February 10, 2021

|

5 min read

Is Your Online Proctoring Platform FERPA Compliant? What US Educational Institutions Need to Know

FERPA governs how US educational institutions and their vendors handle student education records, and online proctoring data tied to specific students falls squarely within its scope. This guide explains how FERPA applies to proctoring vendors, what institutions must look for to maintain compliance, and how Integrity Advocate's data minimization, human review, and 24-hour deletion practices support your FERPA obligations.

Privacy & Data Protection
Compliance
Caroline Esteves
Growth Marketing Specialist
Share
integrity-advocate-staging.webflow.io/resources/is-your-online-proctoring-platform-ferpa-compliant-what-us-educational-institutions-need-to-know
Copy link
Woman working on a laptop at a home desk, with plants and natural light in the background.

The Family Educational Rights and Privacy Act has governed student education records in the United States since 1974. For most of its history, compliance meant controlling access to paper files and transcripts. Today, it means carefully evaluating every technology platform that touches student data, including online proctoring.

If your institution is subject to FERPA and you use online proctoring, the data your proctoring vendor collects may constitute part of a student's education record. That makes vendor selection a FERPA decision, not just a technology decision.

This guide explains what FERPA requires, how it applies to online proctoring, and how Integrity Advocate is built to support your institution's compliance obligations.

What Is FERPA and Who Does It Apply To?

The Family Educational Rights and Privacy Act is a United States federal law that protects the privacy of personally identifiable information in students' education records. It applies to any educational institution that receives funding from the US Department of Education, which includes virtually all public schools, colleges, and universities.

FERPA gives students two primary rights. First, the right to access their own education records. Second, the right to control the disclosure of those records to third parties. Institutions that violate FERPA risk losing federal funding.

Under FERPA, an education record includes any record directly related to a student that is maintained by an institution or a party acting on its behalf. When a proctoring platform collects session data, identity images, and behavioral flags tied to a specific student, that data can fall within the definition of an education record.

How FERPA Applies to Online Proctoring

FERPA addresses proctoring vendors through the concept of a school official with legitimate educational interest. Institutions can share student education records with third-party vendors without explicit student consent if the vendor meets specific criteria:

  • The vendor performs a service or function that the institution would otherwise perform itself
  • The vendor is under the direct control of the institution with respect to the use and maintenance of education records
  • The vendor uses the data only for the purposes for which the disclosure was made
  • The vendor does not re-disclose the data without authorization

This means your proctoring vendor must operate as a legitimate school official under your institution's direction, not as an independent party free to use student data for its own purposes.

Proctoring vendors that use student session data for product development, algorithmic training, secondary research, or any purpose beyond delivering the proctoring service are operating outside what FERPA permits.

What FERPA Requires of Proctoring Vendors

For a proctoring vendor to support rather than undermine your FERPA compliance, they must be able to demonstrate the following:

Data Use Limitation

Student data collected during proctoring sessions must be used only for the purpose of delivering the proctoring service. It cannot be sold, transferred, or used for any secondary purpose without explicit institutional authorization.

Integrity Advocate uses session data exclusively for assessment integrity purposes. Student data is not sold, leased, repurposed for research, or used to train algorithms beyond the scope of the specific session it was collected for.

No Unauthorized Re-disclosure

FERPA prohibits vendors from re-disclosing student education records to third parties without authorization from the institution.

Integrity Advocate does not disclose session data to any third party beyond the institution that deployed the assessment. When a session is flagged, only the minimum information required to document the specific concern is shared. Data from sessions with no violations is not shared at all.

Collection Limitation

While FERPA does not specify collection limits as precisely as some privacy laws, the requirement that vendors act under institutional direction and use data only for authorized purposes creates an implicit obligation to collect only what is necessary.

Integrity Advocate collects only the data required to verify a student's identity and monitor their session. Browser history, desktop file contents, and program inventories are not collected. If a student is not permitted to access other tabs during their exam, Integrity Advocate monitors that and nothing more.

Data Security

Institutions are responsible for ensuring that the vendors they work with protect student data with appropriate security measures.

Integrity Advocate uses 256-bit encryption in transit and at rest, stores data on AWS infrastructure in Montreal by default, and has maintained zero data breaches across 12 or more years of operation. The platform holds SOC 2 certification, providing independent verification of security controls. Student identity images and session recordings are deleted within 24 hours of session completion for sessions with no violations.

Student Notification

FERPA gives students the right to know what information is maintained about them. Integrity Advocate proactively addresses this by sending every student an email after their completed and reviewed session, detailing what data was retained and what conclusions were drawn.

FERPA and the Annual Notification Requirement

FERPA requires institutions to notify students annually of their rights under the Act. If your institution uses online proctoring, that notification should include information about how proctoring session data is handled, how long it is retained, and what rights students have to access it.

Working with a proctoring vendor that provides clear, documented data practices makes this notification straightforward. Working with a vendor whose data practices are opaque or poorly documented creates a disclosure problem your institution has to solve on its own.

FERPA in the Context of AI-Based Proctoring

One area where FERPA compliance is increasingly relevant is the use of automated AI systems to make decisions about students based on session data. When an algorithm flags a student for suspected misconduct and that flag becomes part of the student's record, the accuracy of that flag matters under FERPA.

Integrity Advocate's human review process directly addresses this concern. Every automated finding is reviewed by a trained person before any conclusion is recorded. Students are not penalized based on an algorithm alone, and the information that enters any record reflects a reviewed, documented judgment rather than an automated output.

FERPA Is a Floor, Not a Ceiling

FERPA sets minimum standards for the protection of student education records. Institutions in states with stronger privacy laws, or those serving students subject to GDPR, PIPEDA, or other frameworks, need to meet the higher standard where applicable.

Integrity Advocate is built to support compliance across multiple frameworks simultaneously. The same Privacy by Design architecture that meets FERPA's requirements also supports PIPEDA, FIPPA, PIPA, POPIA, and GDPR, making it a consistent choice for institutions with a geographically diverse student population.

{{post-cta}}

US Institutions Need a Proctoring Partner That Understands FERPA
Integrity Advocate operates as a legitimate school official under your institution's direction, uses student data only for its stated purpose, and deletes session data within 24 hours when no violations are found. Download the compliance brief to see exactly how we support your FERPA obligations.

Book a demo today!

Let us walk you through how IA helps with scalable proctoring in 30 minutes.

Frequently asked questions

Find answers to the most commonly asked questions from our clients.

FERPA is the Family Educational Rights and Privacy Act, a US federal law that protects the privacy of student education records. It applies to any institution receiving federal Department of Education funding, which includes virtually all US colleges and universities. Online proctoring data tied to specific students can constitute part of an education record under FERPA, making vendor compliance directly relevant to your institution's obligations.

Not necessarily. FERPA allows institutions to share student education records with third-party vendors without explicit student consent if the vendor qualifies as a school official with a legitimate educational interest. To qualify, the vendor must perform a service the institution would otherwise handle itself, operate under the institution's direction, use the data only for authorized purposes, and not re-disclose it without authorization.

No. FERPA requires that vendors use student data only for the purposes for which it was disclosed. Proctoring vendors that use session data for algorithmic training, product development, secondary research, or any purpose beyond delivering the proctoring service are operating outside what FERPA permits. Institutions that work with such vendors share the compliance exposure.

Integrity Advocate collects only the data required to verify a student's identity and monitor their assessment session. Session recordings and identity images are deleted within 24 hours of completion for sessions with no violations. Only the minimum information required to document a specific concern is retained when a violation is found. Students receive a post-session email detailing exactly what was retained.

FERPA requires that information in student records be accurate. Integrity Advocate's human review process ensures that every automated flag is assessed by a trained reviewer before any finding is recorded. This means the information that enters a student's record reflects a documented human judgment, not an algorithmic output that may be inaccurate.

FERPA applies to US institutions and the records they maintain, regardless of where students are located. If your institution is subject to FERPA and serves international students, FERPA applies to those students' records. Institutions serving students in other jurisdictions may also need to comply with additional frameworks such as GDPR, PIPEDA, or POPIA.