PrivacySignal
GDPR / Intl

ICO Urges Police to Improve Data Governance in Facial Recognition Roll

Infosecurity Magazine · · International · GDPR & International

The UK's Information Commissioner's Office has called on police forces to strengthen how they manage data as facial recognition technology is deployed more widely. The ICO's intervention signals concerns about compliance and oversight during the rollout.

Why this matters: Facial recognition by police is not a routine data issue. It means your face, captured in public without your knowledge, run against a database, and used to identify you. The ICO telling police to improve data governance suggests that rollout is already outpacing the rules meant to control it. Who gets flagged, how long images are kept, and what happens when the system is wrong are not technical details. They are the whole story. If the regulator is urging improvement mid-rollout, the safeguards were not ready before deployment began.

Who should care: Lawyers · Privacy officers · AI governance · Cybersecurity · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

GDPR / Intl
K keyt.com · · International

State Privacy Regulator Issues Second Decision Penalizing Out-of-State Data Broker

A state privacy regulator has issued its second enforcement decision against an out-of-state data broker, signaling continued regulatory action beyond its own borders. The decision adds to a pattern of state-level agencies asserting jurisdiction over companies that collect and sell resident data regardless of where those companies are based.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#state-privacy#regulation#privacy Read original →
GDPR / Intl
Inside Privacy (Covington) · · International

French CNIL Publishes Note on Agentic AI and Data Protection

France's data protection authority, the CNIL, and the French AI and Digital Council released a joint exploratory note examining how existing data protection rules apply to agentic AI systems. The document is framed as an early-stage analysis rather than binding guidance.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#ai#privacy Read original →
GDPR / Intl
T The National Law Review · · International

HOT OFF THE PRESSES: CalPrivacy Brings First Action Against a Data Broker Under Both the CCPA and Delete Act

California's privacy regulator has filed its first enforcement action against a data broker under both the California Consumer Privacy Act and the Delete Act, marking a significant step in the state's use of its data broker oversight tools.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#state-privacy#privacy Read original →
GDPR / Intl
H Hunton Andrews Kurth LLP · · International

EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence

The European Data Protection Board has called for a review of the EU-U.S. Data Privacy Framework following a U.S. Supreme Court ruling that affects the independence of the Federal Trade Commission, a key enforcement body underpinning the transatlantic data transfer agreement.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#privacy Read original →