January 1, 2020

|

5 min read

Is Your Online Proctoring Platform BIPA Compliant? What Illinois Organizations Need to Know

BIPA sets strict standards for how organizations must collect, store, and use biometric data in Illinois, and online proctoring platforms fall squarely within its scope. This guide breaks down what BIPA requires, where proctoring platforms create compliance risk, and how Integrity Advocate is designed to support your obligations, from informed consent and data deletion to zero commercial use of biometric data.

Compliance
Privacy & Data Protection
Caroline Esteves
Growth Marketing Specialist
Share
integrity-advocate-staging.webflow.io/resources/compliance-brief-bipa-and-integrity-advocate
Copy link
Woman working on a laptop at a home desk, with plants and natural light in the background.

If your organization uses online proctoring and operates in Illinois, or serves Illinois residents, the Biometric Information Privacy Act applies to you. And unlike most privacy legislation, BIPA has teeth. Private individuals can sue directly, without needing to prove actual harm, and statutory damages start at $1,000 per negligent violation and $5,000 per intentional one.

This is not a checkbox compliance exercise. It is a legal and reputational risk that organizations need to address before they deploy any technology that touches biometric data.

This guide explains what BIPA requires, how it applies to online proctoring specifically, and how Integrity Advocate is built to support your organization's compliance obligations.

What Is BIPA?

The Biometric Information Privacy Act is an Illinois state law that establishes standards for how companies must collect, store, use, and disclose biometric information. It was enacted in 2008 and remains one of the strictest biometric privacy laws in the United States.

BIPA covers any information based on an individual's biometric identifiers, including:

  • Retina and iris scans
  • Fingerprints
  • Voiceprints
  • Face geometry and facial recognition data
  • Hand geometry

For online proctoring, the most relevant category is facial geometry. Any platform that uses facial recognition or AI-based facial monitoring to verify identity or flag behavior is collecting biometric data under BIPA's definition.

What BIPA Requires

BIPA places four core obligations on organizations that collect biometric data:

1. Written Policy and Retention Schedule

Organizations must have a publicly available written policy establishing a retention schedule and guidelines for permanently destroying biometric data. Data must not be retained beyond the purpose for which it was collected, or beyond three years, whichever comes first.

2. Informed Written Consent

Before collecting biometric data, organizations must inform individuals in writing that biometric data is being collected, state the specific purpose and length of time for which it will be used, and obtain a written release. Consent cannot be buried in general terms and conditions.

3. No Commercial Benefit from Biometric Data

Organizations are prohibited from selling, leasing, trading, or otherwise profiting from an individual's biometric data. This applies to vendors and service providers as well.

4. Data Security Standards

Biometric data must be stored, transmitted, and protected using the same standard of care as other sensitive and confidential information, and in a manner consistent with the reasonable standard of care within the organization's industry.

Why Online Proctoring Is a BIPA Risk Area

Most online proctoring platforms collect biometric data as a core function. Facial recognition for identity verification, AI monitoring of facial expressions and eye movement, and behavioral biometric analysis all fall within BIPA's scope when delivered to Illinois residents.

The risk isn't hypothetical. Courts have consistently ruled that BIPA applies broadly, and class action litigation against organizations using biometric technology without proper consent frameworks has resulted in significant settlements.

The question isn't whether your proctoring platform uses biometric data. It almost certainly does. The question is whether it handles that data in a way that protects your organization.

How Integrity Advocate Supports BIPA Compliance

Integrity Advocate's identity verification and proctoring services are designed with biometric privacy obligations in mind.

Informed consent is built into the process. Test takers are informed of what data is collected, why it is collected, and how it will be used before any session begins. Consent is obtained as a documented step in the onboarding process, not assumed through general terms.

Data is not sold or used for commercial benefit. Integrity Advocate does not sell, lease, or repurpose biometric or session data for any secondary use. Data collected during a proctoring session is used solely for the purpose of that assessment.

Sensitive data is deleted promptly. Facial images and identity verification data are deleted within 24 hours of session completion, unless retention is required for a specific dispute resolution purpose. This supports compliance with BIPA's retention requirements.

Security standards are robust. Integrity Advocate uses 256-bit encryption in transit and at rest, stores data on AWS infrastructure in Montreal by default, and has maintained zero data breaches across 12+ years of operation.

Human review replaces over-reliance on facial AI. Rather than making automated decisions based on facial monitoring alone, every flagged session is reviewed by a trained person before any outcome is recorded. This reduces the risk of inaccurate findings and limits the extent to which facial geometry data drives decisions.

BIPA Is Part of a Broader Privacy Picture

BIPA is one of several privacy frameworks that organizations using online proctoring need to consider. Depending on where your test takers are located, GDPR, PIPEDA, FERPA, and other state-level legislation may also apply. Integrity Advocate is built to operate across jurisdictions, with privacy-first architecture that supports compliance across multiple frameworks simultaneously.

The Risk of Getting This Wrong

BIPA litigation is active and growing. Organizations that collect biometric data without proper consent frameworks, retain it beyond its purpose, or work with vendors who repurpose it commercially are exposed. Statutory damages per violation, multiplied across a class of test takers, add up quickly.

Choosing a proctoring partner that takes biometric privacy seriously is not just a compliance decision. It is a risk management decision.

{{post-cta}}

Biometric Data Requires a Partner You Can Trust
Integrity Advocate handles biometric data with documented consent, prompt deletion, zero commercial resale, and human review on every flagged session. Download our BIPA compliance brief to see exactly how we meet Illinois standards.

Book a demo today!

Let us walk you through how IA helps with scalable proctoring in 30 minutes.

Frequently asked questions

Find answers to the most commonly asked questions from our clients.

The Illinois Biometric Information Privacy Act is a state law that governs how private entities collect, store, use, and destroy biometric identifiers and biometric information. Biometric identifiers include fingerprints, retina scans, iris scans, voiceprints, and scans of hand or face geometry. Biometric information means any information based on those identifiers used to identify an individual. BIPA applies to any private entity that collects or possesses biometric data from Illinois residents, regardless of where the entity is located.

Yes. Online proctoring platforms that capture facial images for identity verification are collecting scans of face geometry, which is a biometric identifier under BIPA. Any platform that uses facial recognition, facial matching, or continuous facial monitoring during an exam session is engaging in biometric data collection that triggers BIPA's requirements for Illinois residents.

BIPA requires that before collecting biometric data, organizations must inform the individual in writing that biometric data is being collected and the specific purpose and length of time for which it is being collected. Organizations must obtain a written release from the individual before collection. They must establish and make publicly available a written policy with a retention schedule and guidelines for permanently destroying biometric data. And they must not sell, lease, trade, or profit from biometric data under any circumstances.

BIPA's statutory damages make it one of the most consequential privacy laws in the United States. Individuals can recover $1,000 per negligent violation or $5,000 per intentional or reckless violation, plus attorney fees. Because BIPA allows class action claims, a single systemic violation can generate liability across every affected Illinois resident in a class. The BNSF Railway settlement reached $75 million and the White Castle settlement reached $10 million, both arising from BIPA class actions related to biometric data collection without proper consent.

Integrity Advocate collects facial images for identity verification only for the stated purpose of confirming learner identity. This data is not sold, shared, or used for any secondary purpose. For compliant users, identity images are deleted within 24 hours of session completion. Integrity Advocate's Privacy by Design architecture ensures that biometric data collection is limited to what is strictly necessary, retained only as long as required, and handled in a way that is transparent to both the institution and the learner.