LIVE · cybersecurity feed
Live wire
security

ICO Urges Police to Improve Data Governance in Facial Recognition Rollouts

The UK’s privacy watchdog has called on police using facial recognition to follow its recommendations

zeroday.news ·

The UK's data protection watchdog, the Information Commissioner’s Office (ICO), has called on police forces to enhance their data governance practices when deploying live facial recognition (LFR) technology. The ICO's deputy commissioner for regulatory policy, Emily Keaney, stated in an article published on August 18 that an increasing number of forces are implementing LFR without prior experience in its public use.

Keaney highlighted that some forces are even experimenting with new methods, such as officer-initiated facial recognition, where individuals are stopped in public and their faces are cross-referenced against a watchlist. While acknowledging that LFR can aid law enforcement in crime prevention and detection, Keaney also warned of significant risks, including the potential for wrongful intervention, accusation, or arrest due to false matches.

To ensure LFR is used lawfully and proportionately, with robust oversight, accountability, and safeguards compliant with data protection law, the ICO conducted audits of several police forces' use of the technology. The findings revealed inconsistencies in data protection compliance across the five audited forces, indicating that while some good practices exist, substantial improvements are still necessary.

The ICO recommends that police forces across England and Wales utilize these audit findings to bolster their data protection governance. The compliance rates for LFR were found to be higher than for retrospective facial recognition (RFR), but several critical areas still require immediate attention.

These areas include ensuring senior oversight, accountability, and adequate training for staff utilizing facial recognition technology (FRT). Forces must also maintain clear records detailing what personal information is used, its origin, how it is processed, and with whom it is shared. Furthermore, the ICO emphasized the need to ensure RFR images are sourced appropriately and not retained longer than necessary.

A crucial recommendation involves verifying the accuracy of facial recognition systems and implementing measures to mitigate the risk of unfairness or bias. This point is particularly pertinent given a Home Office report from December 2025, which identified racial bias in RFR systems used by the police. That report indicated that, under specific circumstances, the algorithm was more prone to incorrectly including certain demographic groups in its search results.

At the time of the Home Office report, Keaney had called for urgent clarity to assess the situation and determine subsequent actions. In its latest update, the ICO noted that police forces have shown a willingness to engage and implement changes based on the audit findings. The ICO maintains that strong data protection governance is vital for building the public trust necessary for FRT to be an effective policing tool. Rights groups have consistently advocated for stronger legislative safeguards before widespread police adoption of this technology.

ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Brinqa acquires PlexTrac to bring validated remediation to exposure management

Brinqa has announced its acquisition of PlexTra, adding the ability to verify that remediation efforts have actually worked. The combined capabilities uniquely position Brinqa to identify and prioritize the exposures that matter most, drive remediation, and validate that fixes hold, closing the CTEM loop. “We’ve spent over a decade building the platform enterprise security teams trust to prioritiz

vulnerability

943 Patches Rolled Out With Oracle’s August 2026 Security Update

The fixes resolve over 1,000 vulnerabilities across two dozen products, including over 460 remotely exploitable bugs. The post 943 Patches Rolled Out With Oracle’s August 2026 Security Update appeared first on SecurityWeek.

ai

OpenAI puts major frontier AI training run on hold over cyber risks

OpenAI temporarily paused reinforcement learning (RL) training on its latest models intended for deployment for two weeks while it hardened and red-teamed research environments and expanded monitoring. “Our largest planned frontier RL run remains on hold while we conduct smaller-scale training and evaluations to assess model behavior, validate our safeguards, and establish more evidence of alignme

security

UK Fraud Cases Hit Record High in 2026

Cifas data finds account takeover and identity fraud are driving a surge in fraud cases

breach

50,000 Stripe Secrets Leaked in Public Code

Over 50,000 exposed Stripe API keys show how leaked secrets can enable fraud, data access and account abuse within hours. Ransomnews researchers have documented a large-scale leak of Stripe merchant API keys found exposed in public code repositories, GitHub Actions logs, and misconfigured web servers, with over 50,000 unique keys identified in total. The research […]

security

Cyberattack forces UT San Antonio to delay start of fall semester

The University of Texas at San Antonio pushed back the start of its fall semester by three days after a cyberattack targeted its academic network over the weekend. Classes that were due to begin on Wednesday, August 19 will now start on Monday, August 24. UT San Antonio is one of the largest universities in Texas, serving more than 42,000 students. According to a statement issued by Andrea Marks,