When an institution moves an exam online, it quietly takes on a second job it may not have planned for: it becomes a custodian of student data. Webcam feeds, screen activity, IP addresses, timestamps, device fingerprints — the machinery that makes remote assessment possible also generates a stream of personal information about minors and adults alike. Handling that stream carelessly is not just a privacy problem; in most of the world it is a legal one.
This guide is a plain-English orientation for teachers, administrators, and anyone evaluating an online exam or proctoring tool. It is not legal advice — every institution should confirm its obligations with its own data-protection officer or counsel — but it will help you ask the right questions.
What online exam tools actually collect
Not all tools collect the same things, and the differences matter enormously. Broadly, the data falls into tiers of sensitivity:
- Basic assessment data: the student's answers, scores, and submission times. Every assessment collects this; it is the least contentious tier.
- Session telemetry: tab-switch events, focus changes, fullscreen exits, connection drops. This describes behaviour during the exam without recording the student's person.
- Biometric and environmental data: webcam video, screen recordings, audio, room scans. This is the most sensitive tier — it captures the student's face, their surroundings, and often other people in the household.
A key insight is that these tiers are not a package deal. A tool can provide meaningful integrity monitoring using only the first two tiers. The heaviest privacy costs come almost entirely from the third — and the third is exactly the tier that regulators scrutinise most closely.
GDPR: the European framework (and its global reach)
The EU's General Data Protection Regulation applies whenever you process the personal data of people in the EU or UK, regardless of where your institution is based. Several of its principles bear directly on online assessment.
Lawful basis and consent
You need a lawful basis to process personal data. For assessment, institutions often rely on "public task" or "legitimate interests" rather than consent — because consent that a student cannot freely refuse (sit the exam or fail) is not valid consent under GDPR. This is a subtle but important point: bolting a "click to consent to webcam monitoring" checkbox onto a mandatory exam does not, on its own, make the processing lawful.
Data minimisation
Article 5 requires that data be "adequate, relevant and limited to what is necessary." This is the principle that should shape every proctoring decision. If a class quiz can be secured with focus tracking alone, recording video "just in case" is very hard to justify. The question is never "what could we collect?" but "what is the minimum we need for this specific assessment's risk?"
Special category data
Biometric data used to uniquely identify someone receives extra protection under Article 9. Facial-recognition-based identity verification can fall into this category, which raises the bar significantly. Many tools sidestep this by doing presence checks rather than biometric identification — a meaningful distinction both technically and legally.
The data protection impact assessment (DPIA). For high-risk processing — and large-scale monitoring of students generally qualifies — GDPR expects a DPIA before you deploy. This is not bureaucratic box-ticking; it is a structured way to notice, in advance, that you were about to collect far more than you needed.
FERPA: the US framework
In the United States, the Family Educational Rights and Privacy Act governs "education records" held by institutions that receive federal funding. FERPA is built around a different core idea than GDPR: it is primarily about access and disclosure — who may see a student's records, and the conditions under which they may be shared with third parties.
For online exams, the practical FERPA questions are: Does the proctoring vendor become a "school official" with a legitimate educational interest, allowing data to be shared with them without separate consent? What does the vendor do with the data afterwards — is it used only to provide the service, or repurposed? For students under 18 in K–12 settings, additional protections and parental rights apply, and some states layer their own student-privacy statutes on top.
The questions to ask any vendor
Whether you are bound by GDPR, FERPA, or both, the same short list will tell you most of what you need to know about a tool:
- What is the minimum data required to use it? Can monitoring be dialled down per assessment, or is heavy collection all-or-nothing?
- Where is video processed? Streamed to a server, or analysed locally in the browser and discarded? Local processing means there is no footage to breach, subpoena, or misuse.
- What is actually stored, and for how long? Raw video, or only an event log? Who controls the retention period — you or the vendor?
- Who owns the data? The institution should. Responses and records should belong to you, not become the vendor's asset.
- Is any data used to train models or shared with third parties? This should be a clear, contractual "no" for student data.
- Can students see, in advance, exactly what will be monitored? Transparency is both a legal expectation and a matter of basic fairness.
The design principle underneath all of it
Both GDPR and FERPA, for all their differences, point in the same direction: collect less, be transparent, and keep control of what you collect. The architecture that best satisfies this is "privacy by design" — building the system so that sensitive data is never collected or never leaves the student's device in the first place, rather than collecting everything and promising to guard it well. A breach cannot expose footage that was never uploaded.
This is not only a compliance strategy; it is a trust strategy. Students who understand that their exam is monitored proportionately, transparently, and without their bedroom being recorded to a server are far more likely to accept the monitoring as legitimate. Privacy and integrity are usually framed as a trade-off. Handled well, they reinforce each other.
References & Further Reading
- Regulation (EU) 2016/679 — General Data Protection Regulation (GDPR), official text: gdpr-info.eu.
- Family Educational Rights and Privacy Act (FERPA), U.S. Department of Education: studentprivacy.ed.gov.
- UK Information Commissioner's Office — guidance on data protection impact assessments: ico.org.uk.
This article is general information, not legal advice. Confirm your obligations with your institution's data-protection officer or legal counsel.