GDPR check

Is Inspera GDPR compliant? What universities should check

Inspera, founded in Oslo in 1999, provides Inspera Assessment for digital exams and Inspera Originality for similarity and AI content checks, with proctoring and AI-assisted marking as further products. Inspera says it works with more than 160 institutions. This page sets out what Inspera publicly documents and what a university should check under the GDPR and the EU AI Act.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

Inspera is a Norwegian company, and Inspera Assessment is hosted on AWS with processing locations listed as Ireland, Germany and Italy. Inspera publishes a subprocessor list that names a transfer mechanism for each entry, including group companies and providers in the US, India, Australia and Kosovo under standard contractual clauses. Its platform offers minimisation, pseudonymisation and anonymisation privacy modes. The AI features matter most: Inspera Originality can predict AI-generated text using Pangram, Inspera Proctoring flags behaviour with AI, and Inspera Graide suggests grades. Under the EU AI Act, AI used to evaluate learning outcomes or to monitor students during tests is listed as high-risk, with deployer duties from 2 December 2027.

What Inspera documents publicly

This summary reflects Inspera's sub-processor and DPA page, security statement, GDPR page, product pages and website privacy notice as read on 7 October 2026.

TopicWhat the vendor statesSource
Company and establishmentDocumented Inspera AS and its subsidiaries; founded in Oslo, Norway, in 1999. Group companies are listed in Sweden, Denmark, the UK, Portugal, Australia, the US and India.About Inspera [5], Privacy notice [4], Sub-processors and DPA [1]
Where data is stored and processedDocumented Inspera Assessment is "hosted entirely on Amazon Web Services", and Inspera says it does not transfer data outside the AWS cloud. The subprocessor list gives AWS EMEA SARL with processing in Ireland, Germany and Italy.Security statement [2], [1]
Data processing agreementPlan-dependent Inspera says it has DPAs for Inspera Assessment, compliant with the GDPR and national laws, and that it does not disclose personal data to third parties other than listed subprocessors. A public DPA template was not found in public documentation (checked 7 October 2026).[1]
SubprocessorsDocumented A public list (last updated 21 November 2025) including AWS, Elasticsearch, Databricks, Zendesk, Atlassian, Google Cloud, Microsoft, TrackJS, Harness, Pangram and Talview, plus providers with processing in Bulgaria, the UK and Hungary, India and Kosovo. Inspera says the subprocessors used depend on the services purchased. The list does not describe each subprocessor's role.[1]
International transfers (DPF, SCCs)Documented Each entry names a mechanism: none needed inside the EEA, an adequacy decision for the UK, SCCs for Inspera's US, Australian and Indian companies and for several US providers, and the EU-US DPF plus SCCs for Atlassian, Google, Microsoft and Zendesk. Pangram (US) is listed with EEA processing and no access from outside the EEA.[1]
AI features and training on customer contentPlan-dependent Originality: optional AI Content Prediction powered by Pangram, with sentence-level likelihood scores flagged for human review. Proctoring: AI flags when students leave the frame, talk to another person or use a second device, validated by proctors. Graide: classification AI trained "exclusively on the institution's own marked data", with no automatic grading. Whether Originality or Proctoring data trains vendor models was not found in public documentation (checked 7 October 2026).Originality [6], AI Content Prediction [7], Proctoring [8], Graide acquisition [9]
Retention and deletionPlan-dependent Privacy modes: minimisation, pseudonymisation and anonymisation, with a data controller API to download or anonymise learner data. Backups are taken at least daily and kept for 7 days. A default retention period for assessment data was not found in public documentation (checked 7 October 2026).GDPR page [3], [2]
Security certificationsPlan-dependent Inspera says it maintains an information security management system "aligned with" ISO/IEC 27001:2022, encrypts data at rest and in transit, and commissions external penetration tests. It cites AWS's own ISO 27001 and SOC 3 reports. An ISO 27001 certificate for Inspera itself was not found in public documentation (checked 7 October 2026).[2]
Institution controls (SSO, admin, education licence)Documented With an external authentication provider and SSO, Inspera says Inspera Assessment can be used without Inspera knowing the test taker's identity. Proctoring recordings are role-based. Originality thresholds and classifications are configurable.[2], [8], [6]

What this means for a university

Validemic's analysis

Student data. An exam platform holds answers, grades, accommodations for disability (which can reveal health data), timestamps and logs, and with proctoring also video, audio and screen recordings. Pseudonymisation through SSO is a real strength: it limits what Inspera itself can link to a named student [2]. Check that it is configured that way in your tenancy.

Transfers. Core hosting is in the EEA, which keeps the main data flow simple [1][2]. The subprocessor list still includes US, Indian, Australian and Kosovan entities, and it does not say what each of them does [1]. Ask which of them can access personal data for the products you buy. The DPF adequacy decision of 10 July 2023 covers certified US companies [11]; the others rely on SCCs.

DPIA likelihood. For digital exams alone, many universities will already have a DPIA. Adding proctoring, AI content prediction or AI-assisted marking changes the risk profile and should trigger an update under Article 35 GDPR [10]. Where an AI score feeds a misconduct case or a grade, Article 22 GDPR on decisions based solely on automated processing is relevant [10]; Inspera's emphasis on human validation helps, but your procedures must make it real.

Product scope. Assessment, Originality, Proctoring and Graide have different data flows. Record which ones you license, and make sure the DPA covers each.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask Inspera before approving it

  1. Which Inspera entity is our processor, and can we review the DPA for each product we license?
  2. Which subprocessors on your list apply to our products, what does each do, and which can access student personal data from outside the EEA?
  3. What is the default retention period for exam data, recordings and Originality reports, and can we set our own?
  4. Is any of our data, including Originality submissions and proctoring recordings, used to train or improve Inspera's or Pangram's models?
  5. How do you classify Inspera Proctoring, AI Content Prediction and Graide under Article 6 and Annex III of the AI Act, and will you provide instructions for use and Article 13 information?
  6. Can you confirm that no proctoring feature infers students' emotions, so that Article 5(1)(f) of the AI Act is not engaged?
  7. What logs of AI flags, AI scores and reviewer decisions can we export, and for how long are they kept?
  8. Is Inspera certified to ISO/IEC 27001, or is the ISMS aligned with it without certification?
  9. How is automated identity verification in Proctoring carried out, and is any biometric template created?

The EU AI Act angle

Three features, two Annex III points. Annex III, point 3, lists as high-risk AI systems intended to evaluate learning outcomes (point 3(b)) and AI systems intended for monitoring and detecting prohibited behaviour of students during tests (point 3(d)) in educational institutions [12]. Graide suggests grades and feedback, which matches point 3(b) on its face even with a human approving every suggestion. Inspera Proctoring's AI flags match point 3(d). AI Content Prediction in Originality supports integrity decisions and could fall under either, depending on intended purpose. Article 6(3) says an Annex III system is not high-risk where it does not pose a significant risk, for example where it performs only a narrow procedural or preparatory task, but an Annex III system that performs profiling of natural persons is always high-risk [13]. We found no public statement of Inspera's classification under the AI Act (checked 7 October 2026).

Deployer obligations. If a feature is high-risk, Article 26 requires the university to use it according to the instructions for use, assign human oversight to competent staff, monitor its operation, keep logs under its control for at least six months, inform students and use the provider's information in its DPIA [14]. Article 27 requires a fundamental rights impact assessment before first use by bodies governed by public law, which includes many public universities [15]. Inspera's own design choices (human validation of flags, educator approval of each grade suggestion) fit these duties, but they do not replace them.

Emotion recognition. Article 5(1)(f) prohibits AI systems that infer emotions in education institutions, except for medical or safety reasons, and has applied since 2 February 2025 [16][17]. Inspera's proctoring page describes behavioural flags, not emotion inference [8]; confirm this in writing.

Timeline. The AI Omnibus, Regulation (EU) 2026/1744, entered into force on 27 July 2026 [18]. Under the amended Article 113, high-risk rules apply to Annex III systems from 2 December 2027 [17]. The AI literacy duty in Article 4, as amended, applies already [19].

Sources

  1. Sub-processors and DPA (last updated 21 November 2025), Inspera, retrieved 7 October 2026
  2. Security Statement (last updated 6 August 2025), Inspera, retrieved 7 October 2026
  3. GDPR Commitment and Compliance Roadmap, Inspera, retrieved 7 October 2026
  4. Website Privacy Notice, Inspera, retrieved 7 October 2026
  5. About Inspera, retrieved 7 October 2026
  6. Inspera Originality, retrieved 7 October 2026
  7. AI Content Prediction, Powered by Pangram, Inspera blog, 30 June 2026, retrieved 7 October 2026
  8. Inspera Proctoring, retrieved 7 October 2026
  9. Inspera Announces the Acquisition of Graide, Inspera press release, 8 June 2026, retrieved 7 October 2026
  10. Regulation (EU) 2016/679 (GDPR), Articles 22 and 35, text read from the Publications Office copy, retrieved 7 October 2026
  11. EU-US data transfers, European Commission, retrieved 7 October 2026
  12. AI Act Annex III, AI Act Service Desk (consolidated text of Regulation (EU) 2024/1689 as at 27 July 2026), retrieved 7 October 2026
  13. AI Act Article 6: Classification rules for high-risk AI systems, AI Act Service Desk, retrieved 7 October 2026
  14. AI Act Article 26: Obligations of deployers of high-risk AI systems, AI Act Service Desk, retrieved 7 October 2026
  15. AI Act Article 27: Fundamental rights impact assessment, AI Act Service Desk, retrieved 7 October 2026
  16. AI Act Article 5: Prohibited AI practices, AI Act Service Desk, retrieved 7 October 2026
  17. AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026
  18. AI Act, Shaping Europe's digital future (European Commission), with link to the AI Omnibus final text (OJ L 2026/1744), retrieved 7 October 2026
  19. AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026

About this page

We read Inspera's sub-processor and DPA page, security statement, GDPR page, website privacy notice, About page, product pages for Originality and Proctoring, its AI Content Prediction article and its Graide press release, plus the GDPR and the consolidated AI Act text, on 7 October 2026. Statements about Inspera come from Inspera's own pages; our interpretation is labelled as Validemic's analysis. This is not legal advice and does not say whether any particular use of Inspera complies with the GDPR or the AI Act. If you see an error or an outdated detail, please contact us and we will correct it.

Frequently asked questions

Is Inspera GDPR compliant?

No tool is GDPR compliant on its own. Inspera says it has data processing agreements for Inspera Assessment, publishes a subprocessor list with the transfer mechanism for each, hosts Inspera Assessment on AWS and offers privacy modes including pseudonymisation and anonymisation. Whether a university's use is lawful depends on its agreement, the products and features it enables, and how results are used.

Where does Inspera store exam data?

Inspera's security statement says Inspera Assessment is hosted entirely on Amazon Web Services and that Inspera does not transfer data outside the AWS cloud. Its subprocessor list gives AWS processing locations as Ireland, Germany and Italy. The list also includes Inspera group companies and other providers outside the EEA, under standard contractual clauses.

Does Inspera Originality detect AI-generated text?

Yes, as an option. Inspera says AI Content Prediction in Inspera Originality is powered by Pangram and gives AI and human scores, a confidence level and flagged segments. Inspera describes these as signals for human review, not conclusions. Its subprocessor list says Pangram processing takes place in the EEA.

Is Inspera Graide automated marking?

Inspera describes Graide, acquired in 2026, as classification AI that suggests grades and feedback which an educator must accept or reject, with no automatic grading. It says the model is trained only on the institution's own marked data. AI used to evaluate learning outcomes is listed as high-risk in Annex III of the EU AI Act.

Is Inspera Proctoring high-risk under the AI Act?

Annex III, point 3(d), lists AI systems intended to monitor and detect prohibited behaviour of students during tests as high-risk. Inspera says its proctoring uses AI to flag behaviour such as leaving the frame or using a second device, with human proctors validating flags. Deployer obligations for Annex III systems apply from 2 December 2027.