Skip to content
CompliancePublished 16 August 2026 · Updated 6 September 2026 · 2 min read

A biometric attendance DPIA planning worksheet

Collect the system facts, alternatives, risks and unresolved decisions needed for a deployment-specific privacy assessment.

By Attendify Vision · Product-led guidance with sources and labeled examples.

Use this as a worksheet, not a completed assessment

A Data Protection Impact Assessment concerns a specific processing proposal. Copying a product description into a form does not establish necessity or acceptable residual risk. The organization proposing the processing needs accountable owners and the appropriate privacy/legal input.

GDPR Article 35 sets out the EU assessment framework. The ICO’s workforce biometric guidance provides UK context and is under statutory review. Check the rules applicable to your proposal.

Record the processing in concrete terms

Scroll the table sideways to read all columns.

Worksheet fieldQuestions to answer
PurposeWhat attendance problem requires this processing?
PopulationWhich workers, sites and devices are involved?
CaptureWhat camera, location and interaction inputs are collected?
ReferenceIs a template stored, where, and who can retrieve it?
MatchingIs identity claimed first or searched across a roster?
ConsequenceWhat happens to attendance, access and pay after failure?
LifecycleWhat is retained, deleted, backed up or transferred?

Use the actual deployment, not assumptions about how every biometric product works. A kiosk need not scan passersby; record whether the chosen capture design does so.

Evaluate alternatives without predetermining the answer

List feasible non-biometric methods and the problem each does or does not address. Include accessibility, support, privacy and evidence quality. A worker consultation can reveal difficulties, but does not by itself establish freely given consent or prove that matching is necessary.

Where a worker cannot or does not use the normal flow, describe the alternative in enough detail to test it. “Contact a supervisor” needs an available person, a way to record the work and an accountable review.

Describe risk and mitigation separately

For each risk, record who may be harmed, the scenario, likelihood/severity reasoning, proposed control, evidence that the control works and remaining uncertainty. Avoid automatically assigning “medium residual risk” because a checklist has been completed.

Consider incorrect rejection, incorrect identification, unauthorized access, unnecessary retention and untrusted capture inputs. A server comparison does not alone resolve all of those risks.

Record a real decision and revisit changes

Identify the decision-maker, unresolved actions, launch conditions and review triggers. A changed purpose, population, model or device arrangement may require revisiting the assessment. Where applicable high residual risk remains, evaluate required regulator consultation rather than treating publication of a privacy page as approval.

For Attendify, verify the documented data boundary and controlled kiosk status. The existing enrollment interaction should not be assumed to settle every identification-purpose notice or fallback question.

Keep reading