Most independent schools install cameras for the same three reasons: deterrence, after-the-fact investigation, and parents' peace of mind. What schools rarely think about, until something happens, is that camera footage can become an education record the moment it is used to identify a student or make a decision about them. That puts the system squarely inside FERPA — and the way most schools deploy cameras would not survive a serious FERPA review.
Where Cameras Intersect FERPA
FERPA, the Family Educational Rights and Privacy Act, protects the privacy of student education records. The statute defines an education record broadly: any record that contains information directly related to a student and that is maintained by an educational agency or institution. The U.S. Department of Education has clarified, in guidance dating back to 2017, that video footage can qualify as an education record under specific conditions.
The trigger is usage. Generic, time-rotating surveillance footage that is never reviewed or attached to a specific student is generally not an education record. But the moment that footage is pulled, attached to a disciplinary file, used in a meeting with parents, or referenced in a determination about a student, it becomes part of that student's record — and all of FERPA's access, disclosure, and retention rules apply.
Identifying the 'Education Record' Inside Your DVR
Most school camera systems retain footage for somewhere between 14 and 60 days, then overwrite it. That rolling window is fine — and is not, by itself, a FERPA problem. The compliance challenge is the smaller subset of footage that gets pulled out of that rotation: a clip saved for an investigation, an export shared with a parent, a still image referenced in a disciplinary letter.
Every school we work with needs a defined process for what happens when footage is pulled. Who authorizes the export? Where does the exported file live? Who can access it? How long is it kept? If you cannot answer all four of those questions in writing, your camera system is generating education records that are not actually being managed as records.
Disclosure Rules and Law Enforcement Carve-Outs
FERPA generally requires written parental consent before education records are disclosed to third parties. There are exceptions — school officials with a legitimate educational interest, transfer requests from another school, and a narrow law enforcement carve-out — but the default assumption should be that you cannot hand a clip to a parent of a different student, post it on social media, or share it with anyone outside the school without consent or a clear statutory basis.
The most common compliance failure we see is a head of school showing footage to a parent during a discipline meeting that captures other students who are not their child. Even if the other students are not the focus of the conversation, you have just disclosed an education record of those other students. The correct workaround is to redact — blur or crop other identifiable students out of the export before showing it.
Practical Controls: Where to Put Cameras (and Where Not To)
Camera placement is half a privacy decision and half a usefulness decision. The two intersect more than people think: cameras in places where students have a reasonable expectation of privacy are both privacy violations and, in practice, of little forensic value because using the footage will create more problems than it solves.
- Common-area corridors and stairwells — appropriate
- Exterior entrances and parking — appropriate
- Gymnasiums and auditoriums during programs — appropriate
- Classrooms — only with very specific, narrow justification and explicit policy
- Locker rooms, restrooms, dorm interiors — never
- Health office, counseling office — never
Retention, Access Logging, and Chain of Custody
A defensible camera system has three logging layers: the system records every camera, the system logs every login and every search, and a separate workflow logs every export. A judge will not be impressed if you can tell them a clip was pulled but cannot tell them by whom and when.
Retention should be policy-driven and short by default. Fourteen to thirty days is the sweet spot for general surveillance retention. Anything longer and you are storing data you almost certainly do not need; anything shorter and you may overwrite an incident before it is reported. For exported, case-specific clips, retention should be tied to the underlying investigation or disciplinary file — not left on a shared drive indefinitely.
Vendor Selection and Cloud Storage
Cloud-managed camera platforms — Verkada, Eagle Eye, Avigilon Cloud, Meraki MV — are increasingly the default. They reduce on-prem complexity and improve uptime, but they also raise FERPA questions: who has access to footage on the vendor side, where is it stored, and what happens if the vendor is breached?
Before you sign with any cloud camera vendor, ask for their FERPA / student-data addendum (most have one, some pretend not to). Ask where data is stored. Ask whether the vendor's support staff can view footage and under what conditions. Ask what their breach notification timeline is. If they cannot give you written answers, find another vendor.
Documenting Your Policy
The single most valuable artifact in a FERPA-defensible camera deployment is a written video surveillance policy — adopted by the board, published in the handbook, and reviewed annually. The policy should cover purpose, locations, retention, access, disclosure, and the request process for parents seeking footage about their own child. It should be short. It should be in plain English. And every administrator who can authorize an export should have read it.
We help schools draft these policies in concert with their legal counsel — not as a substitute for legal advice, but to make sure the policy reflects how the actual system works. A great policy that contradicts what your DVR is doing is worse than no policy at all.
How Mezzoly Approaches This for Schools
Our education infrastructure practice designs camera systems with FERPA built in from the network up: segregated VLANs for camera traffic, role-based access on the management console, exported-clip workflows that route through a single audit log, and vendor agreements that match the school's data policy. If your existing camera system was deployed without any of that in mind, we can audit it and bring it into compliance without starting over.