February 9, 2021

|

5 min read

Is Your Ontario Institution FIPPA Compliant? What Online Proctoring Providers Need to Know

Ontario universities, colleges, hospitals, and designated agencies are subject to FIPPA, and every vendor handling learner personal information must meet its standards. This guide walks through FIPPA's seven key principles and explains how Integrity Advocate meets each one, from limiting collection to automated data deletion, proactive learner notification, and human review that limits what gets shared with institutions.

Privacy & Data Protection
Compliance
Assessment Security
Caroline Esteves
Growth Marketing Specialist
Share
integrity-advocate-staging.webflow.io/resources/is-your-ontario-institution-fippa-compliant-what-online-proctoring-providers-need-to-know
Copy link
Woman working on a laptop at a home desk, with plants and natural light in the background.

If your organization is a university, college, hospital, or designated agency in Ontario, the Freedom of Information and Protection of Privacy Act applies to every vendor you work with that handles personal information, including your online proctoring platform.

FIPPA has governed Ontario institutions since June 10, 2006. It establishes a uniform regulatory framework for how personal information is collected, used, disclosed, retained, and destroyed. For online proctoring, which collects identity data, session recordings, and behavioral information from learners, FIPPA compliance is not optional. It is a condition of operating within Ontario's public sector ecosystem.

This guide walks through FIPPA's seven key principles and explains exactly how Integrity Advocate meets each one.

What Is FIPPA and Who Does It Apply To?

The Freedom of Information and Protection of Privacy Act serves two purposes. First, it gives individuals the right to access information held by Ontario government institutions. Second, and more relevant to online proctoring, it protects the privacy of individuals by limiting how institutions and their service providers collect, use, and disclose personal information.

FIPPA applies to all Ontario government ministries and any agency, board, commission, corporation, or other body designated as an institution under the regulations. In practice, this includes Ontario universities, colleges, hospitals, and a broad range of publicly designated organizations.

When an Ontario institution uses an online proctoring platform, the vendor handling learner data becomes accountable to FIPPA standards. Choosing a vendor that does not meet those standards creates compliance risk for your institution.

Why FIPPA Compliance Matters for Online Proctoring

FIPPA places emphasis on Privacy by Design, meaning privacy protections must be built into information systems from the ground up, not layered on after the fact. For proctoring platforms, this means the architecture itself must reflect the principles of collection limitation, purpose restriction, and timely data destruction.

Organizations using proctoring vendors that collect more data than necessary, retain it longer than required, or share it without appropriate controls are exposed to FIPPA investigations, Information and Privacy Commissioner findings, and reputational risk with learners who have a right to know how their data is handled.

FIPPA's Seven Key Principles and How Integrity Advocate Meets Each One

1. Authority to Collect and Manner of Collection

FIPPA limits the collection of personal information to authorized activities and requires that collection come directly from the individual except in limited circumstances.

Integrity Advocate collects only what is required to verify a learner's identity and monitor their session. If a learner is not permitted to access other browser tabs during their assessment, Integrity Advocate monitors exactly that and nothing more. Other proctoring providers routinely collect browsing history, desktop file lists, and program inventories that go well beyond what any assessment requires.

The only data Integrity Advocate receives from sources other than the learner directly is the learner's first name, last name, and email address, which comes from the Learning Management System solely for the purposes of identity verification and session communication.

2. Notice Requirements

FIPPA requires that individuals be informed of the collection of their personal information before it occurs.

Integrity Advocate presents its privacy policy to every user at the start of every session. Users must actively accept the policy before any personal information is collected. The privacy policy and session instructions are available in dozens of languages to ensure that consent is genuinely informed, regardless of the learner's primary language.

3. Proper Use and Disclosure

FIPPA limits the use and controls the sharing of personal information to authorized activities only.

Integrity Advocate provides a full human review service specifically designed to limit what gets shared with client organizations. When a session produces no violations, no session media is shared. When a session is flagged, only the minimum information required to document the specific concern is shared, with unrelated personal information redacted. This is the opposite of how most proctoring platforms operate, where full session recordings are routinely handed over to institutions regardless of whether a violation occurred.

4. Accuracy

FIPPA requires that processes be in place to keep personal information accurate.

Integrity Advocate session findings represent a documented snapshot of what occurred during a specific assessment. Because findings are based on human review rather than automated algorithmic flags, the information recorded is assessed for accuracy before it becomes part of any record. Session data does not change over time, which eliminates the risk of drift or corruption that can affect systems relying on ongoing data updates.

5. Retention

FIPPA requires that individuals be able to obtain access to their own personal information for a defined period.

Integrity Advocate eliminates the need for learners to submit formal access requests by proactively notifying every user by email after their session is completed and reviewed. The notification details what information was retained beyond the session and what conclusions were drawn. Learners know exactly what is on file about them without having to ask.

6. Security

FIPPA requires that personal information be kept secure and confidential.

Integrity Advocate uses 256-bit encryption for all data in transit and at rest, stores data on AWS infrastructure in Montreal by default, and has maintained zero data breaches across 12 or more years of operation. The platform holds SOC 2 certification, providing independent third-party verification of security controls. Compliant user identification images and session media are deleted within 24 hours of session completion. Personal data that does not exist cannot be breached.

7. Disposal and Destruction

FIPPA requires that the disposal and destruction of personal information be authorized and secure.

Every piece of personal data collected by Integrity Advocate carries a programmatically applied time-to-live setting. When a session is complete, deletion occurs automatically and exactly as communicated to the learner. There is no manual process, no exception handling, and no risk of data persisting beyond its intended retention period.

Built for Ontario Institutions

FIPPA is one of several privacy frameworks that Ontario institutions need to navigate. Depending on the nature of your program and the location of your learners, PIPEDA, PIPA, GDPR, and FERPA may also apply. Integrity Advocate is built to support compliance across multiple frameworks simultaneously, with the same foundational Privacy by Design architecture underlying each.

For Ontario institutions specifically, Integrity Advocate provides the documentation, audit trail, and data handling practices your compliance and legal teams need to demonstrate that your proctoring vendor meets FIPPA's standards.

{{post-cta}}

Ontario Institutions Need a Proctoring Partner Built for FIPPA
Integrity Advocate collects only what is necessary, limits disclosure through human review, notifies every learner of their session data proactively, and deletes information automatically when it is no longer needed. Download the compliance brief to see exactly how we meet FIPPA's seven principles.

Book a demo today!

Let us walk you through how IA helps with scalable proctoring in 30 minutes.

Frequently asked questions

Find answers to the most commonly asked questions from our clients.

FIPPA is Ontario's Freedom of Information and Protection of Privacy Act. It governs how Ontario public institutions and their service providers collect, use, disclose, and destroy personal information. Because online proctoring platforms collect identity data, session recordings, and behavioral information from learners, any proctoring vendor working with an Ontario university, college, hospital, or designated agency must meet FIPPA standards.

FIPPA applies to all Ontario government ministries and any agency, board, commission, corporation, or other body designated as an institution under the regulations. In practice this includes Ontario universities, colleges, hospitals, school boards, and a broad range of publicly designated organizations. If your institution receives public funding or operates under provincial designation, FIPPA almost certainly applies to you.

FIPPA's seven principles are authority to collect, manner of collection, notice requirements, proper use and disclosure, accuracy, retention, and security and disposal. Each principle places specific obligations on how learner personal information must be handled throughout the assessment process, from collection to deletion.

No. FIPPA limits collection to what is authorized for the specific activity. Proctoring platforms that collect browsing history, desktop file inventories, or program lists beyond what is needed to verify identity and monitor the session are not operating within FIPPA's collection limitation requirements. Integrity Advocate monitors only what the assessment rules require and nothing more.

Yes. FIPPA requires that individuals be notified of the collection of their personal information before it occurs. Integrity Advocate addresses this by presenting its privacy policy to every learner at the start of every session, requiring active acceptance before any data is collected, and providing the policy in dozens of languages to ensure genuine informed consent.