Skip to content
KEDBYTE
How Identity Works
Chapter
56

The Right Not to Be Identified

Part V · Identity, Society and the Law|15,496 words|about 67 min read|Volume 5
Fast-moving material. Figures, model names, prices and version numbers in this chapter were verified in August 2026. Claims are separated into established fact, active research and marketing claim. Re-check anything you intend to rely on.

56.0 What this chapter gives you#

  1. You will be able to explain why the cost of identifying a person, rather than the law about it, was the thing that used to limit surveillance, and what changed when that cost collapsed.
  2. You will be able to tell the difference between asking “is this the same person as before” and asking “who is this”, and show with arithmetic why the second question gets harder as the list of wanted people grows.
  3. You will be able to work out roughly how many wrong alerts a live face-matching deployment should expect, given the number of faces scanned, the size of the watchlist and the per-comparison error rate.
  4. You will be able to state what the Court of Appeal actually decided in R (Bridges) v Chief Constable of South Wales Police in August 2020, which three of the five grounds succeeded, and which two did not.
  5. You will be able to name the date each part of the EU AI Act’s biometric rules began to apply, and say what the July 2026 amending regulation moved and what it deliberately left alone.
  6. You will be able to describe the empirical evidence that surveillance changes behaviour, name the studies with their journals and years, give their numbers, and say honestly what they do and do not prove.
  7. You will be able to explain why anonymity is a working requirement of journalism, whistleblowing and dissent rather than a personal preference, and name the judgments that treat it that way.
  8. You will be able to list documented cases where a system built for one purpose was later used for another, with the years, and say what made each drift possible.
  9. You will be able to apply the four-stage proportionality test from Bank Mellat to a real deployment and say at which of the four stages it fails.
  10. You will be able to name at least six design choices that keep the option of not being identified open, and say what each one costs the organization that adopts it.

This book has spent fifty-five chapters on how to prove who somebody is. This chapter is about the other half of the same engineering problem, which is how to build systems that do not answer that question when the question should not be asked.

That is not a soft topic and it is not a political preference. It is a design constraint with an evidence base, a body of case law, a regulation with dates in it, and a set of concrete technical choices that either preserve the option or destroy it. A system that can identify anybody, anywhere, at any time, at a cost near zero, is not the same system as one that can identify a named suspect on a warrant. The two look identical on an architecture diagram. They are separated only by a threshold setting, a watchlist policy, a retention period and a decision about who may point the camera. Those are all things engineers choose.

The thesis is this: a society that can identify everyone everywhere has already changed, whether or not anybody ever misuses the capability, and the technical choices decide whether it does. The change is not “someone will abuse it”, although someone will. The change is that the default condition of public life flips from unrecorded to recorded, and everything downstream of that default flips with it. The person who used to walk to a meeting unremarked now walks to it in a record. Nothing has to go wrong for that to matter.

We will work through one deployment in detail and carry its numbers all the way to the end. We will read what the courts actually held rather than what the headlines said they held, because in this area the two are usually different. We will look at the empirical work on whether being watched changes what people do, including its limits. And we will finish with the part that is properly ours: the list of design choices that keep the option of not being identified alive, and what each of them costs. Chapter 55 covers the data protection and privacy statutes that govern identity data; chapter 57 covers what happens when an identity is taken and used by somebody else. This chapter is about the capability itself.

The plain version#

The clerk on the corner#

Imagine a market town in 1890. The town council decides it would like to know who walks down the high street.

There is exactly one way to do it. You hire a clerk. The clerk stands on the corner with a notebook, and he writes down the name of every person he recognizes and the time he saw them. At the end of the day he hands the notebook to the town hall.

Think about what that clerk can and cannot do. He can only recognize people he already knows, which in a town of eight thousand might be four hundred faces on a good day. He gets tired. He looks away. He confuses the Hollis brothers, who look alike. He works one shift, so nothing is recorded before eight in the morning or after six at night. He watches one corner, so a person who walks down the parallel street is invisible. And his notebook is one notebook: if you want to know whether the same person walked past on three different Tuesdays, somebody has to sit down and read three days of handwriting.

Now suppose the council wants to watch forty streets instead of one, around the clock, for a year. That is forty corners times three shifts, so a hundred and twenty clerks, plus relief for illness and holidays, plus a room full of notebooks, plus a team of people to read the notebooks and cross-reference them. The town cannot afford it. It was never going to be able to afford it. So the question of whether the council ought to be allowed to do it never came up, because it was not a live question.

That is the important part, and it is easy to miss. For all of recorded history, the thing that stopped a government or a company from knowing where everybody was at all times was not a rule. It was a bill. The restraint came free, in the invoice, and because it came free nobody had to legislate for it, argue for it, or defend it.

What the clerk was costing, and what that cost was buying#

Put a number on the clerk. If two thousand people pass his corner in a day he might identify three hundred of them and write down two hundred, because he cannot write as fast as people walk. Call it two hundred identifications for a day’s wages.

Now a camera on a lamp post, connected to software, does the same street. It looks at every face that passes, measures each one, compares each measurement against a list, and writes the result into a file a computer can search in a second. It does this without getting tired, in the dark, at both ends of the street at once, for every hour of every day. Two hundred identifications a day for a wage becomes thirty thousand a day for the price of electricity. That is not an improvement. That is a different thing wearing the same name.

And here is what disappears when the price falls. Every protection that came from expense goes with the expense. The council no longer has to choose which street matters most, because it can watch all of them. It no longer has to justify the outlay, because the outlay is trivial. It no longer has to decide who is worth recognizing, because recognizing everybody costs the same as recognizing one person. It no longer has to throw the notebooks away to make room. Every one of those forced choices was a check on the system, and every one was an accident of cost rather than a deliberate safeguard.

When the cost goes away, the checks have to be rebuilt on purpose, in law and in code, or there are no checks. Nobody removed them. They simply stopped being generated as a by-product.

Two different questions#

There are two quite different things people mean when they say a machine “recognized” someone, and confusing them is the single most common mistake in this whole subject.

The first question is: is this the same person as before? You hold up your phone, it looks at your face, it compares that face against the one face it stored when you set the phone up, and it either unlocks or it does not. There is one comparison. The machine already believes it knows who you claim to be; it is only checking the claim. If the machine gets it wrong, you are locked out of your own phone, which is annoying, or someone who looks like you gets in, which is worse but is still a problem about one phone.

The second question is: who is this? A camera sees a face in a crowd, and the machine compares that face against a list of two thousand faces to see whether it is any of them. There is no claim to check. There are two thousand comparisons, and the machine is looking for a winner.

These sound similar and they behave completely differently. The reason is arithmetic. Suppose the machine makes a mistake once in every ten million comparisons. In the first case, one comparison, so a mistake once in ten million uses. In the second case, two thousand comparisons for every face that walks past, so a mistake roughly once every five thousand faces. Same machine, same error rate, and yet one is essentially never wrong and the other is wrong several times an hour on a busy street.

Longer list, more wrong answers. That relationship is not a flaw to be fixed by better software. It is what comparing against a list means. Doubling the list roughly doubles the wrong answers, and there is nothing anybody can do about that except keep the list short.

Marlbrook High Street, Saturday 15 August 2026#

Let us do one real-shaped deployment with real-shaped numbers and carry them through the rest of the chapter. The town is Marlbrook and the force is Kestrel Vale Police. Both are invented, so that we can be precise without pretending to speak for anybody real. Every rate we plug in is taken from published figures, and we will name each one when we get to it.

Kestrel Vale parks a van on Marlbrook High Street on Saturday 15 August 2026, from ten in the morning until six in the evening. On the roof of the van are two cameras. In the van is a computer holding a list of 1,240 photographs of people the force would like to find: people wanted on warrants, people who have broken the conditions of a court order, a small number of missing people.

Over the eight hours, 31,400 faces pass the cameras and are measured. Three of the 1,240 people on the list happen to walk down the high street that afternoon.

Here is what the day produces. The machine correctly spots two of the three, and misses one because he was looking down at his phone. It also produces no wrong alerts at all, which sounds impressive until we work out what rate that corresponds to, which we will do later. Two people are stopped and spoken to. One is arrested.

Now count the other side of the ledger. 31,397 people were measured who were on nobody’s list, who were not suspected of anything, and who did not consent, because there is nothing to consent to when you are walking to the shops. Their faces were converted into numbers, those numbers were compared against 1,240 other sets of numbers each, and then, in this deployment, the numbers were discarded.

The whole argument in this chapter lives in the gap between those two counts: one arrest, and 31,397 people measured. Everything the courts have said, everything the regulations say, and every design decision we will discuss is an attempt to say something sensible about that ratio.

Why a very accurate machine still touches almost everybody#

People reach for accuracy as the answer. If the machine is accurate enough, the objection goes away. It does not, and the Marlbrook numbers show why.

Suppose the machine were perfect. Zero wrong alerts, ever. The day still ends with 31,397 innocent people measured. Perfection improves the experience of the people who would otherwise have been stopped by mistake, which is a real improvement worth having. It does not change the number of people whose faces were taken and compared. Accuracy is about what happens to the alerts. The scanning is what happens to everybody.

Nor does accuracy tell you where to stop. One van, one Saturday, thirty-one thousand faces; ten vans every Saturday for a year, about sixteen million measurements. Once the measuring is cheap there is no natural stopping point, so somebody has to choose one deliberately, in advance, and write it down. If nobody chooses, the answer defaults to “everywhere”, because everywhere costs the same as somewhere.

The people who need not to be recognized#

The last piece of the plain version is the part that gets treated as sentimental and is actually the most practical of all.

Some people cannot do their jobs if they can be identified as they move.

A person who has seen something wrong at work and wants to tell someone about it has to physically get to that someone. If getting there is recorded, the getting there is the risk, not the telling. A reporter who wants to talk to somebody inside an organization has to meet them, and if both faces are logged at the same corner at the same minute the meeting is on file whether or not a word is ever written. A person going to a support group, a clinic, a place of worship, a union meeting or a political gathering they would rather not explain to an employer is in the same position.

None of these people are doing anything wrong, which is why the argument that only wrongdoers need to hide is wrong on the facts. A society that keeps a record of everybody’s movements has not banned any of those activities. It has made them expensive in a currency that is hard to see: the risk of being known to have done them.

There is a quiet effect on top of that. Most people do not consciously decide to avoid something because they might be seen. They simply find, without much reflection, that they did not go. That is the hardest kind of harm to measure, and later in this chapter we will meet the researchers who measured some of it anyway.

Where the plain version stops being true#

The clerk decides; the machine does not#

The clerk on the corner is a person who looks at a face and forms a belief. The modern system does nothing of the kind, and treating it as a mechanical clerk hides the most important control in the whole apparatus.

What actually happens is that the face is converted into a list of numbers, that list is compared against every list on the watchlist, and each comparison produces a similarity score: a number saying how alike the two measurements are. Nothing in that process says “match” or “no match”. The score is just a number.

Somebody then picks a cut-off. Above this number, raise an alert; below it, stay silent. That cut-off is the threshold, and it is the single most consequential setting in the system. Move it up and you get fewer wrong alerts and miss more of the people you were looking for. Move it down and you catch more of them and stop more innocent people. There is no setting that avoids the trade; there is only a choice about which kind of error you would rather have.

The honest version: a facial recognition system does not recognize anybody. It ranks similarity, and a human policy decision converts that ranking into an accusation. When a force publishes an accuracy figure, that figure is a property of the threshold they chose, the cameras they used, the crowd they pointed them at and the watchlist they loaded, not a property of “facial recognition”. Two forces running the same software can publish wildly different numbers and both be telling the truth.

“Deleted immediately” is doing a great deal of work#

Forces running live face matching say, correctly, that the measurement of a face that does not match anybody is deleted straight away. The Metropolitan Police say exactly this. It is true, and it is much narrower than it sounds.

First, it is true of the measurement, not necessarily of the video. Whether the camera footage is kept, and for how long, is a separate policy with a separate answer.

Second, and much more importantly, the courts have held that immediate deletion does not undo the interference. In the Bridges case in 2020 the Court of Appeal proceeded on the basis that the appellant’s face had been captured and processed even though the data was deleted almost at once, and that this engaged his right to respect for private life under Article 8 of the European Convention on Human Rights. The measuring is the event. Deleting the measurement afterwards is a mitigation, not an erasure of what happened.

Third, deletion of live-scan data says nothing about the other, larger system sitting next to it. Retrospective facial recognition takes a still image from any source and searches it against a stored collection of images that is not deleted at all, because the whole point of it is that it persists. The two capabilities are usually discussed as one and they have opposite retention properties.

Not being identified is not one property but four#

The plain version treats anonymity as a switch. It is at least four separate properties, and a system can give you some and deny you others.

Anonymity means nobody can attach your legal identity to the event. Pseudonymity means the event is attached to a stable handle that is not your legal identity. Unlinkability means two different events cannot be connected to each other. Unobservability means nobody can even tell that the event happened.

These come apart in ways that matter. A system that gives you a random reference number instead of your name gives you pseudonymity, but if it uses the same reference number every time, you have no unlinkability, and after a few visits the pattern identifies you anyway. A system might not know who you are while knowing exactly that somebody used it at 09:14, which is a failure of unobservability that can be fatal if the fact of asking is itself the sensitive thing.

The honest version: “we do not store your name” is not a privacy property. The useful questions are whether two visits can be joined up, whether a third party can see that a visit occurred, and whether the handle survives long enough to become an identifier in practice. We will come back to this when we look at design choices.

Making the machine better does not answer the question#

The plain version implies that the argument is about mistakes. A great deal of the public argument has been about mistakes, and error rates have genuinely fallen a long way. That has a consequence people who oppose these systems have been slow to absorb: as the technology improves, arguments based on inaccuracy get weaker, and if inaccuracy was the whole case then the case evaporates.

It was never the whole case. Dr David Leslie of the Alan Turing Institute, in a 2020 paper on bias in facial recognition, framed the remaining question as one of use-justifiability rather than performance, and pointed at effects on individual self-development, autonomy, democratic agency and community wellbeing. Those effects do not improve when the false alert rate falls. If anything they get worse, because a system that is trusted gets used more.

There is a real disagreement here and it deserves to be stated fairly. One camp holds that the harms of these systems are principally harms of error and bias, and that a sufficiently accurate, sufficiently audited system deployed against serious offenders is a net good. The other holds that the capability itself changes the relationship between a person and the state regardless of accuracy, and that the correct question is not “how well does it work” but “should this exist in public space at all”. Both camps have serious people in them. They are not arguing about the same question, which is why the debate so often fails to move.

There is no single law, and the strictest one has holes#

It is common to hear that “Europe has banned facial recognition”. That is not what happened, and the detail matters if you are the person who has to build or buy one of these systems.

The EU AI Act, Regulation (EU) 2024/1689, prohibits a specific and narrow thing: real-time remote biometric identification in publicly accessible spaces for law enforcement purposes. The prohibition then carries three exceptions, a national opt-in mechanism, a judicial authorization requirement, and a set of reporting duties. Identifying people after the fact, from stored footage, is not prohibited at all; it is classified as high-risk and regulated accordingly. Uses that are not for law enforcement fall outside the prohibition entirely and are governed by general data protection law. And the United Kingdom, where most of the litigation in this chapter happened, is not in the EU and has none of these provisions.

The honest version: there is no jurisdiction on earth, as of August 2026, in which the question “may we point a face-matching camera at a public street” has a single clean answer. There is a patchwork, and the patchwork has different shapes for police and for shops, for live and for retrospective, and for one country and the next.

The harm is mostly not to you, which is why you undercount it#

The plain version invites you to ask what the deployment does to you personally, and for almost every reader the honest answer is: very little. You walk past the van, nothing happens, you buy your shopping.

That framing is why the subject is so persistently underweighted. The harm of general identification is not distributed evenly and is not principally an individual harm at all. It falls on the small number of people for whom being seen at a particular place at a particular time carries a cost, and on everybody collectively in the form of a changed default. Individually each person’s loss is close to zero and hard to articulate; collectively the change is large and easy to describe.

That is a familiar shape in engineering: a shared resource that everyone draws down a little and nobody has an incentive to protect. Anonymity in public space behaves the same way, which is why leaving its preservation to individual choice does not work, and why it ends up being a matter for design and for law.

The technical version#

Identification as infrastructure: the cost curve and what falls out of it#

Treat identification as a utility, like water or power, and ask what the unit cost is and who can draw on it. That framing predicts the last twenty years better than any other.

Four things had to become cheap at the same time, and they did, at different moments:

What got cheap Roughly when What it enabled
Digital image capture 2000s Cameras everywhere
Face measurement 2014 onward Matching without a human
Storage of records 2000s onward Never deleting
Cross-referencing 2010s Joining separate systems

The single largest step change in face matching came from deep convolutional networks. The published landmarks are close together: DeepFace from Facebook AI Research in 2014, FaceNet from Google in 2015, and the wide adoption of deep-learning submissions in the United States National Institute of Standards and Technology’s Face Recognition Vendor Test from around 2017. NIST’s own long-running evaluations record accuracy improving by more than an order of magnitude across that period. Whatever one thinks of the deployments, the technical improvement is an established fact and not a marketing claim.

Once identification is infrastructure rather than an operation, five things become possible that were not possible before, and each is a change in kind rather than degree.

The first is retrospective search. If images are retained, a question asked today can be answered about last March, when no warrant and no suspicion existed and the person who walked past had no opportunity to behave differently. Time-travelling surveillance is a genuinely new capability.

The second is association mapping. Two faces repeatedly logged at the same place within the same minute is a relationship, inferred without anybody deciding to investigate either person. This is the capability that most directly threatens journalism and organizing, and it falls out of the data at no extra cost.

The third is pattern-of-life reconstruction. Where somebody sleeps, works, worships and receives treatment can be read off a movement log with no other source. The log was never designed to answer those questions; it answers them anyway.

The fourth is aggregation across systems that used to be separate. A transport card, a payment record, a mobile network location and a camera log were four unrelated databases when joining them meant matching names by hand. When each carries a strong biometric or device identifier, joining them is a query.

The fifth is exclusion at the door. Once identity can be checked cheaply at a threshold, it becomes tempting to check it at every threshold: a shop, a stadium, a station, a housing block. Identification stops being something that happens when there is a reason and becomes a condition of entry.

None of the five requires anybody to behave badly. They are the ordinary consequences of a cost curve.

Verification, identification, and the arithmetic that separates them#

The professional vocabulary is worth being exact about, because it is the vocabulary the standards and the regulations use.

Verification, also written as one-to-one comparison, tests a claimed identity. One probe sample is compared against one reference. The output is a decision about a claim.

Identification, also written as one-to-many comparison, searches a probe sample against an enrolled gallery of N references and returns the best candidates. There is no claim. The output is a set of hypotheses.

Remote biometric identification is the term used in Regulation (EU) 2024/1689 for identification of people at a distance, without their active participation, by comparing biometric data against a reference database. That definition is doing real work: it is participation, not distance, that distinguishes it from a passport gate where you walk up and present yourself.

The arithmetic is where the two diverge. Write the per-comparison false match rate as f, the gallery size as N, and the number of probe faces as P. The expected number of false alerts in a deployment is approximately

false alerts  ~=  P * N * f

where
  P = probe faces seen during the deployment
  N = number of enrolled images on the watchlist
  f = per-comparison false match rate at the
      chosen threshold

The approximation holds while P times N times f stays small, which it does in every real deployment.

Now apply it to Marlbrook. Kestrel Vale scanned P = 31,400 faces against a watchlist of N = 1,240 images, which is 38,936,000 comparisons in eight hours.

To choose a value for f we can work backwards from a published figure. In its report covering September 2024 to September 2025, the Metropolitan Police stated a false alert rate of 0.0003 per cent measured against more than three million faces scanned, and recorded ten false alerts in the period. Taking 0.0003 per cent of the faces scanned as the per-face false alert rate gives about three false alerts per million faces. That is a per-face figure, not a per-comparison figure. If we assume a watchlist in the low thousands, the implied per-comparison rate is in the region of one in four hundred million. That inference is ours, not the force’s; the Met publishes the aggregate, not f, so treat the implied number as an order-of-magnitude estimate rather than a measured constant.

With f taken as 2.5 in 1,000,000,000, Marlbrook expects:

31,400 * 1,240 * 0.0000000025  =  0.097

expected false alerts on the day: about 0.1
expected true alerts (3 present, 88% detected): 2.6

So the day produces roughly two or three true alerts and, on average, one false alert every ten deployments. That matches what Kestrel Vale reported.

Here is the part that matters. Hold f and P fixed and vary only the watchlist:

Watchlist size N Comparisons Expected false alerts
1,240 38.9 million 0.10
12,400 389 million 0.97
124,000 3.9 billion 9.7
1,240,000 38.9 billion 97

Nothing changed except the length of the list. The software is identical, the threshold is identical, the crowd is identical. A watchlist of a million turns a deployment with essentially no false alerts into one that wrongly flags roughly ninety-seven people in a single afternoon.

This is the technical fact that ought to govern policy in this area, and it is the one most often left out of public statements. Watchlist discipline is not an administrative nicety. It is the dominant term in the error budget. Any published accuracy figure that does not state the watchlist size alongside it is uninterpretable.

For comparison, the historical figures show what a different configuration produces. At the 2017 UEFA Champions League final in Cardiff, South Wales Police’s system generated 2,297 incorrect matches, which the force’s own published figures put at 92 per cent of the matches made that day. That is not a different technology from the 2025 deployments. It is a different threshold, a much older algorithm generation, and a crowd photographed in conditions the system handled badly.

What a live facial recognition deployment is actually made of#

Strip out the branding and every live deployment has the same seven stages.

 [1] camera  ->  video frames
       |
 [2] detector  ->  face bounding boxes
       |
 [3] quality gate -> discard blurred/angled faces
       |
 [4] encoder  ->  feature vector (the "template")
       |
 [5] matcher  ->  similarity score vs each of N
       |
 [6] threshold -> alert if score >= T
       |
 [7] human adjudication -> stop / no stop
       |
       +--> if no alert: template discarded

Stage 4 is where a face becomes biometric data in the legal sense. The output is a feature vector, commonly a few hundred floating-point values, sometimes called a template or an embedding. It is not a picture and cannot be viewed as one, which is why the phrase “we do not store images” is technically true and answers a question nobody asked. Under Article 4(14) of the UK and EU General Data Protection Regulation, biometric data resulting from specific technical processing that allows unique identification is special category data, and the template is squarely within it. Chapter 55 covers what that classification requires.

Stage 6 is the policy dial. Stage 7 is the control that police forces rely on most heavily in their public defence of these systems, and it is worth being precise about what it can and cannot do. A human reviewing an alert can catch an obvious mismatch. A human cannot catch a systematic bias, cannot recover the people the system silently failed to detect, and is subject to automation bias: the well-documented tendency to defer to a machine’s suggestion. The 2019 independent report on the Metropolitan Police’s trials by Professor Pete Fussey and Dr Daragh Murray of the University of Essex examined this directly and found the human review process considerably weaker in practice than in policy.

Two variants of the same pipeline are worth naming because the law treats them differently. Live or real-time facial recognition runs the loop above on a video feed as people walk past. Retrospective facial recognition takes a still image after the fact and runs stages 4 to 7 against a stored gallery. Operator-initiated facial recognition puts stages 1 to 7 on an officer’s handheld device, pointed at one person at a time; the Metropolitan Police have been trialling this. The privacy arithmetic differs sharply between the three, and so should the authorization.

Bridges: the facts, the five grounds and the two impermissible discretions#

R (on the application of Edward Bridges) v Chief Constable of South Wales Police and others is the case that everybody cites and few people read. The neutral citation is [2020] EWCA Civ 1058. Judgment was handed down on 11 August 2020 by Sir Terence Etherton MR, Dame Victoria Sharp PQBD and Lord Justice Singh, on appeal from the Divisional Court at [2019] EWHC 2341 (Admin), which had dismissed the claim on 4 September 2019.

The facts, taken from the Court’s own press summary, are worth having exactly. South Wales Police deployed a system called AFR Locate on about fifty occasions between May 2017 and April 2019. Deployments were overt rather than covert. Watchlists contained between 400 and 800 people, against a maximum system capacity of 2,000 images, and included people wanted on warrants, people who had escaped custody, suspects, people who might need protection, vulnerable people, people of possible intelligence interest, and people whose presence at a particular event caused concern. The system could scan 50 faces per second. Across the deployments in 2017 and 2018, an estimated 500,000 faces may have been scanned. Edward Bridges, a civil liberties campaigner from Cardiff, was in the vicinity of two deployments: Queen Street in Cardiff city centre on 21 December 2017, and an arms fair at the Motorpoint Arena on 27 March 2018. He was not on any watchlist. South Wales Police did not dispute that his image was captured.

He appealed on five grounds. The decision was unanimous. Three succeeded and two failed.

Ground Subject Outcome
1 Article 8 legality Succeeded
2 Article 8 proportionality Failed
3 DPIA, s.64 DPA 2018 Succeeded
4 Policy document, s.42 DPA 2018 Failed
5 Equality duty, s.149 EA 2010 Succeeded

Ground 1 is the holding that matters most. The Court accepted that a legal framework existed: primary legislation in the Data Protection Act 2018, secondary material in the Surveillance Camera Code of Practice, and local South Wales Police policies. It held that framework insufficient, because it contained no clear guidance on two questions. Those are the two impermissible discretions, and they are the sentence to memorize:

Impermissible discretion 1:
  WHO may be placed on a watchlist.

Impermissible discretion 2:
  WHERE the technology may be deployed.

Leaving both to the judgement of individual officers was, the Court held, too broad a discretion to satisfy the quality-of-law requirement in Article 8(2) of the Convention.

Ground 2 failed, and this is the part most commonly misreported. The Court held that the Divisional Court had correctly weighed the actual and anticipated benefits of AFR Locate against the impact on Mr Bridges, found the benefits potentially great and the impact on him minor, and concluded that the use was proportionate. Bridges is not authority that live facial recognition is disproportionate. On the contrary.

Ground 3 succeeded on a narrow and instructive point. Section 64 of the Data Protection Act 2018 requires a data protection impact assessment for processing likely to result in a high risk to rights and freedoms. South Wales Police had produced one, but it had been written on the premise that Article 8 was not infringed. Since the Court held that Article 8 was infringed and the framework inadequate, the assessment proceeded from a false premise and was therefore deficient. The lesson generalizes well beyond facial recognition: an impact assessment that assumes away the risk it was written to assess is not an impact assessment.

Ground 4 failed for a procedural reason rather than a substantive one. The Court held that the Divisional Court had been right not to decide whether South Wales Police had an appropriate policy document within the meaning of section 42 of the Data Protection Act 2018, because the two deployments in issue predated the coming into force of that Act.

Ground 5 succeeded and has had more practical effect on procurement than anything else in the judgment. The Public Sector Equality Duty in section 149 of the Equality Act 2010 requires a public authority to have due regard to the need to eliminate discrimination. The Court held that the purpose of the duty is to ensure that authorities give thought to whether a policy will have a discriminatory impact, and that South Wales Police had erred by not taking reasonable steps to enquire whether the software had bias on racial or sex grounds. Two qualifications are important and are usually dropped. The Court did not find that AFR Locate was biased. It said explicitly that there was no clear evidence that it was. The failure was a failure to ask, not a finding of discrimination. And the duty is a duty of enquiry, which means a purchaser cannot discharge it by taking a vendor’s word.

The Court granted a declaration reflecting the three successful grounds. South Wales Police confirmed they would not appeal.

The background evidence that made ground 5 arguable is worth naming. Buolamwini and Gebru’s 2018 paper “Gender Shades” measured commercial gender classification systems and found error rates of up to 34.7 per cent for darker-skinned women against 0.8 per cent for lighter-skinned men. NIST’s report NISTIR 8280, “Face Recognition Vendor Test Part 3: Demographic Effects”, of December 2019, found that across demographic groups false positive rates often varied by factors of ten to beyond a hundred, with elevated rates for West and East African and East Asian faces in one-to-one matching and the highest rates among American Indian, African American and Asian faces in one-to-many search. Those are measurements of specific algorithms at specific dates, not permanent properties of the field, and later NIST reports show the spread narrowing for the best systems. They remain the reason the duty of enquiry exists.

Thompson and Carlo, 2026: what six years changed#

The second major British challenge was decided while this book was being written. R (Thompson and Carlo) v Commissioner of Police of the Metropolis, [2026] EWHC 915 (Admin), was handed down by the Divisional Court on 21 April 2026. The Metropolitan Police won on both grounds.

The first claimant was Shaun Thompson, who in February 2024 was falsely matched by a Metropolitan Police live facial recognition camera at London Bridge, stopped, questioned, detained and threatened with arrest. He was matched against his own brother, whose image was on the watchlist. The second claimant was Silkie Carlo, director of Big Brother Watch, who gave evidence that she had modified her behaviour by avoiding protests and public events where the technology was deployed. That second claim is a chilling-effect claim advanced in litigation, which is unusual and worth noting.

The grounds were narrow. Ground 1 was framed around Article 8 of the Convention, ground 2 around Articles 10 and 11, which protect expression and assembly. Interference with those rights was accepted by the force. The dispute was solely about whether the interference was in accordance with, or prescribed by, law: that is, the same quality-of-law question that decided Bridges, applied to the Metropolitan Police’s 2024 overt live facial recognition policy.

The claimants attacked the policy on three fronts, which the Court treated as the why, the who and the where.

On the why, the Court held that the policy confined deployment to three use cases: crime and missing-person hotspots, protective security operations, and locating individuals where there is specific intelligence.

On the who, the policy set out five categories of person eligible for watchlist inclusion, tied to specific offence types or court orders. The Court held that this adequately limited officer discretion and made the targeted offence types foreseeable.

On the where, the Court held it was readily apparent from the policy that a crime hotspot meant a small geographical area. In practice these are defined by a hexagonal grid laid over London, with each hexagon scored using three years of crime data, and hexagons in the top 25 per cent of their command unit’s territory designated as hotspots. The claimants objected that the force also relied on “operational experience”, which they said was too subjective. The Court disagreed, treating it as evidence-based judgement drawn from specialist and corporate knowledge rather than the whim of an individual officer.

Taking the policy as a whole, the Court distinguished Bridges: unlike South Wales Police in 2017 to 2019, the Metropolitan Police had introduced clear criteria for who and where. Both impermissible discretions had been closed.

What the judgment did not decide is at least as important as what it did. Because of how the claimants framed their case, the Court was not asked whether the deployments were necessary, only whether the policy was foreseeable. It did not examine whether any specific deployment was proportionate in practice. A discrimination argument about deployments being concentrated in areas with larger ethnic minority populations was, in the Court’s words, no more than faintly asserted, and was not resolved. An argument that the same watchlist had been reused across different locations was accepted as factually possible but held to be about application rather than policy, and therefore outside the scope. And the Court declined to consider how the policy would apply to permanent fixed camera installations, describing that as speculation.

Thompson indicated an intention to appeal, and Big Brother Watch confirmed the Metropolitan Police had paid Thompson a settlement in response to his claim for damages. As of August 2026 the appeal had not been determined. [UNVERIFIED: whether permission to appeal in Thompson and Carlo had been granted or refused by August 2026]

The practical effect was immediate. The judgment was read across British policing as authorization for a national rollout. By June 2026 at least twelve forces in England and Wales were known to have used the technology. The Home Office funded ten vans across seven forces in 2025 and announced in January 2026 that it would pay for forty more, enough for at least one per force, alongside a National Centre for AI in Policing with 115 million pounds of funding over three years. In mid-May 2026 the Metropolitan Police used live facial recognition at a protest for the first time, at the Unite the Kingdom demonstration in the London borough of Camden.

The scale figures that go with that rollout are the ones to keep. Between September 2024 and September 2025 the Metropolitan Police scanned more than three million faces, made 962 arrests following deployments, and recorded ten false alerts, of which eight involved people from black ethnic backgrounds; the force described the demographic imbalance as not statistically significant on that sample size and said it would keep it under review. In the first four months of 2026, 1.7 million scans in London produced 44 arrests. Essex Police scanned 2.2 million faces across 2024 and 2025 and made 117 arrests. A six-month fixed-camera pilot in Croydon scanned almost half a million faces and, according to the force’s press release, produced one false alert; the full evaluation report had not been published as of August 2026, and in response to a freedom of information request the force said the results would appear in its annual report around October 2026.

Set those against the arithmetic from earlier. Three million faces, 962 arrests, is one arrest per 3,120 faces scanned. That ratio, rather than any accuracy percentage, is the number a proportionality argument has to engage with.

The EU AI Act: Article 5, Article 26(10), and the dates that moved#

The European Union’s rules are the most detailed in the world on this specific question, and as of August 2026 they have just been amended, so precision about dates matters more than usual.

Regulation (EU) 2024/1689, the Artificial Intelligence Act, was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024.

Article 5(1)(h) prohibits the use of real-time remote biometric identification systems in publicly accessible spaces for the purposes of law enforcement, unless and in so far as such use is strictly necessary for one of three objectives:

(i)   targeted search for specific victims of
      abduction, trafficking or sexual exploitation,
      and search for missing persons;

(ii)  prevention of a specific, substantial and
      imminent threat to life or physical safety,
      or a genuine and present or genuine and
      foreseeable threat of a terrorist attack;

(iii) localisation or identification of a person
      suspected of an offence listed in Annex II,
      punishable in the Member State concerned by a
      custodial sentence of at least four years.

Article 5(2) requires that any such use serve only to confirm the identity of a specifically targeted individual, and that it take into account the nature of the situation, including the seriousness, probability and scale of the harm if the system were not used, and the consequences for the rights and freedoms of all persons concerned. It also requires that the deploying authority complete a fundamental rights impact assessment under Article 27 and register the system in the EU database under Article 49 before use, save in duly justified cases of urgency.

Article 5(3) requires prior authorization by a judicial authority or an independent administrative authority whose decision is binding, issued on a reasoned request. In a duly justified situation of urgency use may begin before authorization, provided authorization is requested without undue delay and at the latest within 24 hours. If authorization is refused, use must stop immediately and all data, results and outputs must be discarded and deleted. The article also states in terms that no decision producing an adverse legal effect on a person may be taken based solely on the output of the system.

Article 5(4) requires each use to be notified to the market surveillance authority and the national data protection authority. Article 5(5) makes the whole permission regime optional: a Member State may decide to allow these uses within the stated limits, must lay down detailed national rules if it does, must notify them to the Commission within 30 days of adoption, and may legislate more restrictively. Article 5(6) requires annual reports to the Commission.

The shape is now clear. Article 5(1)(h) is not a ban on facial recognition. It is a ban with three carve-outs, available only if a Member State opts in, subject to case-by-case judicial authorization. A Member State that does nothing has a prohibition. A Member State that legislates has a licensing scheme.

Post-hoc identification is treated entirely differently. It is not prohibited. It is high-risk under Annex III point 1, and Article 26(10) sets the conditions. In the framework of an investigation for the targeted search of a person suspected or convicted of a criminal offence, the deployer must request authorization from a judicial or binding administrative authority, either in advance or without undue delay and no later than 48 hours, except where the system is used for initial identification of a potential suspect based on objective and verifiable facts directly linked to the offence. Each use must be limited to what is strictly necessary for the investigation of a specific criminal offence. If authorization is refused, use must stop immediately and the linked personal data must be deleted. The article states that such systems must never be used for law enforcement in an untargeted way with no link to an offence, proceeding, threat or missing person search, and that no decision producing an adverse legal effect may be taken solely on the system’s output. Each use must be documented in the relevant police file, and deployers must submit annual reports to the market surveillance and data protection authorities.

The dates are where August 2026 matters. The original Article 113 set a staged commencement. Then Regulation (EU) 2026/1744 of 8 July 2026, the Digital Omnibus on AI, amended it. That regulation was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, three days after publication, expressly so that it would be in place before the Act’s general application date.

Date What applies
1 Aug 2024 Regulation enters into force
2 Feb 2025 Article 5 prohibitions
2 Aug 2025 GPAI and governance rules
2 Aug 2026 General application
2 Dec 2026 New Article 5 prohibitions
2 Dec 2027 Annex III high-risk duties
2 Aug 2028 Annex I high-risk duties

The delay is the headline. Recital 40 of Regulation (EU) 2026/1744 gives the reason in terms: the delayed availability of standards, common specifications and alternative guidance, and the delayed establishment of national competent authorities, jeopardized effective entry into application. Sections 1, 2 and 3 of Chapter III now apply from 2 December 2027 for systems high-risk under Article 6(2) and Annex III, and from 2 August 2028 for systems high-risk under Article 6(1) and Annex I.

Three consequences follow for anybody building or buying in this space, and they are easy to get wrong.

First, the Article 5 prohibitions were not delayed. They have applied since 2 February 2025 and continue to apply. A real-time remote biometric identification deployment that falls outside the three exceptions has been unlawful in the Union for a year and a half as of the date of writing.

Second, Article 26(10), which contains the judicial authorization requirement for post-hoc identification, sits in Chapter III Section 3. Its application for Annex III systems moved from 2 August 2026 to 2 December 2027. The prohibition on live identification is in force; the procedural discipline on retrospective identification is not yet.

Third, the omnibus added two new prohibitions to Article 5, on AI systems generating or manipulating non-consensual intimate imagery and child sexual abuse material, taking effect on 2 December 2026. It did not amend Article 5(1)(h). The remote biometric identification prohibition stands as enacted in 2024.

Penalties are set by Article 99(3): non-compliance with the Article 5 prohibitions attracts administrative fines of up to 35,000,000 euro or, for an undertaking, up to 7 per cent of total worldwide annual turnover for the preceding financial year, whichever is higher. That is the highest band in the Regulation, and it is higher than the top band under the General Data Protection Regulation.

One more provision belongs here because it is the clearest statement in any statute of the principle this chapter is about. Article 5(1)(e) prohibits the placing on the market, putting into service for that purpose, or use of AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage. That is a prohibition aimed at a business model, and we will come back to the company it was aimed at.

Chilling effects: what the studies measured and what they did not#

The claim that being watched changes behaviour is old, intuitive, and for a long time unmeasured. Courts have repeatedly refused to act on it precisely because it was unmeasured: a claimant who says surveillance deterred them from doing something lawful has, by definition, no record of the thing they did not do. Since 2013 there has been a real empirical literature. It is worth knowing in detail, including its limits, because it is the evidence base on which the whole “the capability itself is the harm” argument stands or falls.

The central study is Jonathon Penney’s “Chilling Effects: Online Surveillance and Wikipedia Use”, published in the Berkeley Technology Law Journal, volume 31, number 1, at page 117, in 2016.

The design is an interrupted time series. The United States Department of Homeland Security published a list of keywords it used to monitor social media, grouped into categories including Health Concern, Infrastructure Security and Terrorism. Penney selected 48 English Wikipedia articles corresponding to the keywords listed under Terrorism, including terms such as “dirty bomb”, “suicide attack”, “nuclear enrichment” and “eco-terrorism”. He collected monthly page-view counts for those articles across 32 months, from the beginning of January 2012 to the end of August 2014. The interruption is the publication of the mass surveillance revelations in June 2013. Analysis was in Stata, with autocorrelation controlled using the Prais-Winsten method where necessary.

The results, in the order the paper reports them:

Measure Finding
Mean monthly views Down 526,614, about 19.5%
Immediate drop, June 2013 995,085 views, over 30%
Same, outlier excluded 693,617 views, just under 25%
Trend change, monthly views -67,513, reversing +41,421

The first set of results found an immediate reduction of 995,085 views following June 2013, a large and statistically significant drop against a May 2013 baseline of 2,960,778 total views, which is an immediate drop-off of over 30 per cent. Two outlier observations traceable to a surge of traffic to the Hamas article during the 2012 Gaza conflict were then excluded, as best practice requires. With those removed, the immediate drop was 693,617 views against a May 2013 baseline of 2,893,553, just under 25 per cent, and, importantly, the overall trend changed as well: a statistically significant change of minus 67,513 monthly views turned a pre-June trend of plus 41,421 views per month into a declining one. That trend change is the finding that distinguishes this study from a one-off dip. It suggests a lasting effect rather than a momentary reaction to news.

Penney then ran comparator groups, which is what makes the study persuasive. For a group of 30 terrorism-related articles the immediate drop was 225,867, about 26 per cent against predicted May 2013 views of 854,755, with the monthly view trend changing from an increase of 26,129 to a decline, a shift of 38,160 views a month, significant at the 99 per cent confidence level. For a comparator group of 25 domestic security-related articles the reduction was 24,638, with p values of 0.531 and 0.551, not statistically significant, and the regression model itself was not significant. For a group of popular articles including “Google”, “Facebook”, “Breaking Bad” and “World War II”, views were essentially flat across the whole period.

The pattern is the point. Articles a reader might worry about being seen reading dropped and kept dropping. Articles about security that nobody would worry about reading did not. Popular articles did not.

Penney’s study sits alongside three others that are usually cited with it.

Marthews and Tucker examined Google search volumes for privacy-sensitive terms and found a statistically significant 5 per cent reduction in searches for 57 such terms after June 2013. Penney notes that his effect is roughly twice that even on the most conservative reading of his own data.

Elizabeth Stoycheff’s study “Under Surveillance: Examining Facebook’s Spiral of Silence Effects in the Wake of NSA Internet Monitoring”, published in Journalism and Mass Communication Quarterly in 2016, used an experimental design rather than observational data. Participants primed with a reminder of government monitoring were less willing to express minority opinions, and the effect was concentrated among those who said they had nothing to hide.

PEN America’s report “Chilling Effects: NSA Surveillance Drives U.S. Writers to Self-Censor”, published on 12 November 2013, reported a survey conducted in October 2013 by the FDR Group of over 520 American writers. It found roughly one in six writers reporting that they had avoided writing or speaking about a particular topic because of surveillance concerns.

Now the honest part. These studies have real limits and a practitioner should know them before citing them.

Penney’s data is observational. It shows that traffic fell and that the fall coincided with the revelations, and the comparator groups make alternative explanations harder, but it cannot observe why any individual reader did not click. The June 2013 revelations were an enormous news event, and news events shift attention in ways hard to separate from deterrence. The unit of analysis is aggregate monthly page views, not people, drawn from a self-selected English-language Wikipedia population. And, as Penney works through himself, part of the drop is background Wikipedia traffic; his conservative reading is that if a full 15 per cent of the drop is background, 10 per cent remains, still twice the Marthews and Tucker effect. Stoycheff’s experiment supports a causal claim but in a primed laboratory setting, which is not the same as living under surveillance. PEN America’s survey is self-reported, and its sample is writers, a population unusually attentive to the issue.

Taken together, the fair statement is this: there is now good evidence that awareness of surveillance measurably reduces information-seeking and expressive behaviour, the effect sizes measured so far are in the range of 5 to 30 per cent depending on the behaviour and the population, and the effect appears to persist rather than decay. That is a solid empirical claim. It is not a claim that any particular camera on any particular street deterred any particular person, and courts have generally been unwilling to bridge that gap. Silkie Carlo’s evidence in Thompson and Carlo, that she avoided protests where the technology was deployed, is one of the first attempts to put an individualized chilling-effect claim in front of a British court, and the case was decided on other grounds.

Anonymity as a democratic requirement, in the case law#

The claim that anonymity is a requirement rather than a luxury is not a modern civil-liberties invention. It has a long and specific legal record, and the record is useful because it identifies exactly which activities break when anonymity is removed.

The founding example in the Anglo-American tradition is the publication of the Federalist Papers between 1787 and 1788 under the pseudonym Publius, by Alexander Hamilton, James Madison and John Jay. The documents that argued for the ratification of the United States Constitution were themselves anonymous political speech.

The United States Supreme Court has treated that history as legally significant three times over. In NAACP v Alabama, 357 U.S. 449, decided in 1958, the Court held that compelled disclosure of the association’s membership lists violated the members’ freedom of association, on the express reasoning that revelation of membership had exposed members to economic reprisal, loss of employment, physical coercion and public hostility. In Talley v California, 362 U.S. 60, decided in 1960, the Court struck down an ordinance banning the distribution of handbills that did not identify the person who prepared them. In McIntyre v Ohio Elections Commission, 514 U.S. 334, decided in 1995, the Court struck down a prohibition on anonymous campaign literature, holding that an author’s decision to remain anonymous is an aspect of the freedom of speech protected by the First Amendment.

The European jurisprudence approaches it from the direction of journalism. In Goodwin v United Kingdom, decided by the European Court of Human Rights in 1996, the Court held that protection of journalistic sources is one of the basic conditions for press freedom, and that without such protection sources may be deterred from assisting the press in informing the public on matters of public interest. That reasoning is a chilling-effect argument accepted at the highest level of European human rights law, three decades before anybody had data on it.

The whistleblowing framework makes the same assumption structurally. Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law requires internal and external reporting channels with strict confidentiality for the reporting person’s identity. Its Article 6(2) leaves it to Member States to decide whether to require entities to accept and follow up anonymous reports, so anonymity as such is optional under the Directive while confidentiality is not. The practical tooling reflects the same requirement: SecureDrop, first released in 2013 and maintained by the Freedom of the Press Foundation, exists to let a source deliver documents to a newsroom without the newsroom learning who the source is, precisely because a newsroom that knows can be compelled to say.

The functional argument, stripped of jurisdiction, is short. Three activities that democratic systems depend on cannot be performed by an identified person without changing what they are.

Whistleblowing requires the whistleblower to survive the disclosure. Confidentiality that depends on an employer’s good behaviour is not confidentiality, because the employer is the adversary.

Journalism requires sources who can meet a reporter without the meeting itself being evidence. Source protection law defends the reporter’s notebook, and defends nothing at all if the meeting is in a movement log.

Dissent requires that the cost of attending be bounded. A protest that everyone can attend anonymously has one participation cost. A protest at which everyone is identified has a different and much higher one, and the difference is not distributed evenly: it falls hardest on people with insecure employment, insecure immigration status, or family abroad.

That last point is why the first use of live facial recognition at a British protest, in May 2026, is a more significant event than the arrest numbers around it suggest.

Function creep, documented#

Function creep is not a slippery-slope hypothetical. It is a documented pattern with dates, and the pattern is regular enough to be designed against.

System Built for Later used for
US Social Security number Benefits, 1936 Universal identifier
UK DNA database Convicted offenders Retention of unconvicted
Aadhaar Subsidy delivery Private-sector KYC
TraceTogether Contact tracing Criminal investigation
Scraped web photos Face search product Police identification

Take them in order, because each one drifted for a different reason.

The United States Social Security number was created in 1936 to administer a benefits programme. The Social Security Administration’s own records show that from the seventh version of the card, issued in 1946, both card and stub carried the legend “For Social Security Purposes -- Not For Identification”, and that the legend remained until it was dropped from the eighteenth version, issued in 1972. The card that told you in print that it was not identification became the de facto national identifier of the United States and the raw material of an entire fraud economy, which is chapter 57’s subject. The mechanism of drift here was convenience: the number was unique, everybody had one, and nothing stopped anybody asking for it.

The United Kingdom’s national DNA database expanded from a collection of profiles of convicted offenders to include profiles taken on arrest and retained indefinitely regardless of whether the person was ever charged. In S and Marper v United Kingdom, decided by the Grand Chamber of the European Court of Human Rights on 4 December 2008, applications 30562/04 and 30566/04, the Court held that the blanket and indiscriminate retention of fingerprints, cell samples and DNA profiles of persons suspected but not convicted of offences was a disproportionate interference with Article 8 and could not be regarded as necessary in a democratic society. The United Kingdom responded with the Protection of Freedoms Act 2012, which imposed retention limits. The mechanism of drift here was procedural: the trigger for collection moved from conviction to arrest, and nobody re-examined the retention rule when the trigger moved.

India’s Aadhaar was introduced as a system for delivering subsidies and benefits to residents. Section 57 of the Aadhaar Act 2016 permitted bodies corporate to require Aadhaar authentication, which in practice made it a general-purpose identity check for telecommunications and banking. The Supreme Court of India struck down section 57 in its Aadhaar judgment of 26 September 2018. The mechanism of drift here was statutory: the enabling provision was written broadly enough to permit exactly the expansion that later had to be undone by a court. Chapter 55 handles the privacy-law analysis of that judgment.

Singapore’s TraceTogether was built and promoted as a COVID-19 contact tracing system. In January 2021 the government confirmed in Parliament that the data was accessible to the police under the Criminal Procedure Code, which was not what users had been told. Legislation followed within weeks: the COVID-19 (Temporary Measures) (Amendment) Bill, introduced on 1 February 2021, restricted police access to a defined list of seven categories of serious offence set out in a new schedule. The mechanism of drift here is the most instructive of the five, because nothing new was built and no policy was changed. A general law of criminal procedure already reached the data. The system was assumed to be purpose-limited and was not, and the assumption was only tested once somebody asked the right parliamentary question.

Clearview AI built a facial recognition database by scraping images from public websites and social media, then sold search access to law enforcement agencies. The United Kingdom’s Information Commissioner’s Office issued a monetary penalty of 7,552,800 pounds in May 2022 together with an enforcement notice requiring deletion of United Kingdom residents’ data. The First-tier Tribunal allowed Clearview’s appeal on 17 October 2023, holding that the Information Commissioner lacked jurisdiction under the UK GDPR because the processing was carried out for foreign law enforcement purposes. The Upper Tribunal reversed that on 7 October 2025, holding that the First-tier Tribunal had materially erred in law and that the UK GDPR could apply extraterritorially where processing targets United Kingdom residents, and remitted the case for substantive determination. On 19 December 2025 the Upper Tribunal granted Clearview permission to appeal to the Court of Appeal. As of August 2026 the substantive appeal had not been finally determined. [UNVERIFIED: the status of the Clearview AI appeal to the Court of Appeal as at August 2026] The mechanism of drift here was that the data was already public, and “already public” was treated by the collector as equivalent to “free to repurpose”, which every data protection regime in the world says it is not.

The countermeasures fall out of the mechanisms. Against convenience drift, make the identifier useless outside its sector, as Austria’s sector-specific personal identifiers and Germany’s card-specific restricted identifiers do. Against procedural drift, tie retention to the outcome rather than the trigger, and make the retention clock a property of the record rather than a line in a policy. Against statutory drift, do not write the broad enabling clause in the first place. Against assumption drift, put the purpose limitation in a statute that overrides general powers, which is what Singapore did after the fact. Against public-data drift, treat lawful availability and lawful reuse as separate questions, which Article 5(1)(e) of the EU AI Act now does by prohibiting untargeted scraping outright.

The proportionality test applied to three real deployments#

British and European public law has a structured test for whether an interference with a right is justified, and it is a better analytical tool than any checklist a vendor will hand you. The four questions come from Lord Sumption’s judgment in Bank Mellat v Her Majesty’s Treasury (No 2) [2013] UKSC 39, given on 19 June 2013, at paragraph 20, with a parallel formulation from Lord Reed at paragraph 74:

Stage 1  Is the objective sufficiently important
         to justify limiting a fundamental right?

Stage 2  Is the measure rationally connected
         to that objective?

Stage 3  Could a less intrusive measure have been
         used without unacceptably compromising
         the objective?

Stage 4  Has a fair balance been struck between
         the rights of the individual and the
         interests of the community?

Apply it three times.

Deployment one: South Wales Police, AFR Locate, 2017 to 2019. Stage 1 passes without difficulty: locating people wanted on warrants and missing persons is plainly a sufficiently important objective. Stage 2 passes on the evidence: the system did produce arrests, so it is rationally connected, and rational connection is a low bar that does not require the measure to be the best available. Stage 3 is where the argument should have been hardest, since a watchlist of 400 to 800 people scanned against an estimated 500,000 faces invites the question whether targeted intelligence-led policing would have achieved a comparable result, but the Divisional Court and the Court of Appeal both found the balance acceptable. Stage 4 was the express finding: the Court of Appeal held at ground 2 that benefits potentially great weighed against an impact on Mr Bridges that was minor produced a proportionate interference. The deployment passed proportionality and failed on legality, which is the outcome most commentary gets backwards. A measure can be proportionate and still unlawful because the framework governing it leaves too much to individual discretion.

Deployment two: the Metropolitan Police live facial recognition programme, 2024 to 2026. Stage 1 passes; more than a quarter of the arrests in the September 2024 to September 2025 period were of people involved in violence against women and girls, which is about as strong a stage 1 case as exists. Stage 2 passes: 962 arrests from three million scans is a rational connection, even at a ratio of one arrest per 3,120 faces. Stage 3 is unresolved, and that is the important finding. The Divisional Court in Thompson and Carlo was not asked to decide necessity, because the claimants framed their case on foreseeability alone, so no British court has yet examined whether a less intrusive measure would achieve a comparable result. Stage 4 is likewise unexamined at the level of individual deployments; the Court considered proportionality only to ask whether the policy gave decision-makers adequate guidance. The programme has been held lawful on the question that was asked. The two questions that a proportionality analysis would put at the centre have not been answered by a court.

Deployment three: Clearview AI’s scraped database. Stage 1 passes: assisting criminal investigations is an important objective. Stage 2 passes: the product worked. Stage 3 fails decisively. A database built by scraping billions of images indiscriminately is, by construction, the most intrusive possible means, since it enrols the entire population of the internet in order to search for the small number of people any given query concerns. A gallery limited to custody images achieves most of the investigative benefit at a fraction of the intrusion. Stage 4 fails as well: the population bearing the burden and the population benefiting are almost entirely disjoint, and the burdened population has no notice, no consent and no route to removal. This is why the European legislature did not attempt a proportionality assessment for this category and simply prohibited it in Article 5(1)(e).

A fourth deployment is worth a sentence for contrast, because it shows the test producing a middle answer rather than a yes or a no. The Information Commissioner’s Office reviewed Facewatch, a facial recognition system used in retail premises including some Southern Co-op stores, and published its findings on 31 March 2023. The regulator did not prohibit the system. It accepted that there was a legitimate interest in protecting staff from violence and required changes to how the system operated. That is stage 3 doing its work: the answer was not “stop” but “do less of it, and differently”.

The lesson for anybody designing one of these systems is that stages 1 and 2 are almost always satisfiable and almost never where a deployment actually fails. Stage 3 is where the real question lives, and stage 3 is an engineering question. Whether a less intrusive measure exists is a question about system design, and it is answered in the architecture, not in the policy document.

Design choices that preserve the option not to identify#

This is the part of the chapter that belongs to practitioners. Every item here is a concrete decision, with a real cost, that keeps the option of not being identified open. The costs are stated honestly, because a list of free choices would not be a list of engineering choices.

Choose verification over identification whenever the claim exists. If the user can assert who they are, compare one to one. Do not build a one-to-many search because it feels more capable. The cost is that you must have an enrolment step and a way for the user to make the claim, and you lose the ability to answer questions you did not plan for. That loss is the point.

Keep the comparison on the device. A face template that never leaves the phone’s secure element cannot be breached at a server, cannot be joined to another database, and cannot be searched by anybody. The cost is that you cannot revoke or re-verify centrally, and you must handle device loss as a separate recovery problem.

Prove the predicate, not the identity. Almost every real check is a predicate: is this person over 18, is this person entitled to this benefit, is this person an employee. Selective disclosure formats let a credential holder reveal one attribute and withhold the rest. RFC 9901, “Selective Disclosure for JSON Web Tokens”, published in November 2025 by Fett, Yasuda and Campbell, specifies the mechanism for JSON Web Tokens: the issuer signs commitments to individual claims, and the holder chooses which to disclose at presentation time. The shape of a presentation that proves age without disclosing identity is this:

issuer signs:  {_sd: [h1, h2, h3, h4], iss: "gov.example"}
  where h1 = hash(salt1 + "given_name" + "Anita")
        h2 = hash(salt2 + "birth_date" + "1994-03-11")
        h3 = hash(salt3 + "age_over_18" + true)
        h4 = hash(salt4 + "address" + "...")

holder presents:  the signed token
               +  disclosure for h3 only

verifier learns:  age_over_18 = true, signed by
                  gov.example. Nothing else.

The cost is real: your issuers, wallets and verifiers all need to support it, and a verifier that has grown used to receiving a full identity record will have to change its downstream processing. Cryptographic schemes based on BBS signatures go further and allow the same credential to be presented twice without the two presentations being linkable, which selective disclosure alone does not give you.

Make repeat use unlinkable. Selective disclosure hides attributes; it does not, by itself, stop a verifier joining two presentations by their signature values. Where unlinkability matters, use single-use unlinkable tokens. The Privacy Pass family specifies exactly this: RFC 9576 defines the architecture, RFC 9577 the HTTP authentication scheme, and RFC 9578 the issuance protocols, all published in June 2024. A client obtains tokens from an issuer that cannot see where they will be spent, and spends them at an origin that cannot see who obtained them. The cost is an extra round of issuance, token exhaustion handling, and a genuinely harder abuse-prevention story, since you have deliberately given up the ability to link a bad actor’s actions.

Enforce purpose limitation with different identifiers per relying party. Do not issue one identifier that every service can use as a join key. Austria’s sector-specific personal identifiers and the German national identity card’s restricted identification function both work this way: each sector or each service receives a derived, unlinkable identifier for the same person. The cost is that cross-service correlation becomes genuinely impossible, which is inconvenient exactly when someone wants to do something you did not intend to allow.

Set the threshold and the watchlist as governed parameters, not configuration. From the arithmetic earlier, watchlist size is the dominant term in the false alert budget. Treat both the threshold and the maximum watchlist size as values that require named authorization to change, that are logged when changed, and that are published. The cost is operational friction, which is the entire point.

Delete by construction rather than by promise. A retention policy that lives in a document is a promise. A retention rule that lives in the storage layer, with a key that is destroyed on schedule so that the ciphertext becomes unreadable, is a mechanism. The cost is that you cannot change your mind later, including for good reasons.

Keep a non-identified path open and usable. If the only way to buy a ticket, enter a building or see a doctor is to be identified, then the option not to be identified does not exist regardless of what the policy says. A path that exists but is slower, more expensive or more humiliating is not a path. The cost is maintaining two ways of doing everything, and this is the most expensive item on the list, which is why it is usually the first to be cut.

Log the system, not the person. A deployment needs an audit trail. It does not need an audit trail keyed to the people who walked past. Record who authorized the deployment, at what threshold, against what watchlist, for how long, in what area, with what result. Do not record the non-matching faces in order to demonstrate that you did not act on them.

Design against the successor. The organization that inherits your system will not share your intentions, and neither will the government that inherits the organization. The design question is not what you will do with the capability but what the least trustworthy plausible successor could do with it in five years without writing a line of code. If the honest answer is unacceptable, the capability should not be built in that shape.

Two of these deserve a note on standing. RFC 9576, RFC 9577, RFC 9578 and RFC 9901 are standards in the sense that they are published specifications with normative language. Sector-specific identifiers as implemented in Austria and Germany are implementation details of two national schemes rather than a general standard, though the pattern is general. Deleting by destroying keys is a convention with no single specification behind it. And the requirement in Regulation (EU) No 910/2014, as amended by Regulation (EU) 2024/1183, is law: Article 5a(4)(a) requires European Digital Identity Wallets to ensure that selective disclosure of data is possible; a later paragraph requires that the wallet provider neither collect information about wallet use beyond what is necessary to provide the service nor combine that data with personal data from other services; and another requires that the technical framework not allow attestation providers or any other party, after issuance, to obtain data allowing transactions or user behaviour to be tracked, linked or correlated, unless explicitly authorized by the user. Article 5a(1) obliges each Member State to provide at least one wallet within 24 months of the entry into force of the relevant implementing acts. That is the first time a major statute has required unlinkability as a property of an identity system rather than recommending it.

The deployment record that makes review possible#

Everything in this chapter that went wrong went wrong in a way that was invisible until somebody litigated. The cheapest intervention available to a practitioner is to make a deployment reviewable in advance, by recording the parameters that determine its intrusiveness at the moment of authorization rather than reconstructing them afterwards. Every field in the record below corresponds to something a court, a regulator or an inquiry has actually asked for.

deployment_id:      KVP-2026-08-15-MARLBROOK-01
authorised_by:      named officer, rank, date, time
legal_basis:        statute or policy paragraph
purpose:            one of the enumerated use cases
area:               polygon, with the criteria used
                    to select it and the data behind
                    those criteria
period:             start and end, in local time
watchlist_id:       hash of the exact list used
watchlist_size:     1240
watchlist_criteria: enumerated categories only
threshold:          value, and who set it
expected_false_alerts: 0.10  (P * N * f)
signage:            what, where, from when
adjudication:       who reviews alerts, trained when
retention:          templates, video, alert records,
                    each with its own clock
outcome:            alerts, stops, arrests, and the
                    alerts found to be false
publication:        where these figures will appear
                    and by what date

Four fields in that record deserve comment.

The hash of the watchlist matters because it is the only way to answer, after the fact, whether the same list was reused across deployments. That question was raised in Thompson and Carlo and could not be resolved on the material before the Court.

The expected false alerts figure matters because it forces the arithmetic to be done in advance. A force that has to write down “we expect 9.7 false alerts today” before the deployment starts will make different watchlist decisions from one that discovers the number afterwards.

The separate retention clocks matter because “images are deleted immediately” is a statement about one of at least three data types, and the other two are the ones that persist.

The publication commitment matters because the pattern across every deployment discussed in this chapter is that headline figures are published quickly and full evaluations slowly or not at all. The Croydon fixed-camera pilot is the current example: a press release reporting one false alert from almost half a million faces, with the full evaluation deferred to an annual report expected around October 2026.

Nothing in that record is expensive. All of it is the difference between a system that can be reviewed and one that can only be argued about.

56.98 Common wrong ideas#

Wrong: The Court of Appeal in Bridges held that live facial recognition is disproportionate. Right: The Court expressly rejected that argument. Ground 2, on proportionality under Article 8(2), failed; the Court held that the Divisional Court had correctly weighed potentially great benefits against a minor impact on Mr Bridges. The appeal succeeded on grounds 1, 3 and 5: the legal framework was too vague about who could be watchlisted and where deployment could occur, the data protection impact assessment was written on a false premise, and the force had not enquired into whether the software was biased.

Wrong: The Bridges judgment found that the software was racially biased. Right: The Court said in terms that there was no clear evidence that AFR Locate was in fact biased on grounds of race or sex. The breach was of the duty in section 149 of the Equality Act 2010 to make reasonable enquiries about possible discriminatory impact. It is a duty to ask, and it cannot be discharged by relying on a vendor’s assurance.

Wrong: The EU has banned facial recognition in public. Right: Article 5(1)(h) of Regulation (EU) 2024/1689 prohibits real-time remote biometric identification in publicly accessible spaces for law enforcement, subject to three exceptions, an optional national opt-in under Article 5(5), prior judicial or independent administrative authorization under Article 5(3), and notification and reporting duties. Post-hoc identification is not prohibited at all; it is high-risk and governed by Article 26(10).

Wrong: All the AI Act’s biometric rules took effect on 2 August 2026. Right: The Article 5 prohibitions have applied since 2 February 2025 and were not delayed. Regulation (EU) 2026/1744 of 8 July 2026, in force from 27 July 2026, moved the Chapter III high-risk obligations, including Article 26(10) and the Article 27 fundamental rights impact assessment, to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems.

Wrong: If the false alert rate is low enough, the privacy objection goes away. Right: The false alert rate governs what happens to the small number of people who are flagged. It says nothing about the much larger number who are measured. In the Marlbrook deployment, a rate of zero false alerts still leaves 31,397 people scanned, and the Court of Appeal held that capture and processing engages Article 8 even where the data is deleted almost immediately.

Wrong: Accuracy figures published by a force are a property of the technology. Right: They are a property of a configuration. Expected false alerts scale with the number of faces scanned multiplied by the watchlist size multiplied by the per-comparison false match rate. Increasing the watchlist from 1,240 to 1,240,000 entries multiplies expected false alerts by a thousand with no change to the software. Any accuracy figure quoted without the watchlist size is uninterpretable.

Wrong: Chilling effects are a rhetorical device that cannot be measured. Right: They have been measured. Penney’s 2016 study in the Berkeley Technology Law Journal found an immediate drop of just under 25 per cent in views of 48 terrorism-related Wikipedia articles after June 2013 with outliers excluded, and a change of minus 67,513 in the monthly trend, reversing a prior increase of 41,421 views a month, while comparator groups of security-related and popular articles showed no significant change. Marthews and Tucker found a 5 per cent reduction in searches for 57 privacy-sensitive terms over the same period.

Wrong: Only people with something to hide need anonymity. Right: The activities that break without it are whistleblowing, journalism and lawful dissent, all of which are performed by people doing nothing wrong. NAACP v Alabama in 1958 turned on exactly this: disclosure of a membership list exposed members to economic reprisal and physical coercion for lawful association. Stoycheff’s 2016 experiment found the silencing effect was strongest among participants who said they had nothing to hide.

Wrong: Function creep is a slippery-slope argument rather than an observation. Right: It is documented with dates. The United States Social Security card carried the printed legend “Not For Identification” from 1946 until 1972 and became the national identifier anyway. Section 57 of India’s Aadhaar Act 2016 permitted private-sector use until the Supreme Court struck it down on 26 September 2018. Singapore confirmed in January 2021 that police could reach TraceTogether contact tracing data under the Criminal Procedure Code, and legislated in February 2021 to restrict access to seven categories of serious offence.

Wrong: Deleting the face template afterwards means no personal data was processed. Right: The template is biometric data allowing unique identification and is special category data from the moment it is created. Deletion is a mitigation applied after processing has occurred, not a reason processing did not occur, and it says nothing about retention of the underlying video or about retrospective systems, whose galleries persist by design.

56.99 Chapter summary in 20 lines#

  1. The limit on identifying everyone everywhere used to be the cost of doing it, and that limit was an accident of economics rather than a safeguard.
  2. When that cost fell to near zero, every protection that came free with the expense had to be rebuilt deliberately in law and in code, or it did not exist.
  3. Verification tests a claim and makes one comparison; identification asks who a person is and makes one comparison for every entry in the gallery.
  4. Expected false alerts are roughly the number of faces scanned times the watchlist size times the per-comparison false match rate.
  5. Watchlist size is therefore the dominant term in the error budget, and an accuracy figure published without it cannot be interpreted.
  6. A facial recognition system does not recognize anyone; it produces similarity scores, and a chosen threshold turns a score into an accusation.
  7. In R (Bridges) v Chief Constable of South Wales Police [2020] EWCA Civ 1058, decided on 11 August 2020, three of five grounds succeeded and two failed.
  8. Ground 1 succeeded because the framework left two impermissible discretions to individual officers: who may be watchlisted, and where deployment may occur.
  9. Ground 2, on proportionality, failed, so Bridges is not authority that live facial recognition disproportionately interferes with Article 8.
  10. Ground 5 succeeded because the force had not enquired whether the software was biased, and the Court expressly found no clear evidence that it was.
  11. In R (Thompson and Carlo) v Commissioner of Police of the Metropolis [2026] EWHC 915 (Admin), decided on 21 April 2026, both of those discretions were held closed.
  12. That judgment decided neither necessity nor the proportionality of any individual deployment, because the claimants argued foreseeability alone.
  13. Article 5(1)(h) of Regulation (EU) 2024/1689 has prohibited real-time remote biometric identification in public for law enforcement since 2 February 2025, subject to three exceptions and a national opt-in.
  14. Article 26(10) subjects post-hoc remote biometric identification to authorization within 48 hours, a strict necessity limit, documentation and annual reporting.
  15. Regulation (EU) 2026/1744 of 8 July 2026 moved the Chapter III high-risk duties to 2 December 2027 and 2 August 2028, and left the Article 5 prohibitions alone.
  16. Penney’s 2016 study found views of terrorism-related Wikipedia articles fell by just under 25 per cent after June 2013, with the monthly trend reversing and comparator groups unaffected.
  17. Anonymity is a working requirement of whistleblowing, journalism and dissent, and the case law from NAACP v Alabama in 1958 onward treats it that way.
  18. Function creep is documented rather than hypothetical, and each case drifted for its own identifiable reason: convenience, procedure, statute, assumption or public availability.
  19. Almost every deployment passes stages 1 and 2 of the Bank Mellat test; stage 3, whether a less intrusive measure exists, is an engineering question answered in the architecture.
  20. The option not to be identified survives only where somebody chose verification over identification, kept matching on the device, proved a predicate, made repeat use unlinkable, governed the threshold and watchlist, deleted by construction, and kept a usable non-identified path.

Chapter sources: R (on the application of Edward Bridges) v The Chief Constable of South Wales Police and others [2020] EWCA Civ 1058, judgment of 11 August 2020, and the Judiciary of England and Wales press summary of the same date, on appeal from [2019] EWHC 2341 (Admin) of 4 September 2019; R (Thompson and Carlo) v The Commissioner of Police of the Metropolis [2026] EWHC 915 (Admin), judgment of 21 April 2026; Bank Mellat v Her Majesty’s Treasury (No 2) [2013] UKSC 39, judgment of 19 June 2013, Lord Sumption at paragraph 20 and Lord Reed at paragraph 74; Regulation (EU) 2024/1689 of 13 June 2024 laying down harmonised rules on artificial intelligence, published in the Official Journal on 12 July 2024 and in force from 1 August 2024, in particular Articles 5(1)(e), 5(1)(h), 5(2) to 5(6), 26(10), 27, 49, 99(3) and 113 and Annexes II and III; Regulation (EU) 2026/1744 of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI), published in the Official Journal on 24 July 2026 and in force from 27 July 2026, in particular recital 40; Regulation (EU) 2024/1183 of 11 April 2024 amending Regulation (EU) No 910/2014, in force from 20 May 2024, Article 5a; Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law, Article 6(2); Data Protection Act 2018 sections 42 and 64; Equality Act 2010 section 149; Protection of Freedoms Act 2012; Aadhaar Act 2016 section 57 and the Supreme Court of India’s Aadhaar judgment of 26 September 2018; Singapore’s COVID-19 (Temporary Measures) (Amendment) Bill of 1 February 2021; Jonathon Penney, “Chilling Effects: Online Surveillance and Wikipedia Use”, Berkeley Technology Law Journal volume 31 number 1 page 117 (2016); Alex Marthews and Catherine Tucker on search-term chilling effects; Elizabeth Stoycheff, “Under Surveillance: Examining Facebook’s Spiral of Silence Effects in the Wake of NSA Internet Monitoring”, Journalism and Mass Communication Quarterly (2016); PEN America, “Chilling Effects: NSA Surveillance Drives U.S. Writers to Self-Censor”, 12 November 2013; Joy Buolamwini and Timnit Gebru, “Gender Shades” (2018); NISTIR 8280, “Face Recognition Vendor Test Part 3: Demographic Effects”, December 2019; Pete Fussey and Daragh Murray, independent report on the Metropolitan Police Service’s trial of live facial recognition technology, University of Essex, July 2019; David Leslie, “Understanding bias in facial recognition technologies”, Alan Turing Institute, 2020; NAACP v Alabama 357 U.S. 449 (1958), Talley v California 362 U.S. 60 (1960), McIntyre v Ohio Elections Commission 514 U.S. 334 (1995) and Goodwin v United Kingdom, European Court of Human Rights (1996); S and Marper v United Kingdom, applications 30562/04 and 30566/04, Grand Chamber, 4 December 2008; Information Commissioner’s Office monetary penalty notice and enforcement notice against Clearview AI Inc of May 2022, First-tier Tribunal decision of 17 October 2023, Upper Tribunal decision of 7 October 2025 and grant of permission to appeal of 19 December 2025; Information Commissioner’s Office statement on Facewatch of 31 March 2023; Metropolitan Police Service live facial recognition report covering September 2024 to September 2025 and its Croydon fixed-camera pilot press release; Statewatch, “England: Police use of facial recognition technology growing rapidly”, 12 June 2026; Social Security Administration history of design versions of the SSN card; RFC 9576, RFC 9577 and RFC 9578 (Privacy Pass, June 2024) and RFC 9901, “Selective Disclosure for JSON Web Tokens” (November 2025).