Public Services & Administration · United Kingdom · Surveillance & Data Rights

Facial Recognition Cameras in Public: Your Rights Under UK GDPR

Live facial recognition has already been ruled unlawful once by a UK court — and the regulator is now actively auditing police forces over how they've responded. Here's the legal framework and where it currently stands.

The case that set the ground rules: Bridges

In R (Bridges) v Chief Constable of South Wales Police, the Court of Appeal ruled in August 2020 that South Wales Police's use of live facial recognition (LFR) was unlawful, in part because of an inadequate Data Protection Impact Assessment (DPIA) and insufficient legal framework governing who could be placed on a watchlist and where the technology could be deployed. The ruling confirmed that a DPIA isn't optional paperwork — the court will assess whether a public body exercised "reasonable judgement based on reasonable enquiry" in a DPIA before deploying technology this invasive.

What a DPIA has to actually establish

The ICO's guidance requires a DPIA before any facial recognition deployment, alongside a published "appropriate policy document" explaining why, where, when, and how the technology is being used. Deployments must be demonstrably necessary, proportionate, and effective given how invasive the technology is — a generic justification isn't enough, and the DPIA must specifically address watchlist criteria, algorithmic bias affecting different ethnic groups, and the risk of false-positive matches.

Real enforcement action, not just theoretical guidance

The ICO has taken concrete action against non-compliant deployments. In 2024, it reprimanded Chelmer Valley High School for introducing a facial-recognition canteen payment system without completing a required DPIA first, and separately issued enforcement notices ordering Serco Leisure to stop using facial recognition and fingerprint scanning to monitor staff attendance. The ICO published a dedicated AI biometrics strategy in June 2025 and, as of early 2026, has ongoing audits underway of multiple police forces specifically over their use of the technology.

The legal framework is still evolving — and still contested

A more recent judicial review, decided by the High Court in April 2026, examined the Metropolitan Police's tightened live facial recognition policy and applied the same Bridges legal test to it. Live facial recognition remains legally permitted in the UK based on a patchwork of common law powers, legislation, and published police policy — but the government has acknowledged this patchwork framework has real gaps and, as of late 2025, was consulting on a new dedicated legal framework specifically for law enforcement use of biometrics and facial recognition.

How to challenge a deployment you're concerned about

  1. Ask the police force or council directly whether a DPIA and an appropriate policy document exist for the specific deployment, and request to see them.
  2. Check whether the deployment is by police (governed by Part 3 of the Data Protection Act 2018, the law enforcement regime) or by a non-police public body like a council (governed by UK GDPR more directly) — the applicable rules differ.
  3. If you believe you were wrongly included on a watchlist or subjected to a false match, you can request information about the processing and challenge it through the organisation's own complaints process.
  4. Escalate to the ICO if the organisation doesn't provide a satisfactory response, referencing the Bridges case and the specific DPIA requirement.
  5. Consider contacting a civil liberties organisation with experience in this area, particularly for a more significant, precedent-setting concern.

What this means practically

Sources

Related Kibbo Tools