UK data regulator says “significant improvements” are needed in how UK police forces are using facial recognition technologies, after official audits reveal “a mixed picture”.
According to an “outcomes report” from the UK Information Commissioner’s Office (ICO), which has been published alongside its recent facial recognition audits of West Yorkshire Police and Greater Manchester Police, inconsistencies across how a sample of five forces are using the technology have revealed the need for “urgent attention” in a number of areas.
The ICO said that while there are “genuine areas of assurance” (including forces generally having identified and documented a lawful basis for their facial recognition-related data processing), action is needed to ensure there is clear senior oversight, accountability and training for staff using facial recognition technologies, and that they fully understand their roles and responsibilities.
It added that forces will also need to keep clear records of what personal information is being used, where it comes from, how it is used and who it is shared with, as well as take extra steps to reduce the risk of unfairness or bias and ensure systems are accurate.
The ICO said that across audited forces – which also includes South Wales and Gwent, Essex, and Leicestershire – it made 107 recommendations covering both compliance and best practice, all of which were accepted or partially accepted.
The report and audit results come amid a nationwide push to roll out facial recognition and artificial intelligence (AI) tools across UK policing. Prior to this, facial recognition was mostly used by the Metropolitan and South Wales Police.
Further recommendations made by the ICO include forces developing their own facial recognition audit procedures, ensuring there are logging capabilities in place to understand how and why officers are using people’s personal information, and conducing iterative data protection impact assessments to ensure all risks are identified and mitigated.
Compliance rates
The regulator also highlighted that compliance rates were generally higher for the use of live facial recognition (LFR) than retrospective facial recognition (RFR), specifically noting that forces need to make sure images used for the latter are obtained from appropriate sources and not kept for longer than necessary.
“Our audit recommendations give forces the direction they need to get data protection obligations right,” said the ICO. “The forces we have audited all have action plans in place to ensure compliance. We will follow up with forces to ensure they implement these.
“At national level, we are working with the National Police Chiefs’ Council’s (NPCC’s) leads for FRT to support a consistent approach to compliance across forces in England and Wales. Drawing on the findings of our audits and the clear expectations set out in this report. We are also engaging with the Home Office on planned legislative reforms for FRT and national policing.”
The ICO added that “if forces do not make improvements, or if we identify future contraventions of the law, we will not hesitate to use our regulatory tools”.
An audit of how the Metropolitan Police – which first deployed LFR at Notting Hill Carnival 2016 – use facial recognition is due to be conducted later in 2026.
Unlawfully held custody images
The ICO was clear in its report that forces should limit the size of watchlists (in line with data protection principles requiring personal information to be adequate, relevant and not excessive for the intended law enforcement purpose), and should only use images that are accurate, verifiable and lawfully held by the police at the time of use.
However, despite the High Court ruling in 2012 that millions of custody images – including those of people never even charged with or convicted of a crime – were being unlawfully retained by the Home Office in the Police National Database (PND), successive biometrics commissioners have warned that millions of these records are still being kept and could find their way into police watchlists.
In February 2026, for example, it came to light that software engineer Alvi Choudhury was arrested as a result of an RFR search by Thames Valley Police, who was detained after the force used a five-year-old custody image to link him to a crime that he was 80 miles away from at the time of the incident.
That custody image was taken after Choudhury was previously detained – but never charged – in Portsmouth in 2021, following an altercation between two groups.
Senior officers from the Metropolitan and South Wales Police previously told a Parliamentary committee in December 2023 that, given the huge size of watchlists that can run into the thousands, images are selected based on the crime category attached to the photo, rather than context-specific intelligence about that individual.
Computer Weekly contacted the ICO about whether it looked into the custody image issue, and whether it could comment on how the harms of unlawfully held images finding their way onto watchlists can be effectively mitigated given the above context.
An ICO spokesperson said: “Public trust in police use of facial recognition technology depends on robust governance and accountability. Forces must ensure that images used within facial recognition systems are accurate, verifiable and lawfully held in accordance with data protection law.
“They should also be able to evidence that watchlist images are necessary and relevant. We understand this is an area of ongoing concern and we are engaging with the Home Office to understand how these issues are being addressed.”
Upcoming legislation
In December 2025, the Home Office launched a 10-week consultation on the use of LFR by UK police, allowing interested parties and members of the public to share their views on how the controversial technology should be regulated.
The department has said that although a “patchwork” legal framework for police facial recognition exists (including for the increasing use of the retrospective and “operator-initiated” versions of the technology), it does not give police themselves the confidence to “use it at significantly greater scale … nor does it consistently give the public the confidence that it will be used responsibly”.
It added that the current rules governing police LFR use are “complicated and difficult to understand”, and that an ordinary member of the public would be required to read four pieces of legislation, police national guidance documents and a range of detailed legal or data protection documents from individual forces to fully understand the basis for LFR use on their high streets.
Digital surveillance a systemic threat
In June 2026, a landmark United Nations (UN) study found that the “profound” chilling effects of digital surveillance – including via facial recognition – on people’s behaviour means it can no longer be viewed as a targeted measure against specific actors, but as a systemic threat to democracy itself.
It highlighted how chilling effects are amplified by the increasingly remote and asymmetrical nature of contemporary surveillance, which disproportionately harms marginalised and racialised communities, as well as those engaged in seeking accountability for human rights violations or challenging corruption.
One of the major problems with the remoteness and asymmetry of modern surveillance is that those subject to it are unable to gain certainty regarding the level of scrutiny they may be placed under, in turn leaving them uncertain if they will be subject to legal action by the state.
The UN study was also clear that, rather than focusing on specific tools or practices, it is more accurate to view surveillance as an interconnected ecosystem comprised of various digital infrastructures operated by both state and non-state actors.
For example, from the perspectives of those subject to surveillance, the use of facial recognition at a protest, the use of spyware to target a journalist or the infiltration of digital communication channels are not seen as discrete occurrences, but instead as constituent parts of an overall surveillance ecosystem that can be leveraged against them.
“The consequence is that ostensibly discrete surveillance activities in fact exist across a surveillance continuum and persist over time, leaving deep, long-term, society-wide impacts,” it said. “These impacts are enhanced with respect to marginalised and vulnerable groups, and those engaged in socio-political activities clashing with the status quo.
“It is this ecosystem-related impact that plays a decisive role with respect to the degree to which chilling effects are experienced by different individuals and groups. This poses a challenge to traditional human rights law analysis as ecosystem-related chilling effects are not typical ‘cause-and-effect’ harms, whereby a specific incident gives rise to a defined harm.”

