Good. Not only does this ensure that the students enjoy privacy, monitoring children in school with surveillance systems could have come straight out of foucault's discipline and punish. Maybe we should think about how we make schools spaces of freedom for our children rather than turning them into the next panopticon.
That's not the issue (at least as I see it).
The big questions in my head include "Who's storing the biometric data? How are they securing it? Who has authorized access to it, and what processes and mechanisms are n place to ensure they only use it in authorized ways? What are authorized uses of the data? How is it ensured that authorized uses will ot be increased in scope? What process or mechanisms are in place to detect attempts or successful cases of some authorized 3rd party obtaining that data? What penalties are there for unauthorized use of the data and to whom will they be applied? What penalties are there for inadequately securing the data and to whom will those be applied? What processes mechanisms or policies are in place to ensure unauthorized access or failures to secure the data are detected and disclosed? How are those processes mechanisms or policies measured to ensure they're working?"
Pretty much _anyone_ dealing with EU citizen's data should already have the answers to those (and related) questions written down. (If you do not, think about how sure you are that the answer to those " .. to whom will the penalty be applied?" questions will not be "Who's responsible for the data breach? Oh, that'd be Barrin from the dev team. Here, let me give you his full contact details and their HR file! BTW, they'll be fired and marched out before close of business, might be best if you call them on their personal cell phone."