THE GIST
Biometric data collected in schools is increasingly framed as educational insight. But whose insight is it, really? This post examines what happens when the body becomes a data artefact in institutional hands, and why the absence of meaningful consent frameworks is a problem the sector is not yet taking seriously.
There is something quietly unsettling about the phrase “student engagement data.”
It sounds neutral. Managerial, even. But spend a moment with what it can mean in practice. Cameras inferring attention from eye movement. Wearables logging heart rate during exams. Facial recognition tracking emotional states during lessons. The body, rendered legible to an algorithm.
This is not science fiction. It is already happening in schools across multiple countries, and the pace is accelerating. A 2021 review by Prinsloo and colleagues catalogued over forty distinct EdTech products collecting some form of physiological or biometric data from students, ranging from activity trackers to full-face affect detection software (Prinsloo et al., 2021). The UK market is not immune. A 2023 report from the Centre for Data Ethics and Innovation found that schools were among the least well-equipped institutions to assess the data practices of the products they were adopting (CDEI, 2023).
My own research into biometric data in education, developed through projects including DataDrivenDance, has consistently surfaced a tension that institutions rarely name directly. The data collected from bodies is positioned as being for students. Yet students rarely see it, rarely control it, and are almost never asked whether they consent to its collection in any meaningful sense.
The concept I have been developing ‘body as a data artefact’ is useful here (Smith-Nunes, 2023, 2025). When a person’s physical characteristics become persistent digital records, that data does not simply describe the body. It becomes a version of it. One that can be stored, analysed, shared, or sold long after the lesson ends. Unlike a test score or a teacher’s written comment, a biometric record carries something more intimate. It is derived from physiology. It is, in some respects, closer to a medical record than a grade.
When a person’s physical characteristics become persistent digital records, that data does not simply describe the body. It becomes a version of it.
This matters for several reasons. First, biometric data collected in childhood creates a longitudinal record that may follow an individual into adult contexts (employment, insurance, credit) in ways that were never anticipated at the point of collection. The concept of contextual integrity, developed by Nissenbaum (2010), is instructive here. Information flows appropriately when they match the norms of the context in which they were shared. Data collected in a Year 9 maths lesson does not belong in a recruitment algorithm fifteen years later. But without robust legal barriers, that journey is not impossible.
Second, the aggregation problem compounds the risks. Any single data point — heart rate, eye fixation duration, facial expression — may seem trivial in isolation. In combination, and over time, these data points can construct a detailed portrait of an individual’s cognitive and emotional life. Soares and colleagues (2021) demonstrated that multimodal biometric data collected in educational settings could reliably predict not only engagement but also anxiety levels and learning disabilities that had not been formally identified. That is a powerful capability. It is also one that raises profound questions about who has the right to make such inferences about children, under what conditions, and with what consequences.
The UK’s Children’s Code, enforced from 2021 by the Information Commissioner’s Office, offers some protection for young people’s personal data online (ICO, 2021). But the classroom is a different jurisdiction in practice. The Code applies to online services, not to hardware devices operating on school networks. Schools operate under procurement pressures that make robust data governance difficult. Decisions are made quickly, often by administrators without specialist data expertise. EdTech vendors hold significant power in defining what ‘normal’ data collection looks like, and the absence of mandatory data protection impact assessments for school technology purchases remains a gap that policy has not adequately addressed.
Third, there is a power asymmetry that deserves naming directly. Children cannot meaningfully opt out of biometric monitoring in a classroom setting. The implicit coercive quality of institutional contexts that school is compulsory, attendance is monitored, non-participation has consequences. ‘Consent’ a complex concept even before we consider the developmental question of whether children can meaningfully understand what they are consenting to. The UN Convention on the Rights of the Child, in particular Article 16 on privacy, provides a framework for thinking about children’s data rights that goes beyond the minimum requirements of data protection legislation (United Nations, 1989). That framework is rarely invoked in EdTech procurement conversations.
Children cannot meaningfully opt out of biometric monitoring in a classroom setting. The implicit coercive quality of institutional contexts makes "consent" a complex concept
What does a better approach look like? Several principles seem important. Transparency first: students and families should receive plain-language explanations of what data is being collected and why, before any collection begins. Data minimisation second: if a learning objective can be achieved without biometric data, it should be. Purpose limitation third: data collected for one purpose should not be repurposed, even within the same institution. And meaningful review: schools should have access to independent technical expertise when assessing EdTech products, rather than relying on vendor documentation alone.
None of this requires abandoning the technology altogether. There are contexts in which biometric data, collected carefully and with genuine consent, can support learning in ways that more traditional data cannot. My own work has explored this in creative computing and dance, where heart rate and movement data have opened genuinely new pedagogical possibilities (Smith-Nunes, 2023, 2025). The technology is not the problem. The governance is.
The question worth asking is not whether biometric data can improve education. Some evidence suggests it can, in narrow contexts. The question is who benefits, who decides, and what safeguards exist when things go wrong.
Bodies deserve better than to be treated as passive inputs.
Thanks for reading Data in Motion


