A DPIA is a structured assessment required under GDPR Article 35 where processing is likely to result in high risk to individuals. Systematic monitoring of employees or students almost always triggers it.
What it is
It documents the processing, assesses necessity and proportionality, identifies risks and mitigations, records consultation with affected people, and concludes with a residual risk rating.
Where high risk remains after mitigation, Article 36 requires prior consultation with the supervisory authority before processing begins.
Why it matters
For engagement analytics the proportionality section is usually decisive. If a less intrusive method would achieve the same purpose, deploying the more intrusive one is hard to justify — and behavioural signals achieving comparable predictive accuracy makes that argument difficult for camera-based systems.
A common confusion
A DPIA assesses how to conduct processing lawfully. The AI Act asks whether the practice is permitted at all. If Article 5 applies, no DPIA outcome makes it lawful — that is a stop, not a risk to mitigate.
Related
See also biometric data, emotion inference and air-gapped deployment. See the full glossary for the rest, or the DPIA template for the wider context.
See where your content loses people
Book a walkthrough and we will show you the engagement data on your own content.