Infosecurity

ICO Tells Police Forces to Tighten Data Governance as Facial Recognition Rollouts Accelerate

Published

on

A Watchdog’s Warning

The UK’s data protection regulator has a blunt message for police forces embracing live facial recognition: your paperwork isn’t keeping up with your technology.

In an article published on August 18, Emily Keaney, deputy commissioner for regulatory policy at the Information Commissioner’s Office (ICO), noted that a growing number of forces are deploying the tech with zero prior experience of using it in public. Some are even experimenting with operator-initiated facial recognition — where officers stop someone on the street and instantly cross-check their face against a watchlist.

That’s a powerful tool, but it’s also a risky one. As Keaney put it: “A false match can have serious consequences for people, including wrongful intervention, accusation or arrest.”

What the Audits Found

To gauge how forces are handling these risks, the ICO audited five police forces across England and Wales. The results, published this week, paint an uneven picture.

“Our audits reveal inconsistencies in data protection compliance across the five forces audited,” Keaney said. “While there was some good practice, significant improvements are still needed.”

Compliance rates were actually higher for live facial recognition (LFR) than for retrospective facial recognition (RFR), which involves scanning stored images after the fact. But in both cases, the ICO flagged several recurring gaps:

  • Insufficient senior oversight, accountability, and training for staff using the technology
  • Poor record-keeping about what personal data is used, where it comes from, and who it’s shared with
  • RFR images sometimes sourced from questionable places and kept longer than necessary
  • Inadequate checks on system accuracy and bias

The last point stings, given a Home Office report on police facial recognition bias published in December 2025. That report found that, in certain situations, the algorithm was more likely to incorrectly include some demographic groups in its search results. Keaney said at the time that the ICO required “urgent clarity on this matter.”

Why Governance Matters

You might wonder: why is the ICO so focused on administrative details like record-keeping? Because, as the regulator argues, public trust is the foundation for any sustainable use of facial recognition in policing. If people believe the system is sloppy or biased, they won’t accept it — no matter how effective it is at catching criminals.

There’s also a legal dimension. The EU AI Act largely prohibits police use of live facial recognition in public spaces, and while the UK has its own path, the ICO’s guidance signals that British regulators expect similar caution.

Next Steps for Police

The ICO says forces have been “willing to engage and make changes” based on the audit findings. That’s encouraging, but the regulator is clear that more work is needed before LFR becomes a standard policing tool.

For forces looking to get ahead of the curve, the ICO’s recommendations boil down to a few practical actions:

  1. Appoint a senior officer responsible for FRT oversight and ensure all staff are properly trained
  2. Maintain clear, auditable records of every use of the technology
  3. Source RFR images only from approved channels and delete them promptly
  4. Regularly test systems for accuracy and bias, and document the results

These aren’t glamorous tasks, but they’re the difference between a tool that protects the public and one that undermines civil liberties. As the ICO’s Keaney put it, strong data protection governance is essential to fostering the trust that facial recognition needs to flourish as a policing tool.

For more context on how these issues are playing out elsewhere, read about the landmark court ruling on police facial recognition and the Home Office’s findings on racial bias in RFR systems.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version