NoldusViso
HIPAA, GDPR, and FERPA compliant video recording for research and clinical labs
NoldusViso, the Noldus AV recording tool, is used across psychology, healthcare, education, user experience research, and more. In every one of these fields, NoldusViso is built to protect your data.
Data protection is a fundamental right to privacy. On a practical level, it's what makes trust between people and organizations possible.
Noldus Information Technology, Wageningen is ISO/IEC 27001 certified. Our information security management system is independently audited by an accredited certification body.
ISO 27001 Certification arrow_forward
Your data never leaves your control
NoldusViso is a hybrid system. It's installed locally, connects to your own network, and connects to the internet only if you want it to. Your recordings stay on your infrastructure, inside your security perimeter, under your administrators' control. Noldus never receives, stores, or processes the data you collect. It is never on a Noldus server and never in Noldus storage.
Noldus does not require access to any video files, secure health information, or educational records. Even when we provide technical support or perform upgrades, all our activities are carried out independently of participant information access.
Noldus does not maintain an active connection to any NoldusViso system at any time. Such a connection can only be initiated, authorized, and supervised by NoldusViso users.
Because your research data never reaches us, there's no third-party cloud in the chain, no data transfer to authorize, and no list of external processors to review.
How NoldusViso is secured
Password encryption
NoldusViso can integrate with your own LDAP or generate encrypted local credentials. Passwords must contain at least 8 characters with at least one uppercase, one lowercase, one number, and one special character. They must not contain your username nor match any of your last three passwords. Two-factor authentication protects every account, including administrators.
Sophisticated user management
Configurable, role-based access control and user roles determine who can see, play, export, or delete each recording.
Encryption in transit
All traffic between clients, cameras, and the server is protected with strong encryption in transit.
Encryption at rest
NoldusViso facilitates encryption at rest, so recordings can be protected on your own storage under your own key management.
Retention policies
Your administrator sets retention periods. Recordings and audit data are removed automatically when the period expires. There is no manual clean-up and no forgotten archives.
Audit trails
Every login, view, export, and administrative change is logged and time-stamped, with configurable retention. A complete log of all activity regarding video creation, deletion, and access. The retention period can be set to comply with GDPR and HIPAA.
Privacy switches
Physical privacy switches let participants and staff see, and control, when a room is live. Turn on a black mask within the camera itself and use an optional light to indicate live or recording feed status.
Modern technology stack
NoldusViso is built on a modern technology stack, easy to update and upgrade to meet the latest security demands, and easy to support and maintain. If necessary, and only after customer approval and coordination, a remote connection can be made to provide technical support.
Applicable legislations
Noldus complies with the governing laws presiding over our customers' data protection. The legislation of the European Union (EU) and the United States (US) is most prominent.
GDPR
In the EU, the General Data Protection Regulation (GDPR) went into effect on 25 May 2018. GDPR applies to all forms of data that target or are collected in relation to people in the EU. As a global professional IT company, Noldus complies with all GDPR regulations.
Under the GDPR, your organization is the controller of the recordings you make. Because NoldusViso runs on your own infrastructure and Noldus never receives your data, we are not a processor of your research data. There's no transfer outside your organization to safeguard and no external processor in the chain. You set retention periods, you control access through role-based permissions, and every access is logged.
Noldus has an appointed Data Protection Officer for the personal data we hold as a company, such as contact details. See our Privacy Policy.
HIPAA / HITECH
HIPAA protects patients' medical records with rules on collecting and storing patient information. HITECH supports health information management across computerized systems and the secure exchange of health information.
For HIPAA and HITECH, the architecture does most of the work. Protected health information (PHI) stays inside your network: NoldusViso is installed locally, connects to your own systems, and reaches the internet only if you allow it. Noldus never receives recordings or health information.
On top of that, technical safeguards are built in: two-factor authentication (2FA), role-based access control down to the individual recording, strong encryption in transit, facilitated encryption at rest, automatic logout, administrator-set retention periods, and a complete, time-stamped audit trail of every access and export.
Do you need a Business Associate Agreement (BAA)?
No. Because NoldusViso runs on your infrastructure and Noldus doesn't access recordings or health information, Noldus is not normally a Business Associate under HIPAA. If your organization's policy requires an agreement, contact us and we'll review it with you.
FERPA
Recordings of students are education records under FERPA. NoldusViso keeps them inside your institution's own network, restricts access through role-based permissions, logs every view and export, and lets you set automatic retention periods per study.
Three layers of security
Administrative
Policies and procedures for selecting, developing, and maintaining security measures, plus employee training on identifying protected data.
Physical
Facility, workstation, and mobile device security is the responsibility of NoldusViso users, since Noldus never collects or transfers data.
Technical
Built-in user management with access levels, TLS encryption in transit, audit trail functionality, and automatic logout.
VPAT and EU AI Act statement
We are preparing a Voluntary Product Accessibility Template (VPAT) and a statement on how NoldusViso relates to the EU AI Act. These will be published here. Need them for a review already in progress? Contact us and we'll help.
Certifications
ISO/IEC 27001
Noldus Information Technology is ISO/IEC 27001 certified, independently audited by an accredited certification body. Read more.
GDPR
GDPR has no statutory compliance certification. All Noldus software and activity, including NoldusViso, is carefully screened against GDPR requirements.
HIPAA
HIPAA rules don't certify software or off-the-shelf products. Every Noldus employee who may be exposed to protected health information completes a training course.
Risk assessment documentation
Completing a security questionnaire or a vendor risk assessment? Send it to us — we're happy to help.
Contact us arrow_forwardLast reviewed: August 2026 · Version 2.0