Face recognition in the United Kingdom
In the United Kingdom, biometric data used to identify someone is special category data under Article 9 of the UK GDPR. Processing it needs both a lawful basis and a separate Article 9 condition, and a Data Protection Impact Assessment is mandatory before deployment. The Information Commissioner's Office regulates it.
What law governs face recognition in the UK?
Two instruments govern it together. The UK GDPR, retained after withdrawal from the European Union, and the Data Protection Act 2018, which supplements it. Under Article 9(1) of the UK GDPR, biometric data processed for the purpose of uniquely identifying a person is special category data, and its processing is prohibited unless one of the Article 9(2) conditions applies.
That is a second requirement, not a substitute for the first. An operator needs an Article 6 lawful basis for the processing and, on top of it, an Article 9(2) condition for the biometric element. In the commercial sector the condition is usually explicit consent; in the public sector it is more often substantial public interest, which Schedule 1 of the Data Protection Act 2018 sets out in specific, enumerated terms rather than as a general power.
The Information Commissioner's Office is the supervisory authority. It has published guidance specifically on biometric recognition, and it has taken enforcement action over face recognition deployed without an adequate basis.
Is a DPIA required for face recognition in the UK?
Yes, in practice always. Article 35 of the UK GDPR requires a Data Protection Impact Assessment where processing is likely to result in a high risk to people's rights, and it names two triggers that face recognition normally meets: large-scale processing of special category data, and systematic monitoring of a publicly accessible area.
- Describe the processing, its purpose and the lawful basis, including the separate Article 9 condition.
- Assess necessity and proportionality — specifically, whether a less intrusive method would achieve the same purpose.
- Identify the risks to the people whose faces are processed, not the risks to the organisation.
- Record the mitigations, including retention periods, human review of matches and the route to object.
- Consult the ICO before proceeding where a high residual risk remains after mitigation.
The DPIA is a live document rather than a filing. A deployment that changes its camera positions, its watchlist source or its retention period has changed the processing the DPIA assessed.
Where may the face data be processed and stored?
The United Kingdom has no data localisation requirement: personal data may be transferred abroad, but only under one of the transfer mechanisms in Chapter V of the UK GDPR. That means UK adequacy regulations for the destination country, or an International Data Transfer Agreement, or the UK Addendum to the European Commission's standard contractual clauses, together with a transfer risk assessment.
An on-premise or air-gapped deployment sidesteps the mechanism entirely, because there is no transfer to assess. Ayonix face recognition runs on the operator's own hardware — an ATLAS BOX appliance, an existing server estate, or edge hardware at the camera — so face templates are created, matched and deleted inside the operator's own infrastructure and never reach a vendor service.
- Air-gapped: no network route out of the deployment at all, for sites where that is the policy.
- On-premise: the operator's own data centre, under the operator's own retention schedule.
- Edge: processing at or beside the camera, with only the result leaving the device.
- Cloud: available, and the option that makes Chapter V a live question rather than a moot one.
What about public space surveillance and the police?
A separate layer applies to public authorities. The Surveillance Camera Code of Practice, issued under the Protection of Freedoms Act 2012, binds police forces and local authorities in England and Wales, and its principles cover the use of surveillance camera systems including facial recognition. Part 3 of the Data Protection Act 2018 governs processing for law enforcement purposes, with its own regime distinct from the UK GDPR.
Live facial recognition by police in England and Wales has been examined by the courts. In R (Bridges) v South Wales Police, the Court of Appeal found the deployment unlawful in 2020 on grounds including an insufficiently precise legal framework and an inadequate assessment of bias — not on the basis that live facial recognition is unlawful in itself.
What should a UK buyer establish before signing?
- Which Article 6 basis and which Article 9(2) condition the deployment relies on, written down.
- Where face templates are stored, in what form, and who can export them.
- The retention period for templates and for match records, and the mechanism that enforces it.
- Whether a human reviews a match before any consequence follows from it.
- How a person exercises their rights of access, objection and erasure against the system.
- How the system's accuracy was measured on the operator's own cameras, in the operator's own conditions.
Ayonix publishes no headline accuracy figure for the United Kingdom or anywhere else, because a number measured on someone else's cameras is not a number a UK data controller can defend in a DPIA. What Ayonix publishes instead is its participation in the National Institute of Standards and Technology's face recognition evaluations, which are run independently and whose results are public. NIST does not certify, approve or endorse vendors.
This page describes what the named laws require, with each instrument cited so it can be checked. It is not legal advice, and it is not a statement that any particular deployment complies: that assessment belongs to your own counsel and your data protection authority.
Frequently asked questions
- Is face recognition legal in the UK?
- Yes, where it has a lawful basis under Article 6 of the UK GDPR and a separate condition under Article 9(2), and where a Data Protection Impact Assessment has been completed. It is not prohibited, but it is not permitted by default either: the processing is unlawful until both requirements are met.
- Do I need consent to use face recognition in the UK?
- Not always. Explicit consent is one Article 9(2) condition and the usual one in commercial settings, but it is not the only one. Substantial public interest, set out in Schedule 1 of the Data Protection Act 2018, supports many public-sector deployments where consent would be meaningless.
- Does UK data have to stay in the UK?
- No. The United Kingdom has no data localisation requirement. Transfers abroad need a Chapter V mechanism — adequacy regulations, an International Data Transfer Agreement, or the UK Addendum to the standard contractual clauses — plus a transfer risk assessment. An on-premise deployment avoids the question by never transferring anything.
- Who regulates face recognition in the UK?
- The Information Commissioner's Office is the data protection supervisory authority and has published guidance on biometric recognition. For police and local authority camera systems in England and Wales, the Surveillance Camera Code of Practice under the Protection of Freedoms Act 2012 applies in addition.
- Can Ayonix be deployed without an internet connection in the UK?
- Yes. Ayonix face recognition runs on-premise, at the edge or fully air-gapped on hardware the operator specifies, including the ATLAS BOX appliance. In an air-gapped deployment there is no network route out, so face templates never leave the site and no international transfer arises.
- Is Ayonix certified under UK GDPR?
- No. There is no certification that makes a product compliant with the UK GDPR, and any vendor claiming one is describing something else. Compliance is a property of a deployment — its basis, its DPIA, its retention and its governance — not of a piece of software. Ayonix supplies the deployment modes that make those choices possible.
