The Information Commissioner’s Office (ICO) has published findings from consensual audits of five police forces in England and Wales on their use of facial recognition technology (FRT), identifying inconsistencies in data protection compliance and areas requiring improvement, particularly governance, training, awareness and storage limitation. The ICO made 107 recommendations across the audits, including 16 urgent and 54 high priority recommendations, covering matters including governance, lawful basis, data protection impact assessments, data minimisation, security management, accuracy and bias and information rights. The ICO says strong data protection governance, clear oversight, accountability and safeguards are essential as law enforcement use of FRT expands, including live facial recognition, retrospective facial recognition and emerging operator-initiated facial recognition. The participating police forces fully accepted 93 recommendations and partially accepted 14, rejecting none, and the ICO will conduct follow-up audits to assess progress against agreed action plans, with formal enforcement powers to be considered where there are concerns about compliance with data protection legislation.