Security and privacy

AI proctoring privacy: what candidates should know

What data AI proctoring actually collects, how long it's kept, and what questions candidates should ask before sitting a proctored test.

7 min read 11 September 2026
Share
Illustration of a shield with a keyhole at the centre, orbited by three nodes holding a camera, a microphone and a screen, with a clock node sitting outside the orbit

In short

AI proctoring privacy comes down to three things worth checking before you test: what's actually being collected, how long it's kept, and whether a human reviews anything flagged rather than an...

AI proctoring typically collects some combination of identity information, activity logs, and sometimes video or photos during a test session, which depends heavily on the platform, since "AI proctoring" covers everything from lightweight event logging to continuous video and audio monitoring. Candidates are right to want clear answers before sitting a proctored test: what's collected, how long it's kept, who can see it, and whether they have any say in the matter. This guide covers what to actually expect and what to ask. For the broader picture of how these systems work, see our complete guide to AI proctoring software.

What Data AI Proctoring Actually Collects

The range here is wide, and it matters because "AI proctoring" isn't one standardized thing. Depending on the platform, a proctored session might involve:

Four stacked data cards of decreasing width, each carrying one icon, with a thin bracket down the side gathering them together
  • Identity data

    - a photo ID, a live selfie compared against it, or a simpler email-based verification
  • Activity logs

    - tab switches, copy-paste actions, whether a second screen was detected
  • Photos or video

    - anything from a single identity photo to continuous webcam recording throughout the test
  • Audio

    - some systems record or analyze ambient sound for multiple voices or background conversation
  • Device and browser information

    - operating system, browser type, sometimes installed extensions

A candidate sitting a test with lightweight, rule-based monitoring will have a very different data footprint than one sitting a test with continuous video and audio analysis, even though both might be marketed under the same "AI proctoring" label. That distinction is worth understanding before assuming the worst, or the least, about what's being collected. Our guide on how AI proctoring detects cheating covers what specific signals feed into flagging decisions.

Why This Data Is Collected

The stated purpose across most platforms is the same: confirming the right person is taking the test, and detecting behavior that suggests the test conditions weren't followed. Identity checks address impersonation. Activity logs and photo checks address unauthorized help or unauthorized materials.

Whether the amount of data collected is proportionate to that purpose is a fair question to ask of any specific platform - continuous video and audio recording, for example, collects far more than most low-stakes screening tests plausibly need to answer those two questions.

How Long Is It Kept, and Who Sees It

This varies significantly by vendor and by the organization using the platform, and it's one of the more important things to ask about directly rather than assume.

A horizontal timeline with a capture icon at the start, a small eye icon partway along to show access, and a bin icon at the end where the line stops

A few questions worth getting clear answers to:

  • How long is the data retained after the test is complete?
  • Is it deleted automatically, or does it require a request?
  • Who has access - just the hiring team or exam administrator, or does the software vendor retain broader access too?
  • Is the data used for anything beyond the specific test it was collected for?

Reputable platforms are generally upfront about these answers, often in a privacy policy specific to the proctoring feature rather than a generic company-wide policy. If an organization can't or won't answer these clearly, that's worth treating as a signal in itself.

Most jurisdictions with meaningful data protection law require some form of clear consent before biometric or activity data is collected, along with disclosure of what's being collected and why. In the EU, this falls under GDPR. Several U.S. states have specific biometric privacy laws that apply when facial recognition or similar biometric matching is involved, separate from general data protection rules. California's privacy law (CCPA) also applies to personal data collected during proctoring for residents there.

The specific requirements, and what counts as adequate consent, vary by jurisdiction and by exactly what's collected, so this is worth treating as general orientation rather than legal advice. What's consistent across most frameworks is the underlying principle: candidates should be told clearly what's collected before it happens, not discover it after the fact.

Bias and Fairness Concerns With Facial Recognition

This concern applies specifically to systems doing continuous facial recognition or automated biometric matching, not every AI proctoring platform does this, and it's worth knowing which kind you're dealing with. Independent research and reporting have raised documented concerns that some facial recognition systems perform less accurately for certain skin tones and demographic groups, which can mean a higher false-flag rate for those candidates through no fault of their own.

This is a real limitation of that specific technology, not proctoring broadly. Platforms that rely on simpler checks, a photo captured for a human to visually confirm, rather than an algorithm making an automated match decision, sidestep this particular failure mode, though they trade off some of the scale advantage that automated matching provides. Knowing which model a platform uses is a reasonable thing to ask before testing.

Questions Candidates Should Ask Before a Proctored Test

A short list worth having answers to before you sit down:

  • What exactly is being recorded or logged during this test?
  • Is any of this continuous, or limited to specific checks at specific moments?
  • How long is the data kept, and can I request it be deleted?
  • Who reviews flagged sessions, and is there a way to explain a flag if I believe it's a false positive?
  • Do I need to install any software, or does this run in the browser?

A testing organization that can answer all five clearly and quickly is generally a good sign about how seriously they've thought through the privacy side of their process.

What to Expect If You're Flagged

Being flagged doesn't mean you've been found guilty of anything, it means an automated system noticed something worth a closer look, which happens for entirely innocent reasons more often than most candidates expect. A notification popup, a brief absence from frame, a shared network hiccup can all trigger the same kind of flag as something that actually matters. We cover this specifically in AI proctoring false positives, including what a fair review process should look like from the candidate's side.

The Bottom Line

AI proctoring privacy comes down to three things worth checking before you test: what's actually being collected, how long it's kept, and whether a human reviews anything flagged rather than an algorithm deciding alone. TunnelQuiz's approach stays on the lighter end of this spectrum deliberately, tab/focus alerts, second-screen detection, and periodic photo checks reviewed by a person, run entirely in the browser without requiring any software install.

Frequently asked questions

What personal data does AI proctoring collect?

It varies by platform, but commonly includes identity verification data (ID photo or email confirmation), activity logs (tab switches, second-screen detection), and sometimes photos, video, or audio. Lighter platforms collect only specific event logs; heavier ones may record continuously.

Is AI proctoring a privacy violation?

Not inherently, but it depends on whether the data collected is proportionate to the test's stakes, whether candidates were clearly told what's collected, and how the data is stored and used afterward. Excessive or undisclosed data collection is the actual concern, not automated monitoring itself.

Can I opt out of AI proctoring?

This depends entirely on the organization administering the test. Some offer alternative testing arrangements for candidates uncomfortable with monitoring; others require it as a condition of taking a particular exam. It's worth asking directly rather than assuming either way.

How long does AI proctoring data get stored?

Retention periods vary significantly by vendor and organization — anywhere from automatic deletion shortly after the test to longer retention for audit purposes. This is one of the most important questions to ask directly before testing, since it isn't standardized across the industry.

Does AI proctoring use facial recognition on everyone?

Not always. Some platforms use continuous facial recognition and biometric matching; others use simpler periodic photo checks reviewed by a person rather than matched automatically by an algorithm. These carry different privacy and bias implications, so it's worth knowing which one applies to a given test.

What should I do if I think a proctoring flag was unfair?

Ask what the review process is before you test, if possible, and request an explanation or appeal if you're flagged afterward. A platform or organization with a clear, human-reviewed process for handling flags is generally better positioned to treat a false flag fairly than one with an automated pass/fail rule.

Run exams you can actually stand behind.

Human review on every flag, transparent room-scan and lockdown policies, and a pilot-first rollout.

  • Free plan, 50 credits a month
  • Works in any browser
  • Proctoring on every attempt
  • Scored the moment they submit