How to Run Exam Monitoring in Italy Without Getting Fined

24 August, 2026

Three Italian institutions. Three fines. The same underlying mistake each time. Italian regulators are not rejecting biometric monitoring. They are rejecting the way institutions keep deploying it.

In brief

  • Three Italian institutions have been fined for biometric or camera-based monitoring: Bocconi University (initially €200,000; later reduced to €150,000), eCampus University (€50,000), and a secondary school (€4,000).
  • Across all three cases, the regulator found no adequate statutory basis for the biometric processing, even though the underlying institutional purpose was legitimate.
  • The systems that survive review establish legal basis first, document every decision, and keep a human in the loop.

In 2021, Bocconi University received a €200,000 fine from the Italian Data Protection Authority after its remote exam-proctoring system processed biometric data without adequate transparency or legal basis. Subsequent court proceedings resulted in the official sanction being recorded as €150,000. In 2026, eCampus University was fined €50,000 for using facial recognition to verify attendance in online courses without establishing lawful grounds. In 2025, a secondary school was fined €4,000 for fingerprint-based staff attendance without an adequate legal basis.

 

The pattern is not coincidence. It is a signal. Italian regulators scrutinize biometric systems in education because institutions keep deploying them without the governance the law requires. So the question is not whether to monitor exams. It is how to do it in a way that survives regulatory review.

What Italian regulators are actually looking for

Every fine involved the same core finding: absence of statutory authorization to use biometric data for the stated purpose, despite acknowledging that the underlying institutional goal (exam integrity, attendance verification, security) was legitimate.

 

This is the operational gap. Institutions typically ask "Can we use this technology?" after they have already chosen a vendor. Compliant institutions ask a different question first: "Do we have lawful permission for the specific data this system collects?" They ask it before procurement starts.

 

For remote exam proctoring, an institution must identify an appropriate legal basis for the personal data involved and, where biometric data are processed, a valid condition for processing special-category data. It must also document proportionality, why less intrusive methods would not work, and whether a data-protection impact assessment is required before implementation.

 

Institutions that get this right build legal review into the project timeline. They do not retrofit compliance after choosing the tech. They do not discover governance gaps during a regulatory review.

The research behind this article

This piece summarizes our full market-research paper, Camera-Based AI in Italian Classrooms: The State of Evidence, including sources and methodology.

The five gaps behind the fines

Transparency as an afterthought. Bocconi's fine specifically cited the failure to provide clear information about what monitoring occurred and how data would be used. In Italy, transparency means documented, up-front disclosure at registration, not a privacy policy read at exam time.

Data collection without limits. Bocconi and eCampus both faced findings related to data minimisation or retention in exam and online-attendance contexts. Institutions should define what data is necessary, how long it will be retained, and why.

Human accountability must be clear. In the Bocconi case, the software flagged anomalies and the teacher made the final decision. Human review is important, but it does not replace the need for a lawful basis and appropriate safeguards.

 

Alternatives must be assessed. Bocconi offered alternative exam arrangements, and the Tropea school also had a badge-based option. Institutions still need to document necessity and whether the same purpose can be achieved through a less intrusive method.

 

Contracts are necessary but not sufficient. Universities with processor agreements and Standard Contractual Clauses for cross-border data transfers still face regulatory scrutiny if they don't verify the safeguards work in practice. Institutions must assess the actual processing, not rely on contract wording alone.

 

Building systems that survive review

Institutions planning remote proctoring in Italy should not build the technology first and add compliance second. They should treat the evidence and governance layer as a design requirement.

 

In practice, that means establishing the legal basis before launch, documenting key decisions, assigning human accountability, and providing clear information about what monitoring will occur and how long data will be retained.

 

Constructor Proctor is built for this Italian pathway. It requires you to specify your legal basis before exam configuration, supports Italian data residency, and provides templated Data Processing Agreements aligned to Italian regulation. Every verification is documented with human review, so when a regulatory review arrives, the institutional decision-making is already on record.

Discover Constructor Proctor

See how Constructor Proctor documents legal basis, human review, and Italian data residency before an exam goes live.