Every OSCE station, MMI interview, MCQ exam, or ePortfolio submission run through a digital assessment platform generates something far more sensitive than a score. It generates personal and, often, special category data – video recordings, performance histories, and health-related competency records that can shape a candidate’s professional future.
Protecting that data means treating cybersecurity and GDPR compliance as core assessment infrastructure, not afterthoughts. Our previous blog on Safe Exam Browser, you’ll know that exam security is increasingly a layered discipline. The same is true of data protection: it has to be built into the platform, not bolted on afterwards.
Why Assessment Data Is a Special Category of Risk
Digital assessment platforms sit at an unusual intersection of data sensitivity:
- Special category data. OSCE and MMI stations often touch on health information, disability accommodations, and, in proctored exams, biometric-adjacent signals such as facial video or gaze tracking.
- High-stakes decisioning. Assessment outcomes feed licensing, progression, and certification decisions, so errors or breaches carry professional consequences for candidates, not just reputational risk for institutions.
- Long retention windows. Accreditation bodies frequently require multi-year retention of assessment evidence, extending the period during which data must stay protected.
This risk profile is why Qpercom treats data governance as core assessment infrastructure, not an add-on.
GDPR: The Legal Backbone
For candidate data connected to the EU or UK, GDPR sets the baseline. A few principles shape how Qpercom’s platform is built and operated:
Data Minimisation
Proctoring and monitoring features are designed to collect only what supports exam integrity or accessibility, nothing more.
Lawful Basis and Transparency
Candidates are told, before they sit an assessment, what’s collected, why, how long it’s kept, and who can access it.
Data Protection Impact Assessments (DPIAs)
Proctoring and any AI-assisted marking features are assessed for risk before deployment, not after.
EU-based Hosting and Processor Agreements
Institutions know exactly where candidate data lives and have clear Data Processing Agreements covering every sub-processor.
Rights to Access and Erasure
Candidates can exercise these rights through defined workflows that don’t compromise the audit trails accreditation bodies require.
Where the EU AI Act Now Overlaps with GDPR
Assessment platforms using AI for automated scoring, anomaly detection, or adaptive testing; now sit inside a second regulatory framework layered on top of GDPR. Under the EU AI Act, AI systems used to evaluate learning outcomes or score people in educational or professional contexts are classified as high-risk under Annex III – the EU AI Act’s list of high-stakes use cases. That status brings specific obligations: documented human oversight, technical documentation, transparency to candidates, and registration in the EU AI database.
Since February 2025, AI systems that infer emotion or analyse facial expressions or stress signals during proctoring have been prohibited outright. Qpercom’s proctoring capability is built to stay clear of this category entirely – verifying exam conditions and candidate identity without emotion or stress inference.
Security Controls Behind the Platform
Certifications provide the governance backbone. Qpercom is ISO 27001:2022 certified and hosted on AWS infrastructure. However, the controls that matter day-to-day for candidates and institutions include:
- Encryption in transit and at rest for all recordings, responses, and personal data.
- Role-based access control, so examiners, administrators, and IT staff see only what their role requires.
- Audit logging that records who accessed what and when.
- Secure exam delivery infrastructure, including protections against unauthorised access during live proctored sessions.
- Incident response processes aligned to the 72-hour GDPR breach-notification requirement.
- AI assistance is optional but it can help with the heavy lifting, but humans remain the decision-makers.
Enhancing Institutional Confidence Through Transparent Governance
Security and compliance measures are most effective when they strengthen trust as well as protect data. Institutions are more likely to trust an assessment platform when data handling is clearly documented, retention rules are consistent, and the vendor’s compliance posture is transparent rather than asserted.
Qpercom is not ISO 42001 certified yet, but it’s on our radar. As AI-assisted features expand across the platform, it’s a certification worth revisiting to strengthen our AI governance stance further.
What Institutions Should Ask Before They Sign
For procurement teams and assessment leads evaluating a digital assessment platform, a short due-diligence list:
- Where is candidate data hosted, and is there a signed Data Processing Agreement?
- What and how deep is AI being used in the scoring and proctoring of assessment data? Is there “human in the loop” oversight?
- Has a DPIA been completed for AI-assisted scoring or proctoring features?
- Does the proctoring solution avoid emotion, facial-expression, or stress-signal inference?
- What’s the data retention policy, and how are erasure requests handled without breaking required audit trails?
- What certifications back up the vendor’s claims – ISO 27001, Cyber Essentials, and increasingly ISO 42001?
Frequently Asked Questions
Is Qpercom’s platform GDPR compliant?
Yes. Qpercom uses EU-based hosting options, signed Data Processing Agreements, data minimisation by design, and defined workflows for candidate access and erasure requests, all aligned to GDPR requirements.
Does Qpercom’s proctoring use emotion or stress detection?
No. Qpercom’s proctoring verifies exam conditions and candidate identity without inferring emotion, facial expression, or stress signals. This is a category of AI use prohibited under the EU AI Act since February 2025.
What security certifications does Qpercom hold?
Qpercom is ISO 27001:2022 certified and hosted on AWS infrastructure. ISO 42001, the AI management systems standard, is being monitored as a future step as AI-assisted features expand.
The Future of Trusted Digital Assessment
Digital assessment platforms will keep adding AI-assisted features and that trend isn’t reversing. The institutions and vendors who treat GDPR and the EU AI Act as design constraints from the start, rather than retrofits, are the ones candidates and accreditation bodies will trust with their most sensitive data. At Qpercom, security and compliance aren’t separate from assessment quality, they’re part of it.
Curious how Qpercom’s platform handles this in practice? Get in touch or book a demo to see it for yourself.




























