September 17, 2026

|

5 min read

Online Proctoring Under GDPR and PIPEDA: What Your Vendor Must Be Able to Prove

Your organization, not your proctoring vendor, carries the liability under GDPR and PIPEDA. This guide breaks down exactly what each law requires and the five questions to ask before you sign.

Privacy & Data Protection
Compliance
Defensible Outcomes
Caroline Esteves
Growth Marketing Specialist
Share
integrity-advocate-staging.webflow.io/resources/online-proctoring-gdpr-pipeda-vendor-compliance
Copy link
Woman working on a laptop at a home desk, with plants and natural light in the background.

When a testing result gets challenged, and eventually one will, the first question isn't whether your proctoring vendor was compliant. It's whether you can prove it.

Under both GDPR and PIPEDA, liability for how personal data is collected, stored, and used sits with the organization running the assessment, not the vendor supplying the software. Regulators and courts have been consistent on this point: the vendor is the data processor, but the organization deploying that vendor is the data controller, and controllers carry the accountability. That distinction matters far more than most procurement checklists reflect.

This means your proctoring vendor isn't just a feature set. It's part of your compliance posture. Before you sign, you need to know exactly what they can document, not just what they claim.

What GDPR Actually Requires From a Proctoring Vendor

GDPR applies to any organization handling data belonging to EU residents, regardless of where that organization is based. For online assessment specifically, seven principles apply directly:

  • Lawfulness, fairness, and transparency in how data is collected and used
  • Purpose limitation, meaning data collected for identity verification can't quietly be repurposed
  • Data minimization, collecting only what's necessary
  • Accuracy of the data retained
  • Storage limitation, with clear deletion timelines
  • Integrity and confidentiality, meaning real security measures, not policy language
  • Accountability, meaning the organization can demonstrate compliance on request, not just assert it

GDPR adds two further requirements on top of those seven principles, and both are worth checking closely. The first is "privacy by design," a separate obligation under Article 25 requiring that data protection be built into the product from the start, not layered on afterward as a policy update. The second is consent: it has to be freely given, specific, informed, and unambiguous. A checkbox buried in terms of service doesn't meet that bar.

What PIPEDA Requires

PIPEDA remains Canada's governing federal privacy law for private-sector organizations. Its 10 Fair Information Principles, set out in Schedule 1, cover accountability, identifying purposes, consent, limiting collection, limiting use and disclosure, retention, accuracy, safeguards, openness, and individual access. For proctoring specifically, three principles carry the most weight:

Limiting collection. The vendor should only be capturing what's needed to verify identity and confirm participation, nothing else.

Retention and disposal. Personal information shouldn't be held longer than necessary to fulfill its original purpose. If your vendor can't tell you exactly when biometric or ID data is deleted, that's a gap.

Safeguards. Protection has to be proportionate to the sensitivity of the data. Government ID and biometric data are among the most sensitive categories a vendor will ever touch.

Five Questions to Ask Before You Sign

Most vendor evaluations stop at "are you GDPR compliant?" That's not specific enough to protect your organization. Ask these instead:

  1. What exactly do you collect, and can you show me the complete list? Not a category description. The literal fields.
  2. When is biometric and ID data deleted, and is that automatic or dependent on someone remembering to act on it?
  3. Where is our data stored, and can we specify the jurisdiction?
  4. What happens when a learner asks what data you hold on them? Is there a documented process, or does it depend on a support ticket getting escalated?
  5. If a result gets challenged, what's the audit trail? Can you produce the reviewer's reasoning, not just the automated flag?

If a vendor can't answer these clearly and specifically, you're the one holding the risk when a regulator or a challenged candidate comes asking.

How This Should Show Up in Practice

A proctoring vendor built for this standard should be able to show you specifics, not principles. That looks like: identity capture limited to what's actually needed (not full document scans retained indefinitely), biometric processing that happens on the user's device rather than being transmitted and stored, sensitive images and ID data deleted on a fixed schedule measured in hours, not months, and data residency options that let you keep information within a specified jurisdiction by default.

It also means the compliance story doesn't end at data handling. When a session gets flagged, the record needs to include not just the automated signal but a trained reviewer's documented judgment. That's the difference between a flag and a decision, and it's the difference between a result you can defend and one you can't.

The Real Question Isn't Compliance. It's Proof.

Every proctoring vendor will tell you they take privacy seriously. Few can produce the documentation to back it up on demand: the retention schedule, the data flow diagram, the access log, the reviewer's reasoning behind a specific outcome. That documentation is what actually protects your organization and your reputation when a regulator, an auditor, or a challenged candidate asks you to show your work.

Integrity Advocate is built around exactly that standard: privacy-first data handling paired with human review on every flagged session, so every outcome your program issues is fair, trustworthy, and defensible.

{{post-cta}}

See the compliance story behind every session
Privacy-first data handling and human review on every flagged result, documented and ready to show your auditors.
Pour obtenir de l'aide, veuillez visiter notre centre d'assistance

Réservez une démo dès aujourd'hui !

Laissez-nous vous montrer en 30 minutes comment IA facilite la surveillance d'examens à grande échelle.

Frequently asked questions

Find answers to the most commonly asked questions from our clients.

No items found.