A DPIA is required for systematic monitoring of employees or students. For engagement analytics it should cover: the lawful basis, whether biometric data is processed, whether emotional states are inferred, the EU AI Act Article 5 position, necessity and proportionality against less intrusive alternatives, retention, and the outcome of consultation with affected people.
This template reflects the standard ICO and EDPB DPIA structure applied to this specific category of processing. Your DPO or legal counsel should review the completed assessment.
When you need one
Under GDPR Article 35 a DPIA is required where processing is likely to result in high risk. Engagement analytics in training or education will usually trigger at least one, and often several, of the standard criteria:
- Systematic monitoring of people, including in the workplace
- Evaluation or scoring, including profiling and prediction of behaviour
- Data processed at scale
- Vulnerable data subjects — employees and students both qualify, because of the power imbalance
- Innovative use of technology
- Biometric data, if facial or voice analysis is involved
Two or more criteria means a DPIA is effectively mandatory. For most engagement analytics deployments, you will hit three or four.
Section 1 — Describe the processing
Set out the facts before you assess anything.
| Field | What to record |
|---|---|
| Purpose | Be specific. "Improve training" is too vague. "Identify which sections of mandatory compliance modules cause learner drop-off, to prioritise content redesign" is assessable. |
| Data subjects | Employees, students, contractors. Include numbers and whether any are minors. |
| Data categories | List every field. Behavioural events, timestamps, session identifiers, any biometric data, any derived scores. |
| Signal sources | Which APIs and inputs. Page Visibility, focus events, camera, microphone. |
| Derived outputs | Engagement scores, predictions, risk flags. Note whether these are individual or aggregate. |
| Recipients | Who sees what. Managers? Instructors? Only the content team? |
| Retention | How long, and what triggers deletion. |
| Transfers | Any processing outside the UK/EEA, and the transfer mechanism. |
| Processors | The vendor and any sub-processors. |
The single most useful thing you can do in this section is draw the data flow. Where does each signal originate, where is it computed, what leaves the device, what is stored and for how long. Most problems become obvious in the diagram before they appear in the analysis.
Section 2 — Necessity and proportionality
This is the section that decides the outcome, and the one most often written thinly.
Answer honestly:
- What is the actual purpose, and does this processing achieve it? If the purpose is content improvement, individual-level data may not be necessary at all.
- What is the least intrusive way to achieve it? Document the alternatives you considered and why you rejected them. If a behavioural-only approach would achieve the same purpose, deploying facial analysis is very difficult to justify as proportionate.
- What is your lawful basis? For employee monitoring, consent is fragile — it is rarely freely given in an employment relationship. Legitimate interests requires a documented balancing test. Public task may apply for some education institutions.
- If special category data is involved, what is your Article 9 condition? Biometric data processed for identification purposes needs one.
- How do you ensure accuracy? What is the error rate, and what happens to someone incorrectly flagged?
- What are people told, and when? Transparency obligations under Articles 13–14.
- How do people exercise their rights? Access, objection, and where automated decision-making is involved, Article 22 rights.
Section 3 — The AI Act screen
This section is specific to this category and did not exist in older DPIA templates. It comes before the risk assessment, because it is a gating question rather than a risk to be mitigated.
Work through the four-part test:
| Question | Answer | If yes |
|---|---|---|
| Is it an AI system under Art. 3(1)? | Continue | |
| Does it infer emotions? | Continue | |
| From biometric data (Art. 3(34))? | Continue | |
| In a workplace or education context? | ⛔ Prohibited under Art. 5(1)(f) |
If all four are yes, stop. The medical and safety exception is narrow — CE-marked therapeutic devices, or protecting life and health. General wellbeing monitoring does not qualify.
If the Article 5 screen comes back positive, there is no mitigation that makes the processing lawful. No consent, no works council agreement, no DPIA conclusion. You change the system or you do not deploy it. Record this clearly so the decision is auditable.
Also record the vendor's written position, the specific configuration deployed, and any change-control commitment preventing emotion inference being enabled in a later release.
Section 4 — Risks and mitigations
Assess each risk for likelihood and severity, then record the residual position after mitigation.
| Risk | Typical mitigation |
|---|---|
| Function creep — engagement data used for performance management | Contractual and policy prohibition; restrict access to content team only |
| Chilling effect on learners | Transparency; content-level rather than individual reporting |
| Inaccurate inference leading to unfair treatment | No automated decisions about individuals; human review; documented error rates |
| Discriminatory impact on disabled or neurodivergent people | Impact assessment; opt-out; avoid gaze and expression-based signals |
| Excessive retention | Defined retention schedule; automatic deletion |
| Re-identification of aggregated data | Minimum cohort size before reporting; k-anonymity threshold |
| Security of transmitted data | Encryption in transit and at rest; client-side processing where possible |
| Scope creep to new populations | Change control requiring DPIA review |
The mitigation that does the most work across this whole table is reporting at content level rather than individual level. It addresses function creep, chilling effect, unfair treatment and re-identification simultaneously, and for most engagement analytics use cases it costs you nothing — you wanted to know which module to fix.
Section 5 — Consultation
GDPR Article 35(9) requires you to seek the views of data subjects or their representatives where appropriate.
For employee monitoring this means works councils or trade unions where they exist. In Germany, the Netherlands and much of the Nordics, works council agreement is a practical prerequisite rather than a courtesy. For education, it means student representatives.
Record what you asked, what they said, and what you changed as a result. A consultation that changed nothing invites the inference that it was performative.
Section 6 — Sign-off
| Field | |
|---|---|
| DPO advice | |
| Residual risk rating | |
| Article 36 prior consultation needed? | Required if high risk remains after mitigation |
| Approved by | |
| Date | |
| Review date | Set one — annually, or on any material change |
The proportionality trap
One argument sinks more of these assessments than any other, and it is worth understanding before you start rather than after.
Proportionality asks whether you could achieve the same purpose by less intrusive means. In engagement analytics, the answer is frequently yes — and the evidence base says so.
Research published in 2024 found tab-switching to be the strongest single predictor of disengagement in online courses, outperforming self-regulation and satisfaction measures. Studies adding facial expression to behavioural signals report accuracy moving from roughly 91.5% to 94.6%.
So if you are justifying camera-based monitoring, you are arguing that roughly three percentage points of classification accuracy justifies processing biometric data from employees or students who cannot meaningfully refuse. That is a hard argument to win in front of a regulator, and a harder one in front of a works council.
The corollary is straightforward: a behavioural-only deployment makes Section 2 and Section 4 dramatically easier to complete, and turns Section 3 into a single line.
Frequently asked questions
Do I need a DPIA for behavioural-only engagement tracking?
Can I skip the DPIA if data is aggregated?
Who signs off a DPIA?
How does the AI Act change the DPIA?
Need the vendor-side answers for your DPIA?
We'll complete your supplier assessment, data-flow section and sub-processor list — usually within two working days.