# CNIL-compliant proctoring: what délibération 2023-058 actually says

> France’s data protection authority does not ban remote proctoring. It asks institutions to match the level of monitoring to the stakes of the exam, to offer an in-person alternative, and to drop automated analysis of candidate behaviour. A guided reading of délibération n° 2023-058 of 8 June 2023, article by article, with paragraph numbers so every claim can be checked.

Source: https://evalmee.com/en/blog/cnil-compliant-proctoring-deliberation-2023-058/
Published: 2026-08-15
Updated: 2026-09-07
ES: https://evalmee.com/es/blog/proctoring-conforme-cnil-deliberacion-2023-058/
ES-ES: https://evalmee.com/es-es/blog/proctoring-conforme-cnil-deliberacion-2023-058/
FR: https://evalmee.com/fr/blog/proctoring-conforme-cnil-deliberation-2023-058/
IT: https://evalmee.com/it/blog/proctoring-conforme-cnil-delibera-2023-058/

---

The CNIL — France’s data protection authority — does not ban remote proctoring. It asks for three things: match the system to the real stakes of the exam, offer an in-person alternative whenever possible, and drop automated analysis of candidate behaviour. Everything else — legal basis, retention, encryption, logging — follows from the GDPR and is not specific to exams.

That is the substance of **délibération n° 2023-058** of 8 June 2023, published in the French Journal officiel no. 0203 of 2 September 2023 (text no. 63). It runs to six articles and fifty-seven numbered paragraphs, and it is the reference text on the subject in France. This article walks through it in order, citing paragraph numbers so that every claim can be checked against [the text the CNIL published](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf).

A note on names: the French terms are kept as they are. A _délibération_ is a formal decision of the CNIL; _télésurveillance_ is the French word for remote proctoring. The text has no official English version, so quoting it means quoting French.

## A recommendation, written after the pandemic

The CNIL starts from an observation: since the COVID-19 crisis, French public and private higher education institutions have relied far more on digital, remote exams ([§ 1](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=1)). The possibility itself is not new — article D. 611-12 of the Education Code has framed it since 2017 and requires three guarantees: checking that the candidate has the technical means to sit the exam, verifying their identity, and supervising the exam in line with the rules that apply to exams ([§ 2](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=1)).

The text is not a regulation. It is a recommendation restating GDPR obligations and encouraging good practice around tools the CNIL calls intrusive "by nature" ([§ 3](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=1)), adopted after a public consultation the CNIL reports on in [§ 37](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=7). Its scope is broad: it covers remote proctoring for online exams "for any type of exam or certification, organised by a public institution or a private body" ([§ 9](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=2)). A private training provider is therefore in scope exactly as a university is.

Two framing observations deserve to be read before any tool is chosen. First, remote exams remove the levelling of material conditions that a physical exam hall provides: candidates in areas with poor connectivity, without a quiet room or a fast enough computer are penalised, and the CNIL asks that [remote proctoring](/en/assessment-glossary/#remote-proctoring) be free of any discriminatory bias "as regards the origin of the students concerned", with particular attention to disabled candidates ([§ 4](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=1)). Second, remote proctoring means monitoring "a private computer terminal, inside a private room", and it stays "necessarily imperfect" — if only because it cannot cover the whole room ([§ 5](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=2)).

## Article 1: decide whether to monitor before choosing how

This is the longest article, and the one most often skipped. It is barely about technology.

The institution that decides to use a remote proctoring solution **is the data controller** ([§ 10](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=3)). That is not a formality: it must use proven, reputable solutions, test them beforehand under degraded conditions — low bandwidth, temporary loss of connection, compatibility with candidates’ devices and operating systems — and involve its data protection officer to confirm the system’s compliance ([§ 10](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=3) and [§ 11](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=3)). The platform vendor is a processor ([§ 17](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=4), [§ 51](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=9)). No checkbox in a piece of software moves that responsibility.

Paragraph 12 lists the principles to be taken into account: the duty to inform, the rights of data subjects and the right of access in particular, purpose limitation, [data minimisation](/en/assessment-glossary/#data-minimisation), security and confidentiality, proportionality and relevance, storage limitation, and limits on transfers outside the European Union.

Three requirements are then stated unusually plainly:

- **Inform early, and precisely.** Beyond the legal duty to fix exam arrangements before the end of the first month of the academic year, the CNIL "strongly encourages" institutions to publish the planned arrangements and the proctoring systems that may be used far enough in advance for students to choose their programme with full knowledge of them ([§ 13](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=3) and [§ 14](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=3)).
- **Do not treat it as a convenience.** Remote proctoring "must not be a convenience alternative intended solely to make the organisation of assessment less burdensome or less expensive"; supervision by humans in a room "often remains the most appropriate way" to guarantee that no fraud occurs ([§ 18](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=4)).
- **Offer the in-person route as a matter of course.** Where an institution runs a remotely proctored exam, the CNIL recommends that an in-person alternative be systematically offered, with equal treatment between candidates ([§ 19](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=4)). Having no alternative should be reserved for specific cases: a health crisis, or institutions built entirely around distance learning — in which case the arrangements must be known to students when they enrol ([§ 20](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=4)).

The article closes on a sentence that reframes the whole debate: these tools "are not meant to be more effective than in-person exam supervision, nor even to guarantee an equivalent level of supervision" ([§ 21](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=4)). The CNIL also notes that some assessment formats certify competence remotely without any proctoring at all — a dissertation, a project defence — or reduce how intrusive it is: oral exams, open-book exams, sitting the exam in dedicated premises ([§ 7](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=2)).

## Article 2: the legal basis

Legal bases are determined under article 6 GDPR ([§ 22](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=4)). The CNIL identifies two as appropriate:

- **public interest task** (article 6(1)(e)), for higher education institutions that pursue one ([§ 23](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=5));
- **contract** (article 6(1)(b)), where no legal provision supports the first, and provided the exam arrangements are set out in that contract and therefore known to the student before enrolment ([§ 24](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=5)).

The others "appear less appropriate" ([§ 25](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=5)). Consent requires an in-person alternative with no adverse consequence, and the ability to withdraw — that is, to change one’s mind. Legitimate interests imply a right to object, which the CNIL considers "difficult to manage in the context of organising an exam". For a private certification body, contract is therefore often the workable route — but it is prepared in the enrolment terms, not the day before the exam.

### Three consequences for the documents you write

This is the part of the text that turns most directly into sentences someone has to write — in exam regulations, in enrolment terms, in a privacy notice.

**Consent is not the legal basis for proctoring.** An "I accept the monitoring tool" checkbox ticked as the exam starts grounds nothing: at that moment the candidate has no choice left, and consent that is not freely given is not consent. What grounds the processing is the public interest task ([§ 23](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=5)), or a contract whose arrangements are set and known before enrolment ([§ 24](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=5)). The wording follows from that: "the candidate is informed that the exam is remotely proctored, as follows…", not "the candidate accepts". The duty to inform is untouched — article 13 GDPR applies in full, and the arrangements must be restated before the candidate connects to the platform ([§ 29](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=5)): what you collect at that point is an acknowledgement, not consent.

**The in-person alternative is not required everywhere.** It must be "systematically offered" ([§ 19](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=4)), but the CNIL itself carves out institutions whose organisation is entirely remote: no alternative is required there, provided the arrangements are known to candidates from enrolment ([§ 20](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=4)). A fully remote training body therefore does not have to open an exam hall; it has to write its arrangements in the right place, and early enough. Failing both the alternative and that carve-out, its absence has to be justified and documented ([§ 31](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=6)).

**A fallback procedure is still needed, case by case.** Having a legal basis exempts nobody: a candidate may raise their particular situation — shared housing, a disability, unsuitable equipment, an unstable connection — and, where the processing rests on the public interest task, exercise the right to object under article 21 GDPR. Exam regulations do well to answer the question before it is asked: another slot, another venue, another exam format, or an exam without proctoring where the stakes allow it ([§ 7](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=2)). It is also what [§ 4](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=1) calls for, asking for a system "free of any discriminatory bias" and attentive to candidates with disabilities.

## Article 3: what article 82 changes for the candidate’s device

Article 82 of the French Data Protection Act — the national transposition of the ePrivacy rules on terminal equipment — requires consent for read/write operations on a user’s device, unless they are strictly necessary to deliver a service the user has requested ([§ 26](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=5)); systems deployed on networks not open to the public — intranets, extranets over a VPN — are in principle out of scope ([§ 27](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=5)). The CNIL’s conclusion is pragmatic: collecting consent at the start of the exam "seems hardly compatible" with an exam that cannot take place unsupervised ([§ 29](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=5)), so read and write operations on the device of a candidate requesting access to the service can be treated as strictly necessary to deliver it ([§ 30](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=5)) — provided the proctoring arrangements and the nature of the data collected have been restated before the candidate connects to the platform ([§ 29](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=5)).

## Article 4: proportionality, assessed as a whole

This is the heart of the text, and the part that separates a defensible setup from one that is not.

The analysis must be carried out **globally, not measure by measure** ([§ 33](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=6)). Two consequences follow: a system that fails to prevent fraud effectively is "by nature disproportionate", and if no fair balance can be struck between effectiveness and intrusiveness, the institution should consider an in-person exam or a different assessment format. The CNIL adds that the design of the paper itself — essay or short answer, identical questions or not, time allowed per question — is one of the levers against fraud.

The choice of tools is assessed "in the light of the context and the stakes of the exam" ([§ 34](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=6)). Enhanced monitoring seems appropriate for a competitive entrance exam; conversely, a low-stakes assessment "such as a mock exam should be run without remote proctoring".

Two procedural duties frame that analysis: involve, where possible, academic leads, student representatives and the data protection officer, and test the systems beforehand on a representative sample of candidates’ hardware ([§ 31](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=6)); and carry out, with the data protection officer and before the processing begins, a [data protection impact assessment](/en/assessment-glossary/#analyse-d-impact-aipd-french-data-protection-impact-assessment) — an _AIPD_ in French — "unless the system used does not create high risks to students’ rights and freedoms" ([§ 32](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=6)).

### The four measures cited as proportionate

For exams that require enhanced monitoring, paragraph 35 lists the measures that "appear proportionate":

1. real-time video and audio monitoring of the candidate by the people responsible for proctoring, with no retention except where fraud is suspected;
2. real-time monitoring of the candidate’s activity through screen sharing, on the same no-retention terms;
3. monitoring the candidate’s activity through an online platform able to detect, or even block, access to other tabs;
4. a one-off check of the student’s environment via their camera at the start of the exam, carried out by a person responsible for proctoring and with no retention except where fraud is suspected.

The list is practical: it is the grid against which to compare a vendor’s feature set, one line at a time.

### What the CNIL recommends against

Automated analysis of candidate behaviour — the exact wording of [§ 37](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=7) — is where the text is at its sharpest. The CNIL separates automated analysis of the candidate’s **environment** — an abnormal noise level, a third party in the room — from automated analysis of their **behaviour** — keystroke frequency, gaze direction, emotions ([§ 36](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=7)).

On the second, it is explicit: such systems are particularly intrusive, the CNIL’s own work and consultation showed "a high risk of false positives", and students may end up focusing on behaving "normally" for the tool rather than on the exam. "Consequently, in view of the principles of necessity and proportionality, the CNIL recommends not using remote proctoring systems that perform automated analysis of candidates’ behaviour" ([§ 37](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=7)).

Environment analysis is judged "more reliable and less intrusive" and may be considered case by case, where candidate numbers are large and the system is sufficiently reliable ([§ 38](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=7)). With one absolute limit: such systems "must never lead to an automated decision with an immediate effect on the candidate". Their only role is to draw a proctor’s attention; under article 22 GDPR, human verification must systematically precede any decision. The worked example is telling: an exam should not be interrupted merely because an abnormal noise level was detected automatically, though alerting a proctor and offering to replay the event may be proportionate ([§ 40](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=7)).

Two points are routinely missed. Incidental collection: institutions must warn students that the system may capture data about their household or surroundings, and advise them to isolate themselves in a quiet, neutral room ([§ 41](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=8)). Dedicated software: it can collect no additional data at all — the CNIL calls this "privacy by design" — but the controller must check that it does not create unequal treatment depending on a student’s hardware, and must guarantee that the vendor does not reuse the data ([§ 50](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=9)).

### Identity verification and biometric data

Verifying candidates’ identity is an obligation ([§ 42](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=8)). The CNIL cites first a document check carried out by a proctor during a video call; automated verification comparing an identity document with the candidate’s face "may sometimes be justified, particularly where student numbers are very large" ([§ 43](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=8)).

That second option processes biometric data under article 9 GDPR. It therefore requires either the consent of the individuals, with an alternative available, or a substantial public interest strictly framed by law and allowing human intervention ([§ 44](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=8)). Four cumulative conditions apply ([§ 45](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=8)): a single identity check, a very large number of candidates given the nature of the exam, an alternative always available, and precise prior information about how consent is collected. Finally, such systems must "under no circumstances" lead to databases of biometric templates, whether at institutions or at proctoring vendors ([§ 46](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=9)), and must serve no other purpose ([§ 47](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=9)).

### Retention

The recommendation sets no single period. It asks the controller to define, **before the system goes live**, who may access the data and the [retention period](/en/assessment-glossary/#data-retention-period) or the criteria for setting it, based on the type of information and the purpose ([§ 48](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=9)). Only one figure is given: where fraud is suspected, retention "should not exceed the legal time limits of the disciplinary or litigation proceedings that could be brought, which are in principle two months" ([§ 49](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=9)). That benchmark has to be checked against the appeal windows in your own exam regulations.

## Articles 5 and 6: transfers and security

Article 5 is a single paragraph: using processors, foreign ones in particular, may involve a transfer outside the European Union, which is only possible where an adequate level of protection is ensured and framed by the legal instruments the regulation provides ([§ 51](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=9)).

Article 6 is a list of concrete measures, anchored in article 32 GDPR ([§ 52](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=10)):

- encryption with algorithms recognised as strong, in transit **and at rest** ([§ 53](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=10));
- read access restricted to people with a need to know — proctors, teaching staff, the disciplinary board — from dedicated premises and dedicated terminals ([§ 54](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=10));
- no modification or deletion of data concerned by ongoing disciplinary or litigation proceedings, and such operations otherwise reserved to system administrators ([§ 55](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=10));
- logging of access to personal data, in line with délibération n° 2021-122 of 14 October 2021, with the logs given their own retention period, "generally between six months and one year" ([§ 56](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=10));
- for software that has to be installed: avoid anything requiring elevated privileges or the disabling of endpoint protections such as antivirus, make sure the device can easily be restored to its original state, prefer open-source solutions and verify the software’s integrity before any personal data is collected ([§ 57](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=10)).

## A checklist before your next session

If you keep one page from this article, keep the questions your file should be able to answer, with the matching paragraph:

| Question                                                                                 | Ref.            |
| ---------------------------------------------------------------------------------------- | --------------- |
| Do the stakes of this exam justify remote proctoring, or would another format do?        | [§ 7](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=2), [§ 15](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=4), [§ 34](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=6) |
| Is an in-person alternative offered? If not, on what grounds?                            | [§ 19](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=4), [§ 20](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=4)      |
| Were the arrangements communicated to students early enough?                             | [§ 13](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=3), [§ 14](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=3)      |
| Which legal basis: public interest task or contract?                                     | [§ 23](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=5), [§ 24](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=5)      |
| Does the privacy notice say the candidate is informed, rather than accepts?              | [§ 25](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=5), [§ 29](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=5)      |
| Was the proportionality analysis run globally, with the DPO and student representatives? | [§ 31](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=6), [§ 33](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=6)      |
| Was a DPIA carried out, or the absence of high risk documented?                          | [§ 32](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=6)            |
| Does the system analyse candidate behaviour?                                             | [§ 37](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=7)            |
| Does human verification precede any decision triggered by an automated alert?            | [§ 38](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=7)            |
| Were retention periods set before go-live?                                               | [§ 48](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=9), [§ 49](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=9)      |
| Are encryption, access restriction and logging in place?                                 | [§ 53](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=10) to [§ 56](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=10)    |

## Where Evalmee stands

We built our [exam monitoring](/en/product/monitor/) around this text, and our position comes down to three deliberate choices.

No automated analysis of behaviour: no gaze tracking, no emotion detection, no keystroke dynamics. Those technologies do not exist in the product, not even as an option — that is paragraph 37 applied literally. What we detect is activity within the exam: leaving full screen, switching to another application, copy-paste, a second screen being present.

Identity verification, in the standard product — the Mini, Pro and Max plans — is a document check: the participant photographs their identity document and their face, the examiner compares the two by eye and decides. That is the first measure [§ 43](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=8) cites, and no biometric template is computed or stored there ([§ 46](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=9)). On the Organisation plan, automated identity verification can be deployed on a quote basis, through a specialist provider: off by default, it is never switched on without an explicit decision by the organisation, is limited to establishing the candidate’s identity — before the exam, or afterwards as an option — and is never used to monitor them during the exam ([§ 47](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=9)). It then processes biometric data under article 9, and it is for the data controller to check that the cumulative conditions of [§ 45](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=8) are met. We push neither way: the choice is yours, we configure the one you have settled on, and our [security page](/en/security/) sets out the conditions.

No automated decision: the fraud risk score is computed from the events detected during the exam, and from nothing else, and it is not a verdict. It closes no exam, reports nobody on your behalf and is no proof of anything: these are leads to be looked into. The examiner opens the integrity report, reads the timestamped events there and decides — the human check [§ 38](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=7) requires by pointing to article 22 GDPR.

One gap, finally, that we would rather write down than leave unsaid. The first of the four measures in [§ 35](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=6) describes real-time monitoring with **no retention** of the data unless fraud is suspected; here, a flagged passage is reviewed after the exam rather than during it, so webcam and microphone recordings are kept for **three months by default, on every plan**. On the Organisation plan, that period can be set by the organisation as data controller, which picks one proportionate to the stakes of the exam and makes it known to candidates — [§ 48](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=9) taken at its word: retention periods are set before the system goes live. Screenshots, for their part, are attached to the candidate’s submission: they follow the retention period of submissions, set by the examining institution, and are deleted along with them. And where disciplinary or legal proceedings are under way, you can ask for the records in that case file to be frozen: they are then kept until the proceedings end, neither altered nor deleted ([§ 49](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=9), [§ 55](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=10)). The request has to be made before the deletion date.

The detail of those commitments — including what we do not hold, neither SOC 2 nor ISO 27001 in our own name — is on our [security page](/en/security/), with a table setting each CNIL recommendation against what Evalmee does. The retention regime, the split of roles and the list of sub-processors are in our privacy policy, our terms and our data processing agreement, updated on 4 September 2026. As the data controller, it is for you to check that the period you settle on matches the appeal windows in your own exam regulations.

## What this article is not

A reading, not legal advice. The paragraphs cited refer to the numbering of the text the CNIL published, but the interpretation is ours and does not bind the CNIL. As the data controller, it falls to you to run your own analysis with your data protection officer and, where applicable, the impact assessment required by paragraph 32.

One last remark, because it is in the text and rarely quoted: the CNIL writes that these tools are not meant to be more effective than in-person supervision ([§ 21](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=4)). The most compliant setup is therefore not the most complete one, but the one that still holds up when a student asks why their webcam was on.

## Frequently asked questions

### Does the CNIL ban remote proctoring for online exams?

No. Délibération n° 2023-058 is a recommendation, not a prohibition. It asks institutions to match the monitoring to the stakes of the exam, to offer an in-person alternative whenever possible, and to rule out automated analysis of candidate behaviour.

### Who is the data controller for a remotely proctored exam?

The institution or organisation that decides to use a remote proctoring solution is the data controller, under paragraph 10 of the recommendation. The platform vendor acts as a processor ([§ 17](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=4), [§ 51](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=9)). The prior analysis, and where applicable the impact assessment, are therefore the institution’s to run.

### Is a DPIA required before proctoring an exam remotely?

Paragraph 32 asks the controller to carry out a data protection impact assessment, jointly with its data protection officer and before the processing begins, unless the system used does not create high risks to students’ rights and freedoms.

### Does the recommendation apply outside French higher education?

Paragraph 9 states that the recommendation covers remote proctoring for online exams for any type of exam or certification organised by a public institution or a private body. A délibération adopting a recommendation is the French authority’s own doctrine, not a binding rule: it is the grid the CNIL will read a French deployment against if it ever inspects one, and its reasoning is a useful benchmark anywhere the GDPR applies.

### Do candidates have to consent to being remotely proctored?

The CNIL places consent among the legal bases it finds less appropriate ([§ 25](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=5)): collected at the start of the exam, it is not freely given, since the candidate can no longer walk away from the exam. The two bases it cites as appropriate are the public interest task ([§ 23](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=5)) and a contract whose exam arrangements are known before enrolment ([§ 24](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=5)). The duty to inform under article 13 GDPR still applies in full, and the arrangements must be restated before the candidate connects to the platform ([§ 29](https://www.cnil.fr/sites/cnil/files/2023-09/recommandation_dispositifs_de_telesurveillance_des_examens.pdf#page=5)): the candidate is informed, rather than asked to accept.

### Is facial recognition allowed to verify a candidate’s identity?

The CNIL cites first the document check carried out by a proctor during a video call. Automated verification comparing a candidate’s face with an identity document processes biometric data under article 9 GDPR: it requires a specific legal ground and the four cumulative conditions of paragraph 45. Paragraph 46 further rules out building any database of biometric templates.

### How long can proctoring recordings be kept?

The recommendation sets no single retention period: paragraph 48 asks the controller to define retention before the system goes live. Where fraud is suspected, paragraph 49 states that retention should not exceed the legal time limits of the disciplinary or litigation proceedings that could be brought, which are in principle two months.
