The ICO ed-tech report - how should exam owners and suppliers respond?
- Geoff Chapman
- 2 days ago
- 3 min read
Quickly following the UK government’s ed-tech market report, this month saw a report from the UK’s Information Commissioner’s Office (ICO) - the independent regulator that enforces data privacy laws, ensures accountability, and handles rules for digital information.
The ICO ed-tech report has deep implications for the e-assessment and exam technology sector. While it focused on K-12 school settings, the compliance gaps identified (ranging from murky controller/ processor definitions to unchecked AI training models) map directly onto the core functionalities of e-assessment platforms and proctoring solutions.
I’ve pulled together some recommendations for both exam technology suppliers and exam owners to consider, as they align with the ICO’s regulatory expectations.
Recommendations for Exam Tech solution providers
For suppliers, to assume you are the ‘data processor’ operating under the exam owner’s instructions is no longer a safe default.
Audit Your Data Role for Secondary Processing If your platform re-purposes candidate data, exam responses, or psychometric logs for product development, system testing, or training AI models, you are acting as a Data Controller for those specific activities. You must independently establish a lawful basis (Article 6) and condition (Article 9) for this data use, rather than relying on the exam owner’s mandate.
Avoid ‘one-size-fits-all’ setups Build self-service dashboards that allow exam owners to customise data retention periods, toggle non-essential features (like advanced facial metrics or keystroke logging) ‘off’ by default, and seamlessly extract or delete complete candidate data records to satisfy individual rights requests.
Enforce Rigorous Sub-processor and AI Governance If your testing platform integrates third-party AI or cloud services (e.g. for automated scoring or remote proctoring), verify their standard terms. The ICO highlighted cases where suppliers inadvertently agreed to third-party terms allowing candidate data to be used for general AI training. Explicitly prohibit this in your supply chain. Secure explicit client authorisation before onboarding new sub-processors.
Adopt Pro-Privacy Data Minimisation Tactics Review what candidate data fields are absolutely mandatory. Where possible, replace unique national identifiers or full names with platform-generated pseudonyms, collect year/month of birth instead of precise birth dates, and evaluate whether highly intrusive data (such as biometric voice or facial recordings) is strictly necessary and proportionate for the exam's validity.
Perform Vulnerability Testing and Untested Breach Protocols Move beyond basic passive encryption. Establish routine penetration testing and clear, distinct operational workflows for data breaches. Crucially, remember that when acting as a data processor, your legal obligation is to report all personal data breaches to the exam owner immediately, regardless of your internal assessment of the risk level.

Action Items for Exam Owners and Awarding Bodies
Exam owners hold ultimate accountability as Data Controllers for candidates taking their qualifications. You cannot contract out this legal responsibility.
Tighten and Individualise Supplier Contracts Move away from accepting standard, generalised vendor Terms of Service. Ensure your Data Processing Agreements (DPAs) outline explicit, documented instructions detailing exactly what data fields the supplier can touch, precise retention timelines, and a mandatory requirement for the supplier to delete or return data at contract expiry.
Conduct Mandated Data Protection Impact Assessments (DPIAs)Â If your exam uses automated profiling, remote proctoring, or AI-driven adaptive testing, a comprehensive DPIA is legally required before processing begins. Ensure these assessments explicitly focus on the risks to the candidate's rights, freedoms, and privacy, rather than just corporate or security risks to your organisation.
Demand Proactive Transparency and Verification Don’t wait for a data incident to audit your suppliers. Ask the supplier to provide access to verifiable evidence of data protection compliance, such as independent penetration test summaries, ISO/SOC certifications, or product DPIA extracts.
Provide Clear, Layered Transparency Information Candidates (and parents/ guardians, if the candidates are minors) must understand exactly how their exam data is handled. Work with the supplier to publish non-technical, plain-language privacy explainers that detail ‘invisible’ back-end processing. This can include how automated proctoring flags flags behaviour, or how algorithmic marking functions.
Platforms now operate across complex networks of sub-processors and third-party AI tools. There’s no doubt that friction will occur when attempting to enforce these contract changes between in-situ suppliers and exam owners.
Nevertheless, the ICO has investigatory and corrective powers, and is able to issue monetary penalties. Suppliers and exam owners would be wise to review the report, and act upon its guidance.