Introduction
Proctor Pro Europe, including its regional operating entities and European examination test centers (hereafter collectively referred to as the “Company”, “us”, “our” or “we”), may act as a data controller or as a data processor depending on its relationship to you, the Data Subject.
This Privacy Policy (hereafter, “Policy”) describes our collection and processing of Personal Data concerning examination candidates, academic and institutional clients, invigilators, contractors, and test delivery partners (hereafter, “Data Subjects”, “you” or “your”).
The Company strictly adheres to all data protection laws and statutory regulations across the European territories where the Company operates facilities, primarily including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (“GDPR”); the UK General Data Protection Regulation and Data Protection Act 2018; the Swiss Federal Act on Data Protection (“FADP”); and other applicable regional data protection statutes governing in-person test administration.
As an organization committed to European data sovereignty, all core candidate processing and storage operations are hosted within the European Economic Area (EEA), the United Kingdom, and Switzerland. Where international frameworks apply, the Company complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) with respect to candidate cross-border transfers and the rights of EU, UK, and Swiss Data Subjects.
Unless otherwise noted, the following definitions apply to this Policy:
“Applicable Law” refers to the relevant member state, national, or regional data protection law or statutory regulation relating to data privacy and security.
“Personal Data” means any information relating to an identified or identifiable natural person (“Data Subject”).
“Processing” means any operation or set of operations performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, physical or digital storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or secure destruction.
“Supervisory Authority” or “Supervisory Authorities” means an independent national Data Protection Authority or Authorities established by a European or national government body and responsible for monitoring and enforcing data protection laws and regulations within a given jurisdiction.
What types of Personal Data do we collect?
The Company may collect the following Personal Data depending on your relationship to the Company, the operational requirements of your examination sponsor, the services rendered, and Applicable Law:
Contact information including legal name, postal address, telephone contact numbers, national registration numbers, institutional email addresses, and testing account credentials
Date of birth
Country of birth
Gender
Academic enrollment or institutional registration dates
Primary language
Preferred communication language
Parent or legal guardian contact details (for minor test-takers)
Candidate examination appointment reservations, time slots, and test venue scheduling records
Assessment details, including candidate registration ID, examinations taken, test dates, official scores, delivery status, and historical session logs
Examination floor incident reports, irregularities, and invigilator walk-through observations
On-site security interventions and rule enforcement notices
In-person attendance and workstation sign-in logs
Assessment submission outputs and answer payloads
Identification numbers where mandated by licensing authorities or institutional test sponsors
Billing records, institutional invoicing data, and payment verification details
Country of residence and legal nationality
Identification photographs captured at reception desks
Physical signatures captured on digital signature pads or paper intake rosters
Audio recordings (only where explicitly authorized by Applicable Law and required by specific examination rules)
Scanned documentation from official identification credentials, such as passports, national identity cards, or residency permits
Transaction and operational audit data, including check-in timestamps, assigned testing carrels, workstation telemetry, and browser lockdown logs
Candidate reservation codes, institutional vouchers, and appointment booking references
In addition, the Company may process special categories of Personal Data, strictly as permitted under Article 9 of the GDPR and Applicable Law, which may include:
Biometric identifiers (such as automated facial feature matching against verified government-issued identification cards during check-in)
Medical records, physician notes, or disability disclosures submitted directly to facilitate physical or technical exam room accommodations
Relevant demographic data only when expressly mandated by statutory authorities or examination sponsors under strict legal safeguards
The Company will never process special categories of Personal Data for purposes other than the specific assessment verification or accessibility requirements for which it was originally collected, unless explicit, affirmative opt-in consent has been provided.
Our in-person test administration protocols require reception staff to inspect and scan valid identification documents, collect signatures, and capture an on-site photo for identity verification before admitting candidates into the testing hall.
Personal Data of Minors
The Company does not knowingly register or admit candidates considered minors under Applicable Law without verified consent from a parent, legal guardian, or sponsoring academic institution. Parents and legal guardians are expected to oversee the registration and appointment scheduling process.
When administering assessments for secondary schools or universities, the Company acts under the direct instructions of the educational institution. Nothing in this Policy limits the statutory rights of students or parents regarding their educational records. The Company will never utilize student or minor personal data for promotional marketing, behavioral profiling, or advertising purposes.
The Company minimizes account information received from educational institutions to the basic elements required for identity validation and room assignment, typically comprising full name, student ID, institutional email address, and examination code. Student responses generated during the examination remain strictly confidential between the candidate, the testing center, and the sponsoring institution.
Parental Rights
The Company enables parents and legal guardians of minors who test at our facilities to exercise all legal rights established under European data privacy legislation.
Parents seeking details regarding their child’s testing records may reach out through the sponsoring educational body or contact our data protection team directly. Sponsoring schools maintain the authority to request data deletion or withdraw consent for data handling, consistent with examination governance standards.
How do we collect your Personal Data?
The Company gathers Personal Data directly from you when you register an appointment, contact our telephone scheduling desk, check in at a testing facility reception desk, or complete an assessment at a testing carrel. In other instances, your data is provided directly to us by your university, professional licensing board, employer, or examination sponsor.
All data transmitted through our web portals or collected on physical premises is maintained under this Policy. Telephone communications with our scheduling desk may include the collection of contact coordinates and appointment parameters to fulfill your booking request.
Use of Cookies
When using our web portal to locate European testing hubs or check appointment schedules, we use cookies and tracking tools to evaluate system stability, user navigation, browser compatibility, and access timestamps. These tools help us optimize portal performance and venue navigation maps.
Where required by European law, non-essential cookies and analytics are deployed only following your explicit consent via our cookie consent banner. You may configure or withdraw your preferences at any time through your browser settings.
Our portal may provide links to external partner institutions, testing organizations, or transit portals. The Company maintains no control or liability over third-party digital environments, and Data Subjects are encouraged to review the distinct privacy statements of any external sites visited.
Collection of Biometric Data
Biometric intake protocols deployed at Proctor Pro test centers confirm candidate identity while maintaining data privacy. During reception intake, an on-site camera captures a reference image to verify facial characteristics against the candidate's government-issued ID card. This ensures that the individual entering the secure examination room matches the registered examinee.
Use of Artificial Intelligence (AI)
The Company utilizes automated decision-support technologies and computer-vision integrity tools to support fraud prevention across testing suites. These technologies include automated ID validation, anomaly detection across testing hardware, and environmental monitoring for prohibited physical materials.
These systems serve to support and enhance—not replace—human supervision. Certified on-site invigilators directly verify any potential anomaly or rule infraction flagged by automated systems before any operational determination is made regarding a candidate’s examination session.
The Company deploys automated technologies in full alignment with the European Union AI Act, the General Data Protection Regulation (GDPR), and related regional frameworks governing transparency and algorithmic accountability.
Why do we collect your Personal Data?
The Company processes Personal Data for the following purposes:
Managing institutional service agreements with universities and examination sponsors
Scheduling and confirming test appointments across our European testing centers
Verifying candidate identity upon arrival at testing venues
Administering examination sessions and recording attendance
Preventing examination fraud, impersonation, and unauthorized access to test materials
Maintaining physical and digital audit logs to guarantee assessment validity
Delivering examination outcomes, answer files, and incident logs to candidates and sponsors
Sending essential operational updates regarding appointment confirmations, center closures, or technical requirements
Upholding legal obligations, facility safety standards, and enforcing testing room conduct rules
Conducting staff training, quality audits, and center performance reviews
Optimizing center scheduling capacity and website functionality
Maintaining and testing facility hardware, lockdown software, and integrity monitoring tools
Validating institutional fee vouchers and test authorization codes
For vendors, service contractors, and facility partners, we process Personal Data for:
Managing vendor contracts and commercial arrangements
Coordinating facility logistics and on-site support
Invoicing, settlement, and financial record-keeping
Fulfilling statutory due diligence, corporate governance, and regulatory requirements
Personal Data is accessed strictly by authorized Proctor Pro personnel, invigilators, and vetted technical processors bound by strict professional confidentiality obligations. The Company does not sell, rent, or lease candidate Personal Data to any commercial third party.
Purpose of Biometric Data Collection
Biometric information collected at our check-in desks is processed exclusively to: (1) authenticate candidate identity prior to entering secure examination rooms; (2) eliminate candidate substitution and impersonation fraud; (3) safeguard the legal validity of professional qualifications; and (4) comply with accreditation standards required by licensing bodies.
If Personal Data is ever required for an operational purpose fundamentally distinct from the purposes outlined in this Policy, advance notification and an explicit opportunity to consent or object will be provided.
What are the legal bases of processing your Personal Data?
Personal Data is processed under the following legal frameworks established by the GDPR and European data regulations:
Performance of a contract: Processing required to schedule, seat, and administer examinations requested by the candidate or by an institution on the candidate’s behalf.
Explicit consent: Processing of special category data, including biometric facial matching or documented medical accommodation records, obtained during intake.
Legal obligation: Processing necessary to comply with European accounting regulations, court orders, statutory anti-fraud mandates, and health and safety requirements.
Legitimate interests: Processing necessary to ensure testing venue physical security, preserve academic and certification integrity, manage center operational capacity, maintain continuity through data backups, and prevent testing irregularities, balanced against individual candidate rights.
Disclosure of Personal Data
Authorized third parties who may receive or access your Personal Data include the examination sponsor (the university, board, or organization commissioning your test), affiliated European testing operations, and essential technical vendors who provide cloud hosting, security monitoring, and hardware support within the European Economic Area.
Public authorities and law enforcement bodies may only obtain access to candidate data where compelled under formal statutory mandates, judicial orders, or binding European legal processes.
Biometric records are held under strict confidentiality and are disclosed to examination sponsors or regulatory bodies solely in formal investigations involving confirmed candidate impersonation, criminal fraud, or serious breaches of examination integrity.
All external service providers operate under formal Data Processing Agreements (DPAs) incorporating technical and organizational safeguards aligned with the GDPR. Where data transfers involve external entities outside the European Economic Area, the Company applies European Commission Standard Contractual Clauses (SCCs) and Data Privacy Framework guarantees.
For how long do we store your Personal Data?
The Company maintains a formal European Data Retention Schedule governing the lifecycle of all testing documentation, digital session telemetry, and surveillance records.
Subject to specific examination sponsor contracts and national legislation, general candidate records and testing logs are retained for the shortest applicable period among the following:
five (5) years following the completion of your test appointment; or
the contractual lifecycle defined by the awarding body or university sponsor; or
the statutory retention requirement established by the European jurisdiction where the center is situated.
Records are permanently purged once retention periods elapse, unless retention is required to resolve an active dispute, misconduct appeal, or regulatory inquiry.
Storing of Biometric Data
Biometric intake scans collected at testing center reception stations are transferred via encrypted tunnels to high-security servers hosted within the European Economic Area (Frankfurt and Dublin regions). In accordance with European data minimization principles, biometric facial template files are purged within thirty (30) days of appointment completion, unless a longer retention schedule is required by an examination sponsor or active integrity investigation. CCTV security footage recorded inside center halls is maintained on a rolling 30-day loop before automatic overwriting.
Cross-border transfers of Personal Data
Proctor Pro operates primarily across the European Economic Area, the United Kingdom, and Switzerland, utilizing regional server architecture to keep candidate files within European borders.
In situations where an examination sponsor is located internationally, or where technical support involves infrastructure outside the EEA, transfers occur strictly under valid legal transfer mechanisms, including:
Standard Contractual Clauses (SCCs) approved by the European Commission
Adequacy decisions adopted by the European Commission
Binding Corporate Rules or adherence to the EU-U.S. Data Privacy Framework, UK Extension, and Swiss-U.S. Data Privacy Framework
The Company performs Data Transfer Impact Assessments (DTIAs) to ensure third-country recipients implement security safeguards equivalent to those established within the European Union.
What are your rights?
Under Chapter III of the General Data Protection Regulation and relevant European statutes, Data Subjects possess the following enforceable rights:
Right of access: The right to request confirmation of and access to your Personal Data held by the Company.
Right to rectification: The right to obtain correction of incomplete or inaccurate records.
Right to erasure (“Right to be forgotten”): The right to request deletion of your Personal Data where retention is no longer legally required.
Right to restriction of processing: The right to limit the processing of your information under specific statutory circumstances.
Right to data portability: The right to obtain a structured, machine-readable export of data provided to us.
Right to object: The right to object to processing grounded on legitimate interests.
Right to withdraw consent: The right to revoke previously granted consent at any time without impacting prior lawful processing.
To exercise these rights, submit a written inquiry to our European Privacy Office as detailed under “How to Contact Us.” Identity verification will be required before fulfilling requests. Where requests cannot be completed due to regulatory examination retention rules or institutional sponsorship constraints, a formal explanation will be issued in writing.
You retain the right to lodge a formal complaint with the relevant national Supervisory Authority in the European Union member state of your habitual residence, place of work, or location of the alleged infringement.
How do we protect your Personal Data?
The Company enforces multi-layered technical, organizational, and physical safeguards across all European testing centers and cloud infrastructure. Protections include end-to-end TLS encryption for transmitted data, AES-256 storage encryption, perimeter access control badges, locked individual candidate storage lockers, and continuous physical invigilator monitoring.
If a Personal Data Breach occurs that presents a risk to candidate rights, the Company initiates its Incident Response Protocol, notifying the competent European Supervisory Authority within seventy-two (72) hours of discovery, alongside direct communication to affected Data Subjects where legally required.
Security architectures and center controls undergo independent third-party audits annually to verify compliance with ISO/IEC 27001 and GDPR data protection principles.
For assessments administered within specific European jurisdictions or international partner frameworks, localized statutory protections govern processing alongside this general Policy.
Candidate intake and workstation supervision adhere to:
Direct supervision guidelines established by national education ministries
Specific national telecommunications and workplace surveillance legislation regarding CCTV operation in examination venues
Statutory record custody timelines mandated for official state certifications and university degrees
Where assessments involve candidate credentials governed by international awarding bodies, local national provisions are coordinated with sponsor guidelines to preserve both candidate privacy and assessment validity.