Skip to content
See VOLT at your school

Insights

AI Video Analytics in K-12: A Compliance Guide for School Districts

VOLT

If your district is evaluating AI video analytics, the compliance question usually arrives before the budget question. A board member asks whether it is legal. A parent asks what happens to the footage. Counsel asks which law applies. And the honest answer is that no single law governs this — a district sits underneath a federal privacy statute written in 1974, a patchwork of state biometric laws, state student-data-privacy rules that govern the vendor contract, and a newer layer of state AI legislation that is still moving.

This guide walks through those four layers in the order they actually matter, and ends with the questions to put to any vendor before signing. It is written for administrators, technology directors and safety committees — not lawyers — and it is not legal advice. Statutes change, and several of the ones below changed while this was being written. Confirm current requirements with your district's counsel before you act.

The short answer

For most districts, the single fact that determines which laws apply is whether the system identifies individual people or only detects objects and events.

Software that measures a face, a fingerprint, an iris or a voice to work out who someone is falls under biometric law. In a handful of states that use is restricted in schools outright, and in Florida it is prohibited. Software that recognises what is happening — a person on a roof after hours, a door propped open, a fall in a corridor — without matching anyone to an identity generally falls outside those statutes, though it still sits squarely inside FERPA and your state's student-records rules.

That distinction does not make the second category unregulated. It changes which chapter of the rulebook you are reading.

Layer 1: FERPA, and when footage becomes a student record

The Family Educational Rights and Privacy Act is the federal floor. The common misconception is that all school camera footage is a protected education record. It is not.

The Department of Education's Student Privacy Policy Office applies a two-part test. A photo or video is an education record when it is "(1) directly related to a student; and (2) maintained by an educational agency or institution or by a party acting for the agency or institution."

Both halves have to be true. A camera recording an empty car park is capturing ambient footage. The Department's own examples of footage that is directly related to a student include surveillance video of two students fighting in a hallway that is used in a disciplinary action, and a classroom video showing a student having a seizure — because in each case the student becomes the focus of the recording.

This has a practical consequence that surprises many districts: the same clip can change status depending on what you do with it. Footage sitting in a retention buffer is one thing. The moment an administrator pulls that clip, attaches it to a disciplinary file and keeps it, it is an education record — with all the parental inspection rights that follow.

The law enforcement unit exception

FERPA excludes records created and maintained by a school's own law enforcement unit for a law enforcement purpose. The Department is explicit that if a law enforcement unit creates and maintains the school's surveillance videos for a law enforcement purpose, those videos are not education records.

Districts lean on this exception more heavily than it can bear. Two cautions are worth holding onto. First, it turns on who created and maintains the record and why — not on the label attached to it afterwards. Second, once a copy moves from the security office to a principal for a disciplinary decision, that copy is being maintained for an educational purpose, and the exception stops protecting it.

Handing footage to police

This comes up in almost every incident. The Department's position is that where footage is a law enforcement unit record, FERPA does not prohibit disclosure to police. Where the footage is an education record, a district may not hand it over on request without either written parental consent or a documented exception — the health-or-safety emergency exception being the one most often relied on in a genuine crisis.

Write the decision path down before you need it. The worst moment to work out who may release footage to whom is during the incident.

Layer 2: state biometric law

This is the layer that most often rules a specific product in or out, and it varies more than any other.

Florida: a direct prohibition

Florida is the clearest case. Under Fla. Stat. § 1002.222, districts may not collect, obtain or retain the biometric information of a student — or of a student's parent or sibling. The statute names fingerprint, hand, eye and voice characteristics and facial geometry scans. There is no consent workaround for districts: it is a prohibition, not a notice requirement.

New York: facial recognition banned by determination

New York arrived at a similar place by a different road. After a 2020 statewide moratorium and a subsequent state report, in September 2023 the State Education Department prohibited schools from purchasing or using facial recognition technology, citing a finding that the risks may outweigh the benefits given limited evidence that it prevents violent incidents. Other biometric technologies were left to local decision, weighed against privacy, civil rights, effectiveness and parental input.

Illinois, Texas and Washington: consent regimes with very different teeth

These three states regulate biometric identifiers generally rather than schools specifically, and the enforcement differences matter enormously:

  • Illinois (BIPA, 2008) is the strictest in the country because it carries a private right of action — individuals may sue directly, with statutory damages of $1,000 for negligent and $5,000 for intentional or reckless violations. Illinois amended BIPA in August 2024 so that repeated collection of the same person's data by the same party counts as a single violation, and in April 2026 the Seventh Circuit held that the damages limitation applies retroactively. The exposure is smaller than it was. It has not gone away.
  • Texas (CUBI, 2009) imposes similar consent and retention duties but has no private right of action — only the Attorney General enforces it, with civil penalties reported at up to $25,000 per violation.
  • Washington maintains a third standalone biometric statute with its own consent and disclosure rules.

Beyond those, the trend is broad: NPR, citing the National Conference of State Legislatures, reported in 2025 that 23 states had passed or expanded laws restricting biometric data collection. If you are a multi-state organisation, assume the answer differs by campus.

Layer 3: the vendor contract

The layer districts most often underestimate. Even where a system is plainly lawful, most states impose specific obligations on the agreement with the vendor. California's AB 1584 is the widely copied template, and comparable statutes now exist in the large majority of states.

The recurring requirements are consistent enough to check against directly. A compliant agreement generally needs to state that student data remains the property and under the control of the district; prohibit use of student data for commercial purposes such as advertising or profile-building; require defined security safeguards; specify deletion on request and at contract termination; and describe how parents may review and correct information.

Ask for the data processing agreement before the demo, not after the board vote. A vendor that cannot produce one quickly is telling you something.

Layer 4: the emerging AI statutes

This is the newest and least settled layer. Several states have moved to regulate "high-risk" AI systems directly, with duties around impact assessments, notice to affected people and protection against algorithmic discrimination.

Colorado's SB 24-205 was the first comprehensive example, and its history is a fair warning about planning around any single date: its effective date was postponed, its enforcement was affected by litigation, and the legislature has since revisited the framework. Rather than quote a date that may have shifted again, check the current status on the Colorado General Assembly's own bill page and ask counsel where your state sits.

The durable point is directional. Legislatures are converging on a small set of expectations — tell people the system is in use, document why you chose it, test it for disparate impact, and keep a human accountable for consequential decisions. Districts that can already answer those questions will not be scrambling when the statute lands.

What good practice looks like regardless of state

Compliance is a floor. The districts that avoid trouble tend to do a handful of things that no statute strictly requires:

  • Write a policy before the purchase. Who may view footage, for what reasons, with what approval, and how access is logged. Board-adopted, published, and reviewed annually.
  • Set a retention period and enforce it automatically. Indefinite retention creates risk with no safety benefit; footage nobody reviewed thirty days ago is rarely useful and always discoverable.
  • Tell families plainly. A short, readable page explaining what the system does and does not do prevents most of the objections that derail deployments. Community trust is easier to keep than to recover.
  • Keep humans in the decision. An alert is information, not a verdict. Every consequential action should have a named person behind it.
  • Do not let cameras substitute for people. Technology shortens the time it takes to notice something. Counsellors, nurses and trained staff are what actually help the student.

Ten questions to ask any vendor

  1. Does the system identify individuals, or only detect objects and events?
  2. Does it use facial recognition or any other biometric identifier — ever, including in optional features?
  3. Where is footage stored, for how long, and who controls deletion?
  4. Can we set retention periods ourselves, and are they enforced automatically?
  5. Who at your company can access our footage, under what circumstances, and is that access logged and auditable?
  6. Will you sign our data processing agreement, and does it meet our state's student-data-privacy statute?
  7. Is student data ever used to train models, and can we decline?
  8. What independent security certification do you hold?
  9. What is the measured false-alert rate, and who reviews an alert before staff are notified?
  10. What happens to our data if we terminate the contract?

On the first two questions in particular, ask for the answer in writing. The difference between "detects behaviours" and "identifies people" is the difference between two entirely different regulatory regimes — and it is the question most likely to decide whether a system is lawful in your state at all. VOLT's own approach is described on our privacy and trust page: the platform analyses behaviours, objects and anomalies rather than individual identities, and does not use facial recognition.

Frequently asked questions

Is AI video surveillance legal in US schools?

Generally yes, but the answer depends on what the system does. Analytics that detect objects and events are lawful in most states subject to FERPA and state student-data-privacy rules. Systems using facial recognition or other biometric identifiers are prohibited in Florida schools under Fla. Stat. § 1002.222, and facial recognition is prohibited in New York schools by a 2023 State Education Department determination. Several other states impose consent requirements. Confirm your own state's position with counsel.

Is school security camera footage a FERPA education record?

Only when it meets the Department of Education's two-part test: the footage must be directly related to a student and maintained by the school or someone acting for it. General ambient footage typically is not. Footage pulled and retained for a disciplinary action typically is.

Can schools give security footage to the police?

If the footage is a law enforcement unit record created and maintained for a law enforcement purpose, FERPA does not prohibit disclosure. If it is an education record, the district needs written parental consent or a documented exception, such as a health or safety emergency.

Does AI video analytics require parental consent?

Federal law does not generally require consent for video surveillance of school premises. Consent obligations arise mainly under state biometric statutes, which apply to systems that identify individuals. Many districts provide notice to families as a matter of policy and community trust even where it is not legally required.

How long should schools keep security footage?

There is no single federal retention period; many districts adopt something in the range of 14 to 90 days, governed by their state's records retention schedule. Check your state schedule, set the period in policy, and enforce it automatically rather than by hand.

Where to go next

If you are earlier in the evaluation than the legal review, our guide to school security systems covers the components and how they fit together, and the school safety statistics page collects the sourced numbers most often quoted to boards. For how alerts are handled once a system is live, see how VOLT works.

This article is general information, not legal advice. Laws in this area are changing quickly — several statutes cited here were amended within the past two years. Confirm current requirements with your district's counsel before making a purchasing decision.

Share

See VOLT on your cameras.

A friendly walkthrough on your own campus, with no pressure.