Skip to content

StudyDrome Security

GDPR Compliance at StudyDrome: Your Students’ Data Deserves the Best Protection

What’s scarier than a security breach?

Losing the trust of your students, your colleagues—and risking fines that can devastate your institution.

🔒 StudyDrome makes sure that never happens.


Your Students’ Privacy is on the Line. Are You Fully Covered?

In today’s digital learning environment, protecting personal data isn’t just nice to have—it’s a legal requirement.

GDPR, ISO standards and rising cyber threats all add pressure. Instructors and training managers like you must guard sensitive information, and prove that you did.

But how can you stay focused on teaching while also staying compliant?

That’s exactly where StudyDrome steps in.

We’re not just another learning platform. We’re built with compliance, security, and peace of mind baked into every feature—so you can focus on what matters: empowering your learners.


Why StudyDrome’s GDPR Compliance Gives You an Unbeatable Edge

At StudyDrome, we treat security as mission-critical, not optional.

Here’s how we deliver enterprise-grade protection—and why it matters to you.

1. Sign-In and Sessions You Stay in Charge Of

What it is:

Your people sign in the way your institution already signs in. StudyDrome supports OpenID Connect per institution, with Google, Microsoft, Okta and generic providers.

How it works:

Two set-up modes are available. Just-in-time creates a recognised user on first sign-in. The other mode requires the account to exist already.

Sessions are token-based. A short-lived token pairs with a longer one held on our servers, never in the browser alone. Refreshing rotates both, and the old one stops working at once. Ending a session is an action, not a wait for it to expire.

The benefit to you:

  • Your own password rules, MFA and joiner-leaver process apply on day one.
  • Users can see their active sessions—address, browser, start time—and end any of them.
  • An administrator can end every session for a user at once.
  • Disabling an account ends its sessions with it.

Real-World Example:

A laptop goes missing the night before finals. The owner opens their session list, ends that session, and the device is locked out before anyone touches an exam.


2. Control Over Who Sits the Exam, and From Where

What it is:

Every exam carries its own access layers. You set them per exam, and each one works on its own.

How it works:

  • Access codes — shared across a cohort, or unique to each candidate.
  • Address rules — an allow-list, checked when a candidate prepares, starts and resumes. It fails closed: an address it cannot read is refused, never waved through.
  • Device binding — an attempt can be tied to the browser it began on. An invigilator can release that binding when hardware fails.
  • Academic holds — a hold carrying the exam-access restriction is checked before any code or address rule.

Violations caught in the exam player are recorded on our servers, against the attempt. Each attempt gets a conduct report with a timeline.

The benefit to you:

  • A candidate sitting from an unapproved location is stopped, not discovered afterwards.
  • Casual attempt-sharing is blocked without installing anything on their machine.
  • Every incident leaves a record you can show.

3. A Record of Every Change

What it is:

A shared audit layer runs across modules. It answers who changed this, and when—without anyone having to remember.

How it works:

Creates, updates, deletes, soft-deletes and restores are each captured as their own kind of event. A delete keeps the full prior value, not a summary. Sensitive field names are redacted as they are captured. Personal data is masked again on render. You set how long records are kept.

Several areas keep their own history alongside that layer:

  • Every grade, re-grade and un-grade writes its own row. Nothing is overwritten.
  • Question edits are stored as sequential versions.
  • Question banks keep a change history.
  • Proctor messages are stored with their delivery status, so you can show what a candidate was told.

The benefit to you:

  • An appeal is answered with a record, not a recollection.
  • A grade dispute shows every mark the paper ever carried.
  • Your data protection officer can see what personal data was touched, and by whom.

GDPR Compliance = Competitive Advantage (Not Just Risk Avoidance)

Still thinking of GDPR as "just paperwork?"

Here’s why your clients, students, and stakeholders will prefer working with you when you partner with StudyDrome:

✅ Build Trust Instantly: Students and parents demand transparency. GDPR-compliant platforms win that trust faster.

✅ Win Bigger Contracts: Corporate clients and schools increasingly require GDPR-proof platforms when signing deals.

✅ Avoid Fines & Legal Risks: Breaches are expensive—non-compliance even more so.

✅ Focus on Learning, Not Legal Stress: With StudyDrome’s GDPR-first approach, you spend less of your week on compliance admin.


Here’s What You Get When You Choose StudyDrome

✔ Data separated per institution, enforced in the database layer itself

✔ Granular permissions, so a role grants exactly what it should and nothing more

✔ Your own identity provider, over OpenID Connect

✔ Exam-time access controls: codes, address rules, device binding and holds

✔ A full audit trail, with sensitive fields redacted and personal data masked

✔ Expiring, signed links for every uploaded file

✔ Written isolation reviews per module, checked before each release

Book a pilot →

StudyDrome’s commitment to GDPR compliance means educational institutions and corporate training programs can trust the platform with their sensitive data.

Isolation between institutions. Granular permissions. Exam-time access controls. A full audit trail. All of it is built into the product, not bolted on. That gives users peace of mind, and lets them focus on delivering impactful learning experiences.

This robust security framework positions StudyDrome as a reliable partner in today's data-conscious educational landscape.

Need more than this page covers? Hosting, data handling, sub-processors, your own review—talk to us directly. We answer in writing.