GDPR check

Is Respondus GDPR compliant? LockDown Browser and Respondus Monitor for universities

Respondus LockDown Browser locks a student's computer during an online exam, and Respondus Monitor adds automated webcam proctoring on top. Both are used from within a learning management system or other assessment platform. This page sets out what Respondus publicly documents and what a European university should check, given US hosting and automated analysis of exam recordings.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

Respondus, Inc. is a US company that acts as a processor when a university licenses LockDown Browser or Respondus Monitor. It publishes an EU/EEA/Swiss DPA referring to the 2021 standard contractual clauses, states that it is certified under the EU-US Data Privacy Framework, and has appointed EDPO as its EU representative. Its DPA says its servers are outside the EEA, and its subprocessor list names AWS storage in the USA. LockDown Browser itself processes little personal data. Respondus Monitor records webcam and screen activity, uses computer vision to flag events, and creates temporary facial templates on the student's device. That makes Monitor the part to assess carefully under both the GDPR and the EU AI Act, where automated proctoring is listed as high-risk with deployer duties from 2 December 2027.

What Respondus documents publicly

This summary reflects Respondus's privacy policy, its EU, UK, Switzerland and EEA supplement, its LockDown Browser and Monitor supplements, its EU/EEA/Swiss DPA and its subprocessor list, as read on 7 October 2026.

TopicWhat the vendor statesSource
Company and establishmentDocumented Respondus, Inc., a US company. For individuals in the EU and UK it names EDPO (Madrid) and EDPO UK (London) as its representatives. When students use the software through an institution, the institution is controller and Respondus is processor.EU, UK, Swiss and EEA supplement [2], Privacy Policy [1]
Where data is stored and processedDocumented The DPA says Respondus's servers "are located outside of the European Economic Area" and that data will be transferred outside the EEA. The subprocessor list gives AWS storage in the USA. An EU hosting option was not found in public documentation (checked 7 October 2026).EU/EEA/CH DPA [5], Subprocessors [6]
Data processing agreementDocumented A public DPA (effective 25 August 2023) supplementing the LockDown Browser and Monitor licence terms, with separate UK and EU/EEA/Swiss versions. It incorporates the 2021 SCCs (Module 2) where applicable.[5], DPA overview
SubprocessorsDocumented A public list (last modified 22 November 2024): AWS (storage), GoTo, Influx, LiveChat, Microsoft 365, Pardot, PayPal, Salesforce, WordPress and Zendesk, all located in the USA. The DPA promises 30 days' notice of new subprocessors and lets the institution object within 10 days and terminate.[6], [5]
International transfers (DPF, SCCs)Documented Respondus states that it complies with the EU-US DPF, the UK Extension and the Swiss-US DPF (status read from the vendor's privacy supplement), with JAMS as its independent recourse body. The DPA says the institution is responsible for establishing the legal basis for transfers, "including TIAs".[2], [5]
AI features and training on customer contentPlan-dependent Monitor uses computer vision to detect faces, lighting and handheld devices and to raise event flags and in-exam alerts. It "does not make any determinations, automated decisions, or recommendations" and uses no large language models. Machine learning is used to develop the computer vision. Purposes for student data include improving Respondus Monitor and internal research.Monitor supplement [3]
Retention and deletionDocumented The institution controls retention of data collected to use the software, and Respondus says institutions can adjust storage time. Monitor Help Center data is kept for up to one year, LockDown Browser Help Center data for up to five years. On request, Respondus confirms deletion in writing within seven days.[1], [3], LockDown Browser supplement [4], [5]
Security certificationsPlan-dependent The DPA commits to encryption in transit and at rest. A SOC 2 report or ISO 27001 certificate was not found in public documentation (checked 7 October 2026).[5], [1]
Institution controls (SSO, admin, education licence)Documented Students sign in through the learning system, which passes an identifier and name. Instructors choose exam settings such as photo or photo ID requirements; administrators can disable the facial template feature and upload photos on file.[3]

What this means for a university

Validemic's analysis

Two products, two risk levels. LockDown Browser on its own processes personal data only in narrow situations [4], so its privacy assessment is fairly light. Respondus Monitor records students in their homes, can capture photo ID documents including passport or licence numbers, and analyses video automatically [3]. Assess them separately.

Facial templates. Respondus says its facial templates are not linked to an identity, stay in temporary memory on the student's device and are cleared after the exam [3]. That design reduces risk, but comparing a face over time is close to the definition of biometric data in Article 4(14) GDPR, and Article 9 restricts biometric data processed to uniquely identify a person [7]. Decide whether to keep the feature enabled, and document the reasoning.

Transfers. All storage is in the US [5][6]. The DPF adequacy decision of 10 July 2023 covers certified US companies [8], and the DPA adds SCCs, but it also places the transfer impact assessment on the institution [5]. Recordings of students at home are among the more sensitive data a university can export.

Product improvement. The Monitor supplement lists product improvement and internal research among the purposes, and allows Respondus staff to review recordings for those reasons [3]. A processor may only process on the controller's documented instructions under Article 28(3)(a) GDPR [7], so agree in writing what product improvement covers, or exclude it.

DPIA likelihood. We would treat a DPIA as required for Respondus Monitor under Article 35 GDPR [7]: systematic monitoring, automated flagging and international transfer. It should cover alternatives to remote proctoring and how flags are reviewed.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask Respondus before approving it

  1. Can you host Respondus Monitor data in the EU, and if not, which data is stored in the US and for how long by default?
  2. Which AWS region stores our recordings and photo ID images, and which other subprocessors can access them?
  3. Can we exclude the use of our students' recordings for product improvement, internal research and model development?
  4. How do you classify Respondus Monitor under Article 6 and Annex III of the AI Act, and what instructions for use and Article 13 information will you provide?
  5. Can you confirm that no Monitor feature infers emotions, stress or intent, so that Article 5(1)(f) of the AI Act is not engaged?
  6. What evidence do you have on flag accuracy across skin tones, disabilities and home environments, beyond your published fairness study?
  7. Can we export logs of event flags and instructor reviews and keep them for at least six months?
  8. Do you hold a SOC 2 Type II report or ISO/IEC 27001 certificate, and can we see it?
  9. How do students who decline remote proctoring get an equivalent alternative under our settings?

The EU AI Act angle

High-risk listing. Annex III, point 3(d), of the AI Act lists as high-risk "AI systems intended to be used for monitoring and detecting prohibited behaviour of students during tests" in educational institutions [9]. Point 3(b) covers AI intended to evaluate learning outcomes, which is less relevant here because Monitor does not grade. Respondus Monitor's computer vision flags, such as a student leaving the frame or more than one person appearing, match point 3(d) on their face [3]. Article 6(3) allows an Annex III system not to be treated as high-risk where it poses no significant risk, for instance by performing only a narrow procedural or preparatory task, but an Annex III system that profiles natural persons is always high-risk [10]. Respondus says Monitor makes no determinations or recommendations and that institutions interpret flags [3]; we found no public statement of its AI Act classification (checked 7 October 2026).

Deployer obligations. If Monitor is high-risk, Article 26 requires the university to follow the instructions for use, assign human oversight to staff with the necessary competence and authority, monitor its operation, keep automatically generated logs under its control for at least six months, inform students that they are subject to a high-risk AI system, and use the provider's information in its DPIA [11]. Article 27 requires a fundamental rights impact assessment before first use by bodies governed by public law, which includes many public universities [12].

Emotion recognition. Article 5(1)(f) prohibits AI systems that infer emotions in education institutions, except for medical or safety reasons, and has applied since 2 February 2025 [13][14]. Respondus describes detection of faces, lighting and devices, not emotions [3].

Timeline. The AI Omnibus, Regulation (EU) 2026/1744, entered into force on 27 July 2026 [15]. Under the amended Article 113, high-risk rules apply to Annex III systems from 2 December 2027 [14]. The AI literacy duty in Article 4, as amended, applies already [16].

Sources

  1. Respondus Privacy Policy (last updated 25 June 2026, effective 24 July 2026), retrieved 7 October 2026
  2. EU, UK, Switzerland, and EEA Privacy Supplement (last updated 12 September 2025), Respondus, retrieved 7 October 2026
  3. Respondus Monitor Privacy Policy Supplement (effective 24 July 2026), retrieved 7 October 2026
  4. LockDown Browser Privacy Policy Supplement (last updated 25 June 2026), retrieved 7 October 2026
  5. Respondus Data Processing Agreement, EU/EEA/CH version (effective 25 August 2023), retrieved 7 October 2026
  6. Respondus List of Subprocessors (last modified 22 November 2024), retrieved 7 October 2026
  7. Regulation (EU) 2016/679 (GDPR), Articles 4(14), 9, 28 and 35, text read from the Publications Office copy, retrieved 7 October 2026
  8. EU-US data transfers, European Commission, retrieved 7 October 2026
  9. AI Act Annex III, AI Act Service Desk (consolidated text of Regulation (EU) 2024/1689 as at 27 July 2026), retrieved 7 October 2026
  10. AI Act Article 6: Classification rules for high-risk AI systems, AI Act Service Desk, retrieved 7 October 2026
  11. AI Act Article 26: Obligations of deployers of high-risk AI systems, AI Act Service Desk, retrieved 7 October 2026
  12. AI Act Article 27: Fundamental rights impact assessment, AI Act Service Desk, retrieved 7 October 2026
  13. AI Act Article 5: Prohibited AI practices, AI Act Service Desk, retrieved 7 October 2026
  14. AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026
  15. AI Act, Shaping Europe's digital future (European Commission), with link to the AI Omnibus final text (OJ L 2026/1744), retrieved 7 October 2026
  16. AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026

About this page

We read Respondus's privacy policy, its EU, UK, Switzerland and EEA supplement, its LockDown Browser and Monitor supplements, its EU/EEA/Swiss DPA and its subprocessor list, plus the GDPR and the consolidated AI Act text, on 7 October 2026. The official Data Privacy Framework list did not return results for automated queries that day, so DPF status is taken from Respondus's own privacy supplement. Statements about Respondus come from Respondus's own pages; our interpretation is labelled as Validemic's analysis. This is not legal advice and does not say whether any particular use of Respondus complies with the GDPR or the AI Act. If you see an error or an outdated detail, please contact us and we will correct it.

Frequently asked questions

Is Respondus GDPR compliant?

No tool is GDPR compliant on its own. Respondus publishes an EU/EEA/Swiss data processing agreement that refers to the 2021 standard contractual clauses, says it is certified under the EU-US Data Privacy Framework, and has appointed an EU representative. Its DPA also says its servers are outside the EEA. Whether a university's use is lawful depends on necessity, settings, transfer assessment and the alternatives offered to students.

Where does Respondus store exam recordings?

Respondus's subprocessor list names Amazon Web Services for storage with the location given as the USA, and its EU DPA says Respondus's servers are located outside the European Economic Area. Recordings and other Monitor data are therefore transferred to the US.

Does Respondus Monitor use facial recognition?

Respondus says Monitor creates a template of the facial features of the person at the start of the exam to check whether the same person stays in the video. It says the template is not linked to any identity, exists only in temporary memory on the student's computer and is cleared after the exam, and that administrators can disable the feature. Respondus notes that some laws may treat these templates as biometric information.

Is LockDown Browser the same as proctoring?

No. Respondus describes LockDown Browser as a client application that locks down the device during an exam, and says it processes students' personal information only in specific situations, such as Help Center use, the Early Exit feature or a detected attempt to bypass its protections. Respondus Monitor is the companion product that records webcam and screen data and flags events.

Is Respondus Monitor high-risk under the EU AI Act?

Annex III, point 3(d), lists AI systems intended to monitor and detect prohibited behaviour of students during tests as high-risk. Respondus Monitor uses computer vision to generate event flags for instructors, which matches that description on its face. Deployer obligations for Annex III systems apply from 2 December 2027.

Does Respondus use exam recordings to improve its product?

Respondus's Monitor supplement lists improving Respondus Monitor and internal research among the purposes for processing student data, says it uses machine learning to develop its computer vision, and says staff may review recordings to resolve technical problems or improve the product. Universities should address this in the contract.