Summary
- ICO audits of five police forces found inconsistent data-protection compliance around facial recognition.
- The regulator issued 107 compliance and best-practice recommendations, all accepted or partially accepted.
- Retrospective facial recognition generally showed weaker compliance than live deployments.
Police use of facial recognition is expanding faster than governance around the technology has become consistent, with a series of regulatory audits finding that forces can establish lawful grounds for deployment while still falling short on oversight, record keeping, image handling, accuracy, and bias controls.
The Information Commissioner’s Office has published combined findings from audits of five police forces in England and Wales using facial-recognition technology. Across the five organisations, the regulator made 107 recommendations covering legal compliance and best practice, all of which were accepted or partially accepted.
The findings do not establish that police facial recognition is inherently unlawful. The ICO identified areas of assurance, including documented lawful bases for deployment, controls intended to prevent unnecessary data collection during live use, and breach-reporting procedures.
Compliance was nevertheless uneven. The regulator wants clearer senior accountability, better staff training, stronger records of what personal information is used and shared, appropriate sourcing and retention of images, and more effective testing for accuracy and unfair bias.
Two forms of facial recognition create different risks
The audits cover both live facial recognition, where cameras compare people moving through an area against a watchlist, and retrospective facial recognition, where an existing image is searched against stored databases after an event. Both use biometric comparison, but their data flows and governance problems differ.
The ICO found higher compliance overall around live deployments than retrospective searches. Live facial recognition has attracted considerable public and regulatory scrutiny for several years, encouraging forces to create more formal procedures around authorisation, watchlists, deployment, and data handling.
Retrospective systems raise separate questions about where images originate, which databases are searched, how long material is retained, and whether photographs collected for one purpose should later become part of a biometric-search process. The regulator specifically wants forces to ensure images are obtained from appropriate sources and not retained longer than necessary.
Those controls become more important as facial-search systems become easier to use. A system does not need to be visibly deployed in a city centre to affect large numbers of people if investigators can search growing image repositories routinely after an incident.
Accuracy is not only a model metric
The ICO also refers to bias identified during 2025 testing of the algorithm used for retrospective facial-recognition searches within the Police National Database. Testing found a higher likelihood of incorrect matches for some demographic groups, prompting mitigation measures including staff training, oversight reporting, equality-impact assessments, and plans to replace the algorithm.
A false match is not equivalent to an arrest because officers can review algorithmic suggestions before acting, although the surrounding process determines how meaningful that safeguard becomes. If errors are distributed unevenly, consequences depend on how users interpret results, what other evidence they seek, and whether incorrect investigative leads fall disproportionately on particular groups.
Governance therefore extends beyond an accuracy percentage produced during technical testing. Forces need to understand the conditions in which an algorithm was evaluated, how image quality affects performance, and what operational controls reduce the chance that an automated suggestion becomes an unjustified intervention.
The ICO says it continues to monitor reports of harm arising from incorrect matches and is working with the Home Office, National Police Chiefs’ Council, and policing inspectorate while retaining the option of further regulatory action.
National deployment needs consistent safeguards
The five audited forces were South Wales and Gwent, Essex, Leicestershire, West Yorkshire, and Greater Manchester. The regulator intends its recommendations to guide all forces using facial recognition rather than remain corrective actions for those already examined.
That consistency becomes increasingly important as deployment spreads. Data-protection safeguards should not vary materially according to whether an image happens to be processed by a force with mature biometric governance or one with weaker documentation and accountability.
The legislative framework is also changing. Government has been considering future arrangements for law-enforcement biometrics and facial recognition, while the ICO has argued that data-protection law should remain the foundation of any new regime and that greater legal specificity could improve clarity.
As facial recognition becomes more embedded in policing, the difficult questions increasingly sit around the software rather than inside it. Watchlists, image sources, retention periods, staff training, algorithm testing, oversight, and human review determine how a technically capable matching system behaves once it enters routine investigative work.
The five-force audit shows that those controls remain uneven, leaving the expansion of facial recognition dependent not only on whether software can identify similarities between faces, but on whether police organisations can demonstrate consistently how those similarities are turned into decisions.












