The ICO has published the outcomes of proactive audits of five police forces using facial recognition, finding inconsistent data protection compliance and setting out what forces must, should and could do

ICO Audits Five Forces on Police Facial Recognition. The Leveraged Years regulation briefing card.

The ICO did not test a single algorithm. It audited governance, and found that five police forces using facial recognition could not consistently show who was accountable, what data they held, where the images came from, or that the systems were accurate.

The short version

Bottom line: A regulator's audit outcomes report, not an enforcement action and not a new rule. It reports proactive audits of five forces, records an agreed action plan with each, and states that the ICO will carry out follow-up audits to assess progress.

Who this affects: Police forces in England and Wales using or considering live, retrospective or operator initiated facial recognition; their data protection officers and senior responsible owners; and suppliers of FRT to law enforcement.

Issue date: Published August 2026, with the accompanying ICO blog dated 18 August 2026. The audit of the Metropolitan Police Service is set to take place later this year.

What changed: No new legal obligation. What is new is a published compliance baseline: the report separates what forces must do, as legislative requirements or binding case law, from what they should and could do.

Analysis: Note what was not examined. The ICO says it did not test any FRT algorithms, though it noted instances involving potential issues of statistical accuracy and bias. The findings are therefore about governance rather than model performance, which makes them harder to dismiss and easier to act on: none of the gaps require a technical fix.

Primary sources: Facial recognition in law enforcement - Outcomes report · Recommendations summary · ICO blog, 18 August 2026

Instrument
Facial recognition in law enforcement - Outcomes report
Authority
Information Commissioner's Office
Jurisdiction
England and Wales
Forces audited
South Wales and Gwent, Essex, Leicestershire, West Yorkshire and Greater Manchester. West Yorkshire and Greater Manchester are the most recently published.
Still to come
An audit of the Metropolitan Police Service, set to take place later in 2026
Status
Published. Consensual audits, with an agreed action plan for each force and follow-up audits planned.
Bindingness
The report is not itself binding. It distinguishes must, being legislative requirements within the ICO's remit or binding case law, from should, being expected good practice, and could, being options.
Technologies covered
Live facial recognition and retrospective facial recognition. Operator initiated facial recognition was observed at one force but drew no formal recommendations because it was still a pilot.
Editorial Note
Informational analysis for working professionals, not legal advice. Confirm how any rule applies to your situation with qualified counsel.
Primary source
https://ico.org.uk/for-organisations/law-enforcement/facial-recognition-in-law-enforcement-outcomes-report/

What was audited, and what was not

Over the past year the ICO proactively audited five police forces: South Wales and Gwent, Essex, Leicestershire, West Yorkshire and Greater Manchester. Executive summaries for the first three were published earlier; West Yorkshire and Greater Manchester are the latest. A further audit of the Metropolitan Police Service is set to take place later this year.

The core audit activity focused on live facial recognition and retrospective facial recognition in England and Wales. The ICO observed operator initiated facial recognition at one force but made no formal recommendations, because the technology was still a pilot.

It adds a point worth carrying over anyway: operator initiated facial recognition relied largely on the same policies and procedures that govern other uses of FRT, so where those had issues, the issues would likely apply to it too.

The scope limit that matters most is stated plainly. The ICO did not test any FRT algorithms, though it noted instances involving potential issues of statistical accuracy and bias in systems. This is an audit of data protection governance, not of model performance.

What the forces got right

The report is not a uniform criticism, and the areas of assurance are worth knowing because they define the baseline the ICO now treats as achievable.

Forces were found to be satisfactory on making sure there is a clear basis in law for using facial recognition data and that this is recorded; on not using more personal information than needed when using live facial recognition; on taking appropriate steps to prevent breaches where personal information is lost, stolen or misused; on checking that third-party suppliers are suitable and overseeing their work; and on making it easier for people to exercise their information rights.

The ICO also records that compliance rates were generally higher for live facial recognition than for retrospective use, and that the forces audited engaged constructively and committed to addressing the issues identified.

That asymmetry between live and retrospective use is the quiet finding. Live deployments attract public and political attention; retrospective searches against stored images do not, and that is where the report finds more of the problems.

The gaps

The ICO found gaps, inconsistencies and several areas for improvement, some in individual forces and some across several of those participating.

The most notable were: making sure there is clear senior oversight, accountability and training for staff using the technology; making sure staff understand their roles and responsibilities; keeping clear records of what personal information is being used, where it comes from, how it is used and who it is shared with; making sure images used for retrospective facial recognition are obtained from appropriate sources and not kept for longer than necessary; and checking that facial recognition systems are accurate and taking steps to reduce the risk of unfairness or bias.

Its summary conclusion is that the audits show inconsistencies in data protection compliance across the audited forces, that forces must improve the governance of their use of FRT, and that this is to avoid the risk of harm to people and to build public trust.

The remedy is procedural rather than declaratory. The ICO agreed an action plan with each audited force and will carry out follow-up audits to assess progress against those plans and check that identified risks are being addressed and mitigated.

Must, should, could

The report uses a three-tier vocabulary deliberately, and anyone drafting a force policy should adopt the same distinction. Must refers to legislative requirements within the ICO's remit, or established binding case law. Should is not a legislative requirement but what the ICO expects forces to do to comply effectively, and a force taking a different approach must be able to demonstrate that its approach also complies. Could is an option or example.

On governance, all forces must understand how the systems they deploy process personal information and the risks arising, and must ensure appropriate governance arrangements including clear oversight, accurate and up-to-date policies and defined roles and processes. Senior leadership should be aware of how FRT processing is carried out and should make it a standing item on appropriate boards and working groups.

The sharpest single obligation is on logging: police forces must have logging capabilities in place for FRT to meet the requirements of the law. Without this, the ICO says, a force may not be able to understand how and why staff are using the personal information on their FRT system.

On documentation, forces must be able to document their use of FRT and maintain records of processing activities. On training, forces must ensure appropriate technical and organisational measures are in place, and should only grant staff access to FRT once they have completed relevant training, using content that is up to date for the specific software in use.

Why this lands the way it does

The ICO situates the work inside its AI and biometrics strategy, and in a policy moment it describes precisely: live facial recognition vans were previously restricted to two forces, rollout has expanded to forces with no prior experience of using the technology in public places, and forces have been exploring operator initiated facial recognition, which could allow officers to stop individuals in the street and check them against a watchlist via a mobile app.

It is careful about both sides of the balance, noting the arguments that live facial recognition can assist in preventing and detecting crime, and the significant risks, including that a false match can lead to wrongful intervention, accusation or arrest.

It also grounds its expectations in its own history in this area, including its 2019 Opinion and its intervention in the judicial review in R (Bridges) v Chief Constable of South Wales Police, and in published research showing that public support for police FRT is conditional on the technology being accurate, unbiased and respecting of privacy.

For a force, the practical consequence is that the ICO now has an evidenced, published baseline and an announced follow-up programme. A force that cannot show senior oversight, logging and image provenance at the next audit will be failing against findings the regulator has already put in the public domain.

Key compliance takeaway

Three things to action if you advise a force. First, logging: the ICO states as a must that forces have logging capabilities for FRT to meet the requirements of the law, and it is the clearest single test in the report. Second, retrospective facial recognition: compliance was generally weaker there than for live deployments, and the specific gaps were image provenance and retention, so check where RFR images come from and how long they are kept. Third, the follow-up audits are announced, not hypothetical, and the Metropolitan Police Service audit is still to come this year. Note also what the report does not do: the ICO did not test any algorithm, so nothing here validates or condemns any vendor's accuracy, and a force cannot answer these findings with a supplier's performance figures.

Source File

https://ico.org.uk/for-organisations/law-enforcement/facial-recognition-in-law-enforcement-outcomes-report/

Open the outcomes report and confirm four things: the contents listing Introduction, Public research and harms, Our audit activity, Recommendations summary, Reforms and devolved use of FRT and Conclusions and impact; the statement in Our audit activity that the ICO did not make formal recommendations on operator initiated facial recognition because it was still a pilot; the must, should and could definitions at the top of the Recommendations summary; and the logging obligation in the governance and accountability section.

Police forces must have logging capabilities in place for FRT to meet the requirements of the law. Information Commissioner's Office, Facial recognition in law enforcement - Outcomes report, Recommendations summary

FAQ

Which forces were audited?

South Wales and Gwent, Essex, Leicestershire, West Yorkshire and Greater Manchester. Executive summaries for the first three were published earlier; West Yorkshire and Greater Manchester are the most recent. An audit of the Metropolitan Police Service is set to take place later this year.

Did the ICO test the accuracy of the technology?

No. It says it did not test any FRT algorithms, although it noted instances involving potential issues of statistical accuracy and bias. The audits examined data protection governance, not model performance.

What did forces do well?

The ICO was satisfied on identifying and recording a clear basis in law, not using more personal information than needed in live deployments, preventing breaches, checking and overseeing third-party suppliers, and making it easier for people to exercise information rights. Compliance was generally higher for live facial recognition than for retrospective use.

What were the main gaps?

Senior oversight, accountability and staff training; staff understanding of roles and responsibilities; records of what personal information is used, where it comes from, how it is used and who it is shared with; the sources and retention of images used for retrospective facial recognition; and checking system accuracy and reducing the risk of unfairness or bias.

What do must, should and could mean here?

Must refers to legislative requirements within the ICO's remit or established binding case law. Should is expected good practice, which a force may depart from only if it can demonstrate its alternative also complies. Could is an option or example.

What happens next?

The ICO agreed an action plan with each audited force and will carry out follow-up audits to assess progress, check that identified risks are being addressed and mitigated, and support improvement.

Sponsored Training

Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.

."}}]}