Online proctoring has a reputation for collecting a lot of data. Webcam video. Audio. Screens. Identity documents. Browser activity. Biometric data. The list can sound extensive, especially when all of these things are mentioned together without explaining when they are collected or what they are actually used for. But that list can also be misleading.

Not every proctored exam collects every type of data a proctoring platform is technically capable of processing. Identity verification may be necessary for a professional certification exam and completely unnecessary for a university practice test. One assessment may require a second camera; another may not even record video.
There is another distinction that often gets lost in discussions about proctoring data: data collected during an assessment is not the same as information generated from that data. A screen recording, for example, is collected data. A session report that brings together detected events and the evidence behind them is generated from it.
So instead of making a suitably alarming list of everything proctoring technology can possibly collect, let’s look at what actually happens to data during a proctored assessment and, more importantly, why.
The slightly flippant answer would be: because the Internet has yet to develop its senses.
In a test center, a surprising amount of information is available without anyone thinking of it as “data collection.” A proctor sees the person entering the room. They can check an ID. They see who else is there. They notice someone opening a book or talking to another person. And if something happens, they can describe what they saw. Move the same assessment online, and none of this context magically travels with it.
Technology has to recreate the parts of that environment that actually matter for the assessment. Depending on the exam, that can mean establishing who is taking it, observing what happens during the session, detecting events relevant to the exam rules, identifying technical problems, and keeping enough evidence for somebody to review the session afterward.
Some information enters the proctoring process before the actual monitoring begins.
There needs to be a way to connect a test taker to the right assessment and session. Depending on how the assessment platform and proctoring system are integrated, that might involve profile information, a user identifier, assessment information, session details, or some combination of these.
And no, the proctoring platform does not necessarily need to know your name.

With an LTI integration, for example, the testing institution can pass an opaque identifier to OctoProctor instead. The institution knows which person that identifier belongs to; OctoProctor can run the proctoring session without needing that particular piece of personal information.
This is a small technical detail, but it illustrates a much bigger principle: the fact that data exists does not mean every system involved in an assessment needs to receive it. The same principle applies to where assessment data is stored and processed — an area where seemingly simple statements about data residency can hide quite a bit of complexity.
Some assessments also need to establish that the person sitting in front of the computer is actually the person who is supposed to be taking the exam.
This is where identity documents, face photographs, and potentially biometric data come in. And this is also where terminology matters.
A webcam recording is not automatically “biometric data” simply because it contains somebody’s face. When automated facial identity verification is enabled in OctoProctor, the system creates a mathematical representation of the face from captured images so that faces can be compared. That representation is biometric data.
The distinction may sound nerdy. It isn't.
“Online proctoring collects biometric data” is a very different statement from “this assessment uses biometric identity verification.” The first makes biometrics sound like an inherent feature of all proctoring. They aren't.

Webcam footage, audio, screen recordings, chat messages, technical events, and biometric identifiers are different kinds of data. Putting them all under one scary umbrella doesn't make the privacy conversation more accurate. It just makes it scarier.
Now we get to the part most people probably imagine when they hear “online proctoring.”
Yes, a proctored exam can be recorded. Yes, that can include audio. And yes, if screen monitoring is enabled, the test taker's screen can be visible or recorded.
Notice the recurring word can.
Depending on the assessment configuration, OctoProctor can capture webcam video or images, microphone audio, the test taker's screen, footage from a secondary mobile camera, and a short room overview. Communication during the assessment, such as chat messages and attachments, can also become part of the session record.
But recording is only part of the picture. A proctoring system also needs to know when relevant things happen.
A test taker switches away from the assessment window. A second display is connected. No face is visible in the camera. Suddenly there are two faces. Conversation is detected. The network connection disappears. The assessment is running in a virtual machine.
These are not all the same type of event, and they certainly don't all mean “cheating.”
Some relate to assessment rules. Some provide context. Some are technical events that may explain what happened later.
Take a network interruption. There is nothing inherently suspicious about someone's Wi-Fi giving up at exactly the worst possible moment. Anyone who has ever joined an important video call knows that technology has an exquisite sense of timing.
But the interruption still matters. If the test taker disappears from the session for several minutes and reconnects, a reviewer may need to know that. The system therefore records the event as part of the session history.
This is where the difference between recording something and detecting something becomes useful.
A screen recording shows what appeared on the screen. A focus-change event says that the test taker moved away from the assessment window. Webcam footage shows what the camera captured. A multiple-face indicator says that the system detected more than one face.
One is evidence. The other helps you find the potentially relevant moment in that evidence.
So far, we have mostly talked about collected data: information supplied before the session and information captured or detected while it is happening.

Then there is information that did not exist before the session. The proctoring process creates it from the data collected. That can include identity-verification results, incidents or flags, session metrics, a credibility score, reviewer comments and conclusions, and ultimately a session report. This distinction matters more than it might appear.
Suppose a second person appears in the webcam frame. The video is collected data. The system identifying that two faces are present is a detected event. That event being surfaced in the session report for somebody to examine is part of the information generated from the session.
And then comes the bit that no algorithm can conveniently make disappear: someone still has to decide what happened.
Maybe another person was helping with the exam. Maybe they walked through the room without realizing an assessment was in progress. Maybe the detection itself was wrong.
The flag tells the reviewer where to look. The underlying evidence gives them something to look at. The conclusion requires interpretation.
This is why OctoProctor does not treat a software flag as an automatic cheating verdict. Our approach to AI proctoring is to use technology to surface potentially relevant events and the evidence behind them, while the testing institution decides whether an event actually represents a violation.
The same principle applies to the credibility score. Metrics collected during the session can contribute to a score that helps reviewers understand the session, but the score is not a substitute for the review itself.
AI is very useful at finding needles in haystacks. It should not be allowed to declare every vaguely needle-shaped object guilty.
A professional certification provider may need strong identity verification because the credential has legal or professional consequences. An employer running a pre-employment assessment may care about different risks. A university may have different requirements for a final exam and a low-stakes quiz.
Even within one institution, there is no reason those assessments should automatically have identical monitoring settings.
It is tempting to think about assessment security like stacking locks on a door: if one control is good, six must surely be excellent. Proctoring doesn't really work that way.
Every additional data source and monitoring method introduces something else to configure, process, explain to test takers, review, secure, and eventually delete. It can also add friction to the assessment experience.
So the goal shouldn't be to collect as much information as technologically possible. It should be to collect enough of the right information. The same logic applies more broadly when defining requirements for proctoring software: more features and more controls do not automatically produce a better assessment process.
The question should therefore be bigger than Can the software record this? It should be: Do we need this information to protect the integrity of this assessment? And immediately after that: What are we going to do with it?
The same principle applies to generated information. More flags are not necessarily better flags. A system that marks every slightly unusual event may look impressively vigilant until somebody has to review hundreds of irrelevant incidents.
Good proctoring should help people concentrate on the evidence that matters, not generate a larger haystack.
Perhaps the easiest way to understand proctoring data is to stop treating it as one thing. A recording is not a flag, a flag is not evidence of intent, and neither is automatically a verdict.
Once those differences are clear, the conversation about proctoring data becomes much less mysterious and much more useful.
The question isn't really how much data online proctoring can collect. Modern technology can collect an impressive amount of almost anything. That's not much of an achievement by itself.
The better question is what information this assessment actually needs to produce a result people can trust. Everything else should have to justify its invitation.
From identity verification to screen, audio, and behavioral monitoring, OctoProctor gives you the options. We’ll help you choose what makes sense for your assessment and leave out what doesn’t.
Talk to our teamThey can be, but recording is not an inherent requirement of every proctored exam. Depending on how the assessment is configured, a session may include webcam video or images, screen recording, audio, or footage from a secondary camera. Other assessments may use only some of these methods. The important distinction is between what a proctoring platform can record and what a particular assessment is configured to record.
They can. If microphone monitoring is enabled, audio may be recorded or analyzed for relevant events, such as conversation or background noise. Whether audio is used depends on the assessment settings and the rules established by the testing institution.
If screen monitoring is enabled, yes. Depending on the setup, the screen may be shared live, recorded, or captured at intervals. The system may also detect related events, such as the test taker switching away from the assessment window.
Again, seeing the screen and detecting a particular event are not quite the same thing: one provides the evidence, while the other helps identify where something potentially relevant happened.
There is no universal proctor view. What is available depends on the assessment configuration and the proctor's permissions.
Depending on the setup, a reviewer may have access to webcam footage, screen activity, audio, secondary-camera footage, chat history, detected incidents, technical events, and the resulting session report. If a particular monitoring method was not enabled for the assessment, there is naturally nothing from that source to review.
Not necessarily. A person's face appearing in a webcam recording does not automatically make that recording biometric data.
Biometric data enters the picture when technology processes physical characteristics for automated identification or verification. In OctoProctor, for example, automated facial identity verification creates a mathematical representation of the test taker's face so that it can be compared with another image. If that functionality is not required for an assessment, biometric identity verification does not have to be used.
No. “Proctoring software” describes a category of products, not a standardized package of monitoring methods. Different platforms offer different approaches to identity verification, webcam and screen monitoring, browser controls, AI-assisted detection, secondary cameras, and session review. And even when two platforms offer similar capabilities, the way they implement them can differ. Our comparisons of OctoProctor and Honorlock and OctoProctor and Proctorio show some of those differences in practice.
That is also why asking “What data does proctoring software collect?” gets you nowhere. The more useful questions are what this particular platform can collect, what this particular assessment is configured to collect, and why each type of data is needed.