Securing Online Exams: A Complete Guide to Proctoring in Moodle 2026
The online proctoring market is expanding aggressively; as of 2026, the industry is valued at $1.07 billion, with research projecting a 25.27% compound annual growth rate (CAGR) that could see the market exceed $8 billion by 2035. That growth reflects a real need: remote exams require some form of verification that the person completing the assessment is who they say they are.
But surveillance carries a cost beyond licensing fees. Student surveys and institutional reporting have repeatedly documented discomfort with webcam-based monitoring, especially around privacy, biometric processing, disability accommodations, and the stress of being watched in private spaces. Institutions should treat proctoring as a risk decision, not a default setting.
This guide gives you a clear framework for choosing the right level of security for each assessment type, implementing Safe Exam Browser step by step, meeting your legal obligations, and, where appropriate, replacing surveillance with smarter assessment design.
Understanding Your Options: Five Proctoring Approaches
1. Live Proctoring: Maximum Security, Maximum Cost
A human proctor monitors the student in real-time via webcam and screen sharing. They verify identity, conduct a room scan, and can intervene immediately if suspicious behaviour is detected.
- When to use: Professional licensure exams, graduate admissions assessments, final exams worth 40%+ of course grade.
- Typical cost: $6-10 per exam session. Contact vendors directly -- pricing varies significantly by volume and institution.
- Student impact: Most intrusive. Requires scheduled appointments and full room visibility to a stranger.
2. Recorded Proctoring: Scalable Review
The entire session -- screen, webcam, audio -- is recorded. AI flags potential incidents for human review. Reviewers examine only flagged segments rather than full recordings.
- When to use: Mid-stakes assessments with large cohorts, asynchronous exam windows spanning multiple days.
- Typical cost: $4-7 per exam.
- Student impact: Moderate -- recording of private space, but no real-time interaction.
3. Automated AI Proctoring: Algorithmic Monitoring Only
Facial recognition, eye tracking, audio analysis, and browser monitoring run automatically. No human reviews footage unless an instructor manually checks flagged incidents.
- When to use: Large-scale assessments where human review is impractical.
- Typical cost: $3-5 per exam.
- Student impact: High privacy concern -- biometric data collection with no human judgment on flagged behaviours. Bias and accessibility concerns have been reported in automated systems, so review vendor evidence and accommodation workflows carefully.
4. Hybrid: AI Screening with Human Review
Automated monitoring during the exam, followed by human review of AI-flagged incidents. Balances scalability with accountability.
- When to use: Programs with diverse student populations, institutions that want defensible human oversight without real-time cost.
- Typical cost: $5-8 per exam.
- Student impact: Moderate automated monitoring plus post-exam review.
5. Lockdown Only: Browser Restrictions Without Surveillance
Browser lockdown prevents access to other websites, applications, or keyboard shortcuts. No webcam, microphone, or identity verification.
- When to use: Deterrence-level security for formative assessments, open-book exams with strong question design, any context where surveillance is disproportionate to stakes.
- Cost: Free (Safe Exam Browser).
- Student impact: Minimal technical restrictions only, no biometric data or recordings.
Proctoring Solutions That Integrate with Moodle
| Provider | Moodle Integration | Cost Model | Key Features | Privacy posture to verify | Best For |
|---|---|---|---|---|---|
| Safe Exam Browser (SEB) | Native (Moodle 3.9+) | Free | Browser lockdown, kiosk mode, multi-quiz support, optional Screen Proctoring via SEB Server | No webcam/audio collection in lockdown-only mode; verify SEB Server settings | Budget-constrained institutions, formative/open-book assessments |
| SMOWL | Moodle Certified | Institution licence | Continuous AI monitoring, ID verification, behavioural analysis | Verify DPA, EU data hosting, FERPA/GDPR documentation | European institutions, strict privacy requirements |
| ProctorU | LTI | $6-10/exam (contact for volume pricing) | Live human proctors 24/7, ID verification, room scan, session reports | Verify FERPA school-official terms, retention, and subcontractors | Professional certifications, high-stakes graduate programmes |
| Respondus LockDown Browser + Monitor | Native Moodle plugin | Campus annual licence | Desktop lockdown + webcam recording, widely used in US higher education | Verify FERPA terms, accessibility documentation, and retention | US universities, semester-length programmes |
| Honorlock | Official Moodle plugin | Contact for current pricing | AI + live hybrid, mobile lockdown, browser guard | Verify FERPA terms, state privacy terms, and deletion controls | Institutions wanting predictable per-student pricing |
| YuJa Verity | LTI Certified | Institution licence | Automated + live, mobile app, cross-platform | Verify selected region, DPA, FERPA/GDPR documentation | Multi-vendor assessment environments |
| Proctortrack | LTI | Tiered pricing | Live/auto/hybrid, advanced ID verification | Verify FERPA terms, biometric notices, and retention | Corporate training, professional development |
Pricing and vendor note: Pricing figures above are indicative public-market ranges, not quotes. Proctoring vendors change pricing, product scope, privacy terms, and data-retention commitments frequently. Before adoption, review current vendor documentation, legal history, accessibility posture, DPA terms, subprocessors, and deletion controls with your compliance team.
Privacy and Legal Compliance
Online proctoring collects some of the most sensitive data categories: biometric identifiers, video of private living spaces, and behavioural patterns. You must understand your obligations before deploying any system.
This section is general operational guidance, not legal advice. Confirm the applicable law, lawful basis, notices, consent model, accommodation process, and vendor contract language with counsel before deploying online proctoring.
GDPR (EU and EEA)
GDPR applies if you enrol students in the EU or EEA, regardless of where your institution is based.
Key requirements:
- Lawful basis and transparency: Identify the lawful basis for processing before the exam, explain the purpose clearly, and avoid relying on consent where students cannot freely decline.
- Data minimisation: Collect only what is strictly necessary for the purpose. Browser lockdown only? Don't add webcam monitoring.
- Purpose limitation: Proctoring data may only be used for academic integrity. Selling or repurposing it violates GDPR.
- Right to erasure: Students can request deletion. Your vendor contract must support this.
- Data Processing Agreement (DPA): Required with every proctoring vendor.
- International transfers: Verify data location, subprocessors, transfer mechanisms, and retention periods with the vendor.
Penalty: Up to EUR20 million or 4% of global annual revenue, whichever is higher.
FERPA (United States)
Proctoring recordings and related logs may be education records when they are directly related to a student and maintained by, or for, the institution.
Key requirements:
- If your vendor allows subcontractors to access recordings, you need student consent.
- Your vendor qualifies as a "school official" only if a written agreement specifies they will not re-disclose data.
- Parents of students under 18 have the right to inspect proctoring recordings.
Penalty: Loss of federal funding. Rarely enforced directly, but institutional reputational and litigation risk is significant.
California (CCPA/CPRA)
California privacy obligations depend on your institution type, student population, vendor role, and whether consumer privacy or student-data laws apply. Key requirements:
- Review whether CCPA/CPRA, California student-data laws, or contract-specific institutional policies apply.
- Disclose what automated or AI-assisted flagging does at a high level, and require vendor documentation where available.
- Verify retention, deletion, sale/share restrictions, sensitive personal information handling, and subcontractor controls.
Regulatory exposure and private rights of action vary by statute and fact pattern. Treat California deployments as counsel-review items.
The Proportionality Principle
Match surveillance level to assessment stakes -- and always offer an alternative:
| Stakes | Recommended approach | Alternative |
|---|---|---|
| Low (<=10% of grade, formative) | SEB lockdown or no proctoring | N/A -- privacy harm exceeds benefit |
| Medium (15-35% of grade) | Automated or recorded proctoring | Open-book format with application questions |
| High (>=40% of grade, certifications) | Live or hybrid proctoring | In-person testing or portfolio assessment |
Student Rights: Tell Students This Before Every Proctored Exam
- What data is collected (video, audio, screen, biometric, environmental)
- How data is used and who has access (vendor, instructors, subcontractors)
- How long data is retained and where it is stored
- How to request data deletion
- What happens if technology fails during the exam
- Alternative assessment options
- Accommodation process for students with disabilities
How to Implement Safe Exam Browser: Step-by-Step
Safe Exam Browser is free, open-source, and natively integrated with Moodle 3.9+. Download the current release from the official Safe Exam Browser downloads page before every exam cycle. As of May 2026, the official page lists Windows 3.10.1, macOS 3.6.1, and iOS/iPadOS 3.6.2; those version numbers will change over time.
SEB Server is an optional companion application that adds Screen Proctoring -- periodic screenshot capture during exams for post-exam review, without full video recording. It is free but requires your own server infrastructure.
What SEB Does and Doesn't Do
- Does: Lock the device into kiosk mode, disable keyboard shortcuts (Alt+Tab, Cmd+Tab, Print Screen), block other websites and files, prevent copy/paste, force full-screen, support multi-quiz sessions, and optionally capture screenshots via SEB Server.
- Does not: Monitor via webcam or microphone, verify student identity, detect a second device, prevent in-room collaboration, or track eye movement.
- Bottom line: SEB deters opportunistic cheating but cannot stop determined misconduct. Use it when you trust your question design more than surveillance.
Step 1: Choose Your Configuration Strategy
Option A: Browser Exam Key (simplest, weakest): Moodle generates a hash key to validate the browser. No SEB download required. Suitable for low-stakes quizzes only, students can potentially spoof the key.
Option B: SEB Client, Default Config (moderate): Students download SEB and use its default configuration. Suitable for mid-stakes assessments.
Option C: SEB Client with Custom Config File (strictest): You create a
.sebfile specifying exactly what is allowed -- whitelisted URLs, permitted tools, quit password. Students open the file to launch SEB pre-configured for your exam. Suitable for high-stakes exams.
Step 2: Configure Your Moodle Quiz
- Open your Quiz -> Edit settings
- Scroll to Extra restrictions on attempts -> Browser security
- Select your level: "Require the use of Safe Exam Browser" (any config) or "Require a Safe Exam Browser with exam configuration from this quiz" (your specific
.sebfile) - If using a custom config, click "Download this quiz's Safe Exam Browser config file"
- For institution-wide templates: Site Administration -> Plugins -> Activity Modules -> Quiz -> Safe Exam Browser
Step 3: Create a Custom Config (Optional)
- Download the SEB Config Tool from safeexambrowser.org
- File -> New Configuration
- Set: quit password, allowed/blocked URLs, file upload permissions, permitted utilities
- Configuration -> Exam URL -- paste your quiz URL and set a Quit URL
- Save as a descriptive
.sebfile and upload to your Moodle course Files area
Step 4: Test, Communicate, and Support
Test first: Run the config yourself -- attempt to switch apps, access blocked sites, and copy/paste. Then pilot with 5-10 students across different operating systems.
Known platform issues:
- macOS may require explicit accessibility permissions on first launch.
- Official SEB downloads cover Windows, macOS, and iOS/iPadOS. Do not assume Android, Linux, or Chromebook support without a tested institutional path.
- For unsupported devices, plan a Browser Exam Key fallback, managed-device lab, or alternative assessment.
Communicate 2 weeks before the exam via announcement and email:
This exam requires Safe Exam Browser (SEB) -- a free lockdown browser.
- Download the current SEB version for your platform from safeexambrowser.org. Official downloads cover Windows, macOS, and iOS/iPadOS.
- Install and launch once to confirm it works
- Download the exam config file: [link]
- On exam day, double-click the config file to begin
Also, create a no-stakes practice quiz with SEB enabled so students can verify their setup before the real exam.
On exam day: Set up a dedicated support channel. Common fixes: add SEB to antivirus exceptions if it won't launch; provide the quit password if a student accidentally closes SEB; offer Browser Exam Key mode as a fallback for incompatible devices. Log all incidents with timestamps.
Step 5: Evaluate After the Exam
- Did SEB prevent the specific type of cheating you were concerned about?
- Did technical issues affect any students' ability to complete the exam?
- Would a better question design achieve the same integrity goals with less friction?
Decision Framework: Choosing the Right Approach
Question 1: What are the stakes?
- <=10% of grade (formative, practice) -> No proctoring or SEB lockdown only
- 15-35% of grade (midterms) -> Continue to Question 2
=40% of grade (finals, certifications) -> Continue to Question 3
Question 2: What is your primary concern?
- Deterring casual cheating -> SEB lockdown (free)
- Evidence for academic integrity cases -> Recorded proctoring with AI flagging
- Accreditation or institutional policy compliance -> Hybrid AI + human review
Question 3: What is your risk tolerance?
- Low -- stakes justify maximum security -> Live proctoring
- Moderate -- balance cost and security -> Hybrid AI + live review of flagged incidents
- Privacy-conscious institution with strong question design -> Recorded proctoring or well-designed open-book exam
Question 4: What are your compliance obligations?
- EU/EEA students -> vendors with documented GDPR posture, DPA terms, transfer mechanisms, and suitable hosting region
- California residents -> verify state privacy obligations, retention, deletion, and sale/share restrictions with counsel
- Students with disabilities -> Confirm vendor supports extended time, screen reader compatibility, flexible room scan requirements
Question 5: What is your budget?
- No budget -> SEB + smart question design
- Per-exam budget -> Automated or recorded proctoring; compare vendors on features vs. privacy record
- Semester/annual budget -> Campus licence (Respondus) or per-student flat rate (Honorlock)
- Enterprise -> ProctorU Live or YuJa Verity enterprise tier
Alternatives to Proctoring: Assessment Design That Reduces Surveillance Need
Before deploying surveillance, consider whether assessment redesign achieves the same integrity goals with less privacy impact.
- Open-Book, Application-Focused Exams Replace "Define photosynthesis" with "A plant in a sealed dark box maintains normal CO2 levels but stops growing. A second plant in a sealed box with light grows normally. Explain the difference." Students can look up the equation -- they cannot look up the reasoning for a novel scenario.
- Randomised Question Pools Create a question bank with 100+ items. Configure each quiz to randomly select 20. Each student sees a different subset -- collaboration becomes impractical. Randomise numerical parameters within questions for additional variation.
- Time-Boxed, Open-Note Exams Design 60 minutes of content into a 60-minute window. Students can use notes and textbooks. Questions require synthesis and application rather than lookup. Time pressure exposes lack of understanding.
- Portfolio or Project-Based Assessment Replace a single timed exam with staged submissions (proposal, draft, final). Staged feedback makes outsourcing obvious and impractical. Instructors develop detailed knowledge of each student's work over time.
- Oral Examinations 15-minute synchronous video conversations with randomised questions from a question bank, or asynchronous video responses. Difficult to outsource in real-time. Instructors can ask follow-up questions to probe understanding.
- Honour Code with Targeted Proctoring Default to unproctored exams with an honour code. Randomly proctor 10-20% of students, or focus proctoring resources on students with prior violations. Reduces surveillance burden while maintaining deterrence.
MooDIY's Proctoring Support: Infrastructure for Exam Day
Regardless of which proctoring solution you choose, your hosting infrastructure must handle the spike loads that exam windows create. A 300-student final exam at 10:00 AM generates simultaneous quiz launches, LTI connections to proctoring services, and database writes. If your server is underpowered, exams fail, and student panic escalates.
What MooDIY provides for exam-day reliability:
- Concurrency planning: We scope exam-window capacity against your expected simultaneous quiz launches, LTI handshakes, and database writes.
- Monitoring and support: Enterprise plans can include scheduled exam-window monitoring and support commitments documented in the commercial agreement.
Ready to run your next exam on infrastructure built for it? Explore MooDIY hosting plans
Related reading: See our high-concurrency quiz guide for handling exam-day traffic, explore the best Moodle plugins for assessment tools, or review Moodle performance optimizations.
Research References
- Market Trends & Student Sentiment
- Market Report 2026-2035: Online Exam Proctoring Market Size & Growth 2026
- Student Privacy Survey: Global Student Impact & Privacy Discomfort Report
- Software & Technical Specs
- Safe Exam Browser (SEB): SEB Download Latest Releases
- SEB Screen Proctoring: SEB Server: Screen Proctoring Documentation
- Legal and Privacy References
- GDPR official text: Regulation (EU) 2016/679
- US Department of Education: FERPA guidance
- California Office of the Attorney General: CCPA overview
