Author: Adrian Ramdat (Director of Training & Consultancy)
August 2025
The Metropolitan Police recently announced they’re planning to double the use of live facial recognition technology on the streets of London. The aim is clear: to identify suspects quickly, prevent crime, and reassure the public.
It’s a bold step and one that will undoubtedly divide opinion.
For some, it’s a logical extension of existing tools in a world where technology can help us respond faster and more effectively. For others, it raises concerns about proportionality, privacy, and how closely our deployment of such tools is being monitored.
Whatever your view, one thing is certain: the legal and ethical frameworks around facial recognition need to keep pace with operational ambition. And that’s where things get a bit more complicated.
Surveillance or Not? That Depends…
A lot of the conversation about facial recognition focuses on whether it's being used “live” or “retrospectively.” But from a legal and oversight perspective, what matters more is how the technology is being used and for what purpose.
Under the Regulation of Investigatory Powers Act 2000 (RIPA) and its Scottish equivalent, the Regulation of Investigatory Powers (Scotland) Act 2000 (RIPSA), certain conditions trigger the need for formal authorisation. If the use of facial recognition is covert, for an investigation or operation, likely to capture private information about a person, or a group of individuals and not responding to immediate events, then it may fall under the definition of directed surveillance.
That might not always be obvious. For example, a public-facing deployment at a transport hub could still raise issues if it's designed to detect specific individuals, particularly if those people don’t know they’re being monitored or could reasonably expect some degree of privacy in the setting.
Are We Clear on the Legal Gateway?
In many cases, deployments are supported by Data Protection Impact Assessments (DPIAs), equality impact reviews, and sometimes legal advice.
But there’s a grey area when facial recognition is used to locate or monitor individuals (or groups) covertly, particularly without notifying them. In those cases, a RIPA or RIPSA authorisation might be not just appropriate but necessary.
This isn’t just theoretical. The Investigatory Powers Commissioner’s Office (IPCO), which oversees how surveillance powers are used across the UK, has raised concerns in its inspections. It has noted examples, across both RIPA and RIPSA jurisdictions, where biometric surveillance, including facial recognition, was used without proper authorisation, even though the circumstances suggested that one should have been sought.
A Fine Line Between Innovation and Intrusion?
None of this is about discouraging the use of new tools. Most officers and operational leads recognise that facial recognition, used well, has huge potential, from safeguarding vulnerable people to locating high-harm offenders.
But the law hasn’t changed just because the technology has.
If we don’t apply the same rigour to facial recognition that we do to other surveillance tactics, we risk undermining the very outcomes we’re trying to achieve. That includes:
- Cases being challenged or dropped
- Complaints escalating into litigation
- Reputational damage to forces
- And a broader erosion of public trust
As deployment increases, particularly in high-profile locations like London, it’s vital that consistency and compliance keep pace.
Public Concerns and Civil Liberties
Groups such as Big Brother Watch have raised persistent concerns about the use of facial recognition in policing. In response to recent announcements, a spokesperson commented: “…this is just the police writing their own rules.” Their criticisms focus not only on the lack of clear statutory regulation but also on how individuals are added to facial recognition watchlists and what happens to the biometric data of innocent people, whose faces may be scanned and processed without any suspicion of wrongdoing.
These concerns speak to a wider public debate. While the technology offers clear benefits for law enforcement, the lack of a clear, defined legislative framework has led to accusations of mission creep and inconsistent standards across forces.
For policing, the challenge is to maintain public confidence by demonstrating transparency, necessity, and legal justification in every deployment.
Questions Worth Asking
If you're deploying (or supporting the deployment of) facial recognition, it’s worth considering:
- Is this use covert and for a specific investigation or operation, at a particular individual or group?
- Might it capture private information, even incidentally?
- Has there been a structured assessment under RIPA or RIPSA and is that documented?
- If there is an authorisation, is it clear, proportionate, and subject to review?
These aren’t barriers, they’re safeguard and they’re just as much about protecting officers and organisations as they are the public.
In Summary
The Met’s announcement is likely to set the tone for how facial recognition is used across the country. It’s an important moment, not just for operational leads, but for legal advisors, policy teams, and those tasked with oversight.
Facial recognition can help us work smarter, faster, and with greater impact. But like any intrusive capability, it must be used carefully, proportionately, and within the current legislative framework.
Training Support to Build Confidence and Compliance
As the use of facial recognition technology expands, so too does the need for clarity, consistency, and confidence when applying the law. Understanding the thresholds for directed surveillance, the correct use of RIPA or RIPSA, and how to evidence decision-making is critical, not just to ensure compliance, but to maintain public trust.
The Signature Brand Training & Consultancy offers tailored training and support for law enforcement and public sector professionals across the UK. Our sessions focus on the real-world application of surveillance powers, legal gateways, and the ethical use of tools like facial recognition.
We also run bitesize virtual events, hour-long sessions delivered via Microsoft Teams for up to 50 participants, exploring key topics such as:
- Understanding Directed Surveillance and How it can Assist Investigations.
- The Legal Tests of RIPA and RIPSA.
- Oversight expectations and common pitfalls.
- Facial recognition in practice.
- Defensible Decision Making.
If your team would benefit from additional input, whether through a short awareness session or a deeper learning opportunity, we’d be happy to help. Check out our website www.thesignaturebrand.co.uk or email us at info@thesignaturebrand.co.uk