Skip to main content
Police Facial Recognition Audits Reveal Governance GapsData Governance Frameworks
5 min readFor Data Governance Teams

Police Facial Recognition Audits Reveal Governance Gaps

The Challenge

The UK's Information Commissioner's Office audited five police forces using live facial recognition (LFR) technology and found a pattern of inconsistent data protection compliance, weak oversight, and inadequate safeguards against bias. These issues weren't just theoretical risks. The ICO identified forces deploying LFR in public spaces without prior operational experience and some testing operator-initiated facial recognition where officers stop individuals to cross-reference them against watchlists.

The consequences are real. A false match can lead to wrongful intervention, accusation, or arrest. A December 2025 Home Office report confirmed racial bias in retrospective facial recognition systems used by police, showing that algorithms incorrectly included certain demographic groups in search results more frequently. Emily Keaney, the ICO's deputy commissioner for regulatory policy, emphasized the seriousness of these findings, demanding urgent clarity before the regulator could determine next steps.

Regulatory Environment

Police forces must comply with the UK General Data Protection Regulation and the Data Protection Act, which require a lawful basis, proportionality, and adequate Technical and Organisational Measures. LFR processes biometric data, which Article 9 of the UK General Data Protection Regulation classifies as special category data needing heightened protection.

The technology itself poses three challenges. First, LFR operates in real time in public spaces, so errors can quickly escalate. Second, watchlists pull from multiple sources with varying data quality and retention policies. Third, the systems rely on algorithmic accuracy, which the December 2025 Home Office report showed to be uneven across demographic groups.

Forces also face a regulatory gap. The EU AI Act largely prohibits LFR in public spaces, but UK forces operate under a different framework. This means they're building governance structures without settled regulatory precedent, making the ICO's audits the de facto compliance baseline.

Audit Approach

The ICO structured its audits around four control areas: senior oversight and accountability, record-keeping practices, data source management and retention, and algorithmic accuracy and bias mitigation.

For oversight, the ICO required forces to establish clear accountability for FRT deployment decisions. This included designating senior officers responsible for authorizing each LFR operation, documenting the legal basis and proportionality assessment, and ensuring operators received role-specific training.

In record-keeping, the ICO mandated that forces maintain logs showing what personal information the system processed, where watchlist data originated, how the system used that data, and who received match alerts. This aligns with Article 30 of the UK General Data Protection Regulation's processing records requirement, but the ICO operationalized it by requiring documentation of each LFR deployment as a discrete processing activity.

Regarding data sources and retention, the ICO focused on retrospective facial recognition, where compliance lagged. Forces had to verify that RFR images came from lawful sources and implement time-to-live controls so images didn't persist beyond necessity. The ICO found forces keeping RFR images without clear retention rules, creating compliance gaps and expanding attack surfaces.

For algorithmic accuracy, the ICO required forces to test systems for demographic bias before deployment and monitor for accuracy degradation over time. After the December 2025 Home Office report, this became a mandatory safeguard.

Results and Metrics

The ICO found higher compliance rates for LFR than RFR but noted that several forces still needed significant improvements across all four control areas. The audits revealed inconsistencies in how forces applied data protection law, suggesting that governance maturity varied more than the technology itself.

The ICO reported that forces were willing to engage and make changes based on audit findings. This indicates that governance gaps stemmed from capacity and precedent issues rather than resistance to oversight.

The December 2025 Home Office report quantified a specific risk: RFR algorithms incorrectly included certain demographic groups in search results at higher rates, though the report limited this finding to "a limited set of circumstances." The ICO characterized this as requiring urgent clarity before assessing regulatory next steps.

Recommendations for Improvement

The ICO's recommendation to forces was clear: use the audit findings to improve data protection governance before expanding FRT deployments. This suggests the regulator sees current governance structures as inadequate for the scale forces are planning.

If forces were starting deployments now, they'd establish senior oversight and bias testing before the first operation. They'd build retention rules into procurement requirements so systems enforce time-to-live limits by default. They'd document each deployment's legal basis and proportionality assessment in advance, creating an audit trail that supports compliance and public accountability.

The ICO's framing implies forces underestimated the governance required for biometric processing in public spaces. They treated LFR as an operational tool that happened to process personal data, rather than as high-risk processing needing a governance framework first.

Takeaways for Your Team

If you're evaluating biometric systems or any high-risk processing technology, build the governance structure before the pilot. This means senior accountability, processing records, retention controls, and bias testing as prerequisites, not post-deployment fixes.

For algorithmic systems, require vendors to provide demographic performance data before procurement. The December 2025 Home Office report showed that accuracy isn't uniform, so your Article 35 data protection impact assessment should quantify accuracy variation across the populations your system will process.

Treat each deployment as a discrete processing activity with its own legal basis, proportionality assessment, and retention period. The ICO found forces running multiple LFR operations without deployment-specific documentation, making it impossible to demonstrate compliance at the operational level.

If you're processing special category data in public spaces, expect supervisory authority scrutiny. The ICO audited five forces and published findings as sector-wide guidance, meaning your governance structure will be benchmarked against those audit criteria whether you're a police force or a private-sector controller.

Finally, recognize that "willing to engage and make changes" isn't the same as compliant. The ICO's characterization suggests forces are cooperative, but cooperation doesn't close the governance gaps the audits identified. Your supervisory authority will measure you against the requirements of data protection law, not your willingness to improve.

You Might Also Like