December 4, 2023

|

5 min read

Is Your Online Proctoring Platform Compliant with Victoria's PDP Act? What Australian Organizations Need to Know

Victoria's Privacy and Data Protection Act 2014 sets 10 Information Privacy Principles that govern how public sector organizations and their vendors must handle personal information, and online proctoring platforms fall squarely within their scope. This guide walks through each principle and explains how Integrity Advocate meets it, from collection limitation and data minimization to human review, proactive learner transparency, and transborder data protections.

Privacy & Data Protection
Compliance
Caroline Esteves
Growth Marketing Specialist
Share
integrity-advocate-staging.webflow.io/resources/is-your-online-proctoring-platform-compliant-with-victorias-pdp-act-what-australian-organizations-need-to-know
Copy link
Woman working on a laptop at a home desk, with plants and natural light in the background.

If your organization is a Victorian public sector body, or works with one, the Privacy and Data Protection Act 2014 governs how personal information must be handled. For online proctoring platforms that collect identity data, session recordings, and behavioral information from learners, compliance with the PDP Act is not optional. It is a condition of operating within Victoria's public sector ecosystem.

The PDP Act's 10 Information Privacy Principles set the minimum standard for how Victorian public sector organizations must manage personal information. This guide walks through each principle and explains how Integrity Advocate meets it.

What Is the PDP Act and Who Does It Apply To?

The Privacy and Data Protection Act 2014 is Victoria's primary privacy legislation for the public sector. Schedule 1 of the Act contains the Information Privacy Principles, which set out the minimum standards for how Victorian public sector organizations collect, use, disclose, store, and manage personal information.

The PDP Act applies to Victorian government departments, agencies, statutory authorities, and other public sector bodies. When a Victorian public sector organization uses an online proctoring platform, the vendor handling learner data becomes accountable to PDP Act standards. Choosing a vendor that does not meet those standards creates compliance risk for your organization.

The 10 Information Privacy Principles and How Integrity Advocate Meets Each One

1. Collection

Organizations can only collect personal information if it is necessary to fulfill one or more of their functions. Collection must be by lawful and fair means, not in an unreasonably intrusive way, and individuals must be notified of the collection through a Collection Notice consistent with the organization's Privacy Policy.

Integrity Advocate collects only the data required to verify a learner's identity and confirm their participation in an assessment session. Data minimization options eliminate the need for ID resubmissions where a learner's image has already been validated. Government-issued ID images are deleted within 24 hours of submission where used.

2. Use and Disclosure

Personal information can only be used and disclosed for the primary purpose for which it was collected, or for a secondary purpose that would be reasonably expected. Disclosure is also permitted in limited circumstances such as with individual consent or for law enforcement purposes.

Integrity Advocate restricts the processing of learner information to its stated purpose of verifying identity and confirming participation. It acts as an intermediary between the organization and the learner's personal data, protecting against the redistribution of personal information where it is not necessary to support a documented rule violation.

3. Data Quality

Organizations must keep personal information accurate, complete, and up to date, verifying accuracy at the time of collection and checking it periodically while it is in use.

Integrity Advocate provides every user with a copy of their retained data, review findings, and reviewer notes after their session is completed. This allows learners to verify the accuracy of the information held about them and the conclusions drawn from it.

4. Data Security

Organizations must protect personal information from misuse, loss, unauthorized access, modification, or disclosure, and must take reasonable steps to destroy or permanently de-identify personal information when it is no longer needed.

Integrity Advocate encrypts all user data in transit and at rest and completes as much data processing as possible on the user's device, minimizing online data transmission. Unnecessary data is deleted promptly after session completion. Any data retained beyond the immediate session is deleted after 24 months unless a specific client or regulatory requirement necessitates a different retention period.

5. Openness

Organizations must have clearly expressed policies on how they manage personal information, and individuals must be able to request access to those policies.

Integrity Advocate requires informed consent from every user before any personal information is collected. The privacy policy explains why information is being requested, how it will be used, and how it will be destroyed. It is available in over 70 languages to ensure genuine informed consent across diverse learner populations.

6. Access and Correction

Individuals have the right to seek access to their own personal information and to request corrections where necessary. Organizations may only refuse in limited circumstances defined by the PDP Act.

Integrity Advocate provides full access capabilities to authorized administrators and users through its secure API and LMS integrations. Users can review all data retained about them immediately after initial processing, as well as the findings of that processing, without needing to submit a formal access request.

7. Unique Identifiers

The use of unique identifiers is only permitted where an organization can demonstrate it is necessary to carry out functions efficiently. There are also restrictions on adopting unique identifiers assigned by other organizations.

Integrity Advocate uses unique identifiers specifically to reliably segregate learner data and to minimize the transmission of personally identifiable information. Identifiers are not used beyond this operational purpose.

8. Anonymity

Where lawful and practicable, individuals should have the option of transacting with an organization without identifying themselves.

Identity verification is a core function of online proctoring and anonymity is therefore not practicable at the point of use. However, once collected information is no longer required for its stated purpose, all data is either deleted or anonymized. The system is designed to minimize the period during which identifiable information is retained.

9. Transborder Data Flows

If personal information travels outside Victoria, privacy protection must travel with it. Organizations can only transfer personal information outside Victoria if the individual consents or the recipient is subject to a law substantially similar to the Victorian IPPs.

Integrity Advocate's default servers are located in Canada, a jurisdiction recognized for its strong privacy laws and substantially equivalent privacy protections. Storage in numerous other jurisdictions is also available and determined based on client preference and jurisdictional requirements.

10. Sensitive Information

The PDP Act places special restrictions on the collection of sensitive information, including racial or ethnic origin, political opinions, religious beliefs, trade union membership, sexual preferences, and criminal record. Organizations can only collect sensitive information in defined circumstances.

Integrity Advocate does not request, collect, retain, or transmit sensitive information as defined under the PDP Act as part of its services.

Why Human Review Matters for PDP Act Compliance

The Data Quality principle requires that personal information used to make decisions about individuals be accurate and complete. For online proctoring, this requirement has direct implications for how session flags are handled.

Automated proctoring systems generate flags based on algorithmic pattern detection. If an automated flag is inaccurate, the decision made on the basis of it is inaccurate, and the organization is exposed to a data quality challenge under the PDP Act. Integrity Advocate addresses this through human review. Every flagged session is assessed by a trained reviewer before any outcome is recorded, ensuring that the information your organization acts on is accurate and defensible.

Built for Australian Organizations

The PDP Act is one of several privacy frameworks relevant to Australian organizations using online proctoring. Depending on the nature of your program and the location of your learners, the Australian Privacy Act 1988, GDPR for international learners, and other state-level legislation may also apply. Integrity Advocate is designed to support compliance across multiple frameworks simultaneously.

{{post-cta}}

Victorian Public Sector Organizations Need a Proctoring Partner Built for the PDP Act
Integrity Advocate collects only what is necessary, limits disclosure through human review, notifies every learner of their session data proactively, and deletes information automatically when it is no longer needed. Download the compliance brief to see how we meet all 10 IPPs.

Book a demo today!

Let us walk you through how IA helps with scalable proctoring in 30 minutes.

Frequently asked questions

Find answers to the most commonly asked questions from our clients.

The Privacy and Data Protection Act 2014 is Victoria's primary privacy legislation for the public sector. It applies to Victorian government departments, agencies, statutory authorities, and other public sector bodies. When a Victorian public sector organization uses an online proctoring platform, the vendor handling learner data must meet the Act's 10 Information Privacy Principles.

The 10 IPPs are collection, use and disclosure, data quality, data security, openness, access and correction, unique identifiers, anonymity, transborder data flows, and sensitive information. Each principle places specific obligations on how personal information must be handled from collection through to deletion.

The PDP Act places special restrictions on sensitive information, but facial images used for identity verification are not automatically classified as sensitive information under the Victorian framework. However, they are personal information and subject to all 10 IPPs, including collection limitation, data quality, and security requirements. Integrity Advocate deletes identity images within 24 hours of session completion where no violations are found.

The data quality principle requires that personal information used to make decisions about individuals be accurate. Integrity Advocate addresses this through human review: every flagged session is assessed by a trained reviewer before any outcome is recorded, ensuring decisions are based on accurate, contextually reviewed findings rather than automated algorithmic flags.