May 2, 2024

|

5 min read

Who Is Liable When Proctoring Goes Wrong? Lessons From Global Legislation and Cases

Courts and regulators across Canada, the EU, and the United States have consistently found that organizations deploying proctoring tools bear liability for how participant data is handled, not the software vendors they use. CASL, GDPR, BIPA, and the Cleveland State Fourth Amendment case all point to the same conclusion: the organization collecting data is the accountable party. This post examines each case and framework and explains what organizations need to do to reduce their exposure.

Defensible Outcomes
Compliance
Privacy & Data Protection
Caroline Esteves
Growth Marketing Specialist
Share
integrity-advocate-staging.webflow.io/resources/who-is-liable-when-proctoring-goes-wrong-lessons-from-global-legislation-and-cases
Copy link
Woman working on a laptop at a home desk, with plants and natural light in the background.

When a proctoring tool violates a participant's privacy, who is responsible? The software vendor? The organization that deployed it? Both?

Recent legislation and court decisions from Canada, the UK, and the United States have answered this question with increasing clarity: the liability rests with the organization running the testing, not the software provider. For anyone deploying online proctoring, this is not an abstract legal point. It is a direct operational risk.

The Core Issue

Organizations that deliver online training and testing have a legitimate need to confirm who is taking their assessments and that participants are engaging in good faith. Meeting that need often requires collecting sensitive personal data: ID images, biometric verification, session recordings, and audio. The question of who bears legal responsibility for how that data is handled has been answered by courts and regulators in ways that most organizations have not fully reckoned with.

The consistent finding across multiple jurisdictions is that the data-collecting organization, not the software vendor, is the accountable party.

CASL: The Canadian Perspective

Canada's Anti-Spam Legislation was created in 2014 to reinforce best practices in electronic communications and combat spam and related cyber threats. Among its provisions, CASL requires organizations to obtain consent and written acknowledgement before using invasive computer programs, and to provide users with assistance in removing such programs afterwards.

Under CASL, software is considered invasive if it interferes with the user's control of their computer system by opening programs, printing, or accessing files without their knowledge, or if it changes system settings, preferences, or commands without their knowledge.

Online proctoring tools that block restricted sites, monitor web use, require camera access, or install browser extensions clearly fall within this definition. And most proctoring plugins do not provide uninstall assistance, remaining active by design after the session ends to reduce support overhead for the vendor.

The risk for organizations: CASL violations carry regulatory penalties of up to $10 million per violation. If your proctoring system leaves you liable to CASL noncompliance, that exposure belongs to you, not your vendor.

GDPR: The Global Standard That Places Liability on the Data Owner

The EU's General Data Protection Regulation has established a universal standard for data privacy that reaches any organization handling the personal data of EU residents, regardless of where that organization is based.

Under GDPR, the organization running the testing is the data controller, while the proctoring tool is the data processor. Fines for inappropriate collection, storage, transfer, or deletion of personal data fall on the data controller, not the data processor.

Ireland's Data Protection Commission made this distinction explicit in a judgment against Slane Credit Union Limited, stating that processors cannot be used by controllers as a legislative safety net, and that it is essential that due diligence is carried out to ensure the protection of personal data.

GDPR fines can reach 20 million euros or 4% of a company's total worldwide annual revenue, whichever is higher. The liability for how a proctoring vendor handles learner data belongs to the organization that chose to deploy it.

BIPA: The Illinois Warning

American organizations are increasingly coming under regulatory scrutiny for proctoring practices. Illinois' Biometric Information Privacy Act is one of the most consequential examples.

BIPA places liability on organizations when biometric data is collected or used in a way that violates participant privacy, including failing to secure written consent and failing to publish a retention schedule outlining when data will be permanently destroyed.

Two landmark cases illustrate how serious this exposure can be.

BNSF Railway Co. was subject to a $228 million jury verdict for scanning the fingerprints of truck drivers without consent. The case was eventually settled for $75 million. The third-party vendor that provided the scanning technology was not implicated in the charges.

White Castle System Inc. faced a separate BIPA lawsuit in which the Illinois Supreme Court ruled that claims accrue with each individual finger scan, exposing the restaurant chain to a potential liability in the billions of dollars. White Castle ultimately settled for approximately $10 million. Again, the vendor supplying the technology was not the party held accountable.

The pattern across both cases is consistent: the organization that deployed the biometric technology bore the liability. The software vendor did not.

Cleveland State: A Fourth Amendment Violation

In 2022, a federal court found that Cleveland State University's remote testing requirement of a room scan constituted unreasonable search and seizure in violation of students' Fourth Amendment rights.

Cleveland State used two separate proctoring providers to facilitate these scans. Both were named in the decision. Neither was fined. The university bore the consequences.

This case illustrates two important points. First, the room scan requirement itself was the violation, regardless of which vendor implemented it. Second, choosing a proctoring tool that conducts room scans does not transfer the legal risk to the vendor. The organization that required the scan is the one that faces the consequences when that requirement is found to violate participant rights.

What This Means for Online Training and Testing Providers

These cases are not outliers. They reflect a consistent and accelerating trend in privacy legislation globally: organizations are responsible for the actions of any third-party software, plugins, or services they deploy. Vendor liability does not substitute for organizational accountability.

For organizations delivering online training and testing, this has direct implications for vendor selection. The question is not just whether a proctoring tool works. The question is whether deploying it creates liability for your organization under CASL, GDPR, BIPA, or other applicable legislation.

The steps that reduce that liability are straightforward: choose a vendor with documented privacy practices, confirm that data handling complies with the legislation applicable to your jurisdiction and your learners' jurisdictions, require clear data deletion timelines, and ensure that any software deployed on learner devices complies with consent and removal requirements.

How Integrity Advocate Approaches This

Integrity Advocate is designed to reduce the compliance exposure that comes with deploying a proctoring tool, not to add to it.

No installation is required in most cases, which eliminates CASL's invasive software provisions entirely for the majority of deployments. Data is collected only for its stated purpose and deleted by default within 24 hours of session completion. Consent is obtained before any data collection begins. Data is stored in GDPR-designated jurisdictions. Room scans are optional rather than mandatory, and can be enabled or disabled based on the organization's assessment of their necessity and proportionality.

These are not policy commitments. They are architectural decisions built into how the platform works.

{{post-cta}}

The Liability for Proctoring Violations Rests With Your Organization, Not Your Vendor
Integrity Advocate is built to reduce that exposure. No mandatory installation, 24-hour data deletion by default, consent-first design, and optional room scans. Choose a proctoring partner that takes your liability seriously.

Book a demo today!

Let us walk you through how IA helps with scalable proctoring in 30 minutes.

Frequently asked questions

Find answers to the most commonly asked questions from our clients.

In most jurisdictions, the organization deploying the proctoring tool is considered the data controller and bears primary liability for how participant data is collected, stored, and handled. The software vendor is typically considered the data processor. Courts and regulators in Canada, the EU, and the United States have consistently found that organizations cannot use third-party vendors as a liability shield.

Canada's Anti-Spam Legislation requires organizations to obtain consent before deploying invasive computer programs and to provide assistance in removing them afterwards. Online proctoring tools that monitor web use, require camera access, block restricted sites, or install browser extensions meet CASL's definition of invasive software. Organizations that deploy non-compliant proctoring tools face penalties of up to $10 million per violation.

Two cases illustrate the scale of BIPA exposure. BNSF Railway Co. received a $228 million jury verdict for collecting truck driver fingerprints without consent, later settled for $75 million. White Castle System Inc. faced potential liability in the billions after the Illinois Supreme Court ruled that BIPA claims accrue with each individual finger scan, ultimately settling for approximately $10 million. In both cases, the third-party vendors supplying the biometric technology were not implicated. The organizations that deployed it bore the consequences. For testing organizations collecting biometric data from participants, the liability structure is identical.

Under GDPR, the organization running the testing is the data controller and bears primary liability for how personal data is handled. The proctoring tool is the data processor. Ireland's Data Protection Commission has explicitly stated that processors cannot be used by controllers as a legislative safety net. GDPR fines of up to 20 million euros or 4% of global annual revenue fall on the data controller.