British Transport Police (BTP) spent roughly £320,000 on a six-month live facial recognition trial. According to reporting by The Register, the British Transport Police facial recognition pilot produced a single alert, and that alert turned out to be a false positive. No genuine matches were recorded.
The figures are small, but the questions they raise are large. What do the public and police get in return for scanning faces in busy public spaces, and what legal footing supports it?
What the BTP Pilot Found
The headline facts, as reported, are simple. The pilot ran for six months, cost around £320K, and generated one alert. That alert was wrong. In practical terms, the system did not identify a single person it was meant to find during the trial.
Live facial recognition (LFR) works by comparing faces captured by cameras against a watchlist of people police want to locate, such as those wanted for offences or reported missing. When the software finds a possible match, it raises an alert for an officer to review. A false positive means the system flagged someone who was not actually on the list.
It is worth being careful about what this result does and does not show. The source reporting does not give a detailed breakdown of how many faces were scanned, where the cameras were placed, or how the watchlists were built, so we cannot draw conclusions about the technology's accuracy in general. Other forces have reported different outcomes from their own trials, and those results are not directly comparable. What the BTP figures do show is a high cost paired with no confirmed operational benefit over this period.
Why a False Positive Matters for Biometric Surveillance
One false alert might sound like a minor statistic. For biometric surveillance it matters for several reasons.
The cost of being wrong falls on individuals. A false positive means a real person, who has done nothing wrong, is flagged to officers. Depending on how a deployment is run, that can mean being stopped, questioned, or delayed in front of other travellers.
Everyone is scanned, not only suspects. To produce even one alert, a system must process the faces of everyone who passes the camera. That is a very different proposition from targeted investigation. The privacy intrusion is spread across a large number of people, while the benefit depends on finding a very small number.
Proportionality becomes harder to argue. Public bodies using intrusive technology are expected to show that it is necessary and proportionate. A six-month trial with no true matches makes that case harder to build, at least on the evidence available from this pilot.
None of this proves that facial recognition can never work in a transport setting. It does suggest that cost, accuracy, and outcomes should be published and scrutinised, not assumed.
What UK Data Protection Law Says About Facial Recognition
Facial images processed to identify a person count as biometric data, which UK law treats as a special category of personal data. That brings stricter requirements than ordinary personal information. For law enforcement use, the rules are set out mainly in the Data Protection Act 2018, which works alongside UK GDPR. Our explainer on the Data Protection Act 2018 and its seven principles covers the framework in more detail, including how fines are applied.
In broad terms, organisations handling this kind of data are expected to:
- Have a clear and lawful basis for processing
- Limit collection to what is necessary for a defined purpose
- Keep data secure and retain it no longer than needed
- Be transparent about what they are doing and why
Police use of LFR is also subject to oversight from the Information Commissioner's Office, and forces typically publish impact assessments and deployment notices. Whether the law is specific enough for live facial recognition is an ongoing debate in the UK, and it is one reason results like the BTP pilot draw attention. Weak outcomes sharpen the argument over whether the privacy trade-off is justified.
What This Means For You
If you travel by rail in the UK, you may pass cameras that are part of a trial like this. You generally cannot opt out of walking through a public station, which is why transparency matters.
The practical points are these:
- Police deployments are usually signposted. Look for notices at stations and on official force pages.
- You have rights over personal data held about you. Our guide to UK GDPR rights and how to access, correct or delete your data explains how to make a request.
- Law enforcement processing has its own rules and some exemptions, so a request may not always produce the result you expect. You can still ask, and you can complain to the ICO if you are unhappy with the response.
- A VPN does not protect you from cameras in a public place. It protects your internet traffic, not your face, so it is not a fix for this issue.
Actionable Takeaways
- Stay informed. Watch for published results, cost figures, and impact assessments from BTP and other forces.
- Know your rights. Read up on how to make a subject access request and what you can ask for.
- Ask questions. Respond to public consultations and contact your MP if you have concerns about biometric surveillance.
- Escalate when needed. If you believe your data was mishandled, the ICO accepts complaints.
The British Transport Police facial recognition pilot is a small data point, but it is a useful one: £320K, six months, one alert, and that alert was wrong. To understand where you stand, start with our guides on UK GDPR rights and the Data Protection Act 2018, and use them to hold public bodies to account.




