conditions for lawful processing are met at all times.

Integrity Advocate's platform is built around a documented privacy management framework. Data governance responsibilities are clearly defined, and clients receive the documentation they need to demonstrate that their proctoring vendor meets POPIA's accountability requirements.

2. Processing Limitation

Personal information may only be processed in a lawful manner and in a way that does not infringe on the privacy of the data subject. Collection must be adequate, relevant, and not excessive.

Integrity Advocate collects only what is required to verify a learner's identity and monitor their assessment session. If a learner is not permitted to access other browser tabs during their session, Integrity Advocate monitors exactly that and nothing more. Browsing history, desktop file contents, and program lists are not collected.

3. Purpose Specification

Personal information must be collected for a specific, explicitly defined, and lawful purpose, and data subjects must be made aware of that purpose before collection.

Integrity Advocate requires every test taker to review and actively accept a privacy policy before any personal information is collected. The policy explains what data is collected, why it is collected, and how it will be used and deleted. It is available in over 70 languages to ensure genuine informed consent across South Africa's multilingual population.

4. Further Processing Limitation

Personal information may not be processed for a purpose that is incompatible with the purpose for which it was originally collected.

Integrity Advocate uses session data exclusively for the purpose of assessment integrity. Data is never repurposed for advertising, research, or any secondary commercial use. It is not sold, leased, or transferred to any third party for purposes beyond what the assessment requires.

5. Information Quality

The responsible party must take reasonably practicable steps to ensure that personal information is complete, accurate, and not misleading.

Integrity Advocate addresses this through human review. Every flagged session is assessed by a trained reviewer before any finding is recorded. This ensures that the information your organization acts on reflects an accurate, contextually reviewed judgment rather than an automated algorithmic flag that may be incorrect.

6. Openness

Data subjects must be notified of the collection of their personal information, and the responsible party must maintain documentation of all processing activities.

Integrity Advocate notifies every test taker of data collection before their session begins through the mandatory privacy policy acceptance step. After each completed and reviewed session, Integrity Advocate sends every test taker an email detailing what information was retained and what conclusions were drawn. This proactive transparency eliminates the need for formal access requests and supports the responsible party's documentation obligations.

7. Security Safeguards

The responsible party must secure the integrity and confidentiality of personal information through appropriate technical and organizational measures.

Integrity Advocate uses 256-bit encryption for all data in transit and at rest, stores data on AWS infrastructure in Montreal by default, and has maintained zero data breaches across 12 or more years of operation. The platform holds SOC 2 certification, providing independent third-party verification of security controls. Session recordings and identity images of compliant users are deleted within 24 hours of session completion. Personal data that does not exist cannot be compromised.

8. Data Subject Participation

Data subjects have the right to request access to their personal information, to request corrections, and to object to the processing of their information.

Integrity Advocate proactively eliminates the need for formal access requests by notifying every test taker by email after their session is reviewed. The notification details what was retained and what was found. Where a test taker believes information is inaccurate, the human review process and documented session record provide the basis for a meaningful correction process.

Special Personal Information and Online Proctoring

POPIA places additional restrictions on the processing of special personal information, which includes biometric data, health information, and information about children. Online proctoring platforms that use facial recognition or biometric verification to confirm identity are processing special personal information under POPIA's definition.

Integrity Advocate's approach to biometric data is proportionate and limited. Facial images used for identity verification are deleted within 24 hours of session completion for compliant users. Biometric data is not retained beyond its immediate purpose, is not shared with third parties, and is not used for any purpose other than confirming the identity of the person completing the assessment.

The Information Regulator and Enforcement

South Africa's Information Regulator has the authority to investigate complaints, conduct audits, issue compliance notices, and impose penalties. Administrative fines under POPIA can reach R10 million, and certain offences carry criminal liability including imprisonment.

Organizations that use proctoring platforms not built to meet POPIA's requirements are exposed. The accountability obligation rests with the responsible party, meaning your organization, not just your vendor.

Built for Global Privacy Compliance

Integrity Advocate is designed to support compliance across multiple privacy frameworks simultaneously. Whether your organization operates under POPIA in South Africa, GDPR in Europe, PIPEDA in Canada, or FIPPA in Ontario, the same foundational Privacy by Design architecture applies: collect only what is necessary, use it only for its stated purpose, protect it to the highest standard, and delete it when it is no longer needed.

{{post-cta}}

Privacy & Data Protection
No items found.
Two people look up at a wall covered in security cameras, illustrating the invasive data collection practices common among online proctoring providers.
Blogs & articles
Education
Training providers
Government
Credentialing
Corporations

Why Most Remote Proctoring Companies Don't Want You to Read Their Privacy Policy

September 15, 2020

|

5 min read

Most proctoring companies collect far more personal data than test takers realize, and their privacy policies say so explicitly. This post breaks down what proctoring providers are actually collecting, shares four real privacy policy excerpts that should concern any organization, and explains how Integrity Advocate's Privacy by Design approach limits collection, mandates deletion, and keeps learner data out of the hands of third parties.

Consider two scenarios.

In the first, security cameras in a school record a student walking through the hallways and interacting with friends. The school stores the recording indefinitely as part of the student record and shares it with other organizations.

That feels wrong.

In the second scenario, cameras capture the same student bullying a younger student. Only the portion of the recording showing the behavior is retained, and it is shared with the organizations responsible for taking appropriate action.

That feels reasonable. There is a legitimate purpose, a proportionate response, and a clear limit on what gets shared and why.

Remote proctoring technology is an extension of the same principle. The question is whether the companies providing it are applying that principle, or ignoring it entirely.

What Proctoring Companies Are Actually Collecting

Most people assume online proctoring captures what it needs to verify identity and monitor an assessment session. The reality, based on the privacy policies of many proctoring providers, is considerably broader.

Many proctoring services collect, intentionally and unintentionally, personal information that includes:

  • Social security numbers, driver's license numbers, and passport numbers
  • Biometric information including facial geometry, physiological and behavioral characteristics, and genetic data
  • IP addresses and device identifiers
  • Full browsing history, search history, and records of interactions with websites and applications
  • Medical information including physical and mental health conditions
  • Drug use history and political affiliations
  • Footage of children, spouses, and other individuals who happen to be in the same space as the person being proctored

This is not a hypothetical. This is what the privacy policies say.

Four Things You Will Find in Proctoring Privacy Policies

The following are real excerpts from proctoring company privacy policies currently in use. Read them carefully.

1. "By accessing and using our Services, you consent to allow free exchange of proctoring information between [Proctoring Service Company] and your educational institution. We, or vendors on our behalf, may track the websites you visited before and after our websites as part of the traffic data described above for our internal business purposes."

2. "If your institution has consented, we may also use third-party solutions to process selected data."

3. "We may disclose information, including video and audio recording of your exam session, to your educational institution/certifying entity upon request. Your information may be sold or transferred as part of that transaction."

4. "We cannot ensure or warrant the security of any information you transmit to us or store on the Services, and you do so at your own risk."

Students and workers taking online assessments are required to submit to proctoring. They do not have the option to choose a different provider or opt out. That disparity in power makes these policies more than a legal formality. It makes them an ethical issue.

Why Privacy by Design Is the Only Acceptable Standard

The school camera analogy holds here too. We expect schools to share footage of students only when there is a legitimate reason and only to the extent necessary. We should expect the same from proctoring technology.

Privacy by Design is not a compliance label. It is an architectural commitment — the decision to build data minimization, purpose limitation, and deletion into the product from the start, rather than adding privacy language to a policy document after the fact.

That is how Integrity Advocate is built.

What Integrity Advocate Collects and What It Deletes

Integrity Advocate collects only what is necessary to verify a learner's identity and confirm whether they followed the rules set by the organization running the assessment. Nothing more.

The approach is similar to how PayPal operates as an intermediary in a financial transaction, protecting both parties without either side needing to expose more than is required. Integrity Advocate sits between the organization and the test taker's personal data, sharing only what is needed and only when there is a documented reason.

In practice, that means:

  • With the exception of a single identity photo, all recordings of the user and their desktop are deleted within 24 hours if no rule violations are found
  • When a session is flagged, only the minimum information required to document the concern is shared with the organization
  • As a Canadian company, Integrity Advocate operates outside US government jurisdiction. In the unlikely event of a compelled disclosure, the data available on the vast majority of users would be limited to a first and last name and a facial image represented as a string of code

Read the privacy policies of other proctoring providers and ask how many of them can say the same.

What to Look for Before Choosing a Proctoring Provider

Before signing a contract with any proctoring platform, your organization should be able to answer the following questions from their privacy policy and data processing documentation:

  • What personal information is collected, and is collection limited to what is necessary?
  • Is data sold, transferred, or shared with third parties beyond the assessment organization?
  • How long is data retained, and what triggers deletion?
  • Is the vendor subject to US government data requests, and what would they be required to disclose?
  • Is there a human review process, or are automated findings shared directly with the institution?

If the answers are not clearly documented, that is an answer in itself.

{{post-cta}}

Privacy & Data Protection
No items found.
A professional works on a laptop, representing the online assessment environments that BC's PIPA privacy legislation is designed to protect.
Compliance briefs
Corporations
Credentialing
Education
Government
Regulated industries

Is Your Online Proctoring Platform PIPA Compliant? What BC Organizations Need to Know

August 25, 2020

|

5 min read

BC's Personal Information Protection Act places specific obligations on organizations that collect personal information from test takers, and online proctoring platforms fall squarely within its scope. This guide walks through what PIPA requires across collection, use, disclosure, and retention, and explains how Integrity Advocate is built to meet each obligation, from data minimization and meaningful consent to human review and proactive transparency with test takers.

If your organization operates in British Columbia and uses online proctoring, the Personal Information Protection Act applies to you. PIPA is BC's provincial private-sector privacy law, and it governs how organizations collect, use, disclose, and retain personal information, including the identity and behavioral data that proctoring platforms collect from every test taker.

Unlike federal PIPEDA, which applies across most of Canada, PIPA is BC-specific legislation with its own requirements and its own Office of the Information and Privacy Commissioner (OIPC) for enforcement. Organizations operating in BC cannot assume PIPEDA compliance covers their PIPA obligations. The two frameworks are substantially similar but not identical.

This guide explains what PIPA requires, how it applies to online proctoring, and how Integrity Advocate is built to support your compliance obligations.

What Is PIPA and Who Does It Apply To?

The Personal Information Protection Act came into force in British Columbia on January 1, 2004. It applies to private-sector organizations operating in BC that collect, use, or disclose personal information in the course of their activities.

For organizations using online proctoring, PIPA applies to any personal information collected from BC-based test takers, including:

  • Name and identity verification data
  • Facial images and biometric confirmation
  • Session recordings and behavioral monitoring data
  • Device and browser activity during an assessment

The law places clear obligations on both the organization deploying the proctoring platform and the platform itself. Choosing a vendor that is not built with PIPA in mind creates compliance exposure for your organization.

What PIPA Requires

PIPA is organized around four core obligations that mirror the intent of federal privacy law while establishing BC-specific standards.

1. Collection of Personal Information

Organizations may only collect personal information that a reasonable person would consider appropriate in the circumstances. Collection must be limited to what is necessary for the identified purpose, and individuals must be notified of what is being collected and why before collection begins.

Integrity Advocate collects only the data required to verify identity and monitor assessment sessions. Test takers are informed of what data is being collected and for what purpose before their session begins, and consent is obtained as a documented step in the onboarding process.

2. Use of Personal Information

Personal information may only be used for the purpose for which it was collected, or for a directly related purpose the individual would reasonably expect.

Integrity Advocate uses session data exclusively for the purpose of assessment integrity. Data is not repurposed, analyzed for secondary uses, or shared beyond what is required to substantiate a specific finding. When a session is flagged, only the minimum information required to document the concern is shared with the organization.

3. Disclosure of Personal Information

Organizations may only disclose personal information with the consent of the individual or in specific circumstances defined by PIPA. Disclosure to third parties requires the same standard of care as the original collection.

Integrity Advocate does not sell, lease, or transfer personal data to any third party for commercial purposes. Session data is shared only with the organization that deployed the assessment, and only to the extent required for the review of flagged sessions.

4. Retention and Disposal of Personal Information

Personal information must not be retained longer than necessary to fulfill the purpose for which it was collected. Organizations must have a defined retention schedule and dispose of personal information securely.

Integrity Advocate deletes sensitive identity data, including facial images and government-issued ID, within 24 hours of session completion unless retention is required for an active dispute. Retention schedules are defined and documented, and disposal is handled securely.

Accuracy and the Case for Human Review

PIPA requires that personal information used to make decisions about individuals be as accurate and complete as possible. For online proctoring, this principle has direct implications for how session flags are handled.

Fully automated proctoring systems generate flags based on algorithmic pattern detection. If that flag is inaccurate, the decision made on the basis of it is inaccurate, and the organization is exposed both to a PIPA accuracy challenge and to a fairness complaint from the test taker.

Integrity Advocate addresses this through human review. Every flagged session is assessed by a trained reviewer before any outcome is recorded. That means the information your organization acts on reflects a reasoned judgment, not an automated signal, and is far more likely to meet PIPA's accuracy standard in the event of a challenge.

Security Safeguards

PIPA requires organizations to protect personal information using security measures appropriate to the sensitivity of the data. For biometric and identity data, that threshold is high.

Integrity Advocate uses 256-bit encryption in transit and at rest, stores data on AWS infrastructure in Montreal by default, and has maintained zero data breaches across 12 or more years of operation. The platform holds SOC 2 certification, providing independent verification of security controls.

Individual Rights Under PIPA

PIPA gives BC residents the right to access their personal information and to request corrections where information is inaccurate or incomplete. Organizations must respond to access requests within 30 business days.

Integrity Advocate proactively addresses this by notifying test takers by email after each completed and reviewed session. The notification details what information was retained and what conclusions were drawn, reducing the likelihood of formal access requests and creating a transparent record that supports both individual rights and organizational accountability.

The OIPC and Enforcement

The Office of the Information and Privacy Commissioner for British Columbia oversees PIPA compliance and has the authority to investigate complaints, conduct audits, and order organizations to take corrective action. The OIPC has been active in the technology and education sectors and has issued findings against organizations that failed to meet PIPA's standards for consent, collection limitation, and data security.

Organizations using non-compliant proctoring platforms carry real exposure. The liability does not rest solely with the vendor. If your platform collects more data than is necessary, fails to obtain meaningful consent, or retains data beyond its purpose, your organization is accountable.

Built for Privacy Across Jurisdictions

Integrity Advocate is designed to support compliance across multiple privacy frameworks simultaneously. Whether your organization operates under PIPA in BC, PIPEDA federally, GDPR for international learners, or FERPA for US-based education, the same foundational principles apply: collect only what is necessary, use it only for its stated purpose, protect it properly, and delete it when it is no longer needed.

That is not a compliance checklist. It is how the platform is built.

Want to see how Integrity Advocate supports your PIPA obligations in practice?
Book a Demo

{{post-cta}}

Privacy & Data Protection
Compliance
No items found.
A compliance professional reviews online proctoring privacy documentation at her desk in a modern Canadian office.
Compliance briefs
All Industries

Your Online Proctoring Platform PIPEDA Compliant? Here's How to Tell

May 25, 2022

|

5 min read

PIPEDA sets the standard for how personal information must be handled in Canada, and online proctoring platforms are not exempt. This guide breaks down all 10 PIPEDA principles and explains exactly how Integrity Advocate meets each one, from minimal data collection and 24-hour deletion of sensitive identity data to human review on every flagged session. If your organization uses online proctoring, here's what compliance actually looks like in practice.

Online proctoring collects sensitive personal information — names, government-issued ID, facial images, behavioral data. That means any organization using a proctoring platform in Canada isn't just making a technology decision. They're making a privacy decision. And under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), that decision carries real accountability.

This guide breaks down what PIPEDA requires, how it applies to online proctoring specifically, and how Integrity Advocate is built to meet every one of its 10 principles so your program can operate with confidence.

What Is PIPEDA and Who Does It Apply To?

PIPEDA is Canada's federal private-sector privacy law. It governs how organizations collect, use, and disclose personal information in the course of commercial activity. For educational institutions, certifying bodies, and training providers using online proctoring, PIPEDA applies to any personal data collected from test takers, including biometric data, session recordings, and identity verification images.

Non-compliance isn't just a legal risk. It's a trust risk. When test takers don't trust how their data is handled, confidence in your program erodes, and that's a problem no assessment result can fix.

The 10 PIPEDA Principles and How Integrity Advocate Meets Each One

PIPEDA is organized around 10 fair information principles. Here's how Integrity Advocate addresses each:

1. Accountability

An organization is responsible for the personal information under its control. Integrity Advocate maintains a clearly defined data governance structure and designates responsibility for PIPEDA compliance internally. Clients receive documentation to support their own accountability obligations.

2. Identifying Purposes

The purposes for collecting personal information must be identified before or at the time of collection. Integrity Advocate collects only the data required to verify identity and monitor assessment sessions, nothing more. Collection purposes are communicated clearly to test takers before any session begins.

3. Consent

Individuals must give meaningful consent for the collection, use, or disclosure of their personal information. Test takers are informed of what data is collected and why before they begin, and consent is obtained as part of the session onboarding process.

4. Limiting Collection

Personal information collected must be limited to what is necessary. Integrity Advocate follows a minimal data collection model. Sensitive data, including facial images and government-issued ID, is deleted within 24 hours of session completion unless retention is required for dispute resolution.

5. Limiting Use, Disclosure, and Retention

Data must not be used or disclosed for purposes other than those for which it was collected, and must be retained only as long as necessary. Session data is used solely for the purposes of assessment integrity. Integrity Advocate does not sell, share, or repurpose personal data for any secondary use.

6. Accuracy

Personal information must be as accurate, complete, and up-to-date as necessary. Integrity Advocate's human review process ensures that session flags are assessed by a trained reviewer, not an algorithm alone, before any outcome is recorded. This reduces the risk of inaccurate findings based on automated misclassification.

7. Safeguards

Personal information must be protected by appropriate security safeguards. Integrity Advocate uses 256-bit encryption in transit and at rest, stores data on AWS infrastructure in Montreal by default, and has maintained zero data breaches across 12+ years of operation.

8. Openness

Organizations must make their privacy policies and practices readily available. Integrity Advocate's privacy practices are documented and available to clients and test takers. Organizations deploying Integrity Advocate can point test takers to clear, accessible privacy information before their session begins.

9. Individual Access

Individuals have the right to access their personal information held by an organization. Integrity Advocate supports client organizations in responding to data access requests in accordance with PIPEDA requirements.

10. Challenging Compliance

Individuals must be able to challenge an organization's compliance with these principles. Integrity Advocate provides the documentation and audit trail that organizations need to respond to any compliance challenge, including detailed session records and human reviewer notes, not just automated flags.

Why Human Review Matters for PIPEDA Compliance

One PIPEDA principle that automated proctoring platforms often struggle with is accuracy. Fully automated systems issue flags based on algorithmic pattern detection. If that flag is wrong, and automated systems do produce false positives, the data on record is inaccurate, the outcome may be unfair, and the organization is exposed.

Integrity Advocate's human review model addresses this directly. Every flagged session is reviewed by a trained person before any decision is recorded. That means the information your organization acts on is accurate, defensible, and consistent with what PIPEDA requires.

Built for Privacy From the Ground Up

PIPEDA compliance isn't a feature Integrity Advocate added. It's reflected in foundational design decisions:

  • Minimal data collection, only what's required for the session
  • 24-hour deletion of sensitive identity data post-session
  • No secondary use of personal data for advertising, research, or resale
  • Data stored in Canada, AWS Montreal by default
  • SOC 2 certified for four consecutive years
  • GDPR and PIPEDA compliant, designed for organizations operating across jurisdiction

Your Program Deserves a Proctoring Partner You Can Stand Behind

Choosing a proctoring platform means trusting a vendor with your learners' most sensitive personal information. That trust needs to be backed by more than a checkbox. It needs to be backed by architecture, policy, and a track record.

Integrity Advocate has operated for 12+ years with zero data breaches and 98% client retention. We're built to be the partner your compliance team can point to with confidence.

{{post-cta}}

Compliance
Privacy & Data Protection
No items found.
The D2L and Integrity Advocate logos side by side, representing the partnership that brings human-reviewed proctoring and AI detection directly into the D2L Brightspace learning management system.
Company updates
All Industries

Integrity Advocate Announces Integration with D2L Brightspace

June 26, 2024

|

5 min read

Integrity Advocate has announced a partnership with D2L, integrating identity verification, participation monitoring, ExposeAI detection, and live proctoring directly into D2L Brightspace. The integration requires no participant installation and generated a 0.65% support rate in 2023, giving Brightspace users a streamlined way to maintain assessment integrity against AI-powered cheating tools.

Integrity Advocate has announced a new partnership with D2L, bringing identity verification, participation monitoring, and AI detection capabilities directly into the D2L Brightspace learning management system.

Why This Partnership Matters Now

The emergence of AI-powered browser plugins has introduced a new challenge for online assessment. These tools can covertly answer exam questions on a participant's behalf without requiring them to leave the assessment page, and they are increasingly easy to obtain and use. Organizations relying on standard LMS controls have no mechanism to detect them.

The Integrity Advocate and D2L partnership addresses this directly, giving Brightspace users access to Integrity Advocate's full suite of monitoring capabilities, including ExposeAI, within their existing platform environment.

{{post-block-quote}}

What D2L Brightspace Users Now Have Access To

The integration gives D2L Brightspace users access to Integrity Advocate's full monitoring suite, seamlessly embedded within Brightspace and fully responsive across all devices.

This includes ExposeAI, Integrity Advocate's purpose-built detection capability for AI-powered browser plugins, as well as live proctoring services for assessments requiring real-time invigilation.

The integration requires no installation from participants. Integrity Advocate is available on demand, around the clock, on any device and browser, without plugins, extensions, or system configuration changes.

In 2023, just 0.65% of Integrity Advocate users required support, a figure that reflects the low friction of the platform for learners and the reduced administrative burden for organizations running assessments at scale.

About Integrity Advocate
Integrity Advocate is an online proctoring platform that delivers end-to-end assessment security backed by human review, so every result your program issues is fair, trustworthy, and defensible. Integrity Advocate serves Higher Education, K-12, Certifying Bodies, and Training Providers across the globe.

About D2L
D2L is a leading provider of cloud-based learning technology, offering the Brightspace learning management system to educational institutions and organizations worldwide.

{{post-cta}}

Compliance
Human Review
No items found.
A lab technician in safety glasses works with equipment while holding a tablet, representing a regulated UK assessment completed through an online proctoring solution.
Case Studies
Associations and Awarding Bodies
Credentialing
All Industries

Case Study: How AIM Group Brought Ofqual-Regulated Assessments Online

January 25, 2026

|

5 min read

AIM Qualifications and Assessment Group, a leading UK Awarding Organisation, recognized that online assessments would soon become the default, but needed a solution that met Ofqual's strict regulatory standards without adding complexity for learners or administrators. AIM partnered with Coelrind and Integrity Advocate to build a seamless, fully compliant remote assessment system that works on any device, requires no installations, and upholds exam integrity across multiple UK testing centres.

Digital transformation in assessment isn't as simple as swapping a classroom for a video call. It requires purpose-built technology and strong partnerships to get it right. AIM Qualifications and Assessment Group, a leading UK Awarding Organisation, recognized that online assessments would soon become the norm, but needed a solution that met Ofqual's strict standards without adding complexity for learners or administrators.

{{post-block-quote}}

Key Outcomes

  • Full regulatory compliance and alignment with Ofqual's assessment standards
  • Seamless accessibility with no plug-ins or installations required
  • Mobile-friendly and user-focused, working on any device
  • Scalable and cost-effective across multiple UK testing centres
  • Minimized technical issues through pre-exam system checks and clear instructions

Challenge

Bringing regulated assessments online comes with high stakes. Security, compliance, and accessibility all need to align without creating unnecessary barriers for test-takers. AIM Group needed a solution that upheld assessment integrity while making the process seamless for learners and administrators alike.

In-person exams were costly and difficult to scale, requiring dedicated invigilators and significant administrative overhead. Most proctoring tools on the market weren't flexible enough, many required plug-ins, lacked tablet compatibility, and introduced unnecessary hurdles for learners. And compliance was critical: every assessment had to meet strict integrity standards to ensure qualifications remained credible in a digital format.

"We were addressing two very specific issues, the tablet issue and the plug-in issue, which were making it impossible to bring one of AIM's largest clients onboard," said John O'Sullivan of Coelrind.

Why Compliance Matters

As an Ofqual-regulated Awarding Organisation, AIM Group must meet the Office of Qualifications and Examinations Regulation's high standards for fairness and security, whether assessments are delivered in person or online. That meant adhering to evolving guidelines covering the responsible use of AI in assessment security, strict invigilation requirements to prevent misconduct, and technical standards ensuring online exams remain as rigorous as traditional assessments.

Solution

AIM Group worked with Coelrind and Integrity Advocate to tailor a remote assessment system that removed technical barriers while ensuring exam integrity. Coelrind provided the technical foundation through its learning and assessment platform, enabling AIM Group to manage exam delivery across multiple testing centres. Integrity Advocate ensured security and compliance with a no-install, mobile-friendly proctoring solution aligned with Ofqual's regulations. User experience remained a top priority throughout, with built-in system checks, clear instructions, and cross-device accessibility ensuring every learner could complete their exam without frustration.

"The main goal was to make this user-friendly, for the end users... to make sure that when they get to the live exam, it all works swimmingly," Bailey said.

Results

Now fully implemented, AIM Group's system has transformed assessment delivery. "It all seems to be working well. Everyone's got a great new asset to support their learners with," Bailey said.

"Integrity Advocate is really easy to work with, really fun to work with and very responsive," Bailey added. "There's always a quick turnaround for change requests; they've kept us updated with their progress. I would recommend them 100%."

AIM Group's experience highlights the complexity of getting online assessment right, especially when working with regulated qualifications. With the right technology and strong partnerships, it's possible to deliver a solution that's easy to use, cost-effective, and puts learners first.

{{post-cta}}

Compliance
Online Proctoring
No Installation
Assessment Security
Defensible Outcomes
No items found.
Smiling woman in gray polo shirt using a tablet with an ID badge clipped to her shirt.
null
To get support, please visit support center