August 25, 2020

|

5 min read

Is Your Online Proctoring Platform PIPA Compliant? What BC Organizations Need to Know

BC's Personal Information Protection Act places specific obligations on organizations that collect personal information from test takers, and online proctoring platforms fall squarely within its scope. This guide walks through what PIPA requires across collection, use, disclosure, and retention, and explains how Integrity Advocate is built to meet each obligation, from data minimization and meaningful consent to human review and proactive transparency with test takers.

Privacy & Data Protection
Compliance
Caroline Esteves
Growth Marketing Specialist
Share
integrity-advocate-staging.webflow.io/resources/is-your-online-proctoring-platform-pipa-compliant-what-bc-organizations-need-to-know
Copy link
Woman working on a laptop at a home desk, with plants and natural light in the background.

If your organization operates in British Columbia and uses online proctoring, the Personal Information Protection Act applies to you. PIPA is BC's provincial private-sector privacy law, and it governs how organizations collect, use, disclose, and retain personal information, including the identity and behavioral data that proctoring platforms collect from every test taker.

Unlike federal PIPEDA, which applies across most of Canada, PIPA is BC-specific legislation with its own requirements and its own Office of the Information and Privacy Commissioner (OIPC) for enforcement. Organizations operating in BC cannot assume PIPEDA compliance covers their PIPA obligations. The two frameworks are substantially similar but not identical.

This guide explains what PIPA requires, how it applies to online proctoring, and how Integrity Advocate is built to support your compliance obligations.

What Is PIPA and Who Does It Apply To?

The Personal Information Protection Act came into force in British Columbia on January 1, 2004. It applies to private-sector organizations operating in BC that collect, use, or disclose personal information in the course of their activities.

For organizations using online proctoring, PIPA applies to any personal information collected from BC-based test takers, including:

  • Name and identity verification data
  • Facial images and biometric confirmation
  • Session recordings and behavioral monitoring data
  • Device and browser activity during an assessment

The law places clear obligations on both the organization deploying the proctoring platform and the platform itself. Choosing a vendor that is not built with PIPA in mind creates compliance exposure for your organization.

What PIPA Requires

PIPA is organized around four core obligations that mirror the intent of federal privacy law while establishing BC-specific standards.

1. Collection of Personal Information

Organizations may only collect personal information that a reasonable person would consider appropriate in the circumstances. Collection must be limited to what is necessary for the identified purpose, and individuals must be notified of what is being collected and why before collection begins.

Integrity Advocate collects only the data required to verify identity and monitor assessment sessions. Test takers are informed of what data is being collected and for what purpose before their session begins, and consent is obtained as a documented step in the onboarding process.

2. Use of Personal Information

Personal information may only be used for the purpose for which it was collected, or for a directly related purpose the individual would reasonably expect.

Integrity Advocate uses session data exclusively for the purpose of assessment integrity. Data is not repurposed, analyzed for secondary uses, or shared beyond what is required to substantiate a specific finding. When a session is flagged, only the minimum information required to document the concern is shared with the organization.

3. Disclosure of Personal Information

Organizations may only disclose personal information with the consent of the individual or in specific circumstances defined by PIPA. Disclosure to third parties requires the same standard of care as the original collection.

Integrity Advocate does not sell, lease, or transfer personal data to any third party for commercial purposes. Session data is shared only with the organization that deployed the assessment, and only to the extent required for the review of flagged sessions.

4. Retention and Disposal of Personal Information

Personal information must not be retained longer than necessary to fulfill the purpose for which it was collected. Organizations must have a defined retention schedule and dispose of personal information securely.

Integrity Advocate deletes sensitive identity data, including facial images and government-issued ID, within 24 hours of session completion unless retention is required for an active dispute. Retention schedules are defined and documented, and disposal is handled securely.

Accuracy and the Case for Human Review

PIPA requires that personal information used to make decisions about individuals be as accurate and complete as possible. For online proctoring, this principle has direct implications for how session flags are handled.

Fully automated proctoring systems generate flags based on algorithmic pattern detection. If that flag is inaccurate, the decision made on the basis of it is inaccurate, and the organization is exposed both to a PIPA accuracy challenge and to a fairness complaint from the test taker.

Integrity Advocate addresses this through human review. Every flagged session is assessed by a trained reviewer before any outcome is recorded. That means the information your organization acts on reflects a reasoned judgment, not an automated signal, and is far more likely to meet PIPA's accuracy standard in the event of a challenge.

Security Safeguards

PIPA requires organizations to protect personal information using security measures appropriate to the sensitivity of the data. For biometric and identity data, that threshold is high.

Integrity Advocate uses 256-bit encryption in transit and at rest, stores data on AWS infrastructure in Montreal by default, and has maintained zero data breaches across 12 or more years of operation. The platform holds SOC 2 certification, providing independent verification of security controls.

Individual Rights Under PIPA

PIPA gives BC residents the right to access their personal information and to request corrections where information is inaccurate or incomplete. Organizations must respond to access requests within 30 business days.

Integrity Advocate proactively addresses this by notifying test takers by email after each completed and reviewed session. The notification details what information was retained and what conclusions were drawn, reducing the likelihood of formal access requests and creating a transparent record that supports both individual rights and organizational accountability.

The OIPC and Enforcement

The Office of the Information and Privacy Commissioner for British Columbia oversees PIPA compliance and has the authority to investigate complaints, conduct audits, and order organizations to take corrective action. The OIPC has been active in the technology and education sectors and has issued findings against organizations that failed to meet PIPA's standards for consent, collection limitation, and data security.

Organizations using non-compliant proctoring platforms carry real exposure. The liability does not rest solely with the vendor. If your platform collects more data than is necessary, fails to obtain meaningful consent, or retains data beyond its purpose, your organization is accountable.

Built for Privacy Across Jurisdictions

Integrity Advocate is designed to support compliance across multiple privacy frameworks simultaneously. Whether your organization operates under PIPA in BC, PIPEDA federally, GDPR for international learners, or FERPA for US-based education, the same foundational principles apply: collect only what is necessary, use it only for its stated purpose, protect it properly, and delete it when it is no longer needed.

That is not a compliance checklist. It is how the platform is built.

Want to see how Integrity Advocate supports your PIPA obligations in practice?
Book a Demo

{{post-cta}}

BC Organizations Deserve a Proctoring Partner Built for PIPA
Integrity Advocate is built on data minimization, meaningful consent, human review on every flagged session, and proactive transparency with test takers. Download the compliance brief to see exactly how we meet BC's PIPA requirements.

Book a demo today!

Let us walk you through how IA helps with scalable proctoring in 30 minutes.

Frequently asked questions

Find answers to the most commonly asked questions from our clients.

PIPA is British Columbia's Personal Information Protection Act, a provincial privacy law that applies to private-sector organizations operating in BC. While PIPA and PIPEDA are substantially similar in their principles, PIPA is BC-specific legislation with its own Office of the Information and Privacy Commissioner for enforcement. Organizations operating in BC cannot assume PIPEDA compliance automatically satisfies their PIPA obligations, though the two frameworks are designed to work together.

PIPA applies to any private-sector organization operating in BC that collects, uses, or discloses personal information in the course of its activities. For online proctoring, this includes any organization delivering assessments to BC-based test takers, regardless of where the organization itself is headquartered.

Under PIPA, personal information includes any information about an identifiable individual. For online proctoring this covers names and identity verification data, facial images used for biometric confirmation, session recordings, behavioral monitoring data, and device and browser activity during an assessment. All of this falls within PIPA's scope.

PIPA's four core obligations are collection, use, disclosure, and retention and disposal of personal information. Organizations must collect only what is necessary for a legitimate purpose, use it only for that purpose, disclose it only with consent or in defined circumstances, and retain it only as long as necessary before disposing of it securely.

The Office of the Information and Privacy Commissioner for British Columbia oversees PIPA compliance and has the authority to investigate complaints, conduct audits, and order organizations to take corrective action. The OIPC has been active in the technology and education sectors and has issued findings against organizations that failed to meet PIPA's standards for consent, collection limitation, and data security.

Integrity Advocate collects only the data required for identity verification and session monitoring, obtains active informed consent before any collection begins, limits disclosure to the minimum required to document specific findings, deletes sensitive identity data within 24 hours of session completion, and proactively notifies every test taker by email of what was retained after their session. These practices directly address each of PIPA's four core obligations.