← Back to Learn
ArticleVR Privacy, Safety & Student Data

Behavioural Biometrics: The Privacy Question VR Needs to Ask

I should begin with a correction. On this site, I have sometimes used the term “hand tracking” when discussing 6 DoF VR. A couple of people have rightly pointed out that this is technically imprecise.

September 25, 2026By Dave Dolan
Behavioural biometrics: Always necessary?
Behavioural biometrics: Always necessary?

I was never referring to hand gestures or camera-based recognition of individual fingers. I was referring to the tracking of a person's hand movements while holding controllers: the movement required when practicing something such as welding, surgery or jewellery-making.

A more accurate description is head-and-controller motion tracking. And when those patterns of movement are analyzed to identify a person or infer characteristics about them, we enter the territory of behavioural biometrics.

So, where older material on this site uses “hand tracking” in this context and has not yet been corrected, that is what I meant.

And the distinction matters.

Your movement can say more than you intended

Behavioural biometrics are not science fiction.

NIST includes behavioural characteristics such as gait, mouse movements, smartphone movement and gyroscope position within the broader field of biometrics. Research in VR has now demonstrated that head and hand movement can also be remarkably identifying.

The controller is not collecting a fingerprint. But the movement it records can behave surprisingly like one.

There is another issue.

Movement may reveal, or appear to reveal, things that the person never consciously disclosed.

Imagine a 17-year-old girl lowering herself carefully into a chair and using her hands for additional support. Pregnancy is known to produce measurable changes in gait, balance and sit-to-stand biomechanics. An algorithm designed to infer health-related characteristics might therefore find patterns it associates with pregnancy.

But she might simply have a sore knee.

An older man might move a controller with a repetitive tremor or unusual slowness. Movement sensors and machine-learning systems are already being researched and used to measure Parkinsonian tremor and bradykinesia.

But a tremor is not a Parkinson's diagnosis. Similar movement could have another neurological cause, be medication-related, or be temporary.

A student might move one arm cautiously after a sports injury. A model looking for persistent differences in reach, speed or symmetry might associate that behaviour with age or physical disability.

But the student may simply have hurt his shoulder playing hockey yesterday.

These examples are not claims that consumer VR systems are diagnosing pregnancy, Parkinson's disease or disability. They illustrate something more fundamental:

Inference is not knowledge.

Algorithms identify patterns. Human beings supply the messy reality behind them. That is precisely why sensitive inferences deserve careful treatment.

The movement itself is not the danger

None of this means that 6 DoF is inherently dangerous.

To provide 6 DoF interaction, a headset has to determine where the headset and controllers are and how they are moving. Some sensor information may be processed locally, used momentarily and discarded. Current documentation from major XR vendors describes examples of raw sensor information being processed on-device or not retained in its original form.

That distinction matters.

Motion is not toxic. Retention, linkage and secondary use are what can make it sensitive.

A welding simulation needs to know where the welding torch is. A surgical simulation may need to know whether an instrument was positioned correctly. That is the point of the technology.

The privacy question is what happens after the movement has served that purpose.

  • Is it discarded?
  • Stored locally?
  • Uploaded?
  • Associated with an account?
  • Available to an application developer?
  • Retained for analytics?
  • Combined with other information?
  • Used later for a purpose that did not exist when the device was purchased?

Those are procurement questions, not conspiracy theories.

Why the company behind the headset matters

The question becomes particularly important when an educational VR ecosystem is connected to a company whose broader business is heavily dependent on advertising, personalization or large-scale consumer data.

That statement should not be interpreted as an accusation that such a company is presently misusing VR motion data.

In fact, current policies may explicitly limit particular uses, restrict developer access or state that certain raw sensor information is discarded.

The concern is more basic.

  • Policies change.
  • Products change.
  • Ownership changes.
  • Business pressures change.
  • Regulation changes.

And corporations have a legitimate obligation to pursue commercial success and shareholder value. There is nothing unusual or sinister about that.

Schools, however, have a different obligation. They are responsible for children.

Corporations have a different obligation. They are responsible for employees, other users, and intellectual property.

That produces a perfectly reasonable question:

Why create a potentially valuable behavioural dataset when the learning objective never required it in the first place?

A policy can promise that data will not be used in a particular way.

An architecture that never transmits that data removes an entire category of risk.

That is the difference between privacy as a promise and privacy by design.

The 99:1 question

At Sensible-VR, we often describe this as the 99:1 question.

It is a design principle, not a claim that someone has scientifically measured every school curriculum or corporate training and marketing plan, and determined an exact percentage.

Our position is that the overwhelming majority of learning objectives do not depend upon accurately measuring a user's physical manipulation of objects.

Understanding photosynthesis does not require it.

Interacting with an assembly line may not require it.

Learning financial literacy does not require it.

Exploring an ecosystem, speaking to another character while learning English, reassembling a 3D engine, walking through a cultural site, or understanding workplace safety procedures usually does not require it either.

We do not collect that kind of data simply because technology makes it possible.

The safest sensitive dataset is the one you never needed to create.

That is privacy by design.

Offline where possible. No student account where it is unnecessary. No social layer simply because one is available. No sensor simply because the technology industry has normalized it.

The educational objective comes first.

And when 6 DoF really is the right tool?

Use it.

There are absolutely learning situations where physical movement matters.

  • Surgery.
  • Welding.
  • Dental procedures.
  • Jewellery-making.
  • Equipment manipulation.

Other psychomotor skills where the movement itself is what the learner is trying to master.

In those cases, richer tracking can justify both the technology and the additional privacy consideration.

It may even justify paying more for equipment designed specifically for institutional or enterprise use with stronger data controls.

Suppose that privacy-appropriate hardware costs $500 more and is used for five years.

That is $100 per year. If 100 learners use it each year, the additional hardware cost is approximately $1 per learner-year.

When the alternative involves the collection, retention or possible future use of deeply personal motion data, one extra dollar is worth considering.

Privacy has a price.

So does getting it wrong.

When there is no alternative

Sometimes the only practical product for a particular learning task may belong to a larger consumer or social-media ecosystem.

That does not mean the school cannot use it. It means the decision should be conscious.

The institution can determine exactly what information is collected, where it goes, what settings can be disabled, how long information is retained, which applications can access it, whether accounts are required and what contractual protections exist.

Users, and parents or guardians where appropriate, can be clearly informed.

A written consent or acknowledgement can document that disclosure and informed choice. But it should not be regarded as a magic release from privacy obligations or future liability. Privacy laws and institutional responsibilities cannot necessarily be signed away.

A better protection is a documented privacy process showing that the institution identified the risk, minimized unnecessary collection, restricted access, selected appropriate settings and vendors, and reviewed what happened to the information afterwards.

Consent should be the last line of defence, not the first.

Anonymous is not necessarily anonymous

Finally, removing someone's name from VR data does not automatically make the movement anonymous.

A Stanford-led study of 511 participants, published in 2020, found that participants could be identified with 95% accuracy from ordinary VR tracking data after the system had been trained on less than five minutes of data per person.

Then the scale became much larger.

In research presented at USENIX Security in 2023, Vivek Nair and colleagues studied 55,541 VR users. After training on five minutes of motion per person, their model identified a user from the entire population with 94.33% accuracy using 100 seconds of head-and-hand motion. Even ten seconds produced 73.20% identification accuracy.

Subsequent research involving 1,006 users found that more than 40 personal attributes could be inferred with statistical significance from VR head-and-hand motion data.

That changes the meaning of the word anonymous.

Removing a name from a dataset is not particularly reassuring if the behaviour inside the dataset can help put the name back.

This deserves a conversation

None of this is an argument against 6 DoF. It is not an accusation against a particular manufacturer. And behavioural biometrics are not inherently bad.

This is simply a technology capable of producing extraordinarily rich information about human movement.

  • Sometimes that information is necessary.
  • Sometimes it is enormously useful.
  • And sometimes it has absolutely nothing to do with what a student, or worker, is supposed to be learning.

That is the distinction schools should make.

If the learning requires the data, protect it.

If the learning does not require the data, ask why you are collecting it at all.

Because privacy by design begins long before someone clicks I Agree.

Sources

National Institute of Standards and Technology (NIST) — Biometrics / Digital Identity Guidelines. NIST defines biometrics as automated recognition based on biological or behavioural characteristics and specifically includes behavioural signals such as gait, device movement and gyroscope position.

Miller, M.R. et al. — “Personal identifiability of user tracking data during observation of 360-degree VR video,” Scientific Reports (2020), Stanford Virtual Human Interaction Lab. 511 participants; 95% identification after training on less than five minutes of tracking data per participant.

Nair, V. et al. — “Unique Identification of 50,000+ Virtual Reality Users from Head & Hand Motion Data,” USENIX Security 2023. Study of 55,541 users; 94.33% identification from 100 seconds of motion and 73.20% from 10 seconds after five minutes of training data per user.

Nair, V. et al. — “Inferring Private Personal Attributes of Virtual Reality Users from Ecologically Valid Head and Hand Motion Data,” IEEE VR 2024. Study of 1,006 VR users reporting that more than 40 personal attributes could be consistently inferred from motion data.

JMIR XR and Spatial Computing — “Cybersecurity and Privacy Issues in Extended Reality Health Care Applications: Scoping Review” (2024). Reviews XR privacy risks including deanonymization and inference of characteristics such as age, height and disability status from motion information.

Pregnancy-induced gait alterations: meta-regression evidence of spatiotemporal adjustments. Systematic review and meta-analysis documenting measurable gait changes during pregnancy.

The Biomechanics of Pregnancy: A Systematic Review. Reviews pregnancy-related biomechanical changes including sit-to-stand movement.

Wearable sensors for Parkinson's disease: which data are worth collecting for training symptom detection models. Research demonstrating the use of movement sensors and machine learning to identify Parkinsonian tremor and bradykinesia.

Meta — Responsible Innovation in AI Glasses & Quest / Developer Data Use documentation. Current documentation describes on-device processing of certain raw Quest sensor images and defines device-derived data including headset position and calculated hand/body information.

Meta — 2025 Full-Year and 2026 Financial Results. Financial reporting shows the company's Family of Apps revenue remains overwhelmingly advertising-derived, while Reality Labs contains its VR/AR hardware, software and content operations.

PICO — Privacy and Developer Data documentation. PICO documentation describes collection and processing of 6 DoF headset/controller tracking data for specified services and describes developer access to headset/controller position and orientation information.