September 20, 2023

|

5 min read

Can Claims of GDPR Compliance by Proctoring Companies Be Trusted?

Many proctoring companies claim GDPR compliance, but those claims are largely self-reported and rest on frameworks that have already been legally challenged. The EU-US Privacy Shield was invalidated in 2020, and its replacement relies on self-certification that does not resolve the underlying conflict between the US Patriot Act and GDPR's prohibition on non-consensual data disclosure. This post examines why US-based data storage creates a structural GDPR problem, what the DPF self-certification actually involves, and why Integrity Advocate's Canadian infrastructure and Privacy by Design architecture represent a substantively different approach.

Compliance
Privacy & Data Protection
Caroline Esteves
Growth Marketing Specialist
Share
integrity-advocate-staging.webflow.io/resources/can-claims-of-gdpr-compliance-by-proctoring-companies-be-trusted
Copy link
Woman working on a laptop at a home desk, with plants and natural light in the background.

Many online proctoring companies claim GDPR compliance. It is worth asking what that claim actually means, and whether it can be verified.

The short answer is that GDPR compliance claims are largely self-reported. There is no mandatory third-party verification process that a company must pass before making the claim. For organizations choosing a proctoring vendor on the basis of GDPR compliance, this creates a significant due diligence gap.

The US Patriot Act Problem

Many proctoring companies are registered in the United States or store data within US jurisdiction. This creates a direct conflict with GDPR that no privacy policy can resolve.

Data protection laws across the EU prohibit the disclosure of personal data without a data subject's consent or knowledge. The US Patriot Act gives the US government the ability to compel data disclosure from US-based companies or companies storing data on US infrastructure, without that consent and without notifying the individual.

A proctoring company that stores learner data on US servers and claims GDPR compliance is operating under two conflicting legal obligations. When those obligations conflict, US law governs US-based companies. The GDPR claim does not change that.

The Privacy Shield Failure

Many US-based organizations attempted to address this conflict by certifying under the EU-US Privacy Shield program, which was designed to provide a legal mechanism for transatlantic data transfers that satisfied GDPR requirements.

On July 16, 2020, Europe's top court invalidated the EU-US Privacy Shield, finding that the transfer mechanism did not ensure compliance with the level of protection required by EU law. The certification that many companies had pointed to as evidence of GDPR compliance was rendered invalid overnight.

The EU-US Data Privacy Framework: A Replacement With Familiar Weaknesses

Following the 2020 decision, negotiations between the EU and the US produced a new framework. On July 13, 2023, the US Department of Commerce launched the Data Privacy Framework program, intended to allow eligible US companies to self-certify their participation in the EU-US Data Privacy Framework.

The mechanism for self-certification is a short questionnaire and a fee to the US International Trade Administration, ranging from $375 to $4,875 USD depending on the company's revenue.

Critics have already noted that the new framework faces the same fundamental shortcomings as its Privacy Shield predecessor, including the unresolved tension between US surveillance law and EU privacy rights. Self-certification through a paid questionnaire does not resolve the underlying Patriot Act conflict.

What Meaningful GDPR Compliance Actually Requires

For a proctoring vendor's GDPR compliance claim to be substantive rather than self-reported, it needs to rest on something more than a certification program that can be obtained by filling out a form and paying a fee.

The most reliable indicator is where the data actually lives. If learner data is stored outside US jurisdiction, on infrastructure not subject to US government compelled disclosure, the conflict between the Patriot Act and GDPR does not arise.

Integrity Advocate's GDPR compliance is grounded in the same Privacy by Design architecture that underpins GDPR itself. All data is hosted in GDPR-designated jurisdictions, out of reach of governments with compelled data access authority. Integrity Advocate collects only what is necessary to confirm a learner's identity and compliance with exam rules, most of which is automatically deleted within 24 hours of session completion.

This is not a self-certification. It is an architectural position.

Questions to Ask Your Proctoring Vendor

Before accepting a GDPR compliance claim at face value, organizations should be able to answer the following:

  • Where is learner data physically stored, and in which legal jurisdiction?
  • Is the vendor registered in the United States or storing data on US infrastructure?
  • Is the GDPR compliance claim based on self-certification, third-party audit, or architectural design?
  • Has the vendor's compliance been reviewed independently, or is it self-reported?
  • What happens to learner data if the vendor receives a government data request?

If the answers are not clearly documented, the GDPR compliance claim deserves further scrutiny.

{{post-cta}}

GDPR Compliance Means More Than a Self-Certification
Integrity Advocate stores all learner data in GDPR-designated jurisdictions, out of reach of US government compelled disclosure. Privacy by Design is not a claim. It is how the platform is built.

Book a demo today!

Let us walk you through how IA helps with scalable proctoring in 30 minutes.

Frequently asked questions

Find answers to the most commonly asked questions from our clients.

GDPR compliance is largely self-reported. There is no mandatory third-party verification process that companies must pass before claiming compliance. The EU-US Data Privacy Framework, which many US-based companies use to support their GDPR compliance claims, is obtained through a self-certification process involving a short questionnaire and a fee. This does not constitute independent verification of data handling practices.

The US Patriot Act gives the US government the authority to compel data disclosure from US-based companies, or companies storing data on US infrastructure, without the consent or knowledge of the individual whose data is being accessed. GDPR prohibits exactly this kind of disclosure without consent. A US-based proctoring company cannot fully satisfy both obligations simultaneously. When they conflict, US law governs US-based companies.

The EU-US Privacy Shield was a certification framework designed to provide a legal mechanism for transatlantic data transfers that satisfied GDPR requirements. On July 16, 2020, Europe's top court invalidated it, finding that it did not ensure compliance with the level of protection required by EU law. Companies that had relied on Privacy Shield certification as evidence of GDPR compliance had that basis removed.

The EU-US Data Privacy Framework was launched in July 2023 as a replacement for the invalidated Privacy Shield. However, critics have raised concerns that it faces the same fundamental shortcomings, including the unresolved conflict between US surveillance law and EU privacy rights. Self-certification through a paid questionnaire does not address the underlying Patriot Act issue.