Security1 publisher3 min readPublished
ICO audits five forces on facial recognition, then tells all of England and Wales to act
The regulator found inconsistent data protection compliance across the forces it audited, and says significant improvements are still needed, including for street stops using operator initiated matching.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The UK's data protection watchdog has urged police forces using live facial recognition (LFR) to improve their data governance in line with best practice.
- Emily Keaney, deputy commissioner for regulatory policy at the ICO, said in an article published on August 18 that a growing number of forces are rolling out LFR despite having no prior experience of using it in public places.
- Some forces are trialling new approaches such as operator initiated facial recognition, where officers stop suspects in the street to cross-reference them against a watchlist, according to Keaney.
- Keaney said: "There are clear arguments that live facial recognition can assist law enforcement agencies in preventing and detecting crime" and that "Its use also carries significant risks - a false match can have serious consequences for people, including wrongful intervention, accusation or arrest."
- The ICO audited several forces' use of the technology to ensure LFR is used lawfully and proportionately with strong oversight, accountability and safeguards that meet the requirements of data protection law.
Compiled by The WatchSomething wrong?How this is made
Why it matters
The Information Commissioner's Office has audited five police forces' use of facial recognition and found inconsistencies in data protection compliance, with some good practice but significant improvements still needed [7]. It is now recommending that police forces across England and Wales use those audit findings to improve their own data protection governance [6], which moves facial recognition out of the procurement column and into the compliance column for forces that were never audited.
Emily Keaney, the ICO's deputy commissioner for regulatory policy, said in an article published on August 18 that a growing number of forces are rolling out live facial recognition (LFR) despite having no prior experience of using it in public places [2]. Some are trialling operator initiated facial recognition, where officers stop suspects in the street and cross-reference them against a watchlist [3]. That is a different operational shape from a fixed van at a shopping centre: the decision to stop a person happens first, in the hands of an individual officer, and the governance questions the ICO is asking follow the officer rather than the deployment plan.
Keaney's framing is not hostile to the technology. She said there are clear arguments that LFR can assist law enforcement in preventing and detecting crime, but that its use carries significant risks, and that a false match can have serious consequences including wrongful intervention, accusation or arrest [4]. The audits were carried out to check that LFR is used lawfully and proportionately with oversight, accountability and safeguards that meet data protection law [5].
Four areas were flagged for urgent attention. Forces need senior oversight, accountability and training for staff using the technology [c9a]. They need clear record keeping covering what personal information is used, where it comes from, how it is used and who it is shared with [c9b]. Images used for retrospective facial recognition (RFR) must come from appropriate sources and must not be kept longer than necessary [c9c]. And systems must be checked for accuracy, with steps taken to reduce the risk of unfairness or bias [c9d]. Compliance rates were higher for LFR than for RFR [8], which puts the weaker record on the older, quieter, less photographed use of the technology.
The bias point has a documented predicate. A Home Office report published in December 2025 found racial bias in police RFR systems, stating that in a limited set of circumstances the algorithm is more likely to incorrectly include some demographic groups in its search results [10]. Keaney said at the time that the ICO required urgent clarity so it could assess the situation and consider its next steps [11].
Two things to watch. The ICO says forces are willing to engage and make changes on the back of the audits [12]; whether that holds for the forces that were not audited is the open question, since the recommendation covers all of England and Wales while the evidence base is five forces [16]. And the legislative gap remains: rights groups have periodically called for stronger statutory safeguards before widespread police use [14], while police use of LFR in public spaces is largely prohibited under the EU AI Act [15]. The ICO's own position is that strong data protection governance is what earns the public trust the technology needs to survive as a policing tool [13].