Skip to content
Live newsroom 142 readers online
Tuesday, August 25, 2026 Live Sync: Just now
Demystifying Finance, Technology, and Global Markets for the Next Generation.
BreakingAussie capitals ‘will be driverless within a decade’, says robotaxi pioneer
Important BUY INTC Stage 2 (Conv: 5/5 | Size: 20%)

ICO police facial recognition audits reveal ‘mixed’ bag

UK data regulator says “significant improvements” are needed in how UK police forces are using facial recognition technologies, after official audits reveal “a mixed picture”. According to an “outcomes report” from the UK Information Commissioner’s Office (ICO), which has been published alongside its recent facial recognition audits of West Yorkshire Police and Greater Manchester Police, […]

By deepak · August 20, 2026 · 4 min read

UK data regulator says “significant improvements” are needed in how UK police forces are using facial recognition technologies, after official audits reveal “a mixed picture”.

According to an “outcomes report” from the UK Information Commissioner’s Office (ICO), which has been published alongside its recent facial recognition audits of West Yorkshire Police and Greater Manchester Police, inconsistencies across how a sample of five forces are using the technology have revealed the need for “urgent attention” in a number of areas.

The ICO said that while there are “genuine areas of assurance” (including forces generally having identified and documented a lawful basis for their facial recognition-related data processing), action is needed to ensure there is clear senior oversight, accountability and training for staff using facial recognition technologies, and that they fully understand their roles and responsibilities.

It added that forces will also need to keep clear records of what personal information is being used, where it comes from, how it is used and who it is shared with, as well as take extra steps to reduce the risk of unfairness or bias and ensure systems are accurate.

The ICO said that across audited forces – which also includes South Wales and Gwent, Essex, and Leicestershire – it made 107 recommendations covering both compliance and best practice, all of which were accepted or partially accepted.

The report and audit results come amid a nationwide push to roll out facial recognition and artificial intelligence (AI) tools across UK policing. Prior to this, facial recognition was mostly used by the Metropolitan and South Wales Police.

Further recommendations made by the ICO include forces developing their own facial recognition audit procedures, ensuring there are logging capabilities in place to understand how and why officers are using people’s personal information, and conducing iterative data protection impact assessments to ensure all risks are identified and mitigated.

The regulator also highlighted that compliance rates were generally higher for the use of live facial recognition (LFR) than retrospective facial recognition (RFR), specifically noting that forces need to make sure images used for the latter are obtained from appropriate sources and not kept for longer than necessary.

“Our audit recommendations give forces the direction they need to get data protection obligations right,” said the ICO. “The forces we have audited all have action plans in place to ensure compliance. We will follow up with forces to ensure they implement these.

“At national level, we are working with the National Police Chiefs’ Council’s (NPCC’s) leads for FRT to support a consistent approach to compliance across forces in England and Wales. Drawing on the findings of our audits and the clear expectations set out in this report. We are also engaging with the Home Office on planned legislative reforms for FRT and national policing.”

The ICO added that “if forces do not make improvements, or if we identify future contraventions of the law, we will not hesitate to use our regulatory tools”.

An audit of how the Metropolitan Police – which first deployed LFR at Notting Hill Carnival 2016 – use facial recognition is due to be conducted later in 2026.

The ICO was clear in its report that forces should limit the size of watchlists (in line with data protection principles requiring personal information to be adequate, relevant and not excessive for the intended law enforcement purpose), and should only use images that are accurate, verifiable and lawfully held by the police at the time of use.

However, despite the High Court ruling in 2012 that millions of custody images – including those of people never even charged with or convicted of a crime – were being unlawfully retained by the Home Office in the Police National Database (PND), successive biometrics commissioners have warned that millions of these records are still being kept and could find their way into police watchlists.

In February 2026, for example, it came to light that software engineer Alvi Choudhury was arrested as a result of an RFR search by Thames Valley Police, who was detained after the force used a five-year-old custody image to link him to a crime that he was 80 miles away from at the time of the incident.

Source: Read the original article on www.computerweekly.com