GDPR check

Is Proctorio GDPR compliant? What universities should check

Proctorio records and analyses students while they sit online exams. That makes it one of the most sensitive tools a university can deploy, under both the GDPR and the EU AI Act. This page sets out what Proctorio publicly documents and what a university should check before using it.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

Proctorio presents itself as a processor acting on the institution's instructions. It states that exam recordings are protected by zero-knowledge encryption that only institution-approved representatives can decrypt, that recordings stay in a storage region chosen for the institution, and that it uses face and gaze detection rather than facial recognition. Contracts outside the US are with Proctorio GmbH in Frankfurt, and the company says it participates in the EU-US Data Privacy Framework. Automated monitoring of students during tests is listed as high-risk in Annex III of the EU AI Act, so universities face deployer obligations from 2 December 2027 in addition to the GDPR. A Dutch appeal court accepted one university's pandemic-era use in 2021, but every deployment needs its own assessment.

What Proctorio documents publicly

This summary reflects Proctorio's privacy notice, terms of service and compliance page as read on 7 October 2026.

TopicWhat the vendor statesSource
Company and establishmentDocumented US agreements are with Proctor.io, Inc. in Scottsdale, Arizona. Notices under other SaaS agreements go to Proctorio GmbH in Frankfurt am Main, Germany. Support staff work in the US, Germany and Serbia, including through Proctorio d.o.o.Terms of Service [2], Privacy Notice [1]
Where data is stored and processedDocumented Recordings are stored on the cloud provider's servers in the US, Europe, Canada, Japan, Australia, South Africa, Singapore or India, depending on the institution's location, and "never leave the controlling location of the Institution". Institutions choose the data centre. Some operational data (IP addresses, administrator and billing information) may go to Germany, Serbia or the US.[1]
Data processing agreementPlan-dependent Proctorio describes itself as a processor acting only on institution instructions, and its privacy notice refers to deletion or return of data under the applicable agreement or data processing agreement. A public template DPA was not found in public documentation (checked 7 October 2026).[1], Privacy and Compliance [3]
SubprocessorsDocumented Listed in the privacy notice: Microsoft Azure (cloud), Cloudflare (CDN and firewall, with its Data Localization Suite) and Constellix (DNS) for all services; Google Workspace, Olark, Proctorio d.o.o., Twilio and Zendesk for support; Stripe for payments and automated identity verification. Updates are published on GitHub.[1]
International transfers (DPF, SCCs)Documented Proctorio states it complies with the EU-US DPF, the UK Extension and the Swiss-US DPF (status read from the vendor's privacy notice), and may also rely on the 2021 SCCs as an additional transfer mechanism.[1]
AI features and training on customer contentPlan-dependent Face detection and gaze detection flag possible suspicious activity for human review, and can be disabled by the institution. Optional, consent-based identity verification and a "Continuity Check" are described separately; Proctorio says the Continuity Check reference exists only in device memory during the exam. The terms say the services are not intended as an automated decision-making tool and require human oversight. A statement on whether test-taker data is used to train or improve models was not found in public documentation (checked 7 October 2026); Proctorio says it cannot decrypt recordings.[1], [2]
Retention and deletionDocumented Recordings are kept for the minimum time required by the institution or by law. Institutional data is kept for up to 30 days after the agreement ends unless the institution specifies otherwise. Pseudonymised usage data (hashed user, exam and course IDs, approximate location, exam length and date) is retained for billing and usage tracking.[1]
Security certificationsDocumented SOC 2 Type 1 and Type 2 audits by A-LIGN, ISO/IEC 27001:2022 (June 2024), ISO/IEC 27018:2019 (2026) and ISO/IEC 42001 for AI management systems (June 2025). End-to-end encryption with AES-GCM, TLS 1.2 or 1.3 in transit and AES-256 at rest.[3], [1]
Institution controls (SSO, admin, education licence)Documented Proctorio runs within the institution's assessment platform, takes user roles from it, and stores decryption keys there so that only institution-approved representatives can view recordings. The institution configures recording, detection and identity verification settings.[1]

What this means for a university

Validemic's analysis

Student data. Proctoring captures video and audio of students in their homes, their screens and browser activity, and with some settings an image of an ID document. Third parties such as family members can appear in recordings. Health information can surface indirectly, for example through adjustments for disability. Article 9 GDPR restricts processing of biometric data used to uniquely identify a person [4], which is why the difference Proctorio draws between face detection and facial recognition, and the consent-based design of its identity features, deserves careful verification in your own configuration.

Minors. Rarely relevant at university, apart from entrance tests taken by applicants who are still under 18.

DPIA likelihood. We would treat a DPIA as required. Article 35 GDPR names systematic evaluation based on automated processing and processing using new technologies likely to result in a high risk [4]. The DPIA should cover necessity (are there alternatives, such as on-campus exams or different assessment formats?), proportionality, the settings chosen and how flags are reviewed.

The Dutch court decision. On 1 June 2021, the Amsterdam Court of Appeal ruled in summary proceedings brought by student councils that the University of Amsterdam could use Proctorio for online exams. The court found the use necessary in view of the Covid-19 measures, that data collection did not go beyond what was needed to prevent fraud, that no adequate alternative was available, and that no special category data was processed (ECLI:NL:GHAMS:2021:1560) [5]. The ruling is useful precedent on how a court weighed proctoring, but it depended on the pandemic context and on the university's own set-up. It does not settle the question for a different institution today.

Transfers. With European storage and a contract with Proctorio GmbH, much of the processing can stay in the EU, while the subprocessor list and support arrangements still involve the US and Serbia [1][2]. The DPF adequacy decision of 10 July 2023 covers certified US companies [6]; for Serbia, check which transfer tool applies.

Plan tier. Most risk-relevant choices are settings rather than plans: whether video is recorded, whether face and gaze detection are on, whether identity verification is used, and who reviews flags.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask Proctorio before approving it

  1. Which entity will we contract with, Proctorio GmbH or Proctor.io, Inc., and can we review the data processing agreement before signing?
  2. Which European data centre will hold our recordings, and which data (operational, support, billing) is processed outside the EU?
  3. How does Proctorio classify its services under Article 6 and Annex III of the AI Act, and what instructions for use and Article 13 information will it provide?
  4. Can you confirm that no feature infers students' emotions, stress or intent, so that Article 5(1)(f) of the AI Act is not engaged?
  5. Is any test-taker data, in any form, used to develop or improve detection models?
  6. Which settings are on by default, and can we disable face detection, gaze detection and identity verification centrally?
  7. What logs of flags and reviewer actions are available to us, and can we keep them for at least six months?
  8. How does the identity verification provider process ID and selfie images, where, and for how long?
  9. What evidence do you have on flag accuracy across skin tones, disabilities and home environments?
  10. How do students exercise access and deletion rights for recordings, given that only we can decrypt them?

The EU AI Act angle

High-risk listing. Annex III, point 3(d), of the AI Act lists as high-risk "AI systems intended to be used for monitoring and detecting prohibited behaviour of students during tests" in educational institutions [7]. Automated proctoring that flags gaze direction, extra faces or browser activity is, on its face, the use case this point describes. Article 6(3) allows an Annex III system not to be treated as high-risk where it poses no significant risk, for instance when it only performs a narrow procedural or preparatory task [8]. Proctorio's terms stress that it is a support tool requiring human oversight [2], but we found no public statement of how Proctorio classifies its services under the AI Act (checked 7 October 2026). Universities should ask for one in writing.

Deployer obligations. If the system is high-risk, Article 26 requires the university as deployer to use it according to the instructions for use, assign human oversight to people with the necessary competence, training and authority, monitor its operation and report risks to the provider, keep automatically generated logs under its control for at least six months, inform students that they are subject to a high-risk AI system, and use the provider's Article 13 information in its DPIA [9]. Article 27 requires a fundamental rights impact assessment before first use by deployers that are bodies governed by public law, which includes many public universities [10].

Emotion recognition. Article 5(1)(f) prohibits placing on the market, putting into service or using AI systems to infer the emotions of a natural person in education institutions, except for medical or safety reasons [11]. This ban has applied since 2 February 2025 [12]. Proctorio's documentation describes face and gaze detection, not emotion inference [1]. Universities should still confirm that no enabled feature, including from third parties, infers emotions such as stress or anxiety.

Timeline. High-risk obligations for Annex III systems were originally due to apply from 2 August 2026. The Commission proposed postponing them in its Digital Omnibus on AI on 19 November 2025, a political agreement was reached on 7 May 2026, and the amending act, Regulation (EU) 2026/1744, entered into force on 27 July 2026 [13]. Under the amended Article 113, the high-risk rules apply to Annex III systems from 2 December 2027 [12]. AI literacy duties under Article 4 apply already [14]. Proctoring contracts signed now will very likely still be running in December 2027, so build these obligations into them now.

Sources

  1. Proctorio Privacy Notice, retrieved 7 October 2026
  2. Proctorio Policies: Terms of Service, retrieved 7 October 2026
  3. Proctorio Privacy and Compliance, retrieved 7 October 2026
  4. Regulation (EU) 2016/679 (GDPR), Articles 9 and 35, text read from the Publications Office copy, retrieved 7 October 2026
  5. Online proctoring bij tentamens UvA blijft toegestaan, Gerechtshof Amsterdam news item, 1 June 2021 (ECLI:NL:GHAMS:2021:1560), Rechtspraak, retrieved 7 October 2026
  6. EU-US data transfers, European Commission, retrieved 7 October 2026
  7. AI Act Annex III, AI Act Service Desk (consolidated text of Regulation (EU) 2024/1689 as at 27 July 2026), retrieved 7 October 2026
  8. AI Act Article 6: Classification rules for high-risk AI systems, AI Act Service Desk, retrieved 7 October 2026
  9. AI Act Article 26: Obligations of deployers of high-risk AI systems, AI Act Service Desk, retrieved 7 October 2026
  10. AI Act Article 27: Fundamental rights impact assessment, AI Act Service Desk, retrieved 7 October 2026
  11. AI Act Article 5: Prohibited AI practices, AI Act Service Desk, retrieved 7 October 2026
  12. AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026
  13. AI Act, Shaping Europe's digital future (European Commission), with link to the AI Omnibus final text (OJ L 2026/1744), retrieved 7 October 2026
  14. AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026

About this page

We read Proctorio's privacy notice, terms of service and compliance page, the Dutch judiciary's announcement of the Amsterdam Court of Appeal ruling, the GDPR and the consolidated AI Act text on 7 October 2026. EUR-Lex was not fully reachable for automated retrieval that day, so we read the AI Act through the Commission's AI Act Service Desk, which reproduces the EUR-Lex consolidated version. We mention court or regulator matters only where we could read an official source, which is why this page covers the Amsterdam ruling and no others. Statements about Proctorio come from Proctorio's own pages; our interpretation is labelled as Validemic's analysis. This is not legal advice and does not say whether any particular use of Proctorio complies with the GDPR or the AI Act. If you see an error or an outdated detail, please contact us and we will correct it.

Frequently asked questions

Is Proctorio GDPR compliant?

No tool is GDPR compliant on its own. Proctorio describes itself as a processor for institutions, stores recordings in a region chosen by the institution, encrypts recordings so that only institution-approved staff can decrypt them, and says it participates in the EU-US Data Privacy Framework. Whether an exam set-up is lawful depends on necessity, proportionality, settings and alternatives offered to students.

Does Proctorio use facial recognition?

Proctorio says it uses facial detection and gaze detection to flag possible suspicious activity, not facial recognition, and that the institution can disable both. Optional identity verification features, used only with the student's consent, can compare a face with an ID document, partly on the student's device and partly through a third-party verification provider.

Is online proctoring high-risk under the EU AI Act?

Annex III, point 3(d), of the AI Act lists AI systems intended to monitor and detect prohibited behaviour of students during tests as high-risk. Automated proctoring matches that description on its face. The deployer obligations in Article 26 apply to Annex III systems from 2 December 2027, following the Digital Omnibus on AI.

Has a court ruled on Proctorio and the GDPR?

Yes, in one national case. On 1 June 2021 the Amsterdam Court of Appeal, in summary proceedings brought by student councils, held that the University of Amsterdam's use of Proctorio during the Covid-19 crisis met the GDPR's requirements (ECLI:NL:GHAMS:2021:1560). The ruling turned on the circumstances at the time.

Where does Proctorio store exam recordings?

Proctorio says recordings are stored on its cloud provider's servers in the US, Europe, Canada, Japan, Australia, South Africa, Singapore or India depending on the institution's location, and that they do not leave the institution's controlling location.

Do universities need a DPIA for online proctoring?

In our view, almost always. Remote proctoring involves systematic monitoring of students in their homes, automated flagging and, with some settings, identity verification. Article 35 GDPR requires a DPIA where processing is likely to result in a high risk, and Article 26(9) of the AI Act links the DPIA to provider information for high-risk systems.