What AI should and shouldn’t do with yearbook photos
Some AI in a yearbook is ordinary photo editing: finding the faces in a picture so nobody’s head is cropped off, or skipping the blurry shot. Other AI works out whose face is in each photo, and that means building biometric data about children, which is a different decision that deserves its own consent.
More yearbook companies are adding face-matching features, and the words used to describe them vary. This page explains the difference in plain language, where a sensible line sits, what the law generally asks about, and the questions any PTA can ask any vendor.
What is the difference between face detection and face recognition?
Face detection answers one question: is there a face in this photo, and where? The result is usually a box around each face. It does not know or care who the person is, and it is not compared against anyone. Photo software uses it to:
- crop a photo without cutting off a face,
- tell a close-up from a crowd shot,
- pick the sharper of two similar photos,
- count roughly how many people are in a frame.
Face recognition answers a different question: whose face is this? It measures a face and turns those measurements into a numeric pattern, often called a face template, faceprint or embedding. It then compares that pattern with patterns made from reference photos, such as picture-day portraits, to find a match. That pattern is a biometric identifier: it identifies a specific person from their body, much as a fingerprint does.
A simple test: if the software could tell you the name of the child in the photo, it is recognition. If all it can tell you is “there is a face here”, it is detection.
Which uses of AI are ordinary, and which involve children’s biometric data?
A practical line for a school or PTA:
Ordinary photo work (no one is identified)
- cropping and framing around faces,
- flagging blurry, dark or duplicate photos,
- colour and exposure correction,
- sorting photos by the class or event folder they were uploaded to,
- laying photos out on a page.
Uses that involve children’s biometric data (someone is identified)
- matching faces in candid photos against portraits,
- building and storing a face template for each student,
- automatically tagging students by name based on their face,
- “how often does each child appear” counts, when they are produced by matching faces.
A separate question: training AI models
Whether student photos are used to train or improve an AI model is a different issue from recognition. A tool can do no recognition at all and still have terms that allow training, or the reverse. Ask about it on its own.
Is there a real benefit to face recognition in a yearbook?
Yes, and it is fair to say so. The honest case for recognition is coverage: if software can tell which children appear in the candids, a coordinator can see who is missing and go and find photos of them before the book closes. Missing children are a real problem in yearbooks, and that is a genuine use.
The cost is that, to do it, the system has to create biometric data about every child in the book, most of whom are too young to understand it. That data has to be consented to, kept secure, limited to its purpose, and deleted. Coverage can also be tracked without faces, by checking which classes and events have photos, though that is coarser than knowing each child.
Neither choice is automatically right. What matters is that the school and families know which one they are getting, and agree to it.
What does the law generally ask for?
This is general information, not legal advice. Laws differ by state, change over time, and depend on facts such as who collects the data and why. Treat everything below as questions to raise with your school or district and its counsel.
Illinois: Biometric Information Privacy Act
BIPA covers a “scan of hand or face geometry”. It excludes photographs themselves, so the concern is the face scan, not the picture. Before a private company collects a biometric identifier, the law generally requires it to tell the person, or their legally authorized representative, in writing that it is collecting it, for what purpose and for how long, and to get a written release. It also requires a public retention and destruction policy, and it bars selling or otherwise profiting from the data.
Question to raise: if a vendor scans faces, who signs the written release for each child, and where is the vendor’s published destruction schedule?
Texas: Capture or Use of Biometric Identifier Act
According to the Texas Attorney General, anyone who captures a “record of hand or face geometry” for a commercial purpose must give notice and get consent first, must protect it with reasonable care, generally may not sell or disclose it, and must destroy it within a reasonable time, no later than one year after the purpose for collecting it has expired.
Question to raise: how and when is notice given and consent collected, and what is the destruction date?
California: CCPA, as amended by the CPRA
California’s law defines biometric information to include face imagery from which a faceprint can be extracted, when used to establish identity. Processing biometric information to uniquely identify someone is “sensitive personal information”, which consumers can ask a business to limit. It applies to businesses that meet the law’s thresholds.
Question to raise: does the vendor treat face data as sensitive personal information, and how can a family use its right to limit?
Federal: COPPA
The FTC finalized changes to its Children’s Online Privacy Protection Rule in January 2025. The amended rule took effect on 23 June 2025, with most provisions requiring compliance by 22 April 2026. It adds to the definition of children’s personal information “a biometric identifier that can be used for the automated or semi-automated recognition of an individual”, naming facial templates and faceprints. COPPA applies to online services that collect personal information from children under 13 in the situations the rule describes, so whether it covers a particular yearbook tool may depend on how that tool works.
Question to raise: does COPPA apply to this service, and if so, whose consent is being relied on?
Federal: FERPA
The US Department of Education says a photo of a student is an education record when it is “directly related” to a student and kept by the school or by a party acting for the school. Whether a given photo is directly related depends on context. A company the school outsources work to may be treated as a “school official” when it is under the school’s direct control over how records are used and kept, and is bound by limits on sharing them.
Question to raise: is the vendor acting for the school under FERPA, and does the agreement cover face data as well as the photos?
New York
On 27 September 2023, the New York State Education Department issued a determination that prohibits schools in New York from purchasing or using facial recognition technology. Other biometric technology is left to local decision, weighing privacy, civil rights, effectiveness and parental input.
Question to raise, for New York schools: how does the determination apply to any yearbook feature that matches faces?
Other states have their own biometric and student-privacy laws. If your school is outside these states, ask counsel which apply.
What should a PTA ask any yearbook company?
A good vendor will answer these plainly, in writing.
- Do you use face recognition, or only face detection? Does any feature match faces to portraits or names, even if it is not called “facial recognition”?
- Is it opt-in, and who opts in? The school, each family, or both? What happens if nobody opts in?
- Is parental consent collected, and how? A signed form, a checkbox, or consent given by the school on families’ behalf?
- What is stored? Face templates or embeddings? Where are they kept, for how long, and on what date are they deleted? Can we get confirmation when they are?
- Is any student photo used to train or improve AI models, yours or anyone else’s?
- Can a family opt their child out without losing their place in the book? Will the child still appear in class pages and candids?
- Who at your company, and at any subcontractor, can see student photos?
Keep the answers with your yearbook records. Next year’s coordinator will want them, and so might your district. The coordinator handover pack covers what else to pass on.
Where does Rethink Yearbooks stand?
We do not use facial recognition, face matching, or any other biometric identification on student photos — not to build the yearbook, and not for anything else.
Each child’s myClass and myGrade pages are built from how the school organizes its photos — by class, grade, and event — not by scanning or identifying anyone’s face. Student photos are also never used to train AI models, are stored on U.S.-based servers, and are deleted before the next school year starts, typically August 1. Final yearbook files are kept longer so schools and families can reorder or reprint copies in the future.
The details are in our FAQ and privacy policy.
AI and yearbook photos, answered.
Is face detection the same as facial recognition?
No. Face detection finds where faces are in a photo, so software can crop or pick sharp images. Facial recognition works out whose face it is by comparing a face pattern against reference photos such as portraits. Recognition creates biometric data about a person; detection is not used to identify anyone.
Is a yearbook photo biometric data?
A photo on its own is usually not treated as a biometric identifier. Illinois’s biometric privacy law, for example, excludes photographs. The biometric data is the face measurement, template or faceprint that recognition software extracts from the photo and uses to identify someone.
Can face recognition help make sure no child is left out of the yearbook?
It can help a coordinator see which children do not appear in the candids. The trade-off is that it creates biometric data about every child. Coverage can also be checked by class and event folders, which is less precise but identifies no one.
Does opting out of face recognition mean my child is left out of the yearbook?
It should not, but it depends on the company. Ask directly whether a child who is opted out still appears in class pages and candids, and how the company makes sure of that.
Is facial recognition allowed in schools?
It depends on the state. New York’s education department prohibited schools from buying or using facial recognition technology in 2023, and states such as Illinois and Texas regulate biometric identifiers generally. Ask your school or district and its counsel what applies to you.
Ask us anything
about the photos.
If you are choosing a yearbook company, we will answer the questions above in writing, and show you how a personalized copy is put together.