• Services
  • Who We Help
  • Resources
  • AboutStart a Conversation

    Article

    AI Proctoring, Biometric Data, and Privacy Risk in Credentialing Exams

    AI proctoring raises privacy, biometric data, accessibility, and exam fairness risks. Explore the decisions credentialing leaders need to evaluate.

    By Dan Liutikas · June 15, 2025 · 7 min read

    Updated October 6, 2026

    AI proctoring can expand access to credentialing exams and help identify conduct that threatens their integrity. It can also collect intimate information about candidates, create disputed misconduct findings, and make a credentialing organization dependent on decisions it does not fully understand. The legal risk turns on what the system actually does, which laws apply, and how the organization uses its output.

    Buying a platform with a privacy policy does not settle those questions. Neither does obtaining a candidate’s acceptance of examination terms. The organization still needs a defensible relationship between its exam-security objective, the information collected, the consequences for candidates, and the responsibilities its vendor accepts. Those connections matter most when a candidate challenges a result or a regulator asks why a particular data practice was necessary.

    Not every recording is biometric data

    A recorded exam session, a facial photograph, an identity document, and a mathematical template used to recognize a face are different things. A platform may collect several of them during the same session. Whether a particular practice involves regulated biometric information depends on the technology and the applicable legal definition, not simply on whether the vendor markets its product as artificial intelligence.

    Illinois’s Biometric Information Privacy Act, or BIPA, illustrates the distinction. Its definition of biometric identifiers includes scans of face geometry and voiceprints, while excluding photographs. A photograph’s exclusion does not answer whether subsequent processing creates a covered identifier. Leaders need an intelligible explanation of identification, authentication, gaze analysis, voice analysis, and the data retained at each stage.

    This distinction has a practical consequence for procurement. A representation that a vendor does not sell biometric data says little about whether it collects such data, shares it with service providers, uses it for product development, or retains it after the exam. Each of those activities can present a different legal and contractual issue.

    Jurisdiction changes the analysis

    BIPA imposes requirements on covered private entities concerning notice, written release, retention, disclosure, and security, and provides a private right of action. Its application to a particular examination program requires attention to the parties, the conduct, and the relevant connections to Illinois. A national candidate population warrants analysis; a candidate’s address alone is not a complete jurisdictional conclusion.

    Other jurisdictions have their own biometric, consumer privacy, employment, and data-security rules. Their definitions, exemptions, enforcement mechanisms, and required permissions differ. An organization’s nonprofit status does not provide a universal exemption. Nor does one national consent form establish compliance with every law that could apply to a distributed testing program.

    For programs with European connections, the EU General Data Protection Regulation raises another set of questions. Its territorial scope is not simply a test of citizenship. Where it applies, biometric processing for the purpose of uniquely identifying a person can engage Article 9’s special-category protections in addition to the ordinary lawful-basis requirements. Explicit consent is one possible condition, not a universal answer to every processing activity.

    The consequence for leadership is a design decision: whether the same technology, settings, and candidate experience can appropriately serve the entire program. Geographic variation, alternative verification methods, and vendor restrictions may affect the economics of the arrangement before any examination is delivered.

    Consent cannot carry the entire privacy program

    Meaningful notice depends on knowing what happens to candidate information. A broad reference to security purposes can obscure materially different uses, such as authenticating a candidate, investigating suspected misconduct, training a model, or evaluating the vendor’s product. A use that is commercially attractive to a vendor may not be necessary to administer the credential.

    Consent also has limits. Its validity and availability depend on the governing law, the information presented, and the candidate’s circumstances. A candidate who must pass an exam to continue working may have little practical bargaining power. A required checkbox should not be treated as proof that all subsequent processing is lawful or that every contractual waiver will be enforceable.

    Retention creates a related tension. The program may need evidence for an appeal, an investigation, or a legal preservation obligation. That does not justify keeping every recording indefinitely. Different records can warrant different retention periods, and contractual deletion promises need to account for copies, subprocessors, backups, and legitimate holds. A defensible position connects the retention decision to a defined purpose and applicable obligations.

    An automated flag is evidence to evaluate

    Unusual movement, a change in lighting, or a background sound may trigger a platform’s alert. The alert is not itself a finding of cheating. Its meaning depends on system limitations, the surrounding facts, the exam rules, and the quality of the available evidence. Overstating what the technology proves can turn a manageable review into a credibility problem for the credentialing program.

    Consequences should therefore be considered alongside system design. Does a flag interrupt an exam, invalidate a score, delay certification, or begin a disciplinary process? Can a reviewer understand the basis for it? Is relevant evidence available if the candidate disputes the outcome? A vendor’s proprietary scoring model may complicate the organization’s ability to explain and defend its own decision.

    The organization also needs an appropriate separation between initial review and appeal. That does not mean every program must adopt the same committee structure. It means the governing rules, reviewer independence, conflicts, and promised procedures should support a credible decision. Consistent treatment requires enough judgment to distinguish genuinely different circumstances, rather than automatic reliance on identical machine-generated labels.

    Accessibility and security must work together

    Remote testing can improve access for some candidates while creating barriers for others. Assistive technology, disability-related movement, breaks, or an accommodation may conflict with the platform’s default monitoring assumptions. A system can be commercially convenient and still be unsuitable for an examination program’s legal obligations or candidate population.

    The ADA’s examination requirements and applicable accommodation rules deserve attention before the organization commits to a platform. The relevant inquiry includes the testing experience, available alternatives, the treatment of accommodation information, and whether security decisions unfairly penalize approved arrangements. Accommodation records can themselves reveal sensitive information and should not become general-purpose material for proctors or product development.

    Technical performance also affects defensibility. A dropped connection, incompatible device, or unavailable alternative can create a result that appears to concern competence but actually reflects the testing environment. Candidate communications and review procedures need to recognize the difference without undermining legitimate exam-security controls.

    The vendor contract should support the program’s decisions

    A vendor’s security certification or marketing assurance does not allocate responsibility for a disputed exam. The commercial agreement needs to address the services actually purchased, the parties’ data roles, approved uses, subcontractors, incident cooperation, evidence access, and the ability to change or discontinue the service. An organization should understand where those commitments stop.

    Liability provisions matter in combination. A biometric claim may involve the vendor’s technology, the organization’s notice, and both parties’ conduct. Indemnities, exclusions, liability caps, insurance, and control of the defense can produce very different outcomes depending on how the contract defines the claim. A promise to comply with law is more useful when the agreement also supports the information and cooperation needed to do so.

    Exit rights deserve the same attention as launch. A credentialing program may need to preserve relevant evidence while migrating away from a provider that stores identity data and historical exam sessions. Access, portability, deletion, transition assistance, and ongoing candidate disputes can create dependencies long after the subscription ends. These issues fit within the broader technology, AI, and data risk framework.

    The opportunity is a more credible credential

    Well-governed proctoring can support wider access, stronger exam integrity, and more consistent administration. Those benefits depend on aligning privacy, accessibility, security, and decision-making authority around the credential’s purpose. The goal is a program that can explain both why it uses the technology and why a particular result deserves confidence.

    Org Law advises credentialing organizations on the governance, contracts, data practices, and disputes that shape these decisions. For the broader program, see running a legally defensible credentialing program. Contact Org Law to discuss the legal implications of a proctoring arrangement or a planned change in examination delivery.

    Legal sources and context

    Relevant primary sources include the Illinois Biometric Information Privacy Act, the GDPR, and the Department of Justice’s testing-accommodation guidance. This article provides general information; application depends on the program, technology, jurisdiction, and current law.

    ORG LAW

    Talk with an attorney.

    Tell us what you need help with. We will follow up within one business day.

    Start a conversation