Privacy Notice
Last modified October 1, 2026
You're viewing a filtered version of this notice. View full notice
1. General
This Privacy Notice applies to your use of the "Service(s)," which include the following:
- Any of our products and services, such as our Automated Proctoring, Lock Down, ID Verification, Originality Verification, our browser plug-in, and other related platform features or modules (collectively, the "Platform") whether as a Test-Taker ("Test Taker") or an Institutional representative or administrative account holder ("Institutional User");
- Our website, located at https://proctorio.com/ (the "Site");
- Contacting us, such as through telephone, email, or mail, for ordering and support.
If you provide Personal Information through Proctorio's Services, Proctorio may process Personal Information for the purposes described in this Privacy Notice.
Note: When education providers and other institutions ("Institutions") use the Proctorio Platform, the type of Service and settings selected by the Institution determine what Personal Information Proctorio processes and what Proctorio can collect from the Test Taker. We describe how these options function in this Privacy Notice; however, this Privacy Notice does not govern an Institution's use of your Personal Information. We process Personal Information on behalf of Institutions per their instructions and subject to our agreements with those institutions. To learn more about how Institutions use your Personal Information, please review their privacy policies or contact them directly. We are not responsible for the privacy or security data practices of Institutions.
2. What is Personal Information
For purposes of this Privacy Notice, "Personal Information" means information that identifies, relates to, describes, is capable of being associated with or could reasonably be linked, directly or indirectly, with a particular consumer or household, such as your name, mailing and email addresses, phone number, and other information that permits us to contact you at a physical location, online, or by electronic communication, including telephone or email.
Capitalized terms not defined herein shall have the meaning given to them in SaaS Agreement and Terms of Service. The SaaS Agreement and the Terms of Service fully detail both Proctorio's and the Institution's obligations in relation to the confidentiality of data.
3. How Our Platform Collects and Processes Personal Information (Data Processor)
When Proctorio operates the Platform on behalf of an Institution, Proctorio processes Personal Information as the Institution's data processor, and this notice is provided as a convenience to Test Takers. Proctorio's processing of Personal Information may be subject to additional restrictions under its agreements with Institutions and Institutions may process data for purposes not described in this Privacy Notice. Any Personal Information Proctorio provides to or receives from an Institution remains subject to the Institution's own privacy policy, which is the primary notice for the Institution's processing.
Proctorio limits the Personal Information collected from end-users through their use of Proctorio's Services. For example:
- Proctorio only collects Personal Information as instructed by your Institution. This is dependent on the Services and settings selected by the relevant Institution-approved representatives.
- Proctorio pseudonymizes specific Test Taker Personal Information.
- Audio, video, and screen recordings and images collected and stored by Proctorio are encrypted and can only be decrypted by Institution-approved representatives. For the avoidance of doubt, Proctorio cannot decrypt the audio, video, screen recordings and images collected and stored by Proctorio.
- If you voluntarily provide Personal Information through Proctorio's Sites or Services, Proctorio may retain this Information.
- Test-taker audio, video, and screen recordings and images received from Institutions and processed by Proctorio are end-to-end encrypted and can only be decrypted by Institution-approved representatives. Only the Institution holds the decryption keys; Proctorio cannot decrypt this content.
Proctorio's Institution Services: When an Institution purchases Proctorio's Services, the type of Service and settings selected by the Institution determine what Personal Information an Institution may provide to Proctorio or what Proctorio can collect from the Test Taker. This is described in more detail below.
3.1 Proctoring
3.1.1 General
Only an Institution may request Proctorio to use Automated or Live Proctoring during the administration of an exam.
With either Automated or Live Proctoring, an exam administrator may instruct Proctorio to monitor Test Takers via a webcam, microphone, browser, and/or desktop in an effort to uphold the integrity of the assessment. Depending on the settings chosen by the Institution, this may include a scan of the Test Taker's surroundings, screen, and computer display, as well as video and other feature-specific categories of Personal Information (described below). This monitoring will either be automated ("Automated Proctoring") and/or conducted by a live proctor ("Live Proctoring"). The Test Taker will be notified, before the beginning of an exam, whether Automated or Live Proctoring is being used.
3.1.2 Live proctors
Live proctors are used for Live Proctoring and Standard ID Services only when selected by an Institution.
Proctorio is a software company, not a proctoring services company. Live proctoring is primarily delivered under Be Your Own Proctor (BYOP), a registered trademark of Proctorio (US, UK, and EU): your institution proctors its own exams with its own personnel, or contracts a third-party proctoring service, an arrangement Proctorio sometimes facilitates. In limited cases arranged in advance with the institution, Proctorio provides proctors from its own staff.
Proctors provided by your institution or by its contracted third party act for your institution and are governed by your institution's arrangements and policies. The protections below describe Proctorio's own proctors:
All Proctorio proctors sign a confidentiality agreement restricting them from using and disclosing any of the Test Taker's Personal Information for any purpose other than providing the testing services.
Any Proctorio proctors are full-time Proctorio employees and are required to go through an extensive background check and fingerprinting process. All Proctorio proctors can view, note, and record exam attempts. Proctorio proctors go through a five-week training process with Proctorio's Proctorio Training Specialists and must complete Privacy & Security Training. The proctors are the only employees who have access to the tools required for Live Proctoring and only company-owned and controlled devices can access this information. This is further restricted using IP address restrictions to ensure these devices are being accessed in appropriate locations. Proctorio proctors are then uniquely identified at sign-on by using two-factor authentication and the device is restricted based on the user's group, department, and access level. Device compliance testing is run regularly and devices out of compliance are blocked from accessing any restricted resources until compliance is restored.
3.2 Automated Proctoring
3.2.1 Video and audio recording
Only your Institution maintains and controls the decryption keys necessary to decrypt Test Taker audio and video recordings and images. As previously stated, Proctorio cannot decrypt the audio, video, and screen recordings and images collected and stored by Proctorio.
The Institution determines whether audio and/or video is used to monitor and/or record exam sessions and only the exam administrators have access to these audio and/or video recordings. If selected, the entire exam session may be recorded.
The Institution also decides whether to record the Test Taker's audio during the exam attempt. If selected, the Test Taker's microphone may be turned on during the session.
Audio, video, and image files are encrypted prior to being transferred to Proctorio's cloud service provider in the location specified by the Institution. The Institution maintains and controls decryption keys, and only the Institution may assign these keys to individuals who the Institution designates as appropriate.
Depending on the Institution's location, these audio and video files are stored on Proctorio's cloud service provider's servers in the US, Europe, Canada, Japan, Australia, South Africa, Singapore, or Abu Dhabi. These files never leave the controlling location of the Institution.
Record Screen, Record Web Traffic, and Record Room/ Periodic Desk Scan are additional options that an exam administrator can select for an exam.
Verify Audio, Video, Desktop and Signature may also be selected by the exam administrator and the Test Taker is required to take those actions prior to the start of the exam.
As a result of these Institution-selected monitoring or verification options, Proctorio may collect Personal Information such as a Test Taker's image and Personal Information that may be shared through the screen, desktop, webcam, web traffic or microphone of the Test Taker's device.
3.2.2 Facial and gaze detection
If your Institution elects to use Proctorio's proctoring Services that enable video recording, Proctorio uses facial detection or gaze detection to flag potentially suspicious test activity to help Institution-approved representatives maintain assessment integrity. The Institution may choose to disable facial detection and gaze detection as a secondary setting of the video recording feature if it wishes to opt out of facial detection and gaze detection, but still record the exam session.
Outside of the optional, consent-based identity features described in this notice (identity verification and re-verification before your exam, and Continuity Check during it, each described in its own section), Proctorio does not use what is conventionally known as "biometrics" or "facial recognition" technology. Facial recognition uniquely identifies specific people by assessing whether the face in one image matches the face in another image. It requires a database of either images of people's faces, or biometric representations of them, and technology that compares new images or biometric representations with entries in that database.
Instead, Proctorio uses "facial detection" or "gaze detection" technology. A fundamental difference between these technologies and biometrics or facial recognition technology is that facial or gaze detection technologies do not use geometry or landmarks as identifiers. Additionally, this difference can be illustrated by the questions they answer:
- Facial Recognition: "Does the face in this picture match the face in this other picture?"
- Facial Detection: "Is there a face in this picture?"
- Gaze Detection: "Is the person looking away from the camera or the exam screen?"
Facial detection can identify that there is a human face present in an image or video recording, but it cannot identify that person – only that there is, indeed, a person in the image or recording.
Gaze detection can determine the direction that the individual is looking, but cannot identify who they are or what they are looking at.
If the exam administrator enables the use of video recording, Proctorio uses facial detection to flag video evidence that may indicate the number of individuals present within the immediate vicinity of the Test Taker, but Proctorio does not attempt to determine who those individuals are.
If a Test Taker is not able to pass the face detection process and enter an exam within three attempts, a Proctorio Support Agent initiates a live chat to troubleshoot the issue. The Support Agent can request access to webcam images from the system, provide instructions that ensure clearly-captured images, and override the system if needed to expedite exam entry.
If the exam administrator enables the use of video recording, Proctorio can use gaze detection to flag video evidence that the individual was looking at something other than the device they were using to take the exam. This helps Institution-approved representatives prioritize where to review exam video recordings to determine if the Test Taker was consulting unauthorized materials or was receiving outside assistance during the exam attempt. However, the Institution may choose to disable facial detection and gaze detection as a secondary setting of the video recording feature if it wishes to opt out of facial detection and gaze detection, but still record the exam session.
3.2.3 Continuity Check
If your institution enables it, Proctorio checks periodically throughout your exam that the person on camera is the same person who started the exam. During your pre-exam camera checks, and only after you consent on Proctorio's pre-exam screen, Proctorio's software measures the positions of your eyes and mouth to create a geometric reference on your device. Throughout the exam, the software periodically compares the face on camera against that reference. If the face in view does not appear to match, the software logs a mismatch event with a confidence value for your institution's approved representatives to review alongside the exam recording.
The geometric reference exists only in your device's memory while your exam session is running. It is never written to disk, stored, or transmitted anywhere, and it is destroyed automatically when your exam session ends. Proctorio cannot see, retrieve, or reconstruct it. The reference cannot be used to determine who you are. This feature uses no database of faces, and its comparison is made only against the person who started your exam, never against anyone else.
Note regarding biometric data collection, retention, and destruction: Proctorio does not collect biometric data. To the extent the geometric reference described above is considered biometric data under applicable law, it is the only such data this feature creates. It exists solely in volatile memory on your device for the duration of your exam session and is permanently destroyed, automatically, when the session ends or the browser or extension is closed, whichever comes first. It is not backed up, logged, or recoverable. Mismatch events themselves (the flag, the time it occurred, and the confidence value) are not biometric data; they are stored with your exam results for your institution's Retention Period. Biometric data processed by our identity verification provider before your exam is retained and redacted as described in the Identity verification section of this notice.
A mismatch event is a flag for human review, not a determination. Your institution's approved representatives review every event and decide whether any action is warranted; Proctorio does not decide whether a mismatch means anything improper occurred. If your institution has enabled it, an exam may be paused, or ended after a configurable warning, when a mismatch event occurs; whether those settings are used, and any consequence for you, is determined and controlled by your institution. If the feature is enabled for your exam, you cannot disable it yourself; your institution can exempt you individually through an accessibility or accommodation override.
3.3 Monitoring during an exam
When exam administrators select Automated or Live Proctoring Services, Proctorio uses technology to automatically collect certain information about a Test Taker's activities during the exam session for purposes of protecting exam integrity. The flagged behaviors may include facial and gaze detection (described above) to monitor if the Test Taker leaves the session, mismatch events where the Institution has enabled Continuity Check (described above), tracked head movement to monitor how frequently the Test Taker looks away, sound detection to monitor if other voices are in the room, question response time, dropped internet connections, and other activities that may indicate irregular testing activities. When using these services, Proctorio's automated technology continually monitors the applications and processes that are running on the device during an exam session and during exam review.
If an Institution has requested reporting, Test Taker data may be aggregated, and then individual Test Taker data may be compared to the aggregated data to look for patterns or anomalies, such as whether a Test Taker spent an unusually long time answering a question relative to other users.
Proctorio does not and has not established "normal" profiles or compare Test Takers against any preserved or aggregated normal.
At the end of an exam session, the Institution-approved representative will have access to a summary report of these flagged activities, as well as the raw data the Service collects from each Test Taker's session. The Institution-approved representative then determines if any further action is warranted. Aggregated data is also provided to the Institution-approved representative (e.g. the average length of time users spent on an exam question, the average time spent on the entire assessment and the average date/time that users started the exam session).
Only an Institution determines whether to enable settings, which settings are enabled for flagging of irregular testing behaviors, and the indication levels (green, yellow, red) assigned to certain activities of the Test Taker during an exam. Following the Institution-approved representative's review, only they can determine what, if any, action to take related to a Test Taker.
Proctorio does not make any decisions related to the Test Taker from flagged activity.
3.4 Identity verification (before your exam)
If your institution requires it, your identity will be verified before your exam begins. Your institution decides whether identity verification is required, which of the options described below are available to you, and how strict they are. Depending on your institution's settings, you may not be able to opt out of presenting a government-issued ID. Depending on the option used, the Personal Information involved may include your name, government ID number, date of birth, your photo, and an image of your government-issued ID.
Proctorio offers the following options:
3.4.1 Capture ID
The simplest option. You take a picture of your ID with your webcam. The software checks only that a card-shaped document is present in the frame; it does not read the document and it does not compare the document to you. You then confirm the picture is accurate and clear. The image is stored with Zero-Knowledge Encryption alongside your exam recording, where your institution's approved representatives can review it. No biometric processing occurs in this option, and it does not create the fraud detection record described below.
3.4.2 Match ID
Your device checks your ID locally. The software reads the document using optical character recognition and, depending on your institution's settings, matches the name on the document, or the name and the document photo, to you. Everything runs on your device: the reading and the photo comparison use the same in-memory technology as Continuity Check, nothing biometric is stored or transmitted, and the comparison data is discarded when the check completes. Match ID never blocks you from an exam; it only creates a flag with the result for your institution's approved representatives to review. The ID image you capture is stored with Zero-Knowledge Encryption alongside your exam recording, like Capture ID. Match ID does not create the fraud detection record described below.
3.4.3 Validate ID
With Validate ID, your identity is verified rather than just captured. Your institution chooses one or both of the following:
3.4.3.A Instant ID
Proctorio uses a specialized third-party identity verification provider, listed in our sub-processor list below. In this method, you submit an image of your ID and, if your institution requires it, a live selfie directly to the provider through the provider's own secure capture flow. This happens only after you consent on Proctorio's pre-exam screen and in the provider's own consent and disclosure flow. The provider checks that the document is genuine and, where a selfie is required, creates a biometric template to confirm that the selfie matches the photo on the ID. That biometric template is created and held by the provider and is never shared with Proctorio. For certain processing described in its own privacy policy, including retention of biometric data for its own fraud prevention, the provider acts as an independent controller. Proctorio receives and stores a verification reference and the verification result (for example, verified or not verified).
If Instant ID cannot verify you, the software does not prevent you from taking an exam. Your verification moves to a trained agent, who reviews the images you already submitted to the provider, rather than asking you to capture them again, and a human makes a final identity verification determination. The agent's decision is recorded and visible to your institution like any other verification result, and the fraud detection record described below is created as with any Validate ID verification.
3.4.3.B Standard ID
A trained live agent visually compares you to your institution accepted ID during your pre-exam checks. In this method, Proctorio captures an image of the ID you present and stores it with Zero-Knowledge Encryption, so it can be viewed only by your institution's approved representatives alongside your exam recording. No facial template or other biometric identifier is created in this method. If your institution's setup includes Automated Re-verification, the Proctorio extension keeps an encrypted re-verification copy of your ID image and approved webcam image on your device, which Proctorio does not receive and cannot access, as described below.
3.4.4 Institution-Provided ID Check
If your institution keeps your ID and photo on file, for example from your enrollment records, it can provide them for verification instead of a live agent or the third-party provider. When your exam launches, your institution supplies secure links to its copy of your ID image and your reference photo. Only the Proctorio extension on your device downloads them, and it compares the reference photo with your live camera image on your device, the same way Continuity Check works. The comparison runs in your device's memory; the downloaded images and all comparison data are discarded when the check completes, and nothing biometric leaves your device. The webcam images captured during your entry are stored with Zero-Knowledge Encryption alongside your exam recording, like Standard ID. Your institution is responsible for the accuracy of the reference images it provides and for telling you how it holds and uses them.
3.4.5 Cross-institution fraud detection
In the Validate ID options (Instant ID and Standard ID), Proctorio stores the type of ID presented and a keyed cryptographic hash (HMAC) of the ID number, computed with a secret key that Proctorio keeps in a secure key store, separate from the stored values. Proctorio does not store the ID number itself, and without the key the stored value cannot be reversed to reveal the number or the contents of your document, or matched against guessed numbers. Proctorio retains this hashed value for a maximum of twelve months from the verification, for a single purpose: detecting when the same ID is presented at more than one institution. If that happens, Proctorio notifies the affected institutions so they can review the matter together. Proctorio does not decide whether anything improper occurred; that determination belongs to your institution. The hashed value is deleted when the twelve month period ends, and earlier if your institution approves your deletion request. Capture ID, Match ID, and the Institution-Provided ID Check do not create this record.
3.4.6 How long verification data is kept
Where your institution has an active verification license, your ID verification data is retained by the provider for one year from the license activation so you can skip re-verification, and it is redacted at the end of that year. Where verification is per exam, your verification data is retained by the provider for at least the exam's eight hour window and is redacted within twenty-four hours of the exam. Any re-verification copy Proctorio keeps for Standard ID follows the same schedule.
3.4.7 Automated Re-verification
If your institution's verification setup includes it, you will not repeat a full ID verification check every time. When you re-enter the same exam, or start another exam while your institution's verification license for you is active, your device downloads the webcam or selfie image that was approved when your identity was last verified (from the verification provider for Instant ID, from the extension's encrypted copy on your device for Standard ID, or from your institution for the Institution-Provided ID Check) and compares it, on your device and in memory, with your live camera image, the same way Continuity Check works. If the comparison confirms you, you are verified automatically, and your institution's reviewers can see that your entry was verified automatically rather than by a fresh check. If it cannot confirm you, you are never locked out automatically: you are directed to a live agent or, where your institution permits, a new verification through the provider. The downloaded image and all comparison data are removed from memory when the check completes; the check itself stores nothing.
To make this work for Standard ID, the Proctorio extension keeps a copy of your verified ID image and your approved webcam image, encrypted, in its isolated browser storage on your device. At no time do Proctorio's servers store these images, and Proctorio cannot access them. If the copy is lost, for example because you reinstalled the extension or changed devices, a live agent will simply verify you again at no cost to you. The copy follows the same retention schedule as provider-held verification data described above. When that period ends, or when your institution approves your deletion request, the extension deletes its copy and its encryption keys from its isolated browser storage on your device; after that, the copy cannot be read or recovered by anyone. If your institution uses the Institution-Provided ID Check, Proctorio keeps no copy at all: your institution supplies its reference images each time your exam launches.
3.4.8 Requesting deletion
Your institution controls your identity verification data. To request deletion at any time, contact your institution. When your institution approves the request, Proctorio initiates redaction with the provider, and the extension deletes any re-verification copy it holds, together with its encryption keys, at no cost to you. Redaction means the data is permanently deleted or de-identified so that it cannot reasonably be reidentified by anyone. Redaction is not instantaneous and may take several days to complete. If you verify again later through the automated method, it is treated as a new verification.
This section describes identity verification before your exam only. It is separate from the facial detection and gaze detection used during exam recording, which are described in the Facial and gaze detection section and do not create biometric templates or identify you. Continuity Check during an exam, where enabled by your institution, is described in its own section of this notice.
3.5 Originality Verification
If an Institution selects Proctorio's Originality Verification tool, the End User may voluntarily submit an assignment that has content or data with Personal Information included.
3.6 Lock Down Settings
If these settings are selected by an Institution and enabled on an assessment that uses Proctorio's Services, these features can be used instead of or alongside the monitoring features described above.
Depending on which features are selected by an Institution, the Test Taker's device will be locked down so that they cannot access websites, files, or other online or device resources. The Test Takers will be prevented from downloading materials or entering information that doesn't relate to the exam only during the exam session. This is done to help ensure test integrity.
When operating as a browser extension, Proctorio only has restricted access to a Test Taker's computer system. This includes no access to any personal documents or files stored on the machine.
Users have the ability to disable the Proctorio extension immediately after an exam is submitted.
Although it is not necessary to do so, Test Takers can uninstall or disable Proctorio immediately after taking an exam, and re-install or enable it only when taking future Proctorio-proctored exams.
3.6.1 Browser Extension Permissions
The Proctorio browser extension requests the following permissions. Exam administrators can choose to implement some, all, or none of the related features during the exam:
Read and change data on the websites you visit
This allows Proctorio to run on each and every website required by your exam administrator or Institution without requiring additional permissions.
Display notifications
Proctorio may display a pop-up notification while you are in the exam if you navigate away from the exam. This notification states that you are required to return to the exam window.
Modify your copy and paste functionality
The Proctorio platform's functionality does not include the ability to read or collect the contents in the test taker's clipboard. Instead, during the exam, Proctorio replaces the clipboard text with Proctorio's own content to prevent exam content distribution.
Capture content from your screen
This recording setting only runs during the exam and exam review. This ensures that test takers are remaining within the exam and showing their work with authorized tools and resources.
Manage your downloads
Downloads by a test taker will be prevented only during the course of the exam. This ensures that exam content is not shared externally.
Identify storage devices
Test-taker storage devices are detected and identified during the exam. Proctorio does not eject storage devices.
Manage your apps, extensions, and themes
Proctorio does not manage the themes of a test taker's device. But Proctorio does manage extensions and applications that may hinder Proctorio from operating properly.
Change your privacy-related settings
Proctorio uses this to temporarily block the test taker's browser "password" fill option during the course of the exam.
Test takers are alerted when Proctorio is recording, through the exam process, by the Proctorio shield icon in the upper-right-hand corner of the browser turns green, and during exam review.
This green icon indicates that the extension is running during the exam.
3.7 Important Additional Information
3.7.1 Zero-Knowledge Encryption
When processing and securing Test Taker Information from an Institution, Proctorio utilizes an end to end encryption method called "Zero-Knowledge Encryption."
"Zero-Knowledge Encryption" means that only Institution-approved representatives at Institutions that the Institution grants access to the decryption key can decrypt and review the encrypted exam recordings on Proctorio's servers.
Proctorio uses Zero-Knowledge Encryption for any audio, video, and screen recordings and images sent by a Test Taker. This means only Institution-approved representatives can decrypt, watch, and review the encrypted Information.
3.7.2 Test-Taker records
All Test-Taker records that are "student" or "educational records" obtained by Proctorio from an Institution are the property of the Institution and are under the control of that Institution.
As noted above, Proctorio will follow the instructions provided by the Institution and Proctorio acts as a processor processing Personal Information on behalf of the Institution. The Institution is the controller and the Institution's Privacy Notice controls with respect to the processing of Personal Information collected from Test Takers. Please reach out to your Institution for more information regarding their privacy practices.
4. How We Collect and Process Personal Information - Non-Platform Services (Data Controller)
The sections below describe Personal Information that may be collected from an Institution-approved representative, from our corporate Site, or other contexts where Proctorio acts as a data "controller."
4.1 Secure Exam Proctor administration - Institution registrations
To register an Institution to use the Proctorio's suite of Services, an administrator account must be created. To register an account for your Institution, an Institution-approved representative must provide Personal Information, such as:
- Institution-approved representative's name
- Phone number
- Institution name
- Campus email address
4.2 Request for demo
For Institution-approved representatives to request a demonstration of the Proctorio Services, you must provide Personal Information such as:
- Institution-approved representative's name
- Phone number
- Institution name
- Campus email address
Demonstration and sales meetings may be recorded.
4.3 Secure Exam Proctor exam enabling
An Institution-approved representative can generally utilize Secure Exam Proctor to conduct exams. To do so, the Institution-approved representative does not have to provide their name or other Personal Information. They only have to provide the single sign-on data managed through the Institution exam platform. Institution-approved representatives configure their exam settings to select whether to collect Test Taker data as described above.
4.4 Secure Exam Proctor Technical Support
To contact technical support, Personal Information such as:
- Institution-approved representative's name
- Phone number
- Email address
may be collected from an Institution-approved representative to facilitate the troubleshooting process.
Disclosure of such information by an exam administrator is voluntary and will not be sold to third parties.
4.5 Cookies
Proctorio only utilizes Single Sign-On technology to authenticate end users. Proctorio does not use registration or a log-in system on any of Proctorio's Site or Services. Proctorio manages sessions without using cookies (or HTML Web Storage) and runs cookie-free domains. Third-party Platforms or payment processors may utilize cookies on their own domains.
Proctorio does not use any client-side tracking pixels such as those used for advertising, marketing, and targeting.
4.6 Bot Detection and Abuse Prevention
Proctorio uses Cloudflare Turnstile, a bot-detection service provided by Cloudflare, Inc. ("Cloudflare"), on its dashboard sign-in and sign-up pages to protect against automated abuse, credential stuffing, and fraudulent account creation. Cloudflare Turnstile operates in the background without requiring visitors to solve a CAPTCHA challenge. Turnstile is not used within proctored exam sessions.
When you access our dashboard sign-in or sign-up pages, Cloudflare Turnstile may automatically collect and process the following information to determine whether you are a human visitor:
- Your IP address
- TLS (Transport Layer Security) fingerprint
- Browser User-Agent header
- Browser type, version, and device characteristics
- Interaction patterns (e.g., mouse movements, time spent on page)
This information is used solely to distinguish legitimate human visitors from automated bots. It is not used to identify, profile, or target individual users. Cloudflare Turnstile does not set any cookies on your device in our implementation.
4.7 Surveys, contests, feedback
Additionally, Proctorio may invite Institution-approved representatives or Test Takers to participate in surveys, questionnaires, contests, or to contact Proctorio with questions, comments, or feedback.
Participation is voluntary and only those that have opted in/consented will be contacted.
Due to the nature of some of these activities, they may include the collection of Personal Information, such as your:
- Institution-approved representative's name
- Institution details
- Location
4.8 Customer service
You may contact Proctorio about Proctorio's products and Services or with customer service inquiries. Depending on the method by which you contact Proctorio, certain Personal Information will be visible to Proctorio, including any personal information you provide in your communication. This information is identified below. Other than this information that is inherently visible based on your selected communication platform and optionally if information is needed to verify your identity, Proctorio never requires that you disclose Personal Information.
4.8.1 Customer service emails
If you contact us by email, Proctorio will obtain and store your email address.
4.8.2 Customer service phone calls
If you contact us by phone call, Proctorio will obtain and store your phone number. Support calls may be recorded.
4.8.3 Customer service Live Chat
If you contact us through chat, Proctorio will obtain your IP Address and store only part of it.
4.8.4 Job applicants
Proctorio may also collect Personal Information from job applicants needed for the employment applications, such as:
- Job applicant name
- Postal address
- Government ID numbers
- Date of birth
- Employment history
- Academic history
Job interviews may be recorded.
4.9 Marketing
Proctorio may also collect Personal Information from Institution representatives and other professionals, such as their name and email address, to send marketing communications about Proctorio's products and Services. These communications will only occur if they have consented to receiving this information. Proctorio does not sell, transfer or utilize your data for any purpose other than to provide Proctorio's Services.
Webinars and marketing events may be recorded.
Proctorio does NOT send marketing communications to Test Takers.
4.10 Automatically collected Information; log Information
When you access the Sites and Services via a browser, application, or other device, Proctorio's servers automatically record certain information. These server logs will include information such as:
- Your web request
- Your interaction with a Service
- IP address (only part of the IP address is stored)
- Browser type (high level only)
- Browser language
- The date and time of your request
Proctorio stores anonymized web server log files by keeping only part of the user's IP address and generalizing the user agent.
Proctorio does not utilize any device fingerprinting in logs.
4.11 Test-Taker payments
Some Institutions may require the Test Taker to pay for the Services. In those instances, Proctorio uses a third-party processor to process Test-Taker assessment payments. The information collected will only be used by Proctorio's third-party processor for the purpose of purchasing the Service. The information collected may include:
- Credit card number
- Credit card 3-4 digit security code
- IP address
- User agent
- Email address - to receive a digital receipt
4.12 Customer accounts and payments
Proctorio may also collect Personal Information from Institution-approved representatives using Proctorio's Services to verify business information, establish customer accounts, and to process payments. Proctorio may collect financial information from potential customers to process Proctorio's customer payments, such as:
- Business name or Business representative
- Business email
- Business phone number
- Business address
- Bank account information
- Tax ID numbers
Sometimes Institution-approved representatives may pay for the Services with a credit card. In those instances, Proctorio uses a third-party processor to process Test-Taker assessment payments. The information collected will only be used by Proctorio's third-party processor for the purpose of purchasing the service. The information collected may include:
- Credit card number
- Credit card 3-4 digit security code
- IP address
- User agent
- Email address - to receive a digital receipt
4.13 Service Information (technical and diagnostic data)
The software processes technical information needed to run your exam: connection status and quality, error and recovery signals, and integrity and security checks of the exam environment. This operational data is part of delivering the exam session itself and is processed only for that purpose, except that it may also be retained in anonymous form to compile aggregate statistics on the use of the Services. Where it requires storing information on your device or reading information already stored there, it is limited to what is strictly necessary to provide the exam you requested; for users in Germany, this is the standard of Section 25(2) of the Telecommunications Digital Services Data Protection Act (TDDDG).
Separately, the software offers optional diagnostic telemetry that helps Proctorio find and fix problems. It is off by default and runs only after you turn it on (opt-in). It collects a minimal set: an event code, the software version and distribution channel, the address of the learning platform in use, timing and count measurements, and a hashed exam and course reference. It is identified only by a random identifier that exists for the running session. It contains no name, no user identifier, no exam content, no grades, and no recordings. Diagnostic telemetry goes only to a Proctorio-operated endpoint; the software uses no third-party analytics services. It is retained only as long as needed for diagnostics and quality improvement and is then deleted or reduced to aggregate statistics.
5. Additional Uses of Personal Information
Proctorio's use of Personal Information depends on whether we are processing Personal Information on behalf of an Institution as a data processor, or if we process Personal Information on our own behalf, e.g. when an individual provides Personal Information to us directly or visits Proctorio's Sites.
5.1 As a data processor
When Proctorio is a processor for an Institution, Proctorio uses Personal Information as instructed by the respective Institution for the following Institution purposes. The information that we collect and how we use that Personal Information when operating the Platform are described in the "How our Platform Collects and Processes Personal Information (Data Processor)" section.
- Automated Proctoring
- Live Proctoring
- Identity Verification (Capture ID, Match ID, Validate ID, Institution-Provided)
- Originality Verification
- Registering an Institution
- Administrative account creation
- Institution assessment platform use
- Administering the Secure Exam Proctor environment
- Processing client payments and/or Test Taker payments
Please Note: The Institution decides which of Proctorio's products or Services to use and which settings and features to enable. While we provide information regarding the collection and sharing of data through these features for the convenience of Institutions and users, note that privacy policies of Institutions apply and Proctorio's processing of Personal Information on behalf of Institutions is subject to those privacy policies.
5.2 As a data controller
As a controller, we use your Personal Information when you register with an institution, to engage and support in customer service, process payments (may be provided by a separate third party controller), conduct surveys, receive and evaluate feedback, send marketing and promotional materials, evaluate job applications, evaluate potential business transactions, to operate and secure the Services, and as necessary to comply with legal obligations. Please note that we do not send marketing or promotional materials to individuals in their capacity as Test Takers. Please see the "How we Collect and Process Personal Information - Non-Platform Services (Data Controller)" section for more information on the personal information we process as a data controller.
In addition to the Service or feature specific processing described in the "How we Collect and Process Personal Information - Non-Platform Services" section, when we act as a data controller, we generally process Personal Information for the following general purposes:
5.3 Site operations and security
As a controller and operator of Proctorio's Site, Proctorio automatically collects information and log details to operate Proctorio's Sites.
Proctorio tracks the total number of visitors to Proctorio's Site, the number of visitors to each page of Proctorio's Site, browser type, and IP addresses. However, Proctorio anonymizes the IP address by removing the last octet of the address, making Proctorio unable to identify you or your exact location.
Proctorio may also analyze tracked data for trends and statistics in the aggregate. Such information will be maintained, used, and disclosed in aggregate form only and will not contain Personal Information.
Proctorio also has in place website security tools and processes, including penetration testing and vulnerability scans, to better ensure Site security and protection of information. In the event of a firewall event or other attempt that triggers a firewall rule, either active or passive, the offending IP address is recorded in its entirety and maintained in our data security tracking systems.
5.4 De-identified data/aggregate information
Proctorio uses de-identified information for billing and utilization analysis of Proctorio's Services and for customer billing and usage.
6. Sharing Your Information
We generally share information in the following manner. Note: Proctorio doesn't sell Test-Taker data to third parties, and Proctorio doesn't share Test-Taker data with third parties for any marketing purposes.
6.1 As a data processor
Test Taker data that enters Proctorio's system has been encrypted using an unshared key stored in an Institution's assessment platform and can only be decrypted by the Institution-approved representative within the assessment platform. Proctorio utilizes the assessment platform to gain information about the user's role. This restricts information from being shared with users who are not labeled as an Institution-approved representative. We may be granted access to Personal Information where granted by the Institution, and institutions may share data as described in the Institution's privacy policy.
For Institutions that have enabled third-party ID verification, Proctorio may use third parties for identity verification with individual consent to successfully enter or submit a proctored exam using Proctorio's Services. We use the identity verification services of the Verification Provider identified in our sub-processor list below. The provider's retention and redaction of verification data follow the schedule described in the Identity verification section of this notice.
We may also share Personal Information with our service providers who process data on our behalf, as described below.
6.2 As a data controller
In instances where Proctorio is the controller and Proctorio collects Personal Information as described in the "How we Collect and Process Personal Information - Non-Platform Services" section, we may share Personal Information as described in this Section.
6.3 Law and harm
Proctorio may disclose Test-Taker Information if Proctorio believes that it is reasonably necessary to comply with a law, regulation, or legal request; to protect the safety of any person; to address fraud, security, or technical issues; or to protect Proctorio's rights or property.
6.4 Business transfers
Test-Taker Personal Information maintained in the Institution's exam platform is the property of the Institution. Test-Taker audio, video, and screen recordings and images stored within the Proctorio servers are pseudonymized and encrypted and will not be sold. If Proctorio is involved in an acquisition, merger or other corporate reorganization transaction, they may be transferred to the successor entity only as part of that transaction, remain protected by Zero-Knowledge Encryption, and the successor must commit to using them in a manner consistent with applicable law and this Privacy Notice. In such instances, and consistent with and limited to data protection laws and privacy commitments, marketing analytics data, CRM data, customer lists, and other pseudonymized data may be disclosed or transferred as part of a corporate reorganization transaction.
Proctorio does not and will not sell or otherwise transfer your data to any third party except as specifically stated in this Privacy Notice.
6.5 Payment processing
Proctorio uses a third-party payment processor to process payments. Proctorio does not directly collect payment information and is not a money-services business. To the extent such functionality is made available in the Services, it is provided by an unaffiliated third party, and like any other third-party service, is subject to their terms of use.
6.6 Third-party service providers
Proctorio uses third-party service providers to help provide Proctorio's Services, such as hosting Proctorio's various blogs, Help Center, and knowledge bases, and to help Institutions understand the use of Proctorio's Services. Since Proctorio uses Zero-Knowledge Encryption for audio, video, screen recordings and images, Test-Taker data is encrypted and not accessible by the third-party service provider. In all instances, third-party services providers can only use any data for Proctorio's (or, where Proctorio is a data processor, an Institution's) business purposes as specified in Proctorio's written agreement with them and not their own purposes, except as expressly described in this Privacy Notice (for example, the Verification Provider's own fraud-prevention retention described in the Identity verification section). These Services may collect information sent by your browser as part of a web page request, such as cookies or your IP request.
The sub-processors that Proctorio uses are listed below but Proctorio may update this list periodically. To ensure you are aware of all updates, please periodically check for updates here. You can also subscribe to receive update notifications at github.com/proctorio/policies.
6.6.1 Required sub-processors for all services:
Azure
Purpose: Cloud Service Provider
Location: International
Website: https://azure.microsoft.com/
Cloudflare
Purpose: Content delivery network (CDN), web application firewall (WAF), reverse proxy with Data Localization Suite for regional traffic processing, and bot detection (Cloudflare Turnstile) on dashboard sign-in and sign-up pages.
Location: International (Data Localization Suite for regional processing)
Website: https://cloudflare.com/
Constellix (Digicert)
Purpose: DNS Services
Location: International
Website: https://constellix.com/
6.6.2 Optional sub-processors for support services:
Google, Inc. (Workspace)
Purpose: Email support provider
Location: USA and Europe
Website: https://workspace.google.com/
Olark
Purpose: Chat support provider
Location: USA
Website: https://olark.com/
Proctorio d.o.o
Purpose: Support Services
Location: Serbia
Website: https://proctorio.com/
Twilio
Purpose: Call routing and SMS provider
Location: USA
Website: https://twilio.com/
Zendesk
Purpose: Helpdesk and support
Location: USA
Website: https://zendesk.com/
6.6.3 Optional sub-processors for payment services:
Stripe
Purpose: Payment processing; automated identity verification (identity document and selfie verification)
Location: USA and Europe
Website: https://stripe.com/
Privacy policy: https://stripe.com/privacy
6.6.4 Marketing
Proctorio uses search engines (Bing and Google), paid social media (LinkedIn, Twitter, and Facebook), email marketing (current and future Proctorio blog), contests (CRM info), surveys, (anonymous and/or CRM), and lead generation forms (Facebook, G2 and LinkedIn) to provide marketing to Institution representatives, who have opted in to receive marketing materials.
Proctorio does not market to Test Takers.
6.6.5 Data transfers from Proctorio branches
Support Tickets are assigned an anonymous ID so that no support inquiry is personally identifiable. Additionally support tickets do not contain embedded Personal Information unless specifically provided by the user in the text of the support request. Proctorio Support Representatives are located in the US, Germany, and Serbia.
Support Representatives will have read-only access to the ID assigned to the user, along with any Personal Information needed to verify identity or that is voluntarily given by the user. The Support Representatives are required to delete all Personal Information, required or voluntarily given, immediately after responding to and resolving the support request.
In addition, Proctorio may collect and transfer the following information to Germany, Serbia and/or the US when deemed necessary for operating of business or hired service(s):
- IP addresses
- User agent details
- Administrator account information
- Assessment platform functionality information
- Client billing information
This data is transferred depending on what is required by the Institution, its users, and what is deemed necessary for the operation of Proctorio's website(s), application(s), and/or Services.
7. Data Security and Retention
7.1 Security
Proctorio employs procedural and technical security measures that are reasonably designed to help protect Proctorio's Test Takers' Personal Information from loss, unauthorized access, disclosure, alteration, or destruction, which includes encryption and other security measures to help prevent unauthorized access to a Test Taker's Personal Information. The data a Test Taker transmits as part of their use of the Institution Services ("Storage Data") is encrypted and Proctorio does not have the decryption keys to decrypt or review Test Taker Storage Data in its unencrypted form.
Towards this end, Proctorio takes the following actions:
- Proctorio limits employee access to Test Taker information to only those employees and contractors who need the information to fulfill their job responsibilities;
- Proctorio conducts regular employee privacy and data security training and education; and
- Proctorio protects your Information with technical, contractual, administrative, and physical security safeguards in order to protect against unauthorized access, release, or use.
Proctorio is SOC 2, ISO 27001, and ISO 27018 certified and conducts regular security audits including penetration testing and vulnerability assessments. Institutions or their designated representatives may review security testing results, subject to confidentiality requirements, or conduct their own security audit of Proctorio's data security and storage practices, subject to mutual agreement. Written requests for inspection and testing can be made to security@proctorio.com.
For Test Taker Information that Proctorio processes for an Institution, Proctorio implements Zero-Knowledge Encryption, which means only Institution-approved representatives can decrypt and review encrypted exam recordings.
Test-taker audio, video, and screen recordings and images are secured and processed through three layers of encryption:
- The Zero-Knowledge Encryption layer is used when information is stored and is secured using AES-GCM.
- Transmission into the datacenter is over TLSv1.2 / TLSv1.3 and, if the client supports it, Proctorio uses Perfect Forward Secrecy (PFS).
7.2 Data Retention
Proctorio stores Test Taker Personal Information, including all audio, video, and screen recordings and images, which Proctorio collects during the exam for the minimum amount of time required by the Institution or by applicable law.
The length and location of how and where data for operations is stored varies and is dependent on applicable law and the information itself and whether Proctorio is acting as the data controller or the data processor all Personal Information is encrypted in transmission and at rest.
7.2.1 As a data processor
Your Institution sets the retention period for exam data (the "Retention Period") in its agreement with Proctorio and is responsible for informing Test Takers of it. Recording retention also depends on the product tier: the Lock Down tier makes no audio, video, or screen recordings and stores session metadata only; the Basic tier records webcam only, with a seven day standard Retention Period; the Plus tier has a thirty day standard Retention Period, which an Institution may extend to six months, to one year for education customers purchasing a license, or longer by agreement. At the end of the Retention Period, exam recordings and images, and the flags stored with them, are deleted.
Proctorio retains data as directed by an Institution related to the Services that Proctorio provides to them. Proctorio retains Test Taker De-Identified Data to track usage, allow Proctorio to process billing for Institutions that are Proctorio's customers, and track global usage of Proctorio's Services. "De-Identified Data" (or pseudonymized) includes:
- A pseudonymous hash of the User ID
- A pseudonymous hash of the Exam ID
- A pseudonymous hash of the Course ID (when applicable)
- Approximate location where the exam was taken
- Exam attempt number
- Length of exam
- Date of exam
- Anonymous operational events, and anonymous diagnostic telemetry events where you have opted in (see Service Information)
When Proctorio is the data processor, Proctorio uses a third-party cloud provider for the storage of encrypted, collected data. Data is stored in data centers requested or chosen by the partnered Institution. Institutions can choose to store the data in a data center that is geographically relevant to their location or in another, potentially further away data center.
Proctorio retains data only as directed by an Institution related to the Services that Proctorio provides to them. Proctorio will store and maintain Institutional data for up to 30 days after the termination of an applicable agreement, unless otherwise specified by the Institution or as required by applicable law.
Proctorio cannot and does not retain exam attempt recordings or chat transcripts for longer than required by the Institution or applicable law.
When Proctorio is a processor for an Institution, Proctorio will direct the Test Taker to contact their respective Institution with any requests related to their Personal Information.
7.2.2 As a data controller
In situations when Proctorio acts as a data controller, the Personal Information provided by an individual is dependent on the Services, Site(s), or third-party applications accessed by the individual.
Retention, location, data deletion, and destruction
When Proctorio is a data controller, this data is stored in locations and for time frames dependent on the Services used or Site(s) and/or third-party application(s) accessed by the individual.
Proctorio retains the previously described Information only for as long as needed for Proctorio's legitimate business purposes and as required by applicable laws, investigations, or other security matters.
When Proctorio is the data controller, questions regarding data storage, recovery, and deletion should be directed through one of Proctorio's contact channels.
7.2.3 Locations of processing
Proctorio generally stores information in the following locations:
- US Test-Taker Payment Processing: Data is stored within the US by a third-party sub-processor headquartered in the US.
- US Client Payment Processing: Data is stored within the US by a third-party sub-processor headquartered in the US.
- US User and Client Support: Data is stored by a third-party sub-processor headquartered in the US and Europe.
- EU Test-Taker Payment Processing: Data is stored by a third-party sub-processor headquartered in Ireland.
- EU Client Payment Processing: Data is stored within Germany by a third-party sub-processor headquartered in Germany.
- EU User and Client Support: Data is stored by a third-party sub-processor headquartered in the US and Europe.
- Institution Assessment Platform Monitoring: Data is stored in Europe by a third-party sub-processor based in Europe.
7.3 Security Incident Notification
If Proctorio becomes aware of a security incident affecting Personal Information: where Proctorio acts as a data processor, Proctorio will notify the affected Institution without undue delay and within the timeframe set in its agreement with that Institution, and will provide the information the Institution needs to meet its own notification obligations to Test Takers and regulators. Where Proctorio acts as a data controller, Proctorio will notify affected individuals and regulators as required by applicable law, by email to the address on file and/or by notice on proctorio.com. Proctorio investigates and manages incidents under its Security Incident Policy.
8. Your Rights
You generally have the following rights with respect to your Personal Information. Note, some countries and states have their own privacy and data security laws, which may affect your rights.
8.1 As a data processor
Test Takers, parents, legal guardians, or eligible students should contact their Institution directly if they want to access, correct, delete, export, import, request a copy, exercise other rights they may have, or if they have questions about their Personal Information. Proctorio does not have the ability to edit, revise or delete any Test-Taker data. When Proctorio is a processor for an Institution, Proctorio will direct the Test Taker to contact their respective Institution with any requests related to their Personal Information.
8.2 As a data controller
When Proctorio is the controller, Proctorio will respond to your request regarding your Personal Information held by Proctorio as required by applicable laws and Proctorio's legitimate business purposes. Regardless of where you reside, you have the following rights (see below for information regarding your rights under applicable law and in the jurisdiction you reside).
8.2.1 Consent
If we rely on your consent to our processing of Personal Information, you may withdraw your consent at any time. You may be required to close your account in order to withdraw consent where your consent is necessary to perform essential aspects of our Services.
8.2.2 Marketing Communications
You can withdraw your consent to receive marketing communications by clicking on the unsubscribe link in an email, or for other communications, by contacting us by email at dataprivacy@proctorio.com. To opt-out of the collection of information relating to email opens, configure your email so that it does not load images in our emails.
9. Changes to Proctorio's Privacy Notice
Proctorio reserves the right to amend this Privacy Notice at Proctorio's discretion and at any time. When Proctorio makes changes to this Privacy Notice, Proctorio will notify you by email or through a notice on Proctorio's website homepage.
10. Supplemental Notices for Specific Laws and Jurisdictions
10.1 FERPA
Proctorio adheres to the Family Educational Rights and Privacy Act (FERPA), as applicable, when it is providing Services to educational Institutions in the United States that are subject to FERPA.
Proctorio works with Institutions to ensure compliance with FERPA and applicable privacy laws. One of the most important ways in which we strive to adhere to FERPA and restrict disclosure is to encrypt Test-Taker audio, video, and screen recordings and images. As described in this Privacy Notice, Proctorio uses Zero-Knowledge Encryption to do this when an Institution has an agreement to utilize Proctorio's Services.
10.1.1 What is FERPA?
FERPA is a federal law that affords students (or parents/guardians for students under 18 or not enrolled in a post-secondary Institution) certain rights with respect to their education records.
In the United States, Proctorio has agreements with educational Institutions that are subject to FERPA and Proctorio acts as a third-party service provider of such educational Institutions and must make every effort to comply with FERPA generally as a "School Official." This means Proctorio is providing Proctorio's Services on behalf of the educational Institution and only as authorized by them for legitimate educational purposes.
10.1.2 Why is FERPA important?
FERPA protects students from having their information disclosed to third parties without the eligible student (18+) or parent's/guardian's consent, unless there is an applicable exception under FERPA, such as when a third-party service provider is authorized by an educational Institution by a written agreement to provide services as a "School Official."
Proctorio complies with FERPA by only using student Personal Information as a School Official as authorized by an educational Institution in Proctorio's written agreements.
Audio, video, and screen recordings and images collected during the exam attempt, stored by Proctorio, and received from an Institution are encrypted using Zero-Knowledge Encryption. These recordings and images can only be decrypted and reviewed by Institution-approved representatives within the Institution's assessment platform. Proctorio dictates who these authorized users are by utilizing the educational Institution's assessment platform to gain information about the user's role. This restricts information from being shared with users who do not fall under the "School Official" role. The entire process is transparent to the end user. Proctorio securely delivers all content for the Services encrypted and Proctorio's servers make every effort to comply with industry security standards, including SOC 2, ISO 27001, ISO 27018 and PCI-DSS.
For Proctorio's technical support channels, Proctorio's Support Representatives are trained on privacy and security and are instructed not to ask for information beyond what FERPA defines as "Directory Information". This information may include:
- Student full name
- Campus email address
- Institution name
To better ensure FERPA and privacy and security compliance, Proctorio's employees receive periodic privacy and security training. Proctorio has been SOC 2, ISO 27001 and ISO 27018 certified.
10.2 K-12 deployments
K-12 deployments do not include biometric features, Instant ID or any third-party identity verification, or credit card payments. Capture ID is available to K-12 institutions and is disabled by default.
When a K-12 institution uses Proctorio's proctoring Services, Proctorio may collect the following categories of Personal Information from students on behalf of the institution, as directed and configured by that institution:
- A unique student identifier provided by the institution via LMS integration (no government ID or social security number is collected)
- Webcam video and audio recordings during the exam session, if enabled by the institution
- Screen recording and browser activity during the exam session, if enabled by the institution
- Device information: IP address, device identifier, operating system and browser version
- Behavioral data generated during the exam session: gaze direction indicators and flagged activity events, surfaced to institution-authorized reviewers
Proctorio does not collect biometric identifiers, government-issued identification numbers, financial information, or precise geolocation data from students in K-12 deployments. All audio, video, and screen recordings are protected by Zero-Knowledge Encryption and can only be decrypted by institution-authorized representatives.
Proctorio's automated systems and any underlying AI models are designed to be used as decision-support tools for institutional reviewers, not as autonomous decision-making systems. The service is not intended to be used in isolation, and Proctorio does not make recommendations regarding any action to be taken, or any sanction, or determination to be made with respect to a student. Institution's are not authorized to rely solely on Proctorio's automated signals or any outputs generated by Proctorio's automated or AI systems provided by Proctorio to make decisions, or use them as a substantial portion of any decision. All such decisions are intended to be made by the institution following human review of the relevant event data.
10.2.1 K-12 Student Data Use Commitments
When Proctorio provides Services to K-12 educational institutions, Proctorio collects and processes student Personal Information solely to provide the contracted proctoring service as directed by the institution. Proctorio makes the following commitments with respect to student Personal Information collected in connection with K-12 institutional deployments:
- Proctorio will not sell, rent, or trade student Personal Information to any third party.
- Proctorio will not use student Personal Information for targeted advertising, behavioral advertising, or any form of commercial profiling of students.
- Proctorio will not use student Personal Information to build a profile of a student for any purpose other than providing the educational proctoring service authorized by the institution.
- Proctorio will not disclose student Personal Information to third parties except as necessary to provide the contracted service, as required by law, or as directed by the institution.
- Proctorio will not use student Personal Information to amass a profile of a student for use outside of the educational context.
- Student Personal Information will be used only for the legitimate educational purposes authorized by the contracting institution.
- Proctorio will implement and maintain reasonable security procedures and practices appropriate to the nature of the student's Personal Information to protect it from unauthorized access, destruction, use, modification, or disclosure.
- Upon request from the institution, Proctorio will delete or return student Personal Information within the timeframe specified in the applicable agreement or Data Processing Agreement.
These commitments apply in addition to, and do not limit, any obligations under applicable federal and state student privacy laws, including the Family Educational Rights and Privacy Act (FERPA), the Children's Online Privacy Protection Act (COPPA), the California Student Online Personal Information Protection Act (SOPIPA), New York Education Law Section 2-d, and equivalent laws in other jurisdictions.
10.2.2 Student Data Privacy Agreements (SDPAs)
Proctorio recognizes that many K-12 educational institutions are required by state law or district policy to enter into a Student Data Privacy Agreement (SDPA) or equivalent data governance agreement with third-party service providers prior to deployment.
Proctorio offers a Student Data Privacy Agreement for K-12 institutional customers. The SDPA sets out Proctorio's specific obligations with respect to the collection, use, disclosure, and protection of student Personal Information. As in other cases where Proctorio acts as a data processor, where an institution enters into an SDPA, our processing is subject and controlled by Proctorio's obligations under the SDPA.
K-12 institutions that require an SDPA, or that are subject to state laws requiring a vendor data governance agreement, should contact Proctorio at privacy@proctorio.com to request the Student Data Privacy Agreement or to initiate a review of an institution-specific SDPA template.
10.2.3 COPPA
Proctorio complies with the Children's Online Privacy Protection Act (COPPA), 15 U.S.C. § 6501 et seq., and the FTC's COPPA Rule (16 CFR Part 312), as applicable to its K-12 institutional services.
Except for Proctorio's specific Services offered to K-12 Institutions, Proctorio's Services are directed towards adults who are of the legal age to access them in their respective jurisdictions. Where we provide services to K-12 educational Institutions, we do so as a school official, acting on behalf of the Institution. We process information of individuals under the age of 13 only for the use and benefit of the Institution, and for no other commercial purpose, and we may rely on the consent of the Institution to process Personal Information of individuals under the age of 13.
When a K-12 educational institution engages Proctorio's Services, it does so and collects the Personal Information of children for the use and benefit of the Institution, and for no other commercial purpose. We provide the Institution with our full notice of our collection, use, and disclosure practices in the same way that is required for parents. We rely on the consent of the Institution to process Personal Information of individuals under the age of 13.
If you are under the age of 13, please do not use Proctorio's Sites without explicit permission from your School Official, parent, and/or guardian. If you do not meet these requirements, you must not access or use Proctorio's Sites or Services. If Proctorio learns it has collected or received Personal Information from an individual who was ineligible to access or use the Sites or Services, Proctorio will take steps to remove such Information. If you believe Proctorio might have any Information from or about a user who is ineligible to use the Sites or Services, please contact privacy@proctorio.com.
10.2.4 Parental rights
Parents and guardians of children under 13 enrolled in a K-12 institution using Proctorio's Services have the following rights under COPPA:
- Right to review: parents may review the Personal Information Proctorio has collected from their child by contacting their institution directly.
- Right to request deletion: parents may request deletion of their child's Personal Information by contacting their institution.
- Right to refuse further collection: parents may contact their institution to request that it limit or discontinue collection of their child's Personal Information through Proctorio's Services.
Parents may also contact Proctorio directly at dataprivacy@proctorio.com with questions about the Personal Information Proctorio processes on behalf of an institution. If Proctorio learns that it has collected Personal Information from a child under 13 outside of the school consent model and without verifiable parental consent, Proctorio will take prompt steps to delete such information.
Note, where we act as a data processor, parents, legal guardians, or eligible students should contact their Institution directly if they want to access, correct, delete, export, import, request a copy, exercise other rights they may have, or if they have questions about their Personal Information. Proctorio does not have the ability to edit, revise or delete any Test Taker Personal Information contained in Test Taker records. Proctorio will send all requests regarding Test Taker Personal Information to the respective Institution.
US based consumers should read the US State Consumer Privacy Section below for more information about their rights.
When Proctorio is the controller, Proctorio will respond to your request regarding your Personal Information held by Proctorio as required by applicable laws and Proctorio's legitimate business purposes.
10.2.5 How to exercise your rights
Because Proctorio operates as a data processor on behalf of the K-12 institution (which is the data controller), the Institution is the primary point of contact for most rights requests.
To exercise any of the rights below, you must contact your Institution first. If you are unable to obtain a response from the Institution, or if your request concerns data that Proctorio controls independently of the Institution (such as support records), you may contact Proctorio directly at privacy@proctorio.com or as otherwise set forth in the Your Rights section above.
10.2.6 Contact for K-12 privacy matters
Email: privacy@proctorio.com | Subject line: K-12 Privacy Request — [Institution Name]
Proctorio will acknowledge receipt of K-12 privacy requests within five (5) business days and will work with the relevant institution to facilitate a response within thirty (30) days.
10.3 US State Consumer Privacy Laws
U.S. state privacy laws may apply to residents of those states who use Proctorio's services. Where applicable, Proctorio acts as a processor or service provider under these laws and processes Personal Information only on behalf of and under the instructions of the contracting Institution. Residents of these states may exercise applicable rights (access, correction, deletion, portability, opt-out of sale/targeted advertising) by contacting their Institution in the first instance. Proctorio will assist Institutions in responding to verified data subject requests as required under applicable data processing agreements.
10.3.1 Categories of Personal Information Collected
When Proctorio acts as a controller, we generally collect the following categories of Personal Information under the CCPA:
- Identifiers: name, student or LMS identifier, email address, and, where identity verification is used, the verification fields described in the Identity verification section.
- Contact Data - Identity Data used to contact an individual, e.g. email address, physical address, or phone number.
- Audio/Visual Data: recordings of customer support phone calls, sales and demonstration meetings, webinars and marketing events, and job interviews.
- Device/Network Data: IP address, device identifiers, operating system and browser version, and network performance data.
- General Location Data: non-precise location derived from IP addresses.
- Inference Data: for Institution representatives and prospective customers only, marketing-related inferences such as product interest and customer segment, drawn from the information above. Proctorio does not draw inferences about Test Takers in its capacity as a controller.
- User Content: Personal Information included in content provided by users of the Site in any free-form or unstructured format, such as in a "contact us" box, free text field, in a file or document, or messages to us.
Proctorio has disclosed each category of Personal Information above for our business purposes in the preceding twelve (12) months. Proctorio does not sell, "share," or disclose such Personal Information for commercial purposes.
Proctorio will not collect additional categories of Personal Information or use the Personal Information Proctorio collected for materially different, unrelated, or incompatible purposes without providing you notice.
Third parties receiving Personal Information, including service providers processing Personal Information on Proctorio's behalf, are only permitted to process that Personal Information as described in Proctorio's Privacy Notice and Proctorio's written agreements and are not permitted to sell Personal Information or market to any test-taker.
Note re Biometric Information: Biometric data is processed only as described in the Identity verification, Automated Re-verification, and Continuity Check sections of this notice. Verification biometrics for Instant ID are collected and held by the third party verification provider; the Match ID, Automated Re-verification, and Continuity Check comparisons run only on your device. Proctorio never collects or retains a biometric identifier or template.
Proctorio provides Services to Institutions as a "School Official" under FERPA as described above. Under the CCPA, Proctorio collects, retains, uses, and discloses Personal Information, which may include student data under these Institution agreements only as a "service provider" to Proctorio's Institution customers. The respective Institution's privacy policies apply to their Test Takers.
Please note that government agencies, including public Institutions, are not subject to CCPA. If you have a question or would like to exercise your California consumer rights to knowledge, access, or deletion, please contact your Institution directly.
10.3.2 Sale/Sharing of Data for CCPA purposes
Proctorio does not sell or "Share" (as defined by CCPA) or disclose your Personal Information to any third parties for targeted advertising or direct marketing purposes and has not done so in the past 12 months. Proctorio shares your Personal Information with your consent or to complete any transaction or provide any product you have requested or authorized. We also share data with Proctorio-controlled affiliates and subsidiaries; with vendors working on our behalf; when required by law or to respond to legal process; to protect our customers; to protect lives; to maintain the security of our products; and to protect the rights and property of Proctorio and its users.
10.3.3 Rights of Residents of Applicable US States
If you are a resident of certain US states, you have other rights under your respective states' consumer privacy statutes:
- Right of Know/Access: You can access your collected Personal Information by contacting us at dataprivacy@proctorio.com.
- Right to Correct, Update, or Delete: You can correct, update or request deletion of your Personal Information by contacting the Institution. Proctorio can't make changes to or delete your information in some situations where it is necessary for us to maintain your information, for example if Proctorio needs the Information to comply with applicable law or based on other exceptions as indicated in the CCPA.
- Right of Portability: Please contact us at dataprivacy@proctorio.com to request that we provide certain Personal Information in a common, portable format.
- Rights to Limit Use of Sensitive Information: You may have the right to limit use of any "Sensitive Personal Information" (SPI). SPI includes highly sensitive data such as: social security number; driver's license or government ID data; passport number; financial account information and log-in credentials; precise geolocation data; genetic data; and ethnic origin. We may collect Government ID Data as described in the Identify Verification section described above.
- Right to opt-out of Data sales/ "sharing" and targeted advertising: You may have the right to opt-out of data sales, "sharing" and targeted advertising. Proctorio does not engage in such processing at this time. If you have any questions about these rights, please contact us at dataprivacy@proctorio.com.
- Right to opt-out of Certain Profiling: Depending on your state of residency, you may have the right to know what information of yours we have processed for the purposes of profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer. If you have any questions about these rights or wish to opt-out of any processing of your Personal Information as it relates to profiling, please contact us at dataprivacy@proctorio.com.
- Right to Non-Discrimination: Proctorio does not and will not discriminate against you if you exercise your rights under the US state consumer privacy laws.
- Right to list of Direct Marketing Disclosures: California residents have the right to request a list of Personal Data we have disclosed about you to third parties for direct marketing purposes during the preceding calendar year. If you have any questions about these rights, please contact us at dataprivacy@proctorio.com.
When you contact us regarding any of your rights under the US state consumer privacy laws, we will verify your identity before we provide any information, unless prohibited by law.
To exercise the rights described in this Privacy Notice, please submit a verifiable consumer request to us:
via phone: Toll Free +1 866 948 9087
via email: dataprivacy@proctorio.com
Only you, or depending on your jurisdiction, someone legally authorized to act on your behalf (if in California, the person legally authorized to act on your behalf must be registered with the California Secretary of State), may make a verifiable consumer request related to your Personal Information. You may also make a verifiable consumer request on behalf of your minor child. You may only make a verifiable consumer request for access or data portability twice within a 12-month period. The verifiable consumer request must provide sufficient information that allows Proctorio to reasonably verify you are the person about whom Proctorio collected Personal Information or an authorized representative, which may include the users:
- First name
- Last name
- Email address
Describe your request with sufficient detail that allows Proctorio to properly understand, evaluate, and respond to your request.
Note: government agencies, including public Institutions, are not subject to CCPA or other state consumer privacy laws. If you have a question or would like to exercise your California consumer rights to knowledge, access, or deletion, please contact your Institution directly.
10.3.4 Verification of requests
Proctorio cannot respond to your request or provide you with Personal Information if Proctorio cannot verify your identity or authority to make the request and confirm the Personal Information relates to you. If Proctorio cannot verify your identity or authority, Proctorio will follow procedures to verify your identity and authority. Proctorio attempts to respond to a verifiable consumer request within forty-five (45) days of its receipt, or sooner, if required by law. If Proctorio requires more time (up to 45 days), Proctorio will inform you of the reason and extension period in writing.
If you have an account with Proctorio, Proctorio may deliver Proctorio's written response to that account. If you do not have an account with Proctorio, Proctorio will deliver Proctorio's written response by mail or electronically, at your option.
The response Proctorio provides will also explain the reasons Proctorio cannot comply with a request, if applicable. For data portability requests, Proctorio will select a format to provide your Personal Information that is readily usable and should allow you to transmit the Information from one entity to another entity.
Proctorio does not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If Proctorio determines that the request warrants a fee, Proctorio will tell you why Proctorio made that decision and provide you with a cost estimate before completing your request.
AB 1584 is a California law that defines student and educational agencies' rights regarding student records. Proctorio complies with AB 1584 as described in this Privacy Notice and as applicable in Proctorio's agreements with California Institution(s).
If you have any questions or comments about your rights under your applicable state consumer privacy law, please contact us at dataprivacy@proctorio.com.
10.4 Canadian User Rights — PIPEDA, FIPPA, PIPA, POPA, and Quebec Law 25
Proctorio makes every effort to cooperate with Institutions in compliance with applicable Canadian federal and provincial privacy laws, including:
- Personal Information Protection and Electronic Documents Act ("PIPEDA") — Canada's federal private-sector privacy law governing the collection, use, and disclosure of personal information in commercial activity.
- Freedom of Information and Protection of Privacy Act ("FIPPA") — the public-sector privacy law in British Columbia and Ontario, providing citizens with the right to access information under the control of public institutions.
- Personal Information Protection Act ("PIPA") — the private-sector privacy law in Alberta and British Columbia, declared substantially similar to PIPEDA.
- Protection of Privacy Act ("POPA") — Alberta's new public-sector privacy law, effective June 11, 2025, replacing the former Freedom of Information and Protection of Privacy Act ("FOIP"). POPA establishes requirements for Privacy Management Programs, mandatory Privacy Impact Assessments, and formal breach notification. POPA is accompanied by the Access to Information Act ("ATIA").
- Quebec Law 25 (An Act to modernize legislative provisions as regards the protection of personal information) — Quebec's comprehensive privacy modernisation, fully enforceable since September 2024. Includes provisions for cross-border data transfers and mandatory Privacy Impact Assessments.
- All other applicable federal and provincial laws and regulations, including those related to privacy and health information privacy.
Proctorio's obligations with respect to Canadian privacy law are further detailed in the SaaS Agreement and Terms of Service. With regard to PIPEDA's ten "Fair Information Principles," this Privacy Notice complies with those principles. Proctorio is fully transparent and open with regard to all of its policies. Exam-related data of Canadian Test Takers is stored locally and securely in Canada.
10.4.1 Canada's Anti-Spam Legislation (CASL)
Proctorio complies with Canada's Anti-Spam Legislation ("CASL") in connection with any commercial electronic messages sent to Canadian recipients. Proctorio does not send unsolicited commercial electronic messages and obtains express or implied consent before sending marketing communications to Canadian individuals, as required by CASL.
Canadian recipients may withdraw consent for marketing communications at any time by following the unsubscribe mechanism included in each message or by contacting privacy@proctorio.com.
10.5 Data Transfers; GDPR and EU-US, UK Extension, and Swiss-US Data Privacy Framework
If you are based in the EEA or Switzerland, you acknowledge that Proctorio may transfer your Information (including Personal Information) to Proctorio and Proctorio's facilities in the United States or elsewhere, including those of third parties as described in the "Business transfers" and "Third-party service providers" sections of this Privacy Notice. Proctorio remains liable under the DPF Principles if the third parties process Personal Information in a manner inconsistent with the DPF Principles.
Proctorio complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Proctorio has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of Personal Information received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. Proctorio has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of Personal Information received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this Privacy Notice and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Proctorio commits to resolve DPF Principles-related complaints about our collection and use of your Personal Information. EU and UK and Swiss individuals with inquiries or complaints regarding our handling of Personal Information received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF should first contact Proctorio at: dataprivacy@proctorio.com.
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Proctorio commits to refer unresolved complaints concerning our handling of Personal Information received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF to JAMS, an alternative dispute resolution provider based in the United States. If you do not receive timely acknowledgment of your DPF Principles-related complaint from us, or if we have not addressed your DPF Principles-related complaint to your satisfaction, please visit https://www.jamsadr.com/DPF-Dispute-Resolution. The services of JAMS are provided at no cost to you.
If you as an EU, UK, or Swiss individual believe that Proctorio has violated its obligations under the DPF Principles, there are certain conditions in which you may invoke binding arbitration for complaints regarding DPF Principles that were not resolved through the Company or through JAMS. Please see Annex I for additional information.
The Federal Trade Commission has jurisdiction over Proctorio's compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF).
In addition to the Data Privacy Framework, where required by applicable law or where otherwise appropriate, Proctorio may rely on the European Commission's Standard Contractual Clauses (SCCs) as approved under Commission Decision 2021/914 as an additional transfer mechanism for transfers of Personal Information from the EEA to countries without an adequacy decision. For transfers from the United Kingdom, Proctorio uses the UK International Data Transfer Addendum (IDTA) to the EU SCCs. Copies of the applicable transfer mechanism are available upon request by contacting privacy@proctorio.com.
Proctorio also complies with the EU General Data Protection Regulation ("GDPR"). Proctorio is committed to subjecting all Personal Information received from European Union (EU) member countries and Switzerland to GDPR standards. In situations where public authorities make lawful requests for information, such as to meet national security or law enforcement requirements, Proctorio may be required to disclose Personal Information.
Proctorio's Data Protection Officer contact information is as follows:
Data Protection Officer
UB GmbH
Im Breitspiel 21
69126 Heidelberg
Telephone: 069/6530006-23
E-mail: info@ubg-datenschutz.de
10.5.1 United Kingdom — UK GDPR and Data (Use and Access) Act
Individuals in the United Kingdom have the same data protection rights as those described in the European Economic Area (EEA) or Switzerland User Rights section of this Privacy Notice. The Information Commissioner's Office (ICO) is the UK's data protection supervisory authority.
10.5.2 UK, European Economic Area (EEA) or Switzerland User Rights
When Proctorio is a controller with respect to your Personal Information, such as for customer support, service, and other inquiries, and you are based in the EEA or Switzerland, you may have other rights as provided below:
- Access: If you wish to access your Personal Information that Proctorio collects, you can do so at any time through the Service or by contacting Proctorio using the contact details provided at the bottom of this page.
- Correction, update, or deletion: You can correct, update or request deletion of your Personal Information by contacting us at privacy@proctorio.com. Proctorio can't make changes to or delete your information in some situations where it is necessary for us to maintain your information, for example if Proctorio needs the Information to comply with applicable law or based on other exceptions as indicated by law.
- Data protection authority: You have a right to raise questions or complaints with your local data protection authority at any time.
- Right to object: You have the right to object, on grounds relating to your particular situation, at any time to the processing of your Personal Information by Proctorio. If you exercise this right, your Personal Information will no longer be processed for such purposes by Proctorio. You may exercise this right without incurring any costs.
- Right to withdraw consent: You have the right to withdraw your consent for Proctorio to process your Personal Information when your consent is the lawful basis for processing.
- Right to restriction: You may have the right to restrict Proctorio's processing of your Personal Information unless Proctorio's processing is otherwise authorized by applicable law.
- Right to data portability: You may have the right to receive the Personal Information that you have given Proctorio, in a structured, commonly-used, and machine-readable format. Data portability refers to the ability of individuals to easily and securely transfer their data from one organization or Platform to another. The purpose of data portability is to empower individuals with greater control and flexibility regarding their Personal Information.
Institutions have the ability to export data stored by Proctorio. Test-Takers must contact their Institution and since Test-Taker records are under the control of that Institution.
Marketing: For Institution-approved representatives, you have the right to opt-out of marketing communications Proctorio sends you at any time. You can do this by clicking the "unsubscribe" link in the marketing email Proctorio sent you or by contacting Proctorio using one of the contact channels provided. Please note that such marketing opt-out does not impact any transactional or operational notices that Proctorio may need to send you.
10.5.3 Legal Basis
If you are a Proctorio user or are visiting Proctorio's Site(s) and are located in the UK, Switzerland or European Economic Area ("EEA"), Proctorio's legal basis for collecting and using the Personal Information described above will depend on the Personal Information concerned and the specific context in which Proctorio collects it.
Performance of a contract
The processing of your Personal Information is strictly necessary in the context in which it was provided, e.g. to provide the Site or perform an agreement you have with us, to provide our products or services to you, or to process your requests.
- Cookies (strictly necessary)
- Site Operations
- Sharing
- Payment processing
- Third Party Service Providers
Legitimate interests
This processing is based on our legitimate interests. For example, we rely on our legitimate interest to administer, analyze, and improve our Services, to operate our business, including through the use of service providers and subcontractors, to send you notifications about our Services or your subscriptions, for archiving, recordkeeping, statistical and analytical purposes, and to use your Personal Information for administrative, fraud detection, audit, training, security, or legal purposes. See the Business Purposes of Processing section above for more information regarding the nature of processing performed on the basis of our legitimate interests.
- Site operations and security
- De-identified/Aggregated Data
- Bot Detection
- Sharing
- Third Party Service Providers
- Business Transfers
- Law and harm
Consent
This processing is based on your consent. You are free to withdraw any consent you may have provided, at any time, subject to your rights/choices, and any right to continue processing on alternative or additional legal bases. Withdrawal of consent does not affect the lawfulness of processing undertaken prior to withdrawal.
- Cookies (except strictly necessary)
- Marketing
- Sharing: Marketing
Compliance with legal obligations
This processing is based on our need to comply with legal obligations. We may use your Personal Information to comply with legal obligations to which we are subject, including to comply with legal process. See the Business Purposes of Processing section above for more information regarding the nature of processing performed for compliance purposes.
- Security
- Sharing: Law and Harm
Performance of a task carried out in the public interest
This processing is based on our need to protect recognized public interests. We may use your Personal Information to perform a task in the public interest or that is in the vital interests of an individual. See the Business Purposes of Processing section above for more information regarding the nature of processing performed for such purposes.
- Sharing
- Law and Harm
10.5.4 Submitting Requests
To submit a request, please provide to the appropriate address:
- Full name
- Email address
- Any other relevant information that may be required to address your request
10.5.5 Cloudflare Disclosures
To the extent your personal data is processed under GDPR, Swiss FADP, or UK GDPR, we process this data in connection with Bot Detection and Management (§ 4.6) on the basis of our legitimate interest in protecting our platform and users from automated abuse and ensuring the security of account access (Article 6(1)(f) GDPR). Bot detection on sign-in and sign-up pages is a security measure that directly benefits all users by preventing unauthorized access attempts and fraudulent account creation.
Cloudflare acts as a data processor on our behalf when analyzing these signals to generate a human/bot determination. Cloudflare may also act as an independent data controller for certain aggregated data used to improve its bot-detection services. For more information about how Cloudflare processes data through Turnstile, please see the Cloudflare Turnstile Privacy Addendum at cloudflare.com/turnstile-privacy-policy and Cloudflare's general privacy policy at cloudflare.com/privacypolicy.
Cloudflare uses a Data Localization Suite to process traffic regionally. Data processed by Cloudflare Turnstile may be transferred to and processed in countries outside your country of residence. Cloudflare maintains appropriate safeguards for international data transfers, including EU Standard Contractual Clauses (SCCs) and participation in the EU-U.S. Data Privacy Framework.
10.6 Australian User Rights — Privacy Act 1988
Proctorio is committed to complying with the Australian Privacy Act 1988 (Cth) ("Privacy Act") and the Australian Privacy Principles (APPs) contained in Schedule 1 of the Privacy Act, as applicable to its role as a service provider to Australian educational institutions.
As a service provider acting under instruction from an Australian Institution, Proctorio processes Personal Information on behalf of that Institution in accordance with the Institution's privacy obligations under the Privacy Act. The Institution, as the APP entity responsible for the collection of student data, determines the purposes and means of processing and is responsible for providing required collection notices to students.
10.6.1 Data Localization and Cross-Border Disclosure
Proctorio stores exam recordings and related Personal Information for Australian Institution clients on servers located in Australia or, where applicable, in the European Union. Proctorio does not transfer Australian student data to United States data centers.
Where Personal Information is disclosed to overseas recipients (for example, to Proctorio's parent entity in the United States for support purposes), Proctorio takes reasonable steps to ensure that those recipients do not breach the APPs in relation to that information, consistent with APP 8.
10.6.2 Individual Rights Under the Privacy Act
Students and other individuals whose Personal Information is processed in connection with services provided to an Australian Institution may have rights to access and correct their Personal Information under the Privacy Act. Requests relating to exam recordings and assessment data should be directed to the relevant Institution, which holds the decryption keys required to access such data. Proctorio will assist Institutions in responding to such requests as required under its data processing agreements.
10.7 Brazilian User Rights — LGPD and EDCA
Proctorio is committed to complying with Brazilian Federal Law No. 13,709/2018, the Lei Geral de Proteção de Dados Pessoais ("LGPD"), with respect to the processing of Personal Information relating to individuals located in Brazil.
In its role as a service provider (operador) to Brazilian educational institutions (controladores), Proctorio processes Personal Information solely in accordance with the instructions of the Institution and the terms of the applicable data processing agreement. The Institution is responsible for identifying the appropriate legal basis for collection and processing under Article 7 of the LGPD and for providing required transparency notices to data subjects.
10.7.1 Data Subject Rights
Data subjects in Brazil have rights under Articles 17–22 of the LGPD, including the rights to access, correction, deletion, portability, and information about sharing. Requests relating to exam recordings should be directed to the relevant Institution. Proctorio will assist Institutions in responding to verified data subject requests in accordance with its contractual obligations.
10.7.2 International Transfers
Where Personal Information relating to Brazilian data subjects is transferred outside of Brazil, Proctorio relies on standard contractual clauses or equivalent safeguards as permitted under Article 33 of the LGPD and applicable ANPD regulations.
10.7.3 Digital Child Protection (EDCA)
Proctorio is committed to compliance with the Estatuto Digital da Criança e do Adolescente ("EDCA", Law No. 15.211/2025), in force since March 17, 2026, which establishes privacy-by-design and privacy-by-default requirements for online services directed at or likely to be accessed by children and adolescents in Brazil, including educational software.
10.8 South African User Rights — POPIA
Proctorio is committed to complying with the Protection of Personal Information Act 4 of 2013 ("POPIA") with respect to the processing of Personal Information relating to data subjects located in South Africa.
In its role as an Operator under POPIA, Proctorio processes Personal Information on behalf of South African educational institutions (Responsible Parties) under written mandate and in accordance with the eight Conditions for Lawful Processing set out in POPIA. The Institution, as the Responsible Party, is accountable for compliance with POPIA in respect of student data collected through the use of Proctorio's services.
10.8.1 Conditions for Lawful Processing
Proctorio supports Responsible Parties in meeting the following POPIA Conditions as applicable to remote proctoring: Accountability; Processing Limitation; Purpose Specification; Further Processing Limitation; Information Quality; Openness; Security Safeguards; and Data Subject Participation.
10.8.2 Cross-Border Transfers
Where Personal Information relating to South African data subjects is transferred outside of South Africa, Proctorio ensures that such transfers occur only to countries or recipients that provide an adequate level of protection, or pursuant to binding contractual arrangements consistent with Section 72 of POPIA.
10.8.3 Data Subject Rights
Data subjects have rights under POPIA including the right to access, correction, and deletion of Personal Information. Requests should be directed to the relevant Institution. Proctorio will assist the Institution in responding to data subject requests in its capacity as Operator.
10.9 Japanese User Rights — APPI
Proctorio is committed to complying with Japan's Act on the Protection of Personal Information ("APPI") and its 2022 amendments with respect to the processing of Personal Information relating to individuals located in Japan.
In its role as a consignee (委託先) processing Personal Information under consignment from Japanese educational institutions, Proctorio handles Personal Information in accordance with the instructions of the consigning Institution and implements security management measures necessary and appropriate in light of the APPI and guidelines issued by the Personal Information Protection Commission (PPC).
10.9.1 Third-Party Provision and Cross-Border Transfers
Where Proctorio transfers Personal Information relating to Japanese data subjects to third parties outside Japan, Proctorio ensures that such transfers are conducted in accordance with APPI Article 24. Proctorio provides data subjects with information about the data protection regime of the destination country upon request.
10.9.2 Data Subject Rights
Individuals in Japan have rights under the APPI including the right to request disclosure, correction, addition or deletion, cessation of use, and erasure of their Personal Information. Requests relating to exam recordings should be directed to the relevant Institution.
10.10 Singapore User Rights — PDPA
Proctorio is committed to complying with Singapore's Personal Information Protection Act 2012 ("PDPA") as amended by the Personal Information Protection (Amendment) Act 2020, with respect to the processing of Personal Information relating to individuals in Singapore.
Proctorio processes Personal Information on behalf of Singapore educational organisations as a data intermediary under the PDPA. The organisation retains responsibility for ensuring that its collection, use, and disclosure of Personal Information complies with the PDPA. Proctorio, as data intermediary, implements data protection policies and security arrangements consistent with PDPA obligations.
10.10.1 Data Breach Notification
In the event of a data breach affecting the Personal Information of Singapore individuals that is likely to result in significant harm, Proctorio will notify the relevant Institution without undue delay to enable the Institution to fulfil its mandatory breach notification obligations to the PDPC and affected individuals under the PDPA.
10.10.2 Transfer Limitation
Transfers of Personal Information relating to Singapore individuals to countries outside Singapore are made only to recipients that provide a standard of protection comparable to that under the PDPA, or pursuant to contractual arrangements approved under the PDPA Transfer Limitation Obligation.
10.11 New Zealand User Rights — Privacy Act 2020
Proctorio is committed to complying with the New Zealand Privacy Act 2020 and its thirteen Information Privacy Principles (IPPs) with respect to the processing of Personal Information relating to individuals in New Zealand.
In its role as a service provider to New Zealand educational institutions, Proctorio processes Personal Information on behalf of the Institution in accordance with the Institution's privacy obligations under the Privacy Act 2020. Proctorio supports Institutions in fulfilling their obligations to the Office of the Privacy Commissioner (OPC NZ).
Effective May 1, 2026, IPP 3A requires agencies that collect Personal Information indirectly to take reasonable steps to ensure the individual is aware of specified matters. Proctorio will support institutions in meeting their IPP 3A obligations.
Where Personal Information relating to New Zealand individuals is transferred outside of New Zealand, Proctorio takes reasonable steps to ensure that the recipient is subject to comparable privacy safeguards, consistent with IPP 12.
10.12 UAE and Saudi Arabia Data Protection
10.12.1 United Arab Emirates
Proctorio is committed to complying with the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Information (UAE PDPL) with respect to the processing of Personal Information relating to individuals in the United Arab Emirates.
In its role as a Personal Information processor acting under instruction from UAE educational institutions, Proctorio processes Personal Information in accordance with the UAE PDPL and its implementing regulations. The Institution, as the Personal Information controller, is responsible for identifying the appropriate legal basis for processing and fulfilling disclosure obligations to data subjects.
10.12.2 Saudi Arabia
Proctorio is committed to complying with the Saudi Arabian Personal Information Protection Law (PDPL), issued by Royal Decree M/19 dated 9/2/1443H, with respect to the processing of Personal Information relating to individuals in the Kingdom of Saudi Arabia.
As a service provider to Saudi Arabian educational institutions, Proctorio processes Personal Information on behalf of the Institution (data controller) and implements appropriate technical and organisational measures to protect Personal Information in accordance with the PDPL and regulations issued by the Saudi Data & AI Authority (SDAIA).
10.13 Mexican User Rights — LFPDPPP
Where Proctorio provides Services to institutions in Mexico, Proctorio complies with the Ley Federal de Protección de Datos Personales en Posesión de los Particulares ("LFPDPPP"), Mexico's federal data protection law for the private sector, as reformed effective March 21, 2025.
Under the LFPDPPP, Proctorio respects data subjects' ARCO rights (Access, Rectification, Cancellation, and Opposition).
To exercise your ARCO rights, contact your institution or email Proctorio at privacy@proctorio.com.