ICO calls on police forces to earn public trust over facial recognition use
Published: 18/08/2026
| ICO
In a blog article, Emily Keaney, Deputy Commissioner for Regulatory Policy at the Information Commissioner's Office (ICO), discusses how the regulator has reviewed the expanding use of facial recognition technology (FRT) by police forces across England and Wales. The latest assessment comes amid rapid deployment of live facial recognition (LFR) vans beyond original trial forces, alongside emerging methods such as operator-initiated mobile tools.
While acknowledging potential crime prevention benefits, the ICO stressed that risks, including false matches leading to wrongful interventions or arrests, require robust governance and compliance with data protection laws. Previously published ICO research indicates that public support for FRT is strictly conditional on the technology being accurate, unbiased, and respectful of privacy.
Having undertaken proactive audits of five forces: South Wales and Gwent, Essex, Leicestershire, West Yorkshire, and Greater Manchester, the ICO identified a mixed compliance picture. A final audit of the Metropolitan Police Service (MPS) is scheduled for later this year. Although forces demonstrated lawful bases and higher compliance in LFR than in retrospective facial recognition (RFR), the ICO identified significant gaps in senior oversight, staff training, data record-keeping, and the sourcing and retention of RFR images. Forces were also urged to actively test systems to reduce risks of bias and inaccuracy.
Following the audits, the ICO issued 107 compliance and best practice recommendations, all of which were accepted or partially accepted, leading to the submission of formal action plans. Documented across two outcome reports (links: here and here), the findings are intended to guide all law enforcement bodies. In addition, the ICO is working alongside the National Police Chiefs' Council (NPCC) to drive consistent standards and will share results with Police Scotland and the Police Service of Northern Ireland (PSNI).
Training Announcement: The IAPP Certified Information Privacy Technologist (CIPT) is a privacy-focused IT professional certification from the IAPP that addresses data protection requirements and controls in complex technical environments. It explores the data lifecycle, privacy risk models and frameworks, the principles of Privacy by Design, and the role of privacy-enhancing technologies within the organisation. Find out more.
What is this page?
You are reading a summary article on the Privacy Newsfeed, a free resource for DPOs and other professionals with privacy or data protection responsibilities helping them stay informed of industry news all in one place. The information here is a brief snippet relating to a single piece of original content or several articles about a common topic or thread. The main contributor is listed in the top left-hand corner, just beneath the article title.
The Privacy Newsfeed monitors over 300 global publications, of which more than 3,250 summary articles have been posted to the online archive dating back to the beginning of 2020. A weekly roundup is available by email every Friday.