By clicking the SUBMIT button, I’m providing the above information to Vretta for the purpose of responding to my request.
CONTACTlogo
twitterfacebookfacebook instagram
Assessment Security and Accessibility: What Happens on the Other Side of the Screen?

September 07, 2026

Assessment Security and Accessibility: What Happens on the Other Side of the Screen?

Share:TwitterlinkedinFacebooklink

Subscribe to Vretta Buzz


Key Topics Covered

Before the Exam: Getting Into the Assessment

During the Exam: Security Without Unnecessary Friction

After the Exam: What Happens to the Evidence?


Imagine the following scenario on a computerized exam environment: the candidate has prepared for the assessment. On exam day, the candidate opens the laptop, closes other applications, turns on camera and microphone, shows its identification, and remains under observation throughout the session. For the assessment organization, these are well-architected, sophisticated security measures designed to protect the integrity of the exam. For the candidate, they are simply part of the assessment experience. But how much does the candidate know about what happens behind the scenes, and how much should they know?

In remote assessments, we need to achieve two objectives at the same time: prevent misconduct and ensure that candidates can participate fairly. Assessment practices in Ontario increasingly reflect this balance, with digital assessment environments incorporating accessibility features alongside measures designed to protect assessment integrity.

The challenge is finding the right balance: protecting the assessment without intervening into the privacy of an individual. In this article, I examine the balance through the candidate's journey, from entering the assessment to the handling of assessment information after the exam.

Before the Exam: Getting Into the Assessment

Security starts early. For a remote assessment, candidates may be required to use a secure lockdown browser, verify their identity, and enable their camera and microphone. Each measure serves a clear purpose: the lockdown browser restricts access to other applications, while identity checks and invigilation help to confirm that the right person is taking the assessment under the required conditions.

But these requirements also shape the candidate's experience. A security measure that works smoothly for most candidates may create difficulties for someone using assistive technology, working with a different type of device, or requiring an approved accommodation. This is why accessibility should be considered when security controls are designed, rather than addressed only after a problem occurs. Similarly, on-screen assessment platforms should be compatible with assistive technologies and reasonable adjustments should remain available where needed.

There is another question behind each requirement: what information is actually needed to achieve the security objective? Identity verification may require access to identification documents. Invigilation is likely to involve audio and video. Technical controls may generate logs about the candidate's device and activity. Each should have a defined purpose, appropriate access controls, and a clear retention approach.

The goal is not to remove security controls, but to make sure that they are proportionate, compatible with legitimate accessibility needs, and limited to what is necessary to protect the assessment. 

During the Exam: Security Without Unnecessary Friction

Then the assessment begins. A lockdown browser can prevent candidates from opening other applications or accessing external resources, while invigilators may use audio and video to monitor the session and intervene if something appears unusual.

However, what counts as "unusual"? Not every unusual action is evidence of misconduct. For example, a candidate may need to use an assistive technology, adjust their position, take an approved accommodation, or simply behave differently from what an invigilator expects. A system that treats every deviation from expected behaviour as suspicious risks confusing legitimate candidate behaviour with a security risk.

This is why human oversight matters. When unusual behaviour is flagged, it should prompt an appropriate review rather than automatically become a finding of misconduct. From a legal perspective, this also reflects the principles of necessity and proportionality: monitoring should serve a defined purpose, and organizations should consider whether less intrusive means could achieve the same result.  

The objective is straightforward: detect genuine attempts to compromise assessment integrity while allowing legitimate differences in how candidates participate.

After the Exam: What Happens to the Evidence?

The screen goes dark. The data does not. A remote session can leave behind identification information, video and audio recordings, technical logs, invigilator observations, incident reports, and the assessment result itself. If a session is flagged, some of this information may become evidence in a subsequent review.

So what happens to that information once the exam is over? Organizations should have clear rules about who can access flagged sessions, who is responsible for reviewing them, and how long the information needs to be retained. In case a recording has taken place, access to it and investigation records should be limited to people who genuinely need them for their role. These considerations follow basic data protection principles of purpose limitation, data minimization, and appropriate security.

The distinction between suspicion and proof is particularly important. An unusual action, a technical irregularity, or an invigilator's concern may justify further investigation, but it does not necessarily establish that a candidate cheated. Where the available evidence is inconclusive, the process should allow for that uncertainty rather than automatically treating the suspicion as a finding.

This is also where security and privacy meet most clearly. The more information an organization collects to protect assessment integrity, the greater its responsibility to control that information afterwards. A well-designed process should therefore cover not only how suspicious behaviour is detected, but also how the resulting evidence is reviewed, protected, retained, and ultimately disposed of.

Conclusion

Remote assessment security does not begin with the first question and end when the candidate submits their answers. It covers the entire assessment journey: how candidates enter the exam, how security is maintained during the session, and how the information collected is handled afterwards.

Secure lockdown browsers, identity verification, and invigilation can protect assessment integrity, but they should not create unnecessary barriers for candidates or interfere with legitimate accessibility needs. At the same time, recordings, observations, and other information collected for security purposes need to be carefully managed, particularly when an exam is flagged for investigation.

Ultimately, a strong remote assessment process should achieve both goals: protect the integrity of the assessment while providing candidates with a fair, accessible, and proportionate assessment experience.


About the Author

Jana Begun is an EU-based legal professional specializing in data protection and privacy, with a focus on regulatory compliance. She holds an LL.M. from Stockholm University and is a Certified Information Privacy Professional/Europe (CIPP/E). At Vretta, she supports GDPR compliance and integrates privacy and security principles into the company’s day-to-day operations and digital learning platforms.

Her work centers on making complex legal requirements practical. She enjoys transforming privacy and security into actionable frameworks, helping build a culture where these topics are not just policies, but integral parts of everyday decision-making.

If you are interested in discussing data protection developments and explore how to strengthen security practices, please feel free to get in touch with Jana Begun at: dpo@vretta.com | LinkedIn


References

  1. Education Quality and Accountability Office (EQAO), Multi-Year Accessibility Plan 2024–2029, available on: https://www.eqao.com/about-eqao/accessibility/multi-year-accessibility-plan-2024-2029.
  2.  Ofqual, Regulating on-screen assessment, 11 December 2025, available on: https://www.gov.uk/government/consultations/regulating-on-screen-assessment/regulating-on-screen-assessment.
  3.  Ibid.
  4.  Council of Europe, Privacy Policy for online assessments administered by TestReach on behalf of the Council of Europe, available on: https://rm.coe.int/1680981751.
  5. Information Commissioner's Office (ICO), Data protection and monitoring workers, available on: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/employment/monitoring-workers/data-protection-and-monitoring-workers.
  6. Ibid.
  7. Ibid.