Teaming up with... AVIVA

Welcome to the UKGI weekly regulation update service for Aviva ABC brokers

We hope you find the Updates useful. If you are
interested in subscribing to our affordable
ABC compliance support package, please
email us at ABC@ukgigroup.com or
call UKGI on our dedicated ABC
contact line 01925 767893.

ICO publishes an outcomes report and four accompanying audit reports in relation to the use of Facial Recognition Technology by a number of Police Forces

Link(s):  Facial recognition in policing: earning public trust through strong data protection governance | ICO
Facial recognition technology in police forces | ICO
https://ico.org.uk/action-weve-taken/audits-and-overview-reports/2026/08/facial-recognition-technology-in-police-forces/ Executive summary
TM QA
South Wales Police and Gwent Police | ICO
Essex Police | ICO

Context

The ICO has published an Outcomes report highlighting the key findings and shared themes from five consensual audits of police forces in England and Wales (including West Yorkshire and Greater Manchester) that are using overt facial recognition technology (FRT).  It covers audits conducted between June 2025 and March 2026. The report aims to help all police forces identify potential areas for improvement in their use of FRT.  This is accompanied by a blog by Emily Keaney, the ICO Deputy Commissioner for Regulatory Policy, in which she discusses balancing the risks and benefits of FRT and providing some headline detail about the main findings.

Key points to note and next actions

  • The objective of the audits was to assess the extent to which the following are in place and operational for FRT within each force:
    • Accountability.
    • Policies and procedures.
    • Performance measurement controls.
    • Reporting mechanisms to monitor compliance.
  • From the audit programme, the ICO noted several principal areas for improvement that featured in individual forces or across several of the participating police forces.
  • The key audit findings are set out under the main themes identified, and each contains useful general commentary:
    • Governance and accountability, including oversight, document control, and defined roles.
    • Data mapping and records of processing.
    • Training and awareness.
    • Lawful bases.
    • Data protection impact assessments (DPIAs).
    • Data minimisation and limitation.
    • Contracts and providers.
    • Security management.
    • Accuracy and bias.
    • Individual rights.