The British authority emphasizes the importance of strong governance for police facial recognition to gain public trust
The UK Information Commissioner's Office (ICO) has published the findings of its audits on the use of facial recognition technology by police forces in England and Wales.
The audits conducted with five police forces revealed inconsistencies in data protection compliance. While positive points were noted, such as documenting a legal basis or data minimization for live facial recognition, significant improvements are needed. The main shortcomings concern the lack of oversight, accountability, and staff training, insufficient record-keeping on the use of personal data, the origin and retention period of images for retrospective facial recognition, as well as the absence of system accuracy verification and measures to reduce bias risks. In total, 107 recommendations were made and accepted, with the audited forces committing to implement action plans.
In 2025, a bias was reported in the retrospective facial recognition algorithm of the National Police Database, increasing the risk of incorrect matches for certain demographic groups. The ICO expressed its concerns to the Home Office and the National Police Chiefs' Council (NPCC), which implemented mitigation measures, including training and equality impact assessments, pending the algorithm's replacement. The supervisory authority is monitoring the situation and reserves the right to take further regulatory action.
The ICO is also involved in discussions on the evolution of the legislative framework related to biometrics in England and Wales, emphasizing that data protection legislation must remain the foundation. The authority is also engaged in reflections in Scotland, where the Scottish Police Authority has launched a consultation on the potential use of live facial recognition, as well as in Northern Ireland within the framework of the Justice Bill.
The audits conducted with five police forces revealed inconsistencies in data protection compliance. While positive points were noted, such as documenting a legal basis or data minimization for live facial recognition, significant improvements are needed. The main shortcomings concern the lack of oversight, accountability, and staff training, insufficient record-keeping on the use of personal data, the origin and retention period of images for retrospective facial recognition, as well as the absence of system accuracy verification and measures to reduce bias risks. In total, 107 recommendations were made and accepted, with the audited forces committing to implement action plans.
In 2025, a bias was reported in the retrospective facial recognition algorithm of the National Police Database, increasing the risk of incorrect matches for certain demographic groups. The ICO expressed its concerns to the Home Office and the National Police Chiefs' Council (NPCC), which implemented mitigation measures, including training and equality impact assessments, pending the algorithm's replacement. The supervisory authority is monitoring the situation and reserves the right to take further regulatory action.
The ICO is also involved in discussions on the evolution of the legislative framework related to biometrics in England and Wales, emphasizing that data protection legislation must remain the foundation. The authority is also engaged in reflections in Scotland, where the Scottish Police Authority has launched a consultation on the potential use of live facial recognition, as well as in Northern Ireland within the framework of the Justice Bill.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire