RatedWithAI

RatedWithAI

Accessibility scanner

AI RegulationSeptember 11, 2026

The Exam Starts With a Face Scan Nobody Could Decline.

Remote proctoring verifies the candidate with a face template and then watches the face for two hours. Under Illinois BIPA that is a biometric identifier, collected under conditions where refusal means forfeiting the exam — and the consent screen almost never contains the three elements Section 15(b) requires.

15(b)
Written notice of collection, written notice of purpose and term, and an executed release
3 Years
Outer retention limit — or when the purpose is satisfied, whichever comes first
Two Holders
The institution and the proctoring vendor are both in possession of the templates

What the Software Actually Collects

A remote proctoring session usually contains four distinct data operations, and they have different legal characters. Institutions procure them as one product and therefore analyse them as one thing, which is where the risk gets buried.

  1. Identity match at launch. The candidate holds an ID card to the camera and the system compares the face on the card to the live face. This derives face geometry from both images. This is the clearest biometric identifier in the flow.
  2. Continuous presence monitoring. The system checks throughout the sitting that the same face is present and alone. Whether this is biometric depends on implementation — a template match is; a generic person-in-frame detector may not be — and the vendor documentation frequently does not say which is running.
  3. Behavioural flags. Gaze direction, head pose, and background audio produce integrity flags. These are not biometric identifiers in the BIPA sense, but they are the part that generates accusations against candidates and therefore the part that gets litigated on other grounds.
  4. Session recording. Video and screen capture retained for review. A recording is a photograph-adjacent artefact, but templates derived from it are not excluded — and the recording is what makes later template derivation possible.

The operative question for BIPA is never "does it use a camera." It is whether a scan of face geometry is generated. Ask the vendor, in writing, at which of those four steps a template is produced, where it is stored, and whether it is deleted when the session ends. The answers belong in the procurement file, and a vendor that answers with "we use industry-standard facial recognition" has not answered.

Consent Under Conditions of No Alternative

Section 15(b) is procedural and its elements are easy to check against a screenshot. The subject must be informed in writing that a biometric identifier is being collected or stored. The subject must be informed in writing of the specific purpose and the length of term for which it is being collected, stored, and used. And the subject — or a legally authorized representative — must execute a written release.

Proctoring consent screens fail most often on the second element, because the institution genuinely does not know the retention period. It is set by the vendor, sometimes per-tier, sometimes changed in a release note. A consent screen that says data is kept "as long as necessary" has informed the candidate of nothing and executed a release against an unstated term.

The third element has a further problem specific to exams. A release obtained at the moment the candidate would otherwise forfeit a sitting they paid for and prepared months for is not a comfortable record to hold. The mitigation is timing and alternatives: disclose at registration rather than at launch, and offer a non-biometric verification route that a candidate can take without penalty. The same pattern that makes biometric time clocks a litigation magnet in employment is present here in a sharper form.

Two Entities, One Template

BIPA's duties attach to the private entity in possession of the identifier. In a proctoring deployment the vendor is plainly in possession. Whether the institution is depends on architecture — whether templates or only results come back — and institutions routinely do not know the answer because it was never asked during procurement.

Section 15(d) adds a second exposure: an entity in possession may not disclose or disseminate a biometric identifier without consent. Sending candidate images to a proctoring vendor is a disclosure. Sending flagged sessions onward to a certifying body, an academic integrity office, or an external reviewer is another. Each hop needs to be inside the scope of what the release said.

Contractually, the two clauses worth more than the discount are a retention commitment with a fixed number in it, and an indemnity that actually covers statutory privacy claims rather than excluding them. The vendor-liability allocation in most SaaS paper was written for data breaches, and a BIPA claim is not a breach claim.

The Retention Schedule You Have To Publish

Section 15(a) requires a written retention and destruction policy, made available to the public, and destruction when the initial purpose is satisfied or within three years of the individual's last interaction, whichever occurs first. For proctoring there is a clean answer to "initial purpose satisfied": the result is final and the integrity appeal window has closed.

A defensible proctoring schedule

  • Identity templates: destroyed at session end; never persisted beyond the match.
  • Session recordings: retained only until the result is final plus the appeal window, stated as a number of days.
  • Flagged sessions: retained for the duration of the integrity proceeding, then destroyed on a scheduled job rather than by request.
  • Aggregate integrity statistics: permitted, provided they carry no identifier and no template.
  • Destruction evidence: a log showing the job ran, because the obligation is to destroy, not to intend to.

Compare that list against what the vendor's data retention page actually says. Where the vendor's default exceeds your published policy, your published policy is the one candidates relied on, and the gap is the finding.

Frequently Asked Questions

We are a university outside Illinois. Does BIPA reach us?

Remote exams are taken wherever the candidate is sitting, and a candidate in Illinois is where the collection happens. Institutions with any distance-learning or national certification population should assume Illinois test-takers are present unless they actively exclude them, which almost nobody does. The same logic is why national employers with remote workers ended up inside BIPA without operating in the state.

The vendor says the template is deleted immediately. Is that the end of it?

It is most of the answer for 15(a), and none of the answer for 15(b). Consent obligations attach at collection, so a template that exists for four seconds was still collected from a person who needed to be informed in writing and to execute a release. Immediate deletion is an excellent control and not a defence to the notice requirements.

Can we rely on the vendor's consent screen instead of our own?

You can present it, but the institution is the party with the relationship to the candidate and cannot outsource the adequacy of the disclosure. Read the vendor screen against the three elements yourself. If it omits the length of term — the common failure — ask the vendor for the number and add it, rather than assuming their legal team checked.

What about proctoring for employment tests rather than academic exams?

The BIPA analysis is the same, and a second layer applies: a selection procedure that produces integrity flags used in a hiring decision is also an automated decision tool for purposes of algorithmic hiring rules, with its own notice and validation expectations. The overlap is covered in our piece on AI hiring assessment and proctoring bias.

Are other states' biometric laws a concern too?

Texas and Washington impose biometric duties without a private right of action, enforced by the attorney general, and a growing set of comprehensive state privacy laws treat biometric data as sensitive with consent or limit-use requirements attached. BIPA drives the litigation risk because of the private right of action and per-violation damages; the others drive the compliance baseline.

Screenshot the Launch Flow First

Before reading a single contract, have someone take the exam launch flow end to end and capture every screen. Then check three things against the captures: is collection stated in writing, is the purpose and the length of term stated in writing, and is there an affirmative release distinct from accepting terms of service.

Most institutions find the answer is no, no, and partially — and they find it in twenty minutes, long before anyone has to schedule a meeting about it.