Data Privacy & Security
Overview
Proctorio is committed to protecting data privacy and security at every level. Our systems are built with advanced encryption and intentionally designed to block unauthorized access, including by Proctorio itself. To stay aligned with global standards, we continuously monitor evolving data privacy regulations and voluntarily undergo regular, independent security audits.
Our Promise
Proctorio will never share or sell test-taker data. Why?
- Because it’s the right thing to do.
- Because most data privacy laws prohibit it.
- Because our systems are deliberately designed to make it impossible.
Why it Matters
Taking an exam can already feel stressful, and worries about privacy shouldn’t make it harder. With Proctorio, test-takers can feel confident that their data and recordings are secure and never available to just anyone. Before each exam, we disclose all recording options, as well as the location and retention period of collected data, so test-takers know exactly how their information will be handled. This transparency helps reduce concerns and build trust.
Compliance

Privacy Laws
Proctorio systems and products comply with the following regional privacy laws:
- Family Educational Rights and Privacy Act (FERPA)
- Children's Online Privacy Protection Act (COPPA)
- California Consumer Privacy Act (CCPA)
- Student Online Personal Information Protection Act (SOPIPA)
- Assembly Bill No. 1584 (AB-1584)
- European Union’s General Data Protection Regulation (GDPR)
- Freedom of Information and Protection of Privacy Act (FIPPA)
- Freedom of Information and Protection of Privacy Act (FOIP)
Industry Certifications
Proctorio follows widely recognized industry standards and completes regular internal and independent third-party audits to ensure ongoing compliance. Our certifications and audit reports are available in the Proctorio Trust Center (or by request).
How We Protect Your Data

Zero Knowledge End-to-End Encryption
Proctorio protects all assessment data with advanced encryption. Only the institution or organization holds the decryption key, giving them sole control over who can access the information. Proctorio employees cannot view assessment data or recordings unless access is explicitly granted by the institution.
Pseudonymization
Proctorio uses pseudonymization to protect personal data by replacing identifiers, such as names or email addresses, with unique codes. For example, support agents see only a code instead of a name, allowing them to resolve technical issues without accessing personal details. These codes cannot be used to reconstruct or reveal the original personal information.
Active Avoidance
Proctorio does not collect unnecessary personal information. We only gather the minimum data required to provide services, which reduces both risk and exposure.
Limited Data Retention
Data is stored only for as long as it is needed. Each institution or organization sets its own retention policy, which defines how long data is kept before it is permanently deleted.
Continuous Monitoring
Proctorio’s systems undergo regular internal reviews, independent audits, and security tests to ensure compliance with strict privacy and security standards. Certifications and audit reports are available in the Proctorio Trust Center.
Employee Training
All Proctorio employees complete annual FERPA training and data privacy and security training to ensure information is handled responsibly.
FAQ
Proctorio does not use end-user exam content, video, or recordings to train its AI models. Proctoring and detection models are trained on separate datasets that are either collected with consent or publicly available. Support chat conversations are handled separately, as described below.
Proctorio may use de-identified data from customer support interactions — including conversations conducted via chat, email, voice, or social media, with institution staff and, where applicable, users who contact support directly — to train and improve our AI-powered support tools.