PrivacySignal
GDPR / Intl

UK ICO finds police facial recognition use mostly compliant with data regulations

Biometric Update · · International · GDPR & International

The UK's Information Commissioner's Office reviewed police use of facial recognition technology and found it to be largely compliant with data protection law. The assessment stops short of a full endorsement but does not identify systemic violations.

Why this matters: A regulator saying something is 'mostly compliant' is not the same as saying it is safe or fair. Facial recognition used by police misidentifies people at higher rates if you are a woman or have darker skin. Compliance with data rules does not fix that. It also does not answer whether the surveillance itself is proportionate. The ICO's job is to check whether data is handled correctly, not whether the underlying practice should exist. Those are different questions, and only one of them got answered here.

Who should care: Lawyers · Privacy officers · AI governance · Compliance · Cybersecurity · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

GDPR / Intl
I Infosecurity Magazine · · International

ICO Urges Police to Improve Data Governance in Facial Recognition Roll

The UK's Information Commissioner's Office has called on police forces to strengthen how they manage data as facial recognition technology is deployed more widely. The ICO's intervention signals concerns about compliance and oversight during the rollout.

Who should care: Lawyers · Privacy officers · AI governance · Cybersecurity · General readers · Policy

#gdpr#surveillance#privacy Read original →
GDPR / Intl
K keyt.com · · International

State Privacy Regulator Issues Second Decision Penalizing Out-of-State Data Broker

A state privacy regulator has issued its second enforcement decision against an out-of-state data broker, signaling continued regulatory action beyond its own borders. The decision adds to a pattern of state-level agencies asserting jurisdiction over companies that collect and sell resident data regardless of where those companies are based.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#state-privacy#regulation#privacy Read original →
GDPR / Intl
Inside Privacy (Covington) · · International

French CNIL Publishes Note on Agentic AI and Data Protection

France's data protection authority, the CNIL, and the French AI and Digital Council released a joint exploratory note examining how existing data protection rules apply to agentic AI systems. The document is framed as an early-stage analysis rather than binding guidance.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#ai#privacy Read original →
GDPR / Intl
T The National Law Review · · International

HOT OFF THE PRESSES: CalPrivacy Brings First Action Against a Data Broker Under Both the CCPA and Delete Act

California's privacy regulator has filed its first enforcement action against a data broker under both the California Consumer Privacy Act and the Delete Act, marking a significant step in the state's use of its data broker oversight tools.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#state-privacy#privacy Read original →