I'm struggling to see any actual harm from this use of facial recognition if the video is deleted promptly after processing and conversion to an attendance list.
This facial fingerprint will need to be pretty strongly unique so as to avoid false positives or false negatives. If that information is stolen, the thief has the fingerprint for your face, which is very difficult for you to change.
The level of protection for that stored information then must be very high, because the damage to the individual in case of its loss is very high. The GDPR is in place, in part, to make certain that the justification is sufficient for an organization requiring you to handover such personal and valuable data.
"I want to take attendance" is apparently not sufficient. Further if someone wanted to get creepy, we can imagine what could happen should someone place a foreign agent along the video-recognition-attendance workflow, which then told its owner when and where certain students positively were at any time.