Use this as a worksheet, not a completed assessment
A Data Protection Impact Assessment concerns a specific processing proposal. Copying a product description into a form does not establish necessity or acceptable residual risk. The organization proposing the processing needs accountable owners and the appropriate privacy/legal input.
GDPR Article 35 sets out the EU assessment framework. The ICO’s workforce biometric guidance provides UK context and is under statutory review. Check the rules applicable to your proposal.
Record the processing in concrete terms
Scroll the table sideways to read all columns.
| Worksheet field | Questions to answer |
|---|---|
| Purpose | What attendance problem requires this processing? |
| Population | Which workers, sites and devices are involved? |
| Capture | What camera, location and interaction inputs are collected? |
| Reference | Is a template stored, where, and who can retrieve it? |
| Matching | Is identity claimed first or searched across a roster? |
| Consequence | What happens to attendance, access and pay after failure? |
| Lifecycle | What is retained, deleted, backed up or transferred? |
Use the actual deployment, not assumptions about how every biometric product works. A kiosk need not scan passersby; record whether the chosen capture design does so.
Evaluate alternatives without predetermining the answer
List feasible non-biometric methods and the problem each does or does not address. Include accessibility, support, privacy and evidence quality. A worker consultation can reveal difficulties, but does not by itself establish freely given consent or prove that matching is necessary.
Where a worker cannot or does not use the normal flow, describe the alternative in enough detail to test it. “Contact a supervisor” needs an available person, a way to record the work and an accountable review.
Describe risk and mitigation separately
For each risk, record who may be harmed, the scenario, likelihood/severity reasoning, proposed control, evidence that the control works and remaining uncertainty. Avoid automatically assigning “medium residual risk” because a checklist has been completed.
Consider incorrect rejection, incorrect identification, unauthorized access, unnecessary retention and untrusted capture inputs. A server comparison does not alone resolve all of those risks.
Record a real decision and revisit changes
Identify the decision-maker, unresolved actions, launch conditions and review triggers. A changed purpose, population, model or device arrangement may require revisiting the assessment. Where applicable high residual risk remains, evaluate required regulator consultation rather than treating publication of a privacy page as approval.
For Attendify, verify the documented data boundary and controlled kiosk status. The existing enrollment interaction should not be assumed to settle every identification-purpose notice or fallback question.