I remember the first time my son came home excited about a new “faster” way to register attendance at school — a scanner you press your thumb to so the school “knows you’re there.” The idea sounded modern and efficient. But as a journalist who pays attention to technology and policy, my reaction was a mix of curiosity and caution. Biometric systems promise convenience, but they also raise real questions about privacy, security, fairness, and parental rights. If your child’s school is asking for consent to use systems from providers like idenfit or similar vendors, here are the questions I think every parent should ask — and the reasons why they matter.
What exact biometric data will the system collect?
Be specific. “Biometric” can mean fingerprints, facial images, iris scans, or even behavioral patterns. Some systems store raw images, others store mathematical templates derived from images. Ask whether the vendor collects raw biometric images or templates, and what modality they use.
- Why it matters: Raw images are harder to securely store and more sensitive if leaked. Templates can be safer but are not immune to misuse.
- Follow-up: Ask for technical documentation that explains the data type—templates, hashes, vectors—and whether data can be reverse-engineered into an identifiable image.
Who will have access to the biometric data?
Access control is central. Find out whether only the school can access the data, or whether third parties (the vendor, subcontractors, cloud providers) will have access. Also ask about internal roles: can teachers view raw data, or only an admin?
- Why it matters: More access points increase the risk of misuse or breach. You want minimized access and strict role-based controls.
- Follow-up: Request a list of all organizations and sub-processors that may access the data, along with contractual protections and audits.
Where and how is the data stored?
Is data stored on local school servers, on the vendor’s cloud, or on third-party services? What country hosts the servers? Ask about encryption both in transit and at rest, and whether the school holds encryption keys or the vendor does.
- Why it matters: Location affects which laws apply. If data is stored overseas, different legal standards may reduce parental control or increase surveillance risks.
- Follow-up: Ask for encryption standards (e.g., AES-256) and proof that keys are managed correctly. Prefer solutions where the school controls the keys.
How long will the data be retained, and what is the deletion process?
Retention policies vary. Some systems keep templates indefinitely unless you request deletion; others have automatic purge rules. You should ask for a clear retention timeline and a simple process for data deletion when a student leaves the school or when parents withdraw consent.
- Why it matters: Long retention increases exposure to future breaches and potential misuse.
- Follow-up: Get a written procedure for deletion and a guarantee of deletion from all backups and third-party stores, not just the primary database.
Is consent truly voluntary, and what are the alternatives?
Consent should not be coercive. Parents and students must be offered meaningful alternatives to biometrics — such as ID cards, PINs, or manual sign-in — without negative consequences (like restricted access or disciplinary action).
- Why it matters: In schools, power dynamics can make “consent” feel mandatory. Alternatives preserve choice and fairness.
- Follow-up: Ask the school to document the alternative procedures and ensure they are as convenient as biometric options.
How accurate is the system, and what are the failure modes?
Biometric systems are not perfect. Ask for independent accuracy metrics, false acceptance rates (FAR), and false rejection rates (FRR). Also ask how the system handles edge cases: identical twins, children with certain disabilities, or students with injuries.
- Why it matters: High false rejection can lead to delays or stigma; false acceptance can let unauthorized individuals gain access.
- Follow-up: Request evidence of testing with children of different ages, skin tones, and abilities. Vendors should provide bias testing and mitigation plans.
What legal and regulatory safeguards apply?
Different jurisdictions have different rules about biometric data. Ask whether the vendor and school comply with applicable laws (e.g., COPPA, FERPA in the U.S., GDPR in Europe, or national data protection laws). Request copies of privacy impact assessments and legal opinions that the school used to approve the system.
- Why it matters: Legal compliance is a baseline, not a guarantee of safety. Knowing the legal framework helps you understand your rights and remedies.
- Follow-up: If you find gaps, ask the school what steps they will take to address them and whether they will pause deployment until issues are resolved.
What security certifications and audits does the vendor have?
Request recent security audit reports, penetration test results, and certifications (e.g., ISO 27001). Independent third-party audits are far more meaningful than vendor self-attestations.
- Why it matters: Certifications and audits reduce—but don’t eliminate—risk. They show the vendor takes security seriously.
- Follow-up: Ask for redaction-free summaries of audit findings and remediation timelines for any critical vulnerabilities.
How will the school communicate incidents and breaches?
Inquire about breach notification policies: who will be informed, in what timeframe, and what remediation steps will be taken. A good policy commits to rapid, transparent communication with parents.
- Why it matters: Rapid notification limits harm and allows parents to take protective steps if data is compromised.
- Follow-up: Ask the school to put notification commitments in writing, including thresholds for notifying parents and regulators.
Is there a transparent privacy policy and a privacy impact assessment (PIA)?
PIAs explain risks and mitigations. A transparent privacy policy should be written plainly (not legalese) and be easily accessible to parents. It should detail purpose limitation—what the data will and won’t be used for.
- Why it matters: Transparency builds trust and allows parents to hold schools accountable.
- Follow-up: Ask for the PIA and a plain-language summary focused on classroom impacts and parental rights.
What ongoing governance exists around the system?
Good governance means a standing review process: periodic audits, community oversight, and a clear escalation path for concerns. Ask who in the school or district is responsible for oversight and how parents can participate or raise objections.
- Why it matters: Technology needs continuous monitoring; policies can drift without active governance.
- Follow-up: Request meeting notes or governance charters showing how decisions are made and revisited.
Can I see a demo and a data flow diagram?
Ask for a live demonstration and a detailed data flow diagram showing exactly how data moves from the scanner to storage, who processes it, and where backups live. Seeing the system in action often surfaces practical questions you wouldn’t think to ask otherwise.
- Why it matters: Visuals make abstract risks concrete. A demo also shows whether the system is designed with children in mind.
- Follow-up: Attend vendor presentations and ask to test authentication alternatives in person.
| Question | What to expect from the answer |
|---|---|
| What data is collected? | Clear description (templates vs raw images), technical docs |
| Who has access? | Named parties, role-based controls, sub-processor list |
| Retention & deletion? | Specific timelines and verifiable deletion procedures |
| Alternatives? | Convenient non-biometric options guaranteed |
I’ve learned that asking these questions doesn’t mean opposing technology outright. It means insisting on safeguards before children’s data becomes someone else’s asset. If your school or district is working with providers like idenfit, demand clarity and accountability. Keep records of communications, request written policies, and consider organizing other parents to ask the same questions — systems that are well-designed for safety and privacy often emerge because communities demanded them.