September 15, 2020
|
5 min read
Most proctoring companies collect far more personal data than test takers realize, and their privacy policies say so explicitly. This post breaks down what proctoring providers are actually collecting, shares four real privacy policy excerpts that should concern any organization, and explains how Integrity Advocate's Privacy by Design approach limits collection, mandates deletion, and keeps learner data out of the hands of third parties.

Consider two scenarios.
In the first, security cameras in a school record a student walking through the hallways and interacting with friends. The school stores the recording indefinitely as part of the student record and shares it with other organizations.
That feels wrong.
In the second scenario, cameras capture the same student bullying a younger student. Only the portion of the recording showing the behavior is retained, and it is shared with the organizations responsible for taking appropriate action.
That feels reasonable. There is a legitimate purpose, a proportionate response, and a clear limit on what gets shared and why.
Remote proctoring technology is an extension of the same principle. The question is whether the companies providing it are applying that principle, or ignoring it entirely.
Most people assume online proctoring captures what it needs to verify identity and monitor an assessment session. The reality, based on the privacy policies of many proctoring providers, is considerably broader.
Many proctoring services collect, intentionally and unintentionally, personal information that includes:
This is not a hypothetical. This is what the privacy policies say.
The following are real excerpts from proctoring company privacy policies currently in use. Read them carefully.
1. "By accessing and using our Services, you consent to allow free exchange of proctoring information between [Proctoring Service Company] and your educational institution. We, or vendors on our behalf, may track the websites you visited before and after our websites as part of the traffic data described above for our internal business purposes."
2. "If your institution has consented, we may also use third-party solutions to process selected data."
3. "We may disclose information, including video and audio recording of your exam session, to your educational institution/certifying entity upon request. Your information may be sold or transferred as part of that transaction."
4. "We cannot ensure or warrant the security of any information you transmit to us or store on the Services, and you do so at your own risk."
Students and workers taking online assessments are required to submit to proctoring. They do not have the option to choose a different provider or opt out. That disparity in power makes these policies more than a legal formality. It makes them an ethical issue.
The school camera analogy holds here too. We expect schools to share footage of students only when there is a legitimate reason and only to the extent necessary. We should expect the same from proctoring technology.
Privacy by Design is not a compliance label. It is an architectural commitment — the decision to build data minimization, purpose limitation, and deletion into the product from the start, rather than adding privacy language to a policy document after the fact.
That is how Integrity Advocate is built.
Integrity Advocate collects only what is necessary to verify a learner's identity and confirm whether they followed the rules set by the organization running the assessment. Nothing more.
The approach is similar to how PayPal operates as an intermediary in a financial transaction, protecting both parties without either side needing to expose more than is required. Integrity Advocate sits between the organization and the test taker's personal data, sharing only what is needed and only when there is a documented reason.
In practice, that means:
Read the privacy policies of other proctoring providers and ask how many of them can say the same.
Before signing a contract with any proctoring platform, your organization should be able to answer the following questions from their privacy policy and data processing documentation:
If the answers are not clearly documented, that is an answer in itself.
{{post-cta}}
Find answers to the most commonly asked questions from our clients.
Many proctoring platforms collect significantly more than identity and session data. Depending on the provider, this can include government-issued ID numbers, full browsing and search history, biometric data, medical information, political affiliations, and footage of others in the test taker's environment such as family members or housemates. The only way to know what a specific provider collects is to read their privacy policy in full.
Retention practices vary widely by provider. Integrity Advocate deletes all session recordings and desktop recordings within 24 hours of a completed session where no rule violations are found. Only a single identity photo is retained beyond that point.
US-based proctoring companies are subject to US government data requests, including those made under laws that may not require notification to the individual. As a Canadian company, Integrity Advocate operates outside US jurisdiction. In the unlikely event of a compelled disclosure, the data available on the vast majority of users would be limited to a name and a facial image represented as a string of code.
Privacy by Design means that data minimization and privacy protections are built into the product architecture from the start, not added as policy language after the fact. For proctoring, it means the platform collects only what is necessary, deletes what is not needed, and limits sharing to what is required to document a specific finding. It is the difference between a platform that is private by default and one that is private only when required by law.
Look for clear answers to five questions: what is collected and is it limited to what is necessary; whether data is sold or shared with third parties; how long data is retained and what triggers deletion; whether the vendor is subject to US government data requests; and whether there is a human review process before findings are shared with the institution.