Facial Recognition in Public Spaces: Your UK Privacy Rights

Ask a Question
Facial Recognition in Public Spaces: Your UK Privacy Rights

Facial Recognition in Public Spaces: Privacy Rights in the UK

Live facial recognition (LFR) technology is deployed in UK public spaces, including by police at large events and by retail premises seeking to identify individuals on watchlists. The technology captures facial images from people passing a camera, converts the facial features into a biometric template, and compares that template against a watchlist in near real time. Because this process involves the automated processing of biometric data, it engages some of the most protective provisions of UK data protection law. This article sets out the legal framework, the key case law, and the practical rights available to individuals who believe they have been scanned.

If you believe facial recognition technology has been used inappropriately in your situation, you can describe what happened using our free Rights Situation Checker.

Biometric data as a special category under UK GDPR

Facial recognition processing typically involves biometric data used for the purpose of uniquely identifying a natural person. Under Article 9(1) of the UK GDPR, such data is a special category and its processing is prohibited unless one of the conditions in Article 9(2) applies. The most commonly relied on conditions in the LFR context are explicit consent under Article 9(2)(a), substantial public interest under Article 9(2)(g), and, for law enforcement purposes, the regime under Part 3 of the Data Protection Act 2018.

Where Article 9(2)(g) is relied on, the controller must also identify a basis in UK law and meet the conditions in Schedule 1 to the Data Protection Act 2018, including having an appropriate policy document in place. Explicit consent is rarely a workable basis for LFR in public because consent must be freely given, specific, informed and unambiguous, which is difficult to achieve where individuals are scanned before they have any meaningful opportunity to object.

Police deployment and Part 3 of the Data Protection Act 2018

When police forces deploy LFR for law enforcement purposes, the processing falls within Part 3 of the Data Protection Act 2018 rather than the general UK GDPR regime. Part 3 requires that processing be lawful and fair, based on law, and, where applicable, strictly necessary for the law enforcement purpose. Sections 34 to 40 of the Act set out the data protection principles, with section 35 containing the first principle (lawful and fair processing) and the specific conditions for sensitive processing, which include that the processing be strictly necessary, that it meet one of the conditions in Schedule 8, and that the controller has an appropriate policy document in place.

Part 3 also imposes a data protection impact assessment duty under section 64, and the rights in sections 43 to 54 apply to data subjects, including rights to information, access, rectification, erasure and restriction, and rights in relation to automated decision-making, subject to specific restrictions.

Rights Situation Checker

Rights Situation Checker

Describe what has happened and find out which UK human rights protections apply and what you can do.

Try our Rights Situation Checker free, here on this site →

The Bridges judgment

The leading authority is R (Bridges) v Chief Constable of South Wales Police [2020] EWCA Civ 1058. The Court of Appeal's decision focused on legal and procedural inadequacies in the force's deployment of LFR, known as AFR Locate, which was held to be unlawful on three grounds.

  • The deployment breached Article 8 of the European Convention on Human Rights because the legal framework left too much discretion to individual officers regarding who could be placed on a watchlist and where the technology could be deployed, meaning the interference with Article 8 rights was not in accordance with the law.
  • The force's data protection impact assessment was deficient because it failed properly to assess the risks to the rights and freedoms of data subjects.
  • The force had not complied with the Public Sector Equality Duty under section 149 of the Equality Act 2010, in that it had not taken reasonable steps to satisfy itself that the software did not produce results biased on grounds of race or sex.

Bridges did not hold that LFR is inherently unlawful. It required that deployments be governed by a sufficiently precise legal and policy framework, that DPIAs be substantive, and that equality duties be actively discharged.

Your situation may be slightly different. ask a question below ↓ and our editorial team will reply with our advice.

Private sector and retail use

LFR is also deployed by private operators, including retailers using services that identify individuals on watchlists. Private deployments fall under the general UK GDPR and Parts 1 and 2 of the Data Protection Act 2018, rather than the law enforcement regime.

Private controllers must identify a lawful basis under Article 6, commonly legitimate interests under Article 6(1)(f), and a special category condition under Article 9. They must also carry out a DPIA under Article 35 where processing is likely to result in a high risk to individuals, which the ICO considers to be the case for most LFR deployments. The Information Commissioner's Office has issued guidance and taken enforcement action in respect of private LFR, and has published opinions on the use of LFR in public places and by law enforcement, which should be consulted directly on the ICO website for the current text.

Rights of individuals scanned by LFR

Individuals whose faces are captured and processed by LFR retain the full suite of data subject rights, subject to the exemptions that apply in a law enforcement context.

  • The right to be informed under Articles 13 and 14 of the UK GDPR, which requires clear signage and publicly available information about the processing.
  • The right of access under Article 15, allowing a person to request confirmation of whether their data has been processed and to obtain a copy.
  • The right to object under Article 21, which applies where processing is based on legitimate interests or public task, and which the controller must respect unless it can demonstrate compelling legitimate grounds.
  • The right to rectification and erasure, and the right not to be subject to solely automated decisions that produce legal or similarly significant effects under Article 22.

What to do if you believe you have been scanned unlawfully

If you consider that LFR has been used in relation to you and you wish to explore your rights, the following steps are generally available. As a preliminary matter, it is worth checking whether the organisation has disclosed its use of LFR through public signage, its privacy notice on its website, or in response to a direct enquiry. This information will assist in identifying the controller and understanding the stated lawful basis before taking further steps. In practice, the absence of a match or of any direct interaction may mean there is limited evidence that a given individual was processed, which can affect what a complaint or claim is able to achieve.

  • Complain to the operator. Controllers are required to have procedures for handling data protection complaints and must respond within a reasonable period. Ask for the lawful basis, the DPIA, and the retention period applied to your data.
  • Submit a subject access request under Article 15 of the UK GDPR, or section 45 of the Data Protection Act 2018 where the processing is by a law enforcement authority. The controller must ordinarily respond within one month.
  • Complain to the Information Commissioner's Office. The ICO has powers to investigate, issue enforcement notices, and impose monetary penalties. Current thresholds and procedures are set out on the ICO website.
  • Consider a claim under section 167 of the Data Protection Act 2018 for a compliance order, or a claim for compensation under section 169 of the Act for non-GDPR processing, or under Article 82 of the UK GDPR, where you have suffered material or non-material damage as a result of a breach.
  • Where the processing is by a public authority, a claim under section 7 of the Human Rights Act 1998 for breach of Article 8 of the Convention may also be available.

LFR is subject to regulatory and judicial oversight in the UK. For current guidance and complaint routes, consult the ICO at ico.org.uk and GOV.UK. Individuals seeking advice on a specific deployment should consider taking legal advice from a solicitor with experience in data protection and public law.

The Next Step

Rights Situation Checker

Now that you have read through the advice above, you might want to put it into practice. Our Rights Situation Checker lets you describe what has happened and find out which UK human rights protections apply and what you can do. Try it now →

Ask About Human Rights a Question

Ask About Human Rights a question

Ask our editorial team a question and we will reply with our advice. Tell us as much about your situation as you can: the more detail you give, the more useful our answer can be.

You do not need to use your real name. Please do not include your full address, phone number, email address, or the names of other people. We may edit or remove identifying details for privacy and legal reasons.

Comments are moderated before publication.

Try our free Rights Situation Checker Check My Rights for Free