The UK's Information Commissioner's Office (ICO) has told police forces using facial recognition technology to follow its data protection recommendations more closely, as the technology becomes a routine part of policing across the country. The watchdog's intervention signals growing concern that the pace of facial recognition rollout is outstripping the safeguards meant to protect the personal data it collects.
Facial recognition technology, often deployed as live facial recognition (LFR) at public events, in town centers, or through retrospective searches against custody images, works by scanning faces in real time or from footage and comparing them against police watchlists. Because it processes biometric data, one of the most sensitive categories under UK data protection law, any misstep in how that data is collected, stored, or shared carries outsized privacy risk. The ICO's call for stronger governance reflects a simple reality: powerful surveillance tools require equally powerful accountability structures behind them.
What the ICO Is Asking Police To Do
As the UK's independent data protection regulator, the ICO has authority to scrutinize how public bodies, including police forces, handle personal information under the UK GDPR and the Data Protection Act. Its latest guidance to police centers on data governance: clear documentation of why facial recognition is used, how long biometric data is retained, who has access to watchlists, and how decisions made using the technology can be reviewed or challenged.
This isn't a demand to abandon facial recognition altogether. Rather, the ICO is asking forces to build the kind of internal controls that make the technology's use transparent and defensible, both to the public and to regulators. Strong governance means fewer opportunities for data to be mishandled, retained longer than necessary, or used beyond its original purpose.
Why Data Governance Matters More Than the Technology Itself
It's easy to focus on the accuracy or fairness of facial recognition algorithms, but the ICO's emphasis on governance points to a different vulnerability: what happens to the data once it's collected. Biometric identifiers cannot be changed the way a password can. If facial recognition data is stored insecurely, shared without proper authorization, or kept indefinitely, the consequences of a breach or misuse are far more serious than a leaked email address.
This concern isn't hypothetical for UK policing. Sensitive law enforcement data has already proven attractive to attackers. ExfilSquad's leak of 1.9GB from the Police National Legal Database showed that even systems meant for internal legal reference can become a target and a liability when governance falls short. Facial recognition databases, which centralize highly sensitive biometric records tied to real identities, would represent an even more valuable target if similar gaps in security practice were allowed to persist.
The risks of centralizing sensitive personal data at scale have also played out well beyond policing. The UK Biobank hack affecting 500,000 volunteers demonstrated how large repositories of personal data, even when built for legitimate research purposes, can end up exposed and sold if protections lag behind the scale of collection. Police facial recognition systems face a comparable challenge: the more faces added to watchlists and databases, the greater the potential fallout from any failure in governance.
Enforcement history also underscores why the ICO is stepping in early rather than after the fact. The regulator's nearly £1 million fine against South Staffordshire Water following a breach exposing hundreds of thousands of customer records is a reminder that the ICO does act when organizations fail to meet their data protection obligations, and that facial recognition data governance failures could carry similar consequences for police forces.
What This Means For You
If you live, work, or attend events in areas where police deploy facial recognition, this technology may already be processing your biometric data without your direct knowledge, since live facial recognition typically scans everyone within camera range, not just people on a watchlist. The ICO's push for better governance is ultimately about ensuring that scanning is proportionate, time-limited, and accountable, rather than an open-ended surveillance capability.
For most people, the practical takeaway is that facial recognition oversight is still catching up to deployment. That gap means it's worth paying attention to how and where these systems are used in your area, and supporting calls for transparency around retention periods, watchlist criteria, and independent audits.
Key Takeaways
- Facial recognition processes biometric data, one of the most sensitive personal data categories under UK law, making governance failures higher-stakes than typical data mishandling.
- The ICO's recommendations focus on documentation, retention limits, and accountability, not banning the technology outright.
- Centralized databases, whether biometric, legal, or medical, have repeatedly proven attractive targets when security and governance lag behind data collection.
- Members of the public can look for transparency from local police forces about facial recognition deployments and retention practices, and raise concerns with the ICO directly if safeguards seem lacking.
As facial recognition becomes a more permanent fixture of UK policing, the strength of its data governance, not just its technical accuracy, will determine whether the technology earns lasting public trust.




