I can't access the original study however taking data, explicitly naming security cameras for example, to "use it or merge it with data from external parties such as publishers or public or private sector organizations" will surely not seriously degrade student and staff privacy, right?
The rush to "exploit" data reminds me of the dot com hype. It's one thing to use available data to make more informed decisions about things from course content to building occupancy. It's quite another to rush towards total surveillance because of a Fear of Missing Out of "exploitable data".