Your Face Is a Search Term, With Facial Recognition Technology
Your Face Is a Search Term, With Facial Recognition Technology
The Information Commissioner’s Office published the results of its rolling audits of police facial recognition technology this month, covering West Yorkshire, Greater Manchester, Essex, Leicestershire, South Wales and Gwent. The findings were more awkward than either side of the argument would have liked. Live deployments, the ones that generate the headlines and the protests, were generally run with a documented lawful basis and reasonable controls. Retrospective searching, the quieter business of running images from CCTV and phones against national databases, showed weaker governance, thinner records and patchier training. The regulator issued 107 recommendations, all of which were accepted or partially accepted.

The public debate about facial recognition technology is almost entirely a debate about the police, and it will continue in that register through the courts, a government consultation and eventual legislation. But the ICO’s findings point at something the debate keeps missing. The state’s use of this technology is the most scrutinised, most documented and most heavily regulated use in the country. Everybody else’s is not.
Two technologies sharing one name
Public argument treats facial recognition as a single thing when it is at least two, with very different risk profiles. Live facial recognition compares people passing a camera against a watchlist in real time; according to the parliamentary research briefing on facial recognition technology in policing, it was in use by 13 of the 43 forces in England and Wales as of March 2026, with a national rollout planned. Retrospective facial recognition works after the event, matching collected images against reference databases holding many millions of facial records.
The live version is visible. Vans appear, notices go up, campaigners photograph them, and each deployment is logged. The retrospective version happens at a desk, thousands of times, with nobody watching. It is not remotely a coincidence that the ICO found compliance weaker for the second one. In any surveillance technology, the risk is rarely the dramatic use case that everyone is arguing about. It is the routine one that nobody is counting.

The version anyone can subscribe to
Then there is a third category with no deployment records at all, because it is a consumer product. Commercial face recognition search engines index faces scraped from the open web and sell search access by monthly subscription to anybody with a card. Upload a photograph, receive a list of other places that face appears online.
The reach of these services is not theoretical. Reporting by Liberty Investigates established that one such site was accessed thousands of times from Metropolitan Police computers over a single three-month period, entirely outside the force’s approved systems, before officers were banned from using it. The concern was not that the tool was ineffective. It was that searches through it left no official record and carried none of the safeguards attached to sanctioned systems. If that is what happens inside a police force with a compliance department, it is worth considering the position everywhere else. A password can be changed after it leaks. A face cannot.
Why a professional investigator has less freedom than the public
Clients are sometimes surprised to learn that a professional is more constrained here than a private individual, not less. A face print used to identify someone is biometric data, and biometric data processed for identification is special category data under UK GDPR. That demands a lawful basis, a genuine necessity and proportionality assessment, and in most investigative contexts a data protection impact assessment completed before any search is run. The ICO’s guidance on biometric recognition is unambiguous that convenience comes nowhere near justifying it, and the Commissioner’s office has argued consistently that data protection law is the governance framework for this technology, not an obstacle to it.

The courts have already shown where careless capture leads. In Fairhurst v Woodard, a householder’s camera network was found to breach data protection law and amount to harassment, a case we looked at when examining how the video doorbell changed the doorstep. If a private individual can be liable for how they capture faces, an investigator using an unaccountable scraping engine to identify them is in a considerably weaker position. The tools an investigation relies on become part of the evidence it produces, and material identified through a service of doubtful legality arrives in a case already carrying a challenge.
A facial recognition match is a hypothesis, not a fact
There is a more fundamental problem, and it applies equally to the police systems. A facial recognition match tells you that two images resemble one another to a given confidence threshold. It does not tell you that they are the same person. Error rates worsen sharply with poor lighting, angle and image compression, which describes most real-world material. The wrongful identifications that periodically reach the news share a single cause, which is treating the machine’s suggestion as a conclusion.
Professional practice inverts that. A possible identification is where the work begins: corroborating the identity through independent lawful sources, establishing the person’s actual connection to the matter, and constructing a chain of evidence in which no link depends on an algorithm’s opinion. It is the same discipline, arriving from the opposite direction, that we described in our examination of deepfakes and fabricated evidence. Software now both generates faces and finds them. Neither operation, unsupported, proves anything about a human being.

The law is coming, and it is aimed elsewhere
A government consultation on a dedicated legal framework for facial recognition technology closed in February 2026, and legislation has been signalled. Whatever eventually arrives will almost certainly concentrate on police powers, because that is where the political pressure and the litigation are. The commercial face search engine, the retrospective search that nobody logged, and the subscriber with a grudge will remain governed principally by data protection law, which only works when somebody troubles to apply it.
Which is the uncomfortable summary. Your face is already a search term, and has been for some years. The only remaining question is whether the people searching for it are accountable for what they do with the result.
Frequently Asked Questions
Do private investigators use facial recognition?
Responsible investigators treat it with considerable caution. The data protection threshold for biometric identification is high, and evidence derived from an unaccountable tool invites challenge in any proceedings. The sounder approach is to corroborate identity through lawful, documented sources so that no conclusion rests on software alone.
Is a facial recognition match reliable enough to rely on?
Not by itself. A match is a probabilistic statement that two images resemble one another, and accuracy degrades significantly with poor quality images. It should be treated as a lead requiring independent corroboration through documentary records, witness evidence and verified connections between the individual and the matter in question.
What did the ICO’s audits of police facial recognition technology find?
Across the forces audited, police generally documented a lawful basis and maintained reasonable controls for live deployments, with compliance weaker for retrospective searching, particularly around image sourcing, retention, training and record keeping. The ICO issued 107 recommendations, all accepted or partially accepted, and continues to press for consistent improvement across every force using the technology.
Categories
- Industry News
- People Tracing
Popular Blogs









