February 1, 2023
|
5 min read
GDPR applies to any organization serving EU-based learners, regardless of where the organization is headquartered, and online proctoring platforms that collect biometric and session data from EU learners must meet all seven of its core principles. This guide walks through each GDPR Article 5 principle and explains how Integrity Advocate meets it, from data minimization and purpose limitation to proactive learner transparency, 24-hour deletion, and zero data breaches across more than a decade of operation.

If your organization serves learners based in the European Union, or if you are an EU-based organization serving anyone anywhere, the General Data Protection Regulation applies to you. GDPR is not just a European concern. It is one of the most far-reaching privacy laws in the world, and online proctoring platforms that collect identity data, session recordings, and behavioral information from EU-based learners are squarely within its scope.
Non-compliance carries serious consequences. Fines under GDPR are measured as a percentage of annual global turnover, with maximum penalties reaching 4% of annual revenue or 20 million euros, whichever is higher.
This guide explains what GDPR requires, how its seven key principles apply to online proctoring, and how Integrity Advocate is built to meet each one.
The General Data Protection Regulation came into effect on May 25, 2018. It is designed to protect the privacy of EU citizens and to harmonize data privacy laws across Europe. GDPR applies if the organization collecting or processing data is based in the EU, or if the data subject, meaning the individual person, is based in the EU. This applies to all organizations regardless of where they are headquartered.
According to the European Commission, personal data is any information relating to an individual, whether it relates to their private, professional, or public life. For online proctoring, this includes names, email addresses, facial images, government-issued ID, session recordings, IP addresses, and behavioral monitoring data. All of it falls within GDPR's definition and all of it must be handled accordingly.
GDPR places particular pressure on proctoring services because of the sensitivity of the data they collect and the power imbalance between the platform and the test taker. Learners are required to submit to proctoring to access their assessment. They cannot negotiate the terms or choose a different provider. That makes the obligation on the proctoring platform to handle their data responsibly even more significant.
GDPR requires data protection by design, meaning privacy protections must be built into the product from the start, not added as policy language after a complaint. It also redefines consent, requiring that it be freely given, specific, informed, and unambiguous. For proctoring platforms, that means generic terms and conditions acceptance does not constitute valid GDPR consent for the collection of biometric and session data.
Any data breach must be reported to the relevant supervisory authority within 72 hours and to affected individuals if the breach relates to identity or financial data.
GDPR Article 5 sets out seven key principles for the lawful processing of personal data.
Personal data must be processed lawfully, fairly, and in a transparent manner.
Integrity Advocate has made protecting learner privacy the foundational goal of its platform. Every user is informed of what data is being collected, what may be shared, and what will be deleted, before any collection begins. This transparency applies equally to institutions and to the learners they serve.
Personal data must be collected for specified, explicit, and legitimate purposes and not processed in a manner incompatible with those purposes.
Integrity Advocate restricts the processing of learner information to its stated purpose: verifying identity and confirming participation in the rules established by the client organization. It acts as an intermediary between the institution and the learner's personal data, protecting against any redistribution of that data beyond what is necessary to support a documented rule violation.
Personal data must be adequate, relevant, and limited to what is necessary for the purposes for which it is processed.
Integrity Advocate's data minimization approach eliminates unnecessary collection at every stage. Where a learner's image has been previously validated, the platform eliminates the need for ID resubmission on return visits. Government-issued ID images are deleted within 24 hours of submission. Browsing history, desktop files, and program inventories are not collected.
Personal data must be accurate and, where necessary, kept up to date. Inaccurate data must be erased or rectified without delay.
Integrity Advocate provides every user with a copy of the data retained about them, the review findings, and the reviewer notes after their session is completed. This allows learners to verify the accuracy of the information held about them and the conclusions drawn from it, without needing to submit a formal request.
Personal data must be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which it was collected.
Integrity Advocate deletes all unnecessary data after session completion, defined as data not required to document who participated or to support a documented rule violation. The limited data retained is deleted after 24 months unless a specific client or regulatory requirement necessitates a different retention period.
Personal data must be processed in a manner that ensures appropriate security, including protection against unauthorized processing, accidental loss, destruction, or damage.
Integrity Advocate encrypts all user data in transit and at rest and completes as much data processing as possible on the user's device, minimizing online traffic and the volume of data transmitted to servers. Data for UK-based learners is retained within the UK or on Canadian servers based on client preference. Integrity Advocate has maintained zero data breaches across 12 or more years of operation.
The controller is responsible for demonstrating compliance with all six principles above.
Integrity Advocate supports its client organizations in meeting their accountability obligations by providing the documentation, audit trail, and data handling practices that demonstrate GDPR compliance. The platform's Privacy by Design architecture means compliance is not managed through reactive policy responses. It is built into how the system works.
GDPR places restrictions on transferring personal data to countries outside the EU unless those countries provide an adequate level of data protection. Canada has been recognized by the European Commission as providing adequate protection under GDPR, which means data transfers from the EU to Integrity Advocate's Canadian servers meet GDPR requirements by default.
For organizations with specific data residency requirements, Integrity Advocate also supports storage within the EU and in other jurisdictions based on client preference.
GDPR requires that every instance of data processing have a lawful basis. For online proctoring, the most relevant bases are legitimate interests and legal obligation, though the appropriate basis depends on the specific context and jurisdiction. Organizations deploying proctoring platforms should confirm with their legal team which lawful basis applies to their specific program.
Integrity Advocate's data processing practices are designed to be compatible with whichever lawful basis your organization relies on, with data minimization and purpose limitation ensuring that processing remains within the boundaries of that basis.
GDPR is the most internationally recognized privacy framework and often sets the standard that other jurisdictions follow. Integrity Advocate is designed to support compliance across GDPR, PIPEDA, FIPPA, PIPA, POPIA, FERPA, CCPA, and the Victorian PDP Act simultaneously, with the same Privacy by Design architecture underlying each framework.
{{post-cta}}
Find answers to the most commonly asked questions from our clients.
Yes. GDPR applies to any organization that collects or processes personal data from EU-based individuals, regardless of where the organization is headquartered. If your platform serves EU-based learners, GDPR applies to how you and your proctoring vendor handle their data.
GDPR's seven principles under Article 5 are lawfulness, fairness, and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability. Each principle places specific obligations on how learner personal data must be handled from collection through to deletion.
Under GDPR, personal data includes any information relating to an identifiable individual. For online proctoring, this covers names, email addresses, facial images, government-issued ID, session recordings, IP addresses, device identifiers, and behavioral monitoring data collected during an assessment session.
GDPR fines are structured in two tiers. Less serious violations can result in fines of up to 10 million euros or 2% of annual global turnover, whichever is higher. More serious violations, including breaches of the core data processing principles, can result in fines of up to 20 million euros or 4% of annual global turnover, whichever is higher.
GDPR requires that data breaches be reported to the relevant supervisory authority within 72 hours of discovery, and to affected individuals if the breach relates to identity or financial data. Integrity Advocate has maintained zero data breaches across 12 or more years of operation. Its data minimization approach, including 24-hour deletion of unnecessary session data, means that in the event of a breach, the data available is limited to what is necessary for the session purpose.