Table of Contents
Facial Recognition in Schools: What It Does, Where It's Being Used, and What Parents Can Do
Schools are deploying facial recognition for attendance and security — but the technology has higher error rates for darker-skinned students and raises serious civil liberties concerns.
A parent in Lockport, New York only found out that her 14-year-old son’s face had been scanned, catalogued, and compared against a watchlist database every time he entered school — for weeks — because a civil liberties organization requested records under public disclosure law. The school district had not notified parents in a way that made the surveillance visible, because the system was presented as a security upgrade, not a data collection program. Facial recognition technology in schools is no longer hypothetical. It is in use in U.S. school districts today — for attendance, for campus security, and in some cases for disciplinary tracking. What it does with the data, how well it actually works, and what rights parents have to object are questions most school districts have not answered clearly.
Key Takeaways
- Facial recognition is currently used in U.S. schools for access control, attendance automation, and campus security — with China’s school surveillance programs representing the most extensive global deployment.
- Joy Buolamwini’s Gender Shades research (2018) found error rates up to 34.7% for darker-skinned women vs. 0.8% for lighter-skinned men in commercial facial recognition systems — the same systems being sold to schools.
- New York State suspended school facial recognition in 2020 pending a study; the study recommended against deployment. Several U.S. states have explicit bans or restrictions. Most states have no specific law.
- FERPA may protect student facial recognition data as an “education record” in some circumstances — but this is legally uncertain, and no definitive guidance has been issued by the Department of Education.
- Parents can request information about facial recognition systems under state public records laws, and in some cases can opt children out of biometric data collection under state biometric privacy laws.
What Schools Are Actually Doing With Facial Recognition
The applications fall into roughly three categories, with very different evidence bases for effectiveness:
Access control. Doors, gates, or building entrances equipped with cameras identify enrolled students and staff, allowing entry without physical key cards or ID checks. This is the most technologically straightforward application and the one with the clearest security rationale — it reduces the ability of unauthorized visitors to enter buildings while students are present.
Attendance tracking. Cameras in classrooms or corridors automatically log student presence based on facial recognition, replacing manual roll calls. Some districts in China have deployed this extensively, including attendance tracking that logs each student’s arrival time, face, and in some implementations, attention level during class.
Security watchlist matching. This is the most controversial application — cameras compare faces in real time against a database of individuals who are considered threats (expelled students, sex offenders, custody violations, individuals under restraining orders). This was the primary stated purpose of the Lockport, NY system.
Behavioral and emotion tracking. Less common in the U.S. but documented in China and some other countries — systems that claim to detect student attention, emotional state, or early signs of disruptive behavior based on facial expression analysis. The scientific basis for emotion detection AI is heavily disputed.
The Evidence Problem: Does It Actually Work?
The Lockport case is instructive. The district deployed the Aegis system, built by SN Technologies, in 2020. The system cost $1.4 million (partially grant-funded). It ran for 49 days before the New York State Education Department ordered it suspended pending review. During those 49 days, it produced zero threat identifications. None. The system was sold on the premise that it would identify expelled students, sex offenders, and other threats before they could enter school buildings. It didn’t identify any.
This outcome is consistent with a known problem in security technology: base rate neglect. Even a highly accurate facial recognition system will produce more false positives than true positives when the targeted threats are extremely rare (which they are — school violence perpetrators are vanishingly uncommon among the thousands of people who enter a school building annually). A system with 99% accuracy that scans 1,000 people per day will flag 10 innocent people for every 1 actual threat — and that math assumes the threat appears, which most days they don’t.
NIST’s facial recognition vendor testing (FRVT) data shows significant performance variation across demographic groups in the commercial systems most likely to be deployed in schools. The NIST 2019 report found that many algorithms had false positive rates 10–100 times higher for Black women than for white men on law enforcement databases — a disparity with obvious implications for school security applications.
The Lockport Case in Detail
The Lockport City School District in New York State received a $4.2 million state technology grant in 2018. The district allocated $1.4 million to the Aegis facial recognition system from SN Technologies. The NYCLU (New York Civil Liberties Union) filed a complaint and requested investigation. The state Education Department conducted a review and found the system posed civil rights risks and lacked adequate privacy protections. In 2020, the state legislature passed a moratorium on facial recognition in schools. New York’s subsequent study recommended against deployment. As of 2026, the moratorium has been extended; New York schools cannot use facial recognition.
Legal Landscape: State-by-State
| State | Status | Notes |
|---|---|---|
| New York | Moratorium through 2025+ | SED study recommended against deployment |
| Illinois | Effectively restricted by BIPA | Requires written consent for biometric data; school applications in legal gray zone |
| California | No explicit ban, but strong biometric privacy protections | CCPA/CPRA may apply to student biometric data |
| Texas | CUBI Act restrictions | Biometric data requires disclosure and consent |
| Maine | Explicit ban on K-12 facial recognition | One of few states with direct prohibition |
| Washington | Facial recognition restrictions in law | State agencies restricted; school application unclear |
| Most other states | No specific law | Federal guidance under FERPA is unclear |
FERPA’s role: The Family Educational Rights and Privacy Act protects “education records.” If facial recognition data — photos, identity matches, attendance logs — constitutes an education record, FERPA protections apply. The U.S. Department of Education has not issued definitive guidance on whether facial recognition data is an education record. Legal scholars disagree. The practical consequence is that parents may or may not have FERPA-based rights to access and challenge this data, depending on how the district and courts interpret it.
The Civil Liberties Concerns Beyond Accuracy
Georgetown Law Center on Privacy & Technology has documented what researchers call the “chilling effect” of pervasive surveillance on student behavior. When students know — or believe — that their faces are being tracked continuously, research on surveillance and behavior suggests changes in how freely they express dissent, associate with peers, or engage in political expression on campus. This concern is distinct from and additive to the accuracy concerns.
Mission creep is also documented in other law enforcement facial recognition contexts: technology deployed for one purpose (security watchlist matching) has been expanded to other uses (attendance, behavioral tracking, sharing with law enforcement) after initial deployment. School communities have limited ability to prevent this expansion once the infrastructure is in place.
What Parents Can Do
Find out what technology your school uses. Submit a public records request (most states require schools to respond) asking: what biometric data collection systems are deployed in your district’s schools, what data is collected, how it is stored, how long it is retained, and with whom it is shared.
Review your state’s biometric privacy laws. Illinois BIPA, Texas CUBI, and Washington’s H.B. 1493 all have provisions that may apply to school biometric data. If your state has a relevant law, it may require explicit written consent before your child’s biometric data can be collected — consent that would require an affirmative parental decision.
Contact your school board. School board decisions about technology deployment are made at the board level, often without public notice. Request to be placed on the agenda to ask questions before deployment, not after. Technology acquisition decisions frequently appear as consent-agenda items that receive no public discussion unless a community member requests it.
Connect with civil liberties organizations. The ACLU, EFF, and state-level civil liberties unions have staff who track school surveillance technology. They can advise on specific state legal situations and sometimes provide free legal support for parents seeking to challenge or opt out.
What to Watch For Over 3 Months
Immediately: Check your district’s technology policy (usually available on the school website or through the district office) for any mention of biometric data, facial recognition, or security camera analytics.
Month 1: Review any technology or data privacy consent forms your child’s school has sent home in the past year. Some districts bury biometric data collection consent in broader technology use agreements.
Month 2: Attend a school board meeting or review meeting minutes (often posted publicly) for any technology procurement items. Facial recognition contracts often appear as security infrastructure upgrades.
Month 3: If your district does use facial recognition, request in writing the data retention schedule and sharing policies. How long is your child’s facial geometry data stored? With whom can it be shared? Under what circumstances?
Red flag: a district that is unable or unwilling to clearly answer questions about what biometric data is collected, how long it is retained, and who has access to it. Legitimate security infrastructure has documented privacy practices. Evasion on these questions is itself informative.
Frequently Asked Questions
Is there any evidence that facial recognition actually improves school safety?
Published evidence is very limited. The Lockport case produced zero threat identifications. No peer-reviewed study has demonstrated that school facial recognition systems have prevented school violence. The base rate problem (genuine threats are extremely rare among the large population scanned) means high false positive rates are almost inevitable. Most school safety experts focus on behavioral threat assessment, mental health support, and community intervention — not biometric surveillance.
Can I opt my child out of facial recognition in school?
This depends on your state and district. In Illinois, BIPA requires written consent before collecting biometric data — providing a direct opt-out mechanism. In states without specific biometric privacy laws, the situation is less clear. You can submit a formal written request for opt-out, citing general FERPA rights and privacy concerns. The district may or may not accommodate this request. Contact your state’s ACLU affiliate for guidance on the strongest available legal basis in your state.
Does school facial recognition data get shared with police?
There is no federal prohibition on schools sharing facial recognition data with law enforcement. Individual district policies vary, and many don’t address the question explicitly. Some districts’ vendor contracts include provisions that data collected by the surveillance system may be shared with law enforcement. Asking about law enforcement sharing specifically — in writing — is an important part of any parent inquiry about school facial recognition.
What’s the difference between a security camera and facial recognition?
Standard security cameras record footage and require a human to review it to identify individuals. Facial recognition cameras automate identification in real time or post-hoc, comparing captured faces against a database and flagging matches. The difference is that facial recognition creates searchable biometric records that can be associated with individual students’ identities and linked to their behavioral history — which standard cameras don’t do automatically.
About the author
Ricky Flores is the founder of HiWave Makers and an electrical engineer with 15+ years of experience building consumer technology at Apple, Samsung, and Texas Instruments. He writes about how kids learn to build, think, and create in a tech-saturated world. Read more at hiwavemakers.com.
Sources
- New York State Education Department. (2020). “Report on the Use of Facial Recognition Technology in Schools.” https://www.nysed.gov/edtech/facial-recognition-technology-schools
- Buolamwini, J., & Gebru, T. (2018). “Gender Shades.” PMLR, 81. http://proceedings.mlr.press/v81/buolamwini18a.html
- NIST. (2019). “Face Recognition Vendor Test (FRVT) Part 3: Demographic Effects.” https://doi.org/10.6028/NIST.IR.8280
- Georgetown Law Center on Privacy & Technology. (2019). “Perpetual Lineup: Unregulated Police Face Recognition.” https://www.perpetuallineup.org
- NYCLU. (2020). “NYCLU Complaint: Lockport City School District.” https://www.nyclu.org/en/cases/facial-recognition-lockport-schools
- Illinois General Assembly. (2008). “Biometric Information Privacy Act.” 740 ILCS 14. https://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=3004
- American Civil Liberties Union. (2021). “Face Recognition Technology: America’s Surveillance Network.” https://www.aclu.org/report/face-recognition-technology-americas-surveillance-network