ICO Finds Mixed Data-Protection Compliance in Police Facial-Recognition Audits
Key Takeaways
- 01The ICO found mixed levels of data-protection compliance across audits of five police forces using facial-recognition technology.
- 02The regulator said stronger governance, safeguards and risk management are needed to build public trust in police facial-recognition use.
- 03Police forces using facial recognition should ensure that privacy and data-protection risks are subject to effective governance and controls.
- 04The findings show that the ICO is continuing to scrutinise police use of biometric surveillance technology.
The UK Information Commissioner’s Office (ICO) has reported mixed compliance with data-protection requirements after auditing five police forces’ use of facial-recognition technology. The ICO published its findings on 18 August 2026.
The audits focused on whether police forces have appropriate governance, safeguards and risk-management arrangements for facial-recognition deployments. The ICO stressed that strong data-protection practices are necessary to support public trust when police use technology that processes biometric data.
For police forces, the findings reinforce the need to maintain robust controls around facial-recognition systems, including clear governance and documented assessment of privacy and data-protection risks. The practical implications for individual forces will depend on the ICO’s audit findings and any follow-up action in their cases.
The report also signals continued regulatory scrutiny of police use of biometric surveillance tools, particularly where deployments may affect large numbers of people in public spaces.