January 3, 2023
|
5 min read
The California Consumer Privacy Act gives California consumers rights over their personal information including the right to know, delete, opt out, and since 2023, the right to correct and limit use of sensitive data. This guide explains how each CCPA right applies to online proctoring and how Integrity Advocate meets each one by default through its Privacy by Design architecture, including proactive learner notification, automatic data deletion, and a strict no-sale policy on personal data.

The California Consumer Privacy Act gives California consumers significant control over their personal information. For online proctoring platforms that collect identity data, facial images, and session recordings from California-based test takers, CCPA compliance is directly relevant to how that data must be handled, disclosed, and deleted.
This guide explains what CCPA requires, how it has been strengthened since 2018, and how Integrity Advocate is built to meet and exceed its requirements.
The California Consumer Privacy Act of 2018 was established to give consumers more control over the personal information that businesses collect about them. It has since been strengthened by the California Privacy Rights Act, which came into effect on January 1, 2023, adding new consumer rights and expanding the scope of covered businesses.
CCPA applies to for-profit businesses that do business in California and meet at least one of the following thresholds: annual gross revenue over $25 million, buying or selling the personal information of 100,000 or more consumers or households per year, or deriving 50 percent or more of annual revenue from selling personal information.
Integrity Advocate does not fall within these threshold criteria. However, through its adherence to Privacy by Design principles, Integrity Advocate meets and exceeds CCPA's requirements by default. For organizations using Integrity Advocate that are themselves subject to CCPA, this means your proctoring vendor is not creating compliance risk on your behalf.
Consumers have the right to know what personal information a business collects about them, how it is used, and whether it is shared or sold.
Integrity Advocate provides this transparency proactively, without requiring any action from the test taker. After every completed and reviewed session, Integrity Advocate emails each user a copy of the data retained about them, the review findings, and the reviewer notes. Test takers can verify exactly what information was collected and what conclusions were drawn from it, without needing to submit a formal request.
Consumers have the right to request that businesses delete personal information collected from them, and to require their service providers to do the same.
Integrity Advocate addresses this by default. All unnecessary data, defined as data not required to document who participated in the session or to support a documented rule violation, is deleted automatically after session completion. The limited data retained is deleted after 24 months unless a specific client or regulatory requirement necessitates a different retention period. Data can also be deleted earlier upon individual request.
Consumers may request that businesses stop selling their personal information. Businesses cannot sell personal information after receiving an opt-out request, and must wait at least 12 months before asking the consumer to opt back in.
Integrity Advocate has never sold, shared, or transferred personal information to any third party. The Integrity Advocate privacy policy explicitly states that users own their personal data and it cannot be sold under any conditions. There is nothing to opt out of because the sale of personal data is not and has never been part of how Integrity Advocate operates.
Businesses cannot deny goods or services, charge a different price, or provide a different level of service to consumers who exercise their CCPA rights.
Because Integrity Advocate provides all CCPA rights to every user by default, there is no scenario in which a user exercising their rights would result in different treatment. The protections are built into the platform, not granted on request.
The California Privacy Rights Act added the right for consumers to request correction of inaccurate personal information held by a business.
Integrity Advocate's human review process directly supports this right. Every flagged session is assessed by a trained reviewer before any finding is recorded, significantly reducing the likelihood of inaccurate information entering the record in the first place. Where a test taker believes information is inaccurate, the documented session record and human reviewer notes provide the basis for a meaningful correction process.
The CPRA added the right for consumers to limit how businesses use sensitive personal information, including biometric data.
Integrity Advocate collects biometric data, specifically facial images for identity verification, only for the stated purpose of confirming learner identity. This data is not used for any secondary purpose, is not shared beyond what is required to document a specific finding, and is deleted within 24 hours of session completion for compliant users.
CCPA compliance is easier to demonstrate when privacy protections are built into the product architecture rather than managed through policy responses to individual requests. Integrity Advocate's Privacy by Design approach means that data minimization, deletion timelines, and disclosure limitations are not reactive measures. They are foundational design decisions that apply to every user in every session by default.
For organizations using Integrity Advocate that are themselves subject to CCPA, this means the proctoring vendor you have chosen is not creating compliance exposure on your behalf. It means your learners' data is handled in a way that meets California's privacy standards without requiring your team to manage it.
CCPA is one of several privacy frameworks relevant to US organizations using online proctoring. Depending on the nature of your program and the location of your learners, FERPA, BIPA, GDPR, and other state-level privacy laws may also apply. Integrity Advocate is designed to support compliance across multiple frameworks simultaneously, with the same Privacy by Design architecture underlying each.
{{post-cta}}
Find answers to the most commonly asked questions from our clients.
The California Consumer Privacy Act gives California consumers rights over how their personal information is collected, used, and shared. Online proctoring platforms collect identity data, session recordings, and behavioral information from test takers, all of which constitute personal information under CCPA. Organizations using proctoring platforms that serve California-based learners need to ensure their vendor meets CCPA requirements.
No. Integrity Advocate has never sold, shared, or transferred personal information to any third party. The Integrity Advocate privacy policy explicitly states that users own their personal data and it cannot be sold under any conditions. This goes beyond what CCPA requires.
The CPRA, which came into effect January 1, 2023, added two new consumer rights: the right to correct inaccurate personal information and the right to limit the use of sensitive personal information including biometric data. Integrity Advocate's human review process supports the right to correction by ensuring findings are accurate before being recorded. Biometric data collected for identity verification is used only for that purpose and deleted within 24 hours of session completion for compliant users.
Organizations serving US learners should also consider FERPA for student education records, BIPA for organizations with Illinois-based learners, and emerging state-level privacy laws in Virginia, Colorado, Connecticut, and Texas. Integrity Advocate is designed to support compliance across multiple frameworks simultaneously.