Is WISEflow GDPR compliant? What universities should check
WISEflow is a digital assessment platform from UNIwise, a Danish company that grew out of a project at Aarhus University. It covers exams, coursework, originality checking and several levels of proctoring. This page sets out what UNIwise publicly documents and what a university should check under the GDPR and the EU AI Act.
Short answer
UNIwise ApS, based in Aarhus, Denmark, says it acts as processor for institutions under a data processing agreement and keeps WISEflow data in AWS data centres in Germany and Ireland, encrypted with keys it holds. It states that student submissions, marking and grades are never used to train AI models, that AI features are off until the institution enables them, and that exam data is deleted automatically after two years. It says its security management is certified to ISO/IEC 27001. The higher-risk parts are the proctoring options, especially facial comparison, audio detection and AI flags in full proctoring, and AI-assisted feedback. Under the EU AI Act, monitoring students during tests and evaluating learning outcomes are high-risk uses, with deployer duties from 2 December 2027.
What UNIwise documents publicly
This summary reflects UNIwise's AI and data page, its WISEflow proctoring and add-on pages, its About page, a December 2025 article on WISEflow Originality and its website privacy policy, as read on 7 October 2026. The WISEflow Trust Centre, which UNIwise says holds its DPA, subprocessor list and DPIAs, did not allow automated retrieval that day.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and establishment | Documented UNIwise ApS, Aarhus, Denmark, with offices in Manchester, Skien and Hamburg. WISEflow grew out of a ministry-funded project at Aarhus University; the founders acquired the licence to the prototype in 2012 and UNIwise launched soon after. UNIwise names Monterro as majority owner. | About UNIwise [4], Privacy policy [6] |
| Where data is stored and processed | Documented Data is held in Ireland and Germany on AWS and "stays inside the EU", with main data in Frankfurt and backups in Dublin. Encryption keys are held by UNIwise. The proctoring service runs on separate, EU-hosted infrastructure. | AI and data [1], Proctoring [2] |
| Data processing agreement | Documented UNIwise acts as processor under a GDPR data processing agreement; the institution is controller and chooses the lawful basis. UNIwise says the DPA is in its Trust Centre, which we could not read. | [2], [1] |
| Subprocessors | Not verified UNIwise says the full list of companies involved is in its Trust Centre and that its no-training commitment binds every company it works with. The list itself was not reachable for automated retrieval (checked 7 October 2026). AWS is named as host. | [1] |
| International transfers (DPF, SCCs) | Plan-dependent UNIwise states that data stays inside the EU. Whether any subprocessor or support function involves access from outside the EEA was not found in the public pages we could read (checked 7 October 2026). | [1], [2] |
| AI features and training on customer content | Documented Submissions, marking, feedback, grades and criteria are not used to train or improve any model, and this is written into the agreement. AI features are opt-in at licence level. AI-assisted feedback runs only after grading, and students are told when AI helped draft feedback. Full proctoring can raise AI flags for multiple persons, voices and copy and paste. UNIwise says it does not offer AI writing detection. | [1], Add-on products [3], [2], Originality article [5] |
| Retention and deletion | Documented Exam data is deleted automatically after two years, or kept for the life of the agreement if the institution chooses. Biometric data, audio recordings and device monitoring images are deleted automatically after six months, or sooner. On exit, data is returned or deleted and deletion is confirmed in writing. | [1] |
| Security certifications | Documented Security management certified to ISO/IEC 27001, audited annually by an external body, most recently in April 2026; continuous vulnerability scanning and a yearly external penetration test; breach notification to institutions within 72 hours. We could not view the certificate itself. | [1] |
| Institution controls (SSO, admin, education licence) | Documented Role-based access following the institution's structure; every action, by a person or an AI feature, is logged with a timestamp and exportable. Institutions choose the Originality comparison scope and the proctoring level per exam. Named UNIwise staff can reach the live system for operational reasons, with logged access reviewed every six months. | [1], [2] |
WISEflow describes four integrity levels: Device Monitor (screen captures and application logs), a lockdown browser, facial comparison and audio detection (periodic stills matched against a reference photo, and voice detection with live transcription), and full proctoring with automated ID checks and webcam, screen and audio recording [2].
What this means for a university
Validemic's analysis
Strong defaults, but read the Trust Centre. EU-only hosting, a contractual ban on training, automatic deletion and exportable audit logs are concrete commitments that make a DPO's work easier [1]. Because the DPA and subprocessor list sit behind the Trust Centre, ask for them early and check that the public statements are reflected in the contract.
Biometric data. Facial comparison matches images of a student against a reference photo to confirm identity. Article 9 GDPR restricts processing of biometric data for uniquely identifying a person, so the institution needs an Article 9(2) condition as well as a lawful basis [7]. UNIwise itself advises enabling facial and audio features only where a DPIA addendum evidences necessity and proportionality [2]. Offering an alternative for students who cannot or will not use them is worth considering.
DPIA likelihood. A DPIA under Article 35 GDPR is very likely for proctoring, Device Monitor and AI-assisted feedback [7]. UNIwise says it supplies a DPIA for every AI feature and a dedicated proctoring DPIA [1][2]; use them as input, not as a substitute for your own.
Retention. The two-year and six-month defaults are short compared with many vendors [1]. Check that they fit your own retention schedule for appeals and archives, and change them deliberately.
Plan tier. Proctoring levels and add-ons such as AI feedback and Device Monitor are separately licensed or configured [2][3]. Your DPIA and privacy notice should match what is actually switched on.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask UNIwise before approving WISEflow
- Can we receive the DPA, the current subprocessor list and the ISO/IEC 27001 certificate from your Trust Centre before signing?
- Which subprocessors are used for the proctoring service and for AI-assisted feedback, and where is each established?
- Is any personal data accessible from outside the EU, including for support or by AI model providers?
- How are reference photos and facial comparison templates created, stored and deleted?
- How do you classify facial comparison, full proctoring and AI-assisted feedback under Article 6 and Annex III of the AI Act, and what instructions for use and Article 13 information will you provide?
- Can you confirm that no feature infers students' emotions, so that Article 5(1)(f) of the AI Act is not engaged?
- What evidence do you have on facial match accuracy across skin tones and lighting conditions?
- Can we export logs of flags and reviewer decisions and keep them for at least six months?
The EU AI Act angle
High-risk listing. Annex III, point 3, of the AI Act lists as high-risk AI systems intended to evaluate learning outcomes (point 3(b)) and AI systems intended for monitoring and detecting prohibited behaviour of students during tests (point 3(d)) in educational institutions [8]. WISEflow's AI flags in full proctoring match point 3(d) on their face. AI-assisted feedback drafts grade justifications after a human has graded, which UNIwise designs to avoid influencing the mark [1]; whether that makes it a narrow or preparatory task under Article 6(3) is a question for the provider's classification [9]. Article 6(3) also says an Annex III system that performs profiling of natural persons is always high-risk [9]. UNIwise says it supplies documentation on how its AI features work and supports institutions' fundamental rights assessments [1], but we found no public statement of its formal classification (checked 7 October 2026).
Deployer obligations. If a feature is high-risk, Article 26 requires the university to use it according to the instructions for use, assign human oversight to competent staff, monitor its operation, keep logs under its control for at least six months, inform students and use the provider's information in its DPIA [10]. Article 27 requires a fundamental rights impact assessment before first use by bodies governed by public law, which includes many public universities [11]. WISEflow's exportable action log is useful evidence here [1].
Emotion recognition. Article 5(1)(f) prohibits AI systems that infer emotions in education institutions, except for medical or safety reasons, and has applied since 2 February 2025 [12][13]. WISEflow's proctoring pages describe identity matching, voice detection and behaviour flags, not emotion inference [2].
Timeline. The AI Omnibus, Regulation (EU) 2026/1744, entered into force on 27 July 2026 [14]. Under the amended Article 113, high-risk rules apply to Annex III systems from 2 December 2027 [13]. The AI literacy duty in Article 4, as amended, applies now [15].
Sources
- How UNIwise Handles AI and Student Data, UNIwise, retrieved 7 October 2026
- WISEflow proctoring and exam security, UNIwise, retrieved 7 October 2026
- WISEflow add-on products (AI Feedback, Paper Submission, Chat, Device Monitor), UNIwise, retrieved 7 October 2026
- About UNIwise, retrieved 7 October 2026
- Plagiarism control in the age of AI: why WISEflow Originality takes a stand, UNIwise blog, 15 December 2025, retrieved 7 October 2026
- UNIwise privacy and cookie policy, retrieved 7 October 2026
- Regulation (EU) 2016/679 (GDPR), Articles 9 and 35, text read from the Publications Office copy, retrieved 7 October 2026
- AI Act Annex III, AI Act Service Desk (consolidated text of Regulation (EU) 2024/1689 as at 27 July 2026), retrieved 7 October 2026
- AI Act Article 6: Classification rules for high-risk AI systems, AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 26: Obligations of deployers of high-risk AI systems, AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 27: Fundamental rights impact assessment, AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 5: Prohibited AI practices, AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026
- AI Act, Shaping Europe's digital future (European Commission), with link to the AI Omnibus final text (OJ L 2026/1744), retrieved 7 October 2026
- AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026
About this page
We read UNIwise's AI and data page, its WISEflow proctoring and add-on pages, its About page, its December 2025 article on WISEflow Originality and its website privacy policy, plus the GDPR and the consolidated AI Act text, on 7 October 2026. The WISEflow Trust Centre (trust.uniwise.eu) blocked automated retrieval that day, so we have not verified the DPA, subprocessor list or ISO certificate it is said to contain. Statements about WISEflow come from UNIwise's own pages; our interpretation is labelled as Validemic's analysis. This is not legal advice and does not say whether any particular use of WISEflow complies with the GDPR or the AI Act. If you see an error or an outdated detail, please contact us and we will correct it.
Frequently asked questions
Is WISEflow GDPR compliant?
No tool is GDPR compliant on its own. UNIwise says it acts as processor under a data processing agreement, keeps data in AWS data centres in Germany and Ireland, does not use assessment data to train AI models, and deletes exam data automatically after two years unless the institution chooses longer. Whether a university's use is lawful depends on its agreement, the features it enables and how it uses the results.
Where does WISEflow store data?
UNIwise says data is held in Ireland and Germany on AWS and stays inside the EU, with the main data in Frankfurt and backups in Dublin. It says data is encrypted with keys held by UNIwise. The proctoring service runs on separate infrastructure that UNIwise says is also hosted in the EU.
Does WISEflow use facial recognition?
WISEflow's proctoring options include facial comparison, which captures periodic still images during an exam and matches them against the student's reference photo, with low match scores flagged for an invigilator. UNIwise itself notes that facial and audio features engage special category data and should only be enabled where a DPIA addendum shows necessity and proportionality.
Does WISEflow Originality detect AI-generated text?
UNIwise said in December 2025 that it does not offer AI detection in WISEflow Originality because it considers current detectors unreliable. WISEflow Originality uses semantic similarity analysis, and the institution decides whether its submissions join a shared comparison set.
How long does WISEflow keep exam data and proctoring recordings?
UNIwise says exam data is deleted automatically after two years, or kept for the life of the agreement if the institution needs that. Biometric data, audio recordings and device monitoring images from proctoring are deleted automatically after six months, or sooner if the institution chooses.