AI Regulation Tracker / Enforcement and orders
Spain's AEPD Sanctions University Biometric Exam Proctoring
Spain's data protection authority, the AEPD, sanctioned Universidad Internacional de Valencia (VIU) for imposing a mandatory remote-exam monitoring system that used biometric facial recognition and a dual-camera setup on students. The AEPD found the biometric processing had no valid basis under Article 9 of the GDPR, and that consent obtained at enrollment was not free because students had no real alternative. The published legal-criteria summary is dated June 3, 2025, and the resolution can be appealed.
Here is what the system did, from the AEPD's account. The complaint targeted the Universidad Internacional de Valencia (VIU) over a remote exam-monitoring setup that students had to accept, with no valid alternative, to be assessed. The software used AI facial recognition to capture and analyze images in real time and verify each student's identity continuously during the exam. The AEPD describes a one-to-one comparison based on biometric data, with facial patterns generated and then deleted every few seconds. The system also monitored the student's desktop, capturing screens and detecting programs and connected peripherals, and used a second camera with AI to check the room for other people or forbidden objects. The university said the data was pseudonymized and quickly deleted, and its own data-protection impact assessment acknowledged a very high risk to the rights of those affected.
Why the legal basis collapsed
The AEPD anchored much of its analysis on the nature of the data. Biometric data used to identify a person is special-category data under Article 9 of the GDPR, as the European Data Protection Board confirmed in its Guidelines 5/2022. Article 9 sets a general prohibition on processing such data, lifted only when one of the exceptions in Article 9(2) applies. The AEPD found none applied here.
Consent, the exception under Article 9(2)(a), was the university's main argument. It said students agreed at several points: when reviewing the general terms, when enrolling, when registering their image in the software, and when installing the application. The AEPD rejected this. In the university's own educational ecosystem, the consent was not free, because there was no real and effective alternative. The software was the only permitted way to sit the online exams, and refusing it meant losing the right to be assessed. Mandatory acceptance of general terms at enrollment is not valid consent either.
The university also invoked an essential public interest under Article 9(2)(g), the fight against academic fraud. That failed too. The AEPD found no specific national law in the university-education field that expressly authorizes this biometric processing for remote exams. The general duty in Article 46.3 of the Organic Law on Universities to verify students' knowledge was not enough. Citing Spanish Constitutional Court judgments 292/2000 and 76/2019 and the case law of the European Court of Human Rights, the AEPD said a specific enabling law would be required, one that sets out the cases, conditions, and safeguards under which such biometric processing could take place.
The regulator did not close the door
This is the part worth reading carefully, because it is not a flat prohibition on the technology. The AEPD said it does not rule out using these systems, even AI systems, to identify students and prevent fraud in education. It noted that such systems are expressly treated as high-risk in Annex III of the EU AI Act. But it drew a clear line. The AI Act does not provide legal cover for the current use of this kind of technology in Spanish education. As the AI Act itself indicates, a national or European decision establishing the appropriate safeguards would be required first. In other words, being labeled high-risk under the AI Act is not permission to deploy. It is a signal that a separate, specific legal basis and a set of guarantees still have to exist.
Why this reaches US practice
The AEPD is a Spanish regulator applying EU law, and this decision binds no one in the United States. It still matters for two groups of US professionals. First, if you build or resell proctoring, exam-integrity, or biometric identity software, and any customer deploys it in the EU, this is a map of how the deal can fail. A polished impact assessment did not save the university. The regulator went straight to the legal basis and to whether the people being scanned had a genuine choice. Second, the reasoning travels. Wherever you deploy biometric checks on a captive audience, students, employees, applicants, the question of whether consent is truly free, and whether a specific legal basis exists, is the one a serious regulator asks first. Build a real, usable non-biometric alternative into the product, or expect the consent argument to fall apart under scrutiny.
What to do now
If your system processes biometric data, name the Article 9 exception you rely on before you ship, not after a complaint. Do not lean on consent when the user cannot realistically refuse. A student who must be graded, or an employee who must clock in, is not giving free consent to a face scan if there is no other way through. Where you claim a public-interest or legal-obligation basis, check that a specific law actually authorizes the biometric processing, rather than a general duty that only implies it. And treat an AI Act high-risk classification as extra obligations, not as a shortcut past your GDPR legal basis.
Questions professionals are asking
Why did the consent argument fail?
The AEPD found the consent was not free. The proctoring software was the only permitted way to sit the online exams, so a student who refused lost the right to be assessed. Consent given inside that closed university ecosystem, or through mandatory acceptance of general terms at enrollment, did not meet the GDPR standard for free consent.
Did the AEPD ban AI proctoring outright?
No. The regulator said it does not rule out using such systems, even AI systems, to identify students and prevent fraud. It found the current deployment unlawful because there was no valid Article 9 basis, and said a specific enabling law with proper safeguards would be needed first. The EU AI Act, which treats these systems as high-risk, does not by itself provide that legal cover.
Does this decision apply in the United States?
Not as law. The AEPD applies the GDPR to a Spanish body. For US readers it is a comparative benchmark. US vendors selling proctoring or biometric identity tools into the EU should treat the buyer's legal basis and the freedom of any consent as deal risk, and the same reasoning is useful anywhere biometric checks are imposed on people who cannot easily refuse.
Does this briefing report the fine or file number?
No. The AEPD's published legal-criteria summary sets out the reasoning but does not state a penalty amount or a file number in the text reviewed. Consistent with our sourcing policy, we do not publish figures or reference numbers we cannot see in the official source. The full resolution is published separately in the AEPD's Resoluciones section.
RELATED BRIEFINGS
Browse the full AI Regulation News tracker
Informational analysis for working professionals, not legal advice. Confirm how any resolution, statute, or requirement applies to your situation with qualified professionals in the relevant jurisdiction.