Online exams and proctoring under GDPR and the EU AI Act
Remote proctoring moved from niche to mainstream during the pandemic and has stayed in many universities' toolkits. It is also one of the most intrusive things a university can do to its students: it watches them in their homes, analyses their behaviour and sometimes processes their faces. This guide sets out what the GDPR requires, what courts and data protection authorities have decided, what the EU AI Act adds from December 2027, and how lockdown browsers, live invigilation and AI proctoring compare.
The short answer
- Legal basis: public universities normally rely on public task (Article 6(1)(e) GDPR). Consent is a poor fit: the Italian Garante rejected it in the Bocconi case, and the CNIL considers it workable only where a real in-person alternative exists.
- Biometrics: face detection is not automatically biometric data, but automated comparison of a face with an ID document is. That processing needs an Article 9(2) exception, a real alternative and no biometric database.
- Proportionality: the CNIL recommends against automated analysis of candidates' behaviour, accepts live monitoring and screen sharing for higher-stakes exams, and says an in-person alternative should normally be offered.
- Case law: the Amsterdam Court of Appeal upheld one university's pandemic use of Proctorio in 2021; the Garante found several GDPR breaches at Bocconi, and its fine now stands at EUR 150,000 after court proceedings.
- AI Act: AI proctoring is a high-risk use under Annex III point 3(d), with deployer duties from 2 December 2027. Inferring emotions in education has been banned since 2 February 2025.
What "proctoring" covers
Proctoring is not one technology. The data protection analysis changes completely depending on which of these elements a university switches on:
| Element | What it does | Main data | Intrusiveness |
|---|---|---|---|
| Lockdown browser | Blocks other applications, tabs and copy-paste during the exam | Identifiers, technical events | Low |
| Live remote invigilation | A human watches webcam and screen in real time | Live video, audio, screen | Medium |
| Recorded review | Sessions are recorded and reviewed afterwards | Stored video, audio, screen, room scan | High |
| Automated flagging | Software analyses gaze, faces, sound, keystrokes and flags events | Recordings plus behavioural analysis | High |
| Automated identity check | Compares the candidate's face with an ID document or reference photo | Biometric data | High |
Write down which elements you use for which exams. Almost every question below depends on it.
Legal basis
Article 6(1)(e) GDPR allows processing necessary for a task carried out in the public interest, and Article 6(3) requires that basis to be laid down in Union or Member State law [1]. Running and examining courses is a statutory task for public universities in most Member States, so this is the natural basis for exam supervision. Article 6(1)(f), legitimate interests, does not apply to processing by public authorities in the performance of their tasks [1].
The CNIL's recommendation of 8 June 2023 reaches the same view: higher education institutions with a public-interest mission can rely on Article 6(1)(e); where no legal provision supports that, they may rely on contract (Article 6(1)(b)), provided the exam arrangements are set out in it and known to the student before enrolment [10]. The CNIL considers the other bases less suitable. Consent requires an in-person alternative with no negative consequences and must be withdrawable; legitimate interests implies a right to object that is hard to manage in an exam [10].
The Amsterdam Court of Appeal upheld the first-instance ruling that the University of Amsterdam's processing for Proctorio was grounded in Article 6(1)(e); on appeal it was not in dispute that the software was used to perform a public task, and the court found it necessary for that task [12]. The Garante went the other way on consent at Bocconi: it held that consent did not constitute the legal basis and could not be considered freely given, given the imbalance between students and the university, citing recital 43 [11]. Recital 43 says consent is unlikely to be freely given where there is a clear imbalance, in particular where the controller is a public authority [1].
Validemic's analysis For most public universities the sequence is: public task for the exam itself, a written decision that ties proctoring to the exam regulations, and a separate Article 9(2) exception if any element processes biometric data. Do not use a consent checkbox at the start of the exam to paper over a missing basis.
Biometric data and Article 9
Article 4(14) GDPR defines biometric data as personal data resulting from specific technical processing of physical, physiological or behavioural characteristics, which allow or confirm the unique identification of a person, "such as facial images" [1]. Article 9(1) prohibits processing biometric data "for the purpose of uniquely identifying a natural person" unless an exception applies [1]. Recital 51 adds that photographs are not systematically special category data; they are covered only when processed through specific technical means allowing unique identification or authentication [1].
That gives three distinct cases:
- Video recording reviewed by a human. Not biometric processing in itself. The Amsterdam court rejected the argument that images of an identifiable person, including a shown student card, are automatically special category data revealing race or religion [12].
- Face detection. Software that checks whether a face is present, or whether there are two faces, does not necessarily identify anyone. Vendors draw this line carefully; Respondus, for instance, says its temporary facial templates "are not used to identify an individual" but to confirm that the same person stays present, and acknowledges they may be biometric information under some laws [13].
- Automated identity verification. Comparing a face with an ID document or reference photo is biometric processing under Article 9. The CNIL says so expressly [10]. The Garante found that Bocconi processed students' biometric data through Respondus without a valid legal basis [11].
The CNIL sets cumulative conditions for automated identity checks: a single check before or during the exam; a very large number of candidates that makes manual checks difficult; an alternative always available, such as a supervisor comparing the ID in an individual video call; and advance notice where consent is the basis. The processing must rest on explicit consent (Article 9(2)(a)) with an alternative, or on substantial public interest under a specific legal text (Article 9(2)(g)) with human intervention available. It must never lead to a database of biometric templates at the institution or the vendor [10].
Behavioural signals deserve attention too. The Commission's guidelines on prohibited AI practices treat keystroke dynamics and eye tracking as behavioural biometrics in the AI Act sense [8]. Even where these signals do not identify anyone under the GDPR definition, they bring the system closer to the AI Act's biometric categories.
Necessity and proportionality
Article 5(1)(c) GDPR requires data to be adequate, relevant and limited to what is necessary [1]. The CNIL recommendation is the most detailed regulator guidance on what that means for exams [10]:
- Remote proctoring should not be a convenience that makes exams cheaper or easier to organise. Supervised exams on premises often remain the most appropriate way to prevent fraud.
- Taking an exam remotely should be an option for students, not an obligation. The CNIL recommends offering an in-person alternative systematically, with exceptions such as a health crisis or institutions built entirely on distance learning, where students must be told at enrolment.
- Remote proctoring does not need to match the effectiveness of in-room supervision.
- Proportionality depends on the stakes: stronger supervision may suit a competitive entrance exam, while a mock exam should be held without remote proctoring.
- For exams needing stronger supervision, the CNIL considers proportionate: live video and audio monitoring by a human, live screen sharing, a platform that detects or blocks other tabs, and a one-off camera check of the room, with the live monitoring, screen sharing and room check carried out without storage except where fraud is suspected.
- The CNIL recommends not using automated analysis of candidates' behaviour (such as typing rhythm, gaze direction or emotions), because of the high risk of false positives and the stress it causes. Automated detection of events in the environment, such as another person entering, may be used case by case for large cohorts if reliable and always followed by human review.
- Students should be told how to avoid incidental collection of data about family members and their home.
- Where fraud is suspected, data should not be kept beyond the deadlines for disciplinary or court proceedings, which the CNIL puts in principle at two months. Access logs should be kept, generally for six months to a year.
The CNIL also says a DPIA should be carried out before deploying remote proctoring, unless the system does not create high risks [10]. That matches the WP29 criteria, which include systematic monitoring, evaluation or scoring, sensitive data and innovative technology, with two criteria normally triggering a DPIA [17]. Our DPIA template guide includes a worked proctoring example.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Court rulings and DPA decisions
| Decision | Tool | Outcome |
|---|---|---|
| Gerechtshof Amsterdam, 1 June 2021, ECLI:NL:GHAMS:2021:1560 (summary proceedings) | Proctorio at the University of Amsterdam | Use allowed Public task basis; necessary in view of Covid-19 measures; collection not beyond the purpose; Article 8 ECHR respected |
| Garante per la protezione dei dati personali, provision no. 317 of 16 September 2021 | Respondus LockDown Browser and Respondus Monitor at Bocconi University | Breaches found Articles 5, 6, 9, 13, 25, 35, 44 and 46; fine now EUR 150,000 after court proceedings |
| CNIL, deliberation no. 2023-058 of 8 June 2023 | All remote proctoring in France | Recommendation Conditions for lawful and proportionate use |
Amsterdam Court of Appeal (2021)
Student councils sought to stop the University of Amsterdam from using Proctorio. The court held that the councils had no statutory right of approval (instemmingsrecht) over the decision, that the use of Proctorio met the GDPR's requirements, that it was necessary for the university's task in view of the Covid-19 measures, that collection did not go beyond what was necessary, and that it complied with Article 8 ECHR [12]. The judgment records that the university's board decided on 11 May 2020 to use online proctoring during the Covid-19 crisis for exams where no suitable alternative could be found, and that use outside those circumstances would require a new decision [12]. On automated flagging, the court noted that a visual check always followed and found no use beyond the purpose [12].
Validemic's analysis The ruling supports proctoring as a temporary, last-resort measure with human review. It does not support routine use when campus exams are possible, and it was given in summary proceedings.
Garante: Bocconi University (2021)
The Garante found that Bocconi processed students' biometric data and carried out automated processing to analyse aspects of their behaviour, amounting to profiling, without a suitable legal basis; gave incomplete information to students; breached data minimisation, storage limitation and data protection by design; transferred data to the United States without demonstrating compliance with Chapter V; and did not carry out an adequate DPIA [11]. It also noted that, although the system was not a fully automated decision under Article 22, the information to students did not explain the logic behind the alerts [11]. It ordered the university to stop processing biometric and profiling data through Respondus and to stop transfers to the United States without adequate safeguards [11]. The fine was originally EUR 200,000; a note on the Garante's page states it was reduced to EUR 150,000 following judgments of the Tribunale di Milano, the most recent in 2026 [11].
CNIL recommendation (2023)
The CNIL adopted its recommendation after observing the growth of remote exams since the pandemic, and noted that remote proctoring usually means monitoring a private device in a private room [10]. Its main conditions are summarised in the sections above. It is formally a recommendation, but it is the clearest statement by an EU data protection authority of what it considers proportionate.
Automated flags and Article 22
Article 22(1) gives a right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects [1]. A proctoring flag that leads to an automatic fail or exclusion would fall under it. Most vendors and universities therefore insist that a human reviews every flag.
Two points make that review harder than it looks. First, the WP29 guidelines on automated decision-making say human involvement must be meaningful, "rather than just a token gesture", and carried out by someone with the authority and competence to change the decision [18]. Second, the Court of Justice held in SCHUFA (C-634/21) that an automated score is itself an automated decision where a third party "draws strongly" on it to act [19]. The case concerned credit scoring, but the reasoning is a warning for any process in which examiners routinely confirm automated flags.
The CNIL's position is consistent with this: automated detection should only draw a supervisor's attention to a possibly abnormal situation, and a human check must always take place before any decision or change to the candidate's exam conditions. An exam should not be interrupted solely because an abnormal sound level was detected [10].
The EU AI Act
High-risk: Annex III point 3(d)
Annex III point 3(d) lists as high-risk "AI systems intended to be used for monitoring and detecting prohibited behaviour of students during tests in the context of or within educational and vocational training institutions at all levels" [2]. Under the amended Article 113, the high-risk rules apply to Annex III systems from 2 December 2027 [7].
Article 6(3) lets an Annex III system escape the high-risk label where it does not pose a significant risk of harm, for example because it performs a narrow procedural task or improves the result of a completed human activity. It never applies where the system performs profiling [4]. The Commission's draft examples place AI proctoring using facial recognition, keystroke analysis and screen monitoring, real-time behaviour analysis in online exams, and AI monitoring of in-person exams within point 3(d); they place plagiarism checking outside it, and suggest that an AI that only helps a human proctor confirm suspicious behaviour, or performs identity verification without deciding exam access, may be filtered out under Article 6(3) [9]. These examples are drafts.
If a system is high-risk, the university as deployer must, among other things, use it according to the instructions for use, assign human oversight to competent and trained staff, monitor it, keep logs "of at least six months", use the provider's information for its DPIA, and inform students that they are subject to a high-risk system (Article 26) [5]. Bodies governed by public law and private entities providing public services must also carry out a fundamental rights impact assessment before first use, which may cross-reference the DPIA (Article 27) [6].
Prohibited: emotion inference
Article 5(1)(f) prohibits the use of AI systems "to infer emotions of a natural person in the areas of workplace and education institutions", except for medical or safety reasons [3]. This has applied since 2 February 2025 [7]. The Commission's guidelines give an exam example: eye-tracking software that tracks gaze to detect unauthorised material is not prohibited, because it does not infer emotions, but if the system also detects emotions such as arousal and anxiousness, that falls within the prohibition [8]. The guidelines also say inferring emotions from keystrokes, facial expressions, body postures or movements is based on biometric data and within scope [8].
Validemic's analysis Ask every proctoring vendor, in writing, to confirm that no enabled feature infers stress, anxiety, nervousness or similar states. "Suspicious behaviour" scores built on facial expression need particular scrutiny.
Lockdown browsers versus AI proctoring
A lockdown browser restricts the device; AI proctoring watches the person. The CNIL notes that software preventing other applications or web pages from opening can have the advantage of collecting no additional personal data, as a form of privacy by design. It adds three conditions: the tool must not treat students unequally (for example by not working on some devices or operating systems), the vendor must not reuse the data, and it must not require elevated privileges or disabling antivirus protection. The CNIL also favours open-source solutions and easy uninstallation [10].
Vendor documentation reflects the difference. Respondus describes LockDown Browser as collecting identifiers, interaction and security data and education information such as course and exam name [14], while Respondus Monitor collects webcam videos, screen recordings and other data from the device and exam, and uses computer vision to generate event flags [13].
Validemic's analysis A lockdown browser on its own is unlikely to fall under Annex III point 3(d) unless it uses AI to detect behaviour, and it usually passes a GDPR proportionality test more easily. It does not stop a student from using a second device, which is why it is often combined with live invigilation or exam design that reduces the value of cheating.
What the main vendors document
Each vendor has its own fact sheet. In short, from the vendors' own pages:
- Proctorio: describes face and gaze detection rather than facial recognition, encryption so that only institution-approved staff can view recordings, and regional storage. See our Proctorio page.
- Respondus: describes itself as a processor for institutions; Monitor creates temporary facial templates on the student's computer that are cleared after the exam, and the computer vision "exclusively generates event flags and alerts" without making automated decisions; administrators can disable the facial feature [13]. See our Respondus page.
- WISEflow (UNIwise, Denmark): lists proctoring services and a device monitor as part of its assessment platform [16]. See our WISEflow page for hosting and facial comparison details.
- Inspera: offers the Inspera Integrity Browser and Inspera Proctoring, described as live or recorded remote monitoring with camera, microphone, screen recording and room scanning [15]. See our Inspera page.
Whatever the vendor, the configuration is the university's choice. The same product can run as a lockdown browser only or as full automated proctoring.
Alternatives to remote proctoring
The CNIL points out that some exam formats allow remote validation without proctoring, such as a thesis or a project defence, and others limit intrusiveness, such as oral exams, open-book exams or exams held in dedicated premises. It recommends preferring these where possible, and notes that exam design itself (question type, whether all candidates get the same questions, time per question) helps prevent fraud [10].
| Option | Privacy impact | Fits |
|---|---|---|
| On-campus digital exam with lockdown browser and human invigilators | Low | Most written exams |
| Open-book or take-home exam designed for it | Low | Analytical tasks, essays |
| Oral exam by video, or short oral follow-up | Low to medium | Smaller cohorts, verification of written work |
| Remote exam with live human invigilation, no recording | Medium | Distance programmes, students abroad |
| Recorded or AI proctoring | High | Exceptional cases, with DPIA and alternatives |
Checklist before the next exam period
- Decide per exam, not per platform. Record which proctoring elements are used for which exams and why lower-impact options are not enough.
- Fix the legal basis. Public task (or contract for private institutions), tied to exam regulations published before enrolment or the start of the year. No consent checkbox as the main basis.
- Offer an alternative. An in-person option or another format, with no disadvantage to the student, except in documented exceptional cases.
- Avoid biometrics by default. Use manual ID checks. If automated face comparison is used, meet the CNIL's conditions and identify the Article 9(2) exception.
- Switch off behavioural analysis. Gaze, typing rhythm and expression scoring carry the highest false-positive risk. Confirm nothing infers emotions (Article 5(1)(f) AI Act).
- Human review of every flag by a trained examiner who can and does disagree with the software; record outcomes.
- Retention: no storage of live sessions unless fraud is suspected; a short, documented period for suspected cases; access logs.
- Transparency: tell students in advance what is recorded, what is analysed, who sees it, how flags work and how to avoid capturing others at home.
- Accessibility: test with assistive technology, such as screen readers and text-to-speech; see our assistive technology guide.
- Vendor terms: DPA, subprocessors, storage region, transfers, no reuse of data for product development, and an AI Act classification statement.
- DPIA before first use, and plan the FRIA, logs, oversight and student information needed from 2 December 2027.
Sources
All sources retrieved 7 October 2026.
- Regulation (EU) 2016/679 (GDPR), Articles 4(14), 5, 6, 9 and 22 and recitals 43 and 51, text read from the Publications Office copy of the Official Journal.
- AI Act, Annex III: High-risk AI systems referred to in Article 6(2), AI Act Service Desk.
- AI Act (as amended), Article 5: Prohibited AI practices.
- AI Act (as amended), Article 6: Classification rules for high-risk AI systems.
- AI Act, Article 26: Obligations of deployers of high-risk AI systems.
- AI Act (as amended), Article 27: Fundamental rights impact assessment.
- AI Act (as amended by Regulation (EU) 2026/1744), Article 113: Entry into force and application.
- European Commission, Guidelines on prohibited AI practices, published 4 February 2025 and formally adopted as C(2025) 5052 on 29 July 2025, section 7 (emotion recognition) and behavioural biometrics.
- AI Act Service Desk, Draft guidelines summary: Education and vocational training (draft; see consultation page).
- CNIL, Délibération n° 2023-058 du 8 juin 2023 portant adoption d'une recommandation relative aux modalités de mise en œuvre des dispositifs de télésurveillance pour les examens en ligne; announcement: Télésurveillance des examens en ligne : la CNIL publie une recommandation.
- Garante per la protezione dei dati personali, Ordinanza ingiunzione nei confronti di Università Commerciale "Luigi Bocconi" di Milano, provvedimento n. 317 del 16 settembre 2021 (doc. web 9703988), including the note on the reduction of the fine.
- Gerechtshof Amsterdam, judgment of 1 June 2021, ECLI:NL:GHAMS:2021:1560, case 200.280.852/01, text read via the Rechtspraak open data service.
- Respondus, Additional privacy information: Respondus Monitor.
- Respondus, Additional privacy information: LockDown Browser.
- Inspera, Inspera Proctoring product page, and home page (Inspera Integrity Browser).
- UNIwise, home page (WISEflow modules).
- Article 29 Working Party, Guidelines on Data Protection Impact Assessment (WP248 rev.01).
- Article 29 Working Party, Guidelines on Automated individual decision-making and Profiling (WP251 rev.01).
- Court of Justice of the EU, Judgment of 7 December 2023, SCHUFA Holding (Scoring), C-634/21, operative part, text read from the Publications Office.
About this page
Sources checked on 7 October 2026. We read the GDPR and the Court of Justice judgments from the EU Publications Office, the AI Act through the Commission's AI Act Service Desk, the full text of the CNIL deliberation, the Garante's decision as published on its website (including its note on the reduced fine), and the Amsterdam judgment through the Dutch judiciary's open data service. The Commission's examples for Annex III are drafts. We mention only decisions we could read in an official source; other national decisions on proctoring exist and may point in different directions. Statements about vendors come from their own pages; our interpretation is labelled as Validemic's analysis. This page is not legal advice. If you see an error or know a decision we should add, please contact us and we will correct it.
Frequently asked questions
Is online proctoring legal under the GDPR?
It can be, but it depends on the set-up. The Amsterdam Court of Appeal accepted the University of Amsterdam's pandemic-era use of Proctorio in 2021, while the Italian Garante fined Bocconi University in the same year over its use of Respondus Monitor. The CNIL's 2023 recommendation sets out the conditions it considers proportionate. Each deployment needs its own necessity and proportionality assessment.
Can a university rely on student consent for proctoring?
Usually not. Recital 43 GDPR says consent is unlikely to be freely given where the controller is a public authority. The Garante held in the Bocconi case that consent was not a valid basis because of the imbalance between students and the university. The CNIL considers public task (Article 6(1)(e)) the appropriate basis for public institutions, or contract where exam arrangements are fixed in advance.
Is face detection in proctoring biometric data?
Not necessarily. Under Article 4(14) GDPR, data is biometric when specific technical processing allows or confirms the unique identification of a person. Detecting that a face is present is different from comparing a face against an ID photo. The CNIL treats automated comparison of an ID document with the candidate's face as biometric processing under Article 9.
Is AI proctoring high-risk under the EU AI Act?
Annex III point 3(d) lists AI systems intended to monitor and detect prohibited behaviour of students during tests as high-risk. The rules for Annex III systems apply from 2 December 2027 under the amended Article 113. Systems that infer emotions such as anxiety are already prohibited in education institutions under Article 5(1)(f).
Does a lockdown browser raise the same issues as AI proctoring?
Much less. A browser that only blocks other applications and websites collects little data beyond identifiers and technical events. The CNIL notes such tools can avoid any additional collection of personal data, provided they work on all students' devices, do not need excessive privileges, and the vendor does not reuse the data.
How long can proctoring recordings be kept?
The CNIL recommends live monitoring without storage except where fraud is suspected, and says that in a fraud case data should not be kept beyond the deadlines for disciplinary or court proceedings, which it puts in principle at two months. Your national rules on exam appeals may differ, so set a documented retention period.