Skip to main content
Facial Recognition Audits: What Police DPOs Are Actually AskingSupervisory Authorities & Enforcement
5 min readFor Data Protection Officers (DPOs)

Facial Recognition Audits: What Police DPOs Are Actually Asking

Your force just approved a live facial recognition trial, believing it'll speed up crime detection. Now, your inbox is flooded with questions, and the ICO's latest audit findings aren't helping.

These questions stem from police forces deploying facial recognition technology without prior experience. The ICO audited five forces and found inconsistencies. Some had solid practices; others had significant gaps. Here are the questions DPOs are asking, based on those audits and compliance requirements.

Senior Oversight: Is It Necessary?

Yes, it's essential.

The ICO highlighted insufficient senior oversight as a critical issue. Live facial recognition isn't like body cameras or automatic number plate recognition. A false match can lead to wrongful intervention or arrest, impacting civil liberties.

Senior oversight involves someone at command level owning the deployment decision, reviewing watchlists, and signing off on the legitimate interests assessment before each deployment. They're accountable if something goes wrong. The ICO expects documented governance structures showing who approved what, when, and based on which risk assessment.

If your chief thinks this is just IT procurement, show them the audit findings. Compliance rates were higher for live facial recognition than retrospective facial recognition, but only when treated as a data protection governance issue from the start.

Record Keeping: What Do You Need?

Deployment logs aren't enough. The ICO called out record keeping as needing improvement: what personal information you're using, where it comes from, how it's used, and who it's shared with.

Document:

  • Source of watchlist images (arrest photos, intelligence databases, other forces)
  • Retention periods for both watchlist images and images captured during deployment
  • Who accessed the system and when
  • Match decisions: who reviewed them, what action was taken, how long the review took
  • Data sharing: if you're sending match data to another force or agency, log it

Article 30 requires you to maintain records of processing activities. For facial recognition, that's not a static document. You need audit trails showing the full lifecycle of personal data through each deployment. If the ICO asks you to explain a specific match from three months ago, you should be able to reconstruct what happened without guessing.

Retrospective Facial Recognition: Do the Same Rules Apply?

Yes, but compliance is often worse. The ICO found gaps in checking image sources and deleting images when the retention period expired.

"Appropriate sources" aren't defined in the audit findings, but if you're using images from social media, public websites, or databases you don't control, verify the lawful basis for processing that data. If the original controller didn't collect it for law enforcement purposes, you can't repurpose it under Article 10.

Retention is simpler: if the image was collected for a specific investigation and that investigation is closed, the image should be deleted unless you've documented a continuing law enforcement need. The ICO found forces keeping images indefinitely without justification, which is a compliance failure.

Addressing Racial Bias in Facial Recognition

The December 2025 Home Office report found algorithms more likely to incorrectly include some demographic groups in search results. The ICO's Emily Keaney said they required "urgent clarity" to assess next steps.

Under Article 5(1)(a), your obligation is fairness. If your system produces biased results, you're processing personal data unfairly. The ICO's audit findings included a requirement to check that facial recognition systems are accurate and to take steps to reduce the risk of unfairness or bias.

Practically, that means:

  • Requesting bias testing results from your processor before procurement
  • Running your own bias assessments using demographically diverse test sets
  • Monitoring match accuracy across demographic groups during live deployments
  • Documenting what you found and what you did about it

If you can't demonstrate that you've tested for bias and mitigated it, you're exposed. The ICO expects this work to be done before deployment, not after a wrongful arrest.

Operator-Initiated Facial Recognition: Compliance Challenges

Operator-initiated facial recognition adds complexity. You're adding discretion to a system that already carries significant risk.

The core compliance requirements don't change, but your legitimate interests assessment needs to account for:

  • How officers decide who to scan (risk of discriminatory selection)
  • Whether the person being scanned is informed (transparency obligations under Articles 13-14)
  • What happens if they refuse (lawfulness of processing)
  • How you're documenting each scan (record keeping)

The ICO found inconsistencies in data protection compliance across the five forces audited. Operator-initiated scanning introduces more variables, which means more ways to create inconsistencies. If you're piloting this, your governance framework needs to be tighter, not looser.

The EU AI Act and GDPR Compliance

The EU AI Act largely prohibits live facial recognition by police in public spaces within the EU. You're in England and Wales. It doesn't apply to you, but it signals regulatory direction.

Your compliance obligation is the GDPR and the Data Protection Act 2018. The ICO's position is clear: strong data protection governance is essential to fostering the public trust needed for facial recognition to work as a policing tool. Rights groups are pushing for stronger legislative safeguards. The regulatory environment is tightening.

If your force is banking on weak oversight, the ICO's audit program suggests otherwise. They're willing to engage with forces that make changes based on findings, but they're also documenting where improvements are still needed. That's the language of enforcement preparation, not advisory guidance.

Next Steps

The ICO hasn't published the full audit reports, but Keaney's statements and the audit findings summary provide the compliance baseline. Your force should use those findings as a self-assessment checklist before the ICO schedules your audit.

If you're procuring facial recognition systems, your processor should be able to answer questions about bias testing, data retention capabilities, and audit trail functionality. If they can't, they're not ready for a UK police deployment.

And if your leadership is treating this as a technology decision rather than a data protection governance decision, the ICO's audit findings are your evidence that the approach needs to change.

You Might Also Like