Template

A DPIA template for learner engagement analytics

If you are deploying any form of engagement monitoring to employees or students, you almost certainly need a DPIA. This is the structure, with the questions that specifically matter for this category.

9 min read
In short

A DPIA is required for systematic monitoring of employees or students. For engagement analytics it should cover: the lawful basis, whether biometric data is processed, whether emotional states are inferred, the EU AI Act Article 5 position, necessity and proportionality against less intrusive alternatives, retention, and the outcome of consultation with affected people.

When you need one

Under GDPR Article 35 a DPIA is required where processing is likely to result in high risk. Engagement analytics in training or education will usually trigger at least one, and often several, of the standard criteria:

Two or more criteria means a DPIA is effectively mandatory. For most engagement analytics deployments, you will hit three or four.

Section 1 — Describe the processing

Set out the facts before you assess anything.

Field What to record
Purpose Be specific. "Improve training" is too vague. "Identify which sections of mandatory compliance modules cause learner drop-off, to prioritise content redesign" is assessable.
Data subjects Employees, students, contractors. Include numbers and whether any are minors.
Data categories List every field. Behavioural events, timestamps, session identifiers, any biometric data, any derived scores.
Signal sources Which APIs and inputs. Page Visibility, focus events, camera, microphone.
Derived outputs Engagement scores, predictions, risk flags. Note whether these are individual or aggregate.
Recipients Who sees what. Managers? Instructors? Only the content team?
Retention How long, and what triggers deletion.
Transfers Any processing outside the UK/EEA, and the transfer mechanism.
Processors The vendor and any sub-processors.

The single most useful thing you can do in this section is draw the data flow. Where does each signal originate, where is it computed, what leaves the device, what is stored and for how long. Most problems become obvious in the diagram before they appear in the analysis.

Section 2 — Necessity and proportionality

This is the section that decides the outcome, and the one most often written thinly.

Answer honestly:

  1. What is the actual purpose, and does this processing achieve it? If the purpose is content improvement, individual-level data may not be necessary at all.
  2. What is the least intrusive way to achieve it? Document the alternatives you considered and why you rejected them. If a behavioural-only approach would achieve the same purpose, deploying facial analysis is very difficult to justify as proportionate.
  3. What is your lawful basis? For employee monitoring, consent is fragile — it is rarely freely given in an employment relationship. Legitimate interests requires a documented balancing test. Public task may apply for some education institutions.
  4. If special category data is involved, what is your Article 9 condition? Biometric data processed for identification purposes needs one.
  5. How do you ensure accuracy? What is the error rate, and what happens to someone incorrectly flagged?
  6. What are people told, and when? Transparency obligations under Articles 13–14.
  7. How do people exercise their rights? Access, objection, and where automated decision-making is involved, Article 22 rights.

Section 3 — The AI Act screen

This section is specific to this category and did not exist in older DPIA templates. It comes before the risk assessment, because it is a gating question rather than a risk to be mitigated.

Work through the four-part test:

Question Answer If yes
Is it an AI system under Art. 3(1)? Continue
Does it infer emotions? Continue
From biometric data (Art. 3(34))? Continue
In a workplace or education context? Prohibited under Art. 5(1)(f)

If all four are yes, stop. The medical and safety exception is narrow — CE-marked therapeutic devices, or protecting life and health. General wellbeing monitoring does not qualify.

This is a stop, not a risk

If the Article 5 screen comes back positive, there is no mitigation that makes the processing lawful. No consent, no works council agreement, no DPIA conclusion. You change the system or you do not deploy it. Record this clearly so the decision is auditable.

Also record the vendor's written position, the specific configuration deployed, and any change-control commitment preventing emotion inference being enabled in a later release.

Section 4 — Risks and mitigations

Assess each risk for likelihood and severity, then record the residual position after mitigation.

Risk Typical mitigation
Function creep — engagement data used for performance management Contractual and policy prohibition; restrict access to content team only
Chilling effect on learners Transparency; content-level rather than individual reporting
Inaccurate inference leading to unfair treatment No automated decisions about individuals; human review; documented error rates
Discriminatory impact on disabled or neurodivergent people Impact assessment; opt-out; avoid gaze and expression-based signals
Excessive retention Defined retention schedule; automatic deletion
Re-identification of aggregated data Minimum cohort size before reporting; k-anonymity threshold
Security of transmitted data Encryption in transit and at rest; client-side processing where possible
Scope creep to new populations Change control requiring DPIA review

The mitigation that does the most work across this whole table is reporting at content level rather than individual level. It addresses function creep, chilling effect, unfair treatment and re-identification simultaneously, and for most engagement analytics use cases it costs you nothing — you wanted to know which module to fix.

Section 5 — Consultation

GDPR Article 35(9) requires you to seek the views of data subjects or their representatives where appropriate.

For employee monitoring this means works councils or trade unions where they exist. In Germany, the Netherlands and much of the Nordics, works council agreement is a practical prerequisite rather than a courtesy. For education, it means student representatives.

Record what you asked, what they said, and what you changed as a result. A consultation that changed nothing invites the inference that it was performative.

Section 6 — Sign-off

Field
DPO advice
Residual risk rating
Article 36 prior consultation needed? Required if high risk remains after mitigation
Approved by
Date
Review date Set one — annually, or on any material change

The proportionality trap

One argument sinks more of these assessments than any other, and it is worth understanding before you start rather than after.

Proportionality asks whether you could achieve the same purpose by less intrusive means. In engagement analytics, the answer is frequently yes — and the evidence base says so.

Research published in 2024 found tab-switching to be the strongest single predictor of disengagement in online courses, outperforming self-regulation and satisfaction measures. Studies adding facial expression to behavioural signals report accuracy moving from roughly 91.5% to 94.6%.

So if you are justifying camera-based monitoring, you are arguing that roughly three percentage points of classification accuracy justifies processing biometric data from employees or students who cannot meaningfully refuse. That is a hard argument to win in front of a regulator, and a harder one in front of a works council.

The corollary is straightforward: a behavioural-only deployment makes Section 2 and Section 4 dramatically easier to complete, and turns Section 3 into a single line.

Frequently asked questions

Do I need a DPIA for behavioural-only engagement tracking?
Usually yes, if it involves systematic monitoring of employees or students, because the power imbalance makes it high risk regardless of how benign the signals are. The DPIA will be much easier to complete and much more likely to conclude favourably, because you are not processing special category data and the proportionality argument is far stronger.
Can I skip the DPIA if data is aggregated?
If you genuinely never process personal data — collection is anonymous at source and no individual can be identified or singled out — then GDPR does not apply and a DPIA is not required. That is a high bar. Aggregating after collection does not qualify, because the personal data existed at the collection stage.
Who signs off a DPIA?
Your Data Protection Officer if you have one, otherwise the accountable data controller. Where residual high risk remains after mitigation, GDPR Article 36 requires prior consultation with the supervisory authority before processing begins.
How does the AI Act change the DPIA?
It adds a screening step that comes logically first. A DPIA assesses how to conduct processing lawfully. The AI Act asks whether the practice is permitted at all. If Article 5(1)(f) applies, no DPIA outcome makes the processing lawful — you stop rather than mitigate.

Need the vendor-side answers for your DPIA?

We'll complete your supplier assessment, data-flow section and sub-processor list — usually within two working days.

Request the DPIA pack
Get Started

See what completion rates can't tell you

Find out exactly where your content works, where it fails, and what disengagement looks like before people leave.

Request a Demo