I’m not personally aware of any facial recognition projects for attendance. Never seen it debated either. We have thousands of schools though, so who knows.
As far as the GDPR goes it actually didn’t have a huge technical impact on the public sector. We’ve had stricter local laws for decades, and have build our systems accordingly. We also don’t track you for advertising. So for us the GDPR has mostly been a bureaucratic change, and you’ll notice that’s also the majority of violations. It’s not that data aren’t protected, it’s that no one knows where the contract is, or that we haven’t documented elaborate procedures for whatever. 95% of the GDPR impact on the public sector had been law and legalisation. So the GDPR actually doesn’t impact O365 94 public cloud at all as long as you go to iso27000 certified vendors who provide privacy shield or whatever it’s called these days.
That’s not to say that we aren’t debating public cloud. Because we are. This has more to do with national laws though, we have war-time contingency plans from the cold-war era. Like I said, we had much stricter policies before the GDPR was even a thing.
The issue is that it makes public cloud illegal, but we can’t operate the most digitalised public sector in the world without public cloud. So far everyone is moving to AWS and Azure, pretending the flawed bureaucracy will eventually go away, but our politicians and national digitalisation agency has been refusing to give any meaningful heading, so who knows?
At some point though, someone is going to ask if the privacy bureaucracy is really worth the money it’s costing. At our place you could hire 10 extra teachers a year, just to cover the bureaucratic processes that don’t actually increase security, because a contract or a nice incident plan isn’t actually going to stop anyone from hacking you.