February 9, 2021

|

5 min read

Is Your Online Proctoring Platform POPIA Compliant? What South African Organizations Need to Know

POPIA has been fully enforceable in South Africa since July 2021, and online proctoring platforms that collect identity and biometric data from South African test takers must meet its eight conditions for lawful processing. This guide walks through each condition and explains how Integrity Advocate is built to meet them, from collection limitation and informed consent to 24-hour biometric deletion, human review, and proactive learner transparency.

Privacy & Data Protection
Caroline Esteves
Growth Marketing Specialist
Share
integrity-advocate-staging.webflow.io/resources/is-your-online-proctoring-platform-popia-compliant-what-south-african-organizations-need-to-know
Copy link
Woman working on a laptop at a home desk, with plants and natural light in the background.

If your organization operates in South Africa or processes the personal information of South African data subjects, the Protection of Personal Information Act applies to you. POPIA is South Africa's comprehensive data privacy law, and since the Information Regulator began enforcement on July 1, 2021, non-compliance carries real consequences including fines of up to R10 million and potential criminal liability.

For organizations using online proctoring, POPIA is directly relevant. Proctoring platforms collect identity information, facial images, session recordings, and behavioral data from every test taker. That is personal information under POPIA's definition, and how it is collected, used, stored, and deleted must meet the Act's requirements.

This guide explains what POPIA requires, how it applies to online proctoring, and how Integrity Advocate is built to support your compliance obligations.

What Is POPIA and Who Does It Apply To?

The Protection of Personal Information Act was signed into law in 2013 and came into full effect on July 1, 2021. It governs how both public and private bodies process personal information in the course of their activities. POPIA applies to any organization that processes personal information of South African data subjects, regardless of whether the organization is based in South Africa.

For online proctoring specifically, POPIA applies to any personal information collected from South African test takers, including:

  • Names and identity verification data
  • Facial images and biometric confirmation
  • Session recordings and behavioral monitoring data
  • Device and browser activity during an assessment

The Act places accountability on both the organization deploying the proctoring platform and the platform itself. If your vendor does not meet POPIA standards, your organization shares the compliance exposure.

POPIA's Eight Conditions for Lawful Processing and How Integrity Advocate Meets Each One

POPIA organizes its requirements around eight conditions for lawful processing of personal information.

1. Accountability

The responsible party must ensure that the conditions for lawful processing are met at all times.

Integrity Advocate's platform is built around a documented privacy management framework. Data governance responsibilities are clearly defined, and clients receive the documentation they need to demonstrate that their proctoring vendor meets POPIA's accountability requirements.

2. Processing Limitation

Personal information may only be processed in a lawful manner and in a way that does not infringe on the privacy of the data subject. Collection must be adequate, relevant, and not excessive.

Integrity Advocate collects only what is required to verify a learner's identity and monitor their assessment session. If a learner is not permitted to access other browser tabs during their session, Integrity Advocate monitors exactly that and nothing more. Browsing history, desktop file contents, and program lists are not collected.

3. Purpose Specification

Personal information must be collected for a specific, explicitly defined, and lawful purpose, and data subjects must be made aware of that purpose before collection.

Integrity Advocate requires every test taker to review and actively accept a privacy policy before any personal information is collected. The policy explains what data is collected, why it is collected, and how it will be used and deleted. It is available in over 70 languages to ensure genuine informed consent across South Africa's multilingual population.

4. Further Processing Limitation

Personal information may not be processed for a purpose that is incompatible with the purpose for which it was originally collected.

Integrity Advocate uses session data exclusively for the purpose of assessment integrity. Data is never repurposed for advertising, research, or any secondary commercial use. It is not sold, leased, or transferred to any third party for purposes beyond what the assessment requires.

5. Information Quality

The responsible party must take reasonably practicable steps to ensure that personal information is complete, accurate, and not misleading.

Integrity Advocate addresses this through human review. Every flagged session is assessed by a trained reviewer before any finding is recorded. This ensures that the information your organization acts on reflects an accurate, contextually reviewed judgment rather than an automated algorithmic flag that may be incorrect.

6. Openness

Data subjects must be notified of the collection of their personal information, and the responsible party must maintain documentation of all processing activities.

Integrity Advocate notifies every test taker of data collection before their session begins through the mandatory privacy policy acceptance step. After each completed and reviewed session, Integrity Advocate sends every test taker an email detailing what information was retained and what conclusions were drawn. This proactive transparency eliminates the need for formal access requests and supports the responsible party's documentation obligations.

7. Security Safeguards

The responsible party must secure the integrity and confidentiality of personal information through appropriate technical and organizational measures.

Integrity Advocate uses 256-bit encryption for all data in transit and at rest, stores data on AWS infrastructure in Montreal by default, and has maintained zero data breaches across 12 or more years of operation. The platform holds SOC 2 certification, providing independent third-party verification of security controls. Session recordings and identity images of compliant users are deleted within 24 hours of session completion. Personal data that does not exist cannot be compromised.

8. Data Subject Participation

Data subjects have the right to request access to their personal information, to request corrections, and to object to the processing of their information.

Integrity Advocate proactively eliminates the need for formal access requests by notifying every test taker by email after their session is reviewed. The notification details what was retained and what was found. Where a test taker believes information is inaccurate, the human review process and documented session record provide the basis for a meaningful correction process.

Special Personal Information and Online Proctoring

POPIA places additional restrictions on the processing of special personal information, which includes biometric data, health information, and information about children. Online proctoring platforms that use facial recognition or biometric verification to confirm identity are processing special personal information under POPIA's definition.

Integrity Advocate's approach to biometric data is proportionate and limited. Facial images used for identity verification are deleted within 24 hours of session completion for compliant users. Biometric data is not retained beyond its immediate purpose, is not shared with third parties, and is not used for any purpose other than confirming the identity of the person completing the assessment.

The Information Regulator and Enforcement

South Africa's Information Regulator has the authority to investigate complaints, conduct audits, issue compliance notices, and impose penalties. Administrative fines under POPIA can reach R10 million, and certain offences carry criminal liability including imprisonment.

Organizations that use proctoring platforms not built to meet POPIA's requirements are exposed. The accountability obligation rests with the responsible party, meaning your organization, not just your vendor.

Built for Global Privacy Compliance

Integrity Advocate is designed to support compliance across multiple privacy frameworks simultaneously. Whether your organization operates under POPIA in South Africa, GDPR in Europe, PIPEDA in Canada, or FIPPA in Ontario, the same foundational Privacy by Design architecture applies: collect only what is necessary, use it only for its stated purpose, protect it to the highest standard, and delete it when it is no longer needed.

{{post-cta}}

South African Organizations Need a Proctoring Partner Built for POPIA
Integrity Advocate collects only what is necessary, limits disclosure through human review, notifies every test taker proactively, and deletes biometric and session data within 24 hours of completion. Download the compliance brief to see how we meet POPIA's eight conditions for lawful processing.

Book a demo today!

Let us walk you through how IA helps with scalable proctoring in 30 minutes.

Frequently asked questions

Find answers to the most commonly asked questions from our clients.

POPIA is South Africa's Protection of Personal Information Act. It governs how personal information is collected, used, stored, and deleted by both public and private organizations. Online proctoring platforms collect identity data, biometric information, and session recordings from test takers, all of which constitute personal information under POPIA. Any organization using proctoring in South Africa or processing data from South African test takers must meet POPIA's requirements.

The Information Regulator began enforcing POPIA on July 1, 2021. Organizations that have not yet aligned their data processing practices, including their proctoring vendors, with POPIA's requirements are currently exposed to enforcement action.

POPIA's eight conditions are accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data subject participation. Each condition places specific obligations on how personal information must be handled from collection through to deletion.

Yes. POPIA classifies biometric data as special personal information and places additional restrictions on its processing. Facial images used for identity verification, behavioral biometric data, and any physiological characteristics collected during a proctoring session fall within this category. Integrity Advocate deletes biometric data within 24 hours of session completion for compliant users and does not use it for any secondary purpose.

The Information Regulator can issue compliance notices, conduct investigations, and impose administrative fines of up to R10 million. Certain POPIA offences also carry criminal liability including potential imprisonment. The accountability obligation rests with the responsible party, meaning the organization deploying the proctoring platform, not just the vendor.

Look for a vendor that collects only what is necessary for the assessment, obtains informed consent before collection, uses data only for its stated purpose, does not sell or transfer data to third parties, retains biometric data for the shortest possible period, provides test takers with proactive notification of what was retained, and can demonstrate security certification from an independent third party.