Published
- 21 min read
A Face Scan Lasts Seconds. The Public Rule Must Last Longer
Books by the author
Compare all 5-
The Digital Fortress
Anyone protecting their own money, accounts and family online
Buy on Amazon Buy the book now What's in it, and who it's for -
The Anonymity Playbook
Journalists, sources, activists and anyone whose privacy has stakes
Buy on Amazon Buy the book now What's in it, and who it's for -
Secure Software Development
Developers shipping production code under delivery pressure
Buy on Amazon Buy the book now What's in it, and who it's for -
The Secure Harness
Teams running AI coding agents in repositories others depend on
Buy on Amazon Buy the book now What's in it, and who it's for -
The AI Native Engineer
Engineers taking AI features from a working demo to production
Buy on Amazon Buy the book now What's in it, and who it's for
As an Amazon Associate I earn from qualifying purchases. Buying through these links costs you nothing extra and helps pay for the blog.
A marked police van sat in Nottingham’s Old Market Square on Friday, 21 August 2026. Two cameras watched the crowd. As people crossed the square, software turned each visible face into measurements and compared them with a police watchlist. This was Nottinghamshire Police’s first public deployment of live facial recognition.
The signs around the square mattered. The marked van mattered. An officer reviewing an alert mattered too. None of those facts settles the harder question: who may be placed on the watchlist, for which purpose, at which place, and under whose review?
Police say a face that produces no match is deleted within seconds. Civil-liberties groups argue that the scan itself changes the terms of ordinary movement through a city, even when the resulting template disappears. Both claims can be true. Deletion limits one form of harm, while public rules decide whether the scan should have happened at all.
This is the line to watch. The useful debate starts with the real deployment, follows the data through the system, and ends with documents the public can inspect. A promise from the van cannot carry that whole burden.
What happened in Old Market Square
The first Nottingham deployment was visible and deliberate. The West Bridgford Wire reported that the marked van used a 360-degree dual-camera system in Old Market Square on 21 August. Its photographs and video showed signs around the area. The outlet said the software compared passing faces with a police watchlist and sent possible matches to officers for review.
That deployment followed a July announcement rather than a sudden trial. BBC News reported on 28 July that Nottinghamshire Police planned to use marked vans in public places. The force described a watchlist that could include people wanted for crimes, people subject to banning orders, and missing people. It said an officer would verify every system match and that scans would be deleted within seconds.
Those details narrow the story. This was an overt police operation, rather than a hidden retail camera or a claim about a future purchase. The system looked for people whose images had already been selected. An algorithmic alert did not automatically become an arrest. Local reporting confirms that the first use took place; the earlier BBC report records the police account of intended safeguards.
The public record is still thin as of 24 August. Nottinghamshire Police said deployment results would be posted online, according to the BBC. The material available for this article does not establish how many faces were processed in Old Market Square, how many alerts appeared, whether officers rejected any alerts, or whether anyone was approached or arrested because of the system. Those are results to request, not blanks to fill with guesses.
A result table also needs denominators. “One alert” means little without the number of people who passed the cameras and the number of watchlist subjects who actually entered the recognition zone. An arrest count cannot reveal how many innocent people were scanned. A low alert count may reflect careful targeting, a quiet day, a small watchlist, or a threshold set to avoid false matches. Public reporting should let an outsider tell those possibilities apart.
Police have a concrete reason for wanting the tool. A camera can compare a crowd with a list faster than officers can inspect faces from memory. A prompt, accurate match could help locate a missing person or someone wanted for a serious offence. The same speed removes a natural constraint: without automation, checking every passer-by is too slow to be routine. Once comparison becomes cheap, policy must supply the restraint that human limits used to provide.
That trade deserves better than two slogans. “Another tool” understates the scale of automatic comparison. “Everyone was identified” overstates what the published mechanism proves. Every visible face was processed for comparison, while an identity claim was generated only when the system crossed its matching threshold. Processing a crowd and identifying the crowd are different acts, but both need a lawful and proportionate purpose.
What the camera does before an officer sees an alert
A live facial recognition system begins with ordinary light. A camera captures frames of the people moving through its field of view. Software finds a face, estimates features that remain useful across modest changes in angle or expression, and creates a numerical representation often called a facial template. It then compares that template with templates made from watchlist images.
The comparison returns similarity, not certainty. A threshold decides when a score is strong enough to become an alert. Set the threshold lower and the system may find more possible matches, including more wrong ones. Set it higher and false alerts may fall, while real watchlist subjects become easier to miss. Lighting, camera angle, image quality, movement, watchlist photograph quality, and the model itself can all influence the result.
An officer stands between the score and the approach. The local report says officers review an alert and decide whether to engage the person. That safeguard is valuable because a trained human can notice a different age, hairline, build, or context. It also creates a second place where judgement can fail. A screen that says “match” can anchor the review before the officer has compared the two images with care.
The distinction between a lead and proof has to survive the whole operation. An alert should prompt visual comparison and checks against other information. It should never become a reason to assume the passer-by committed the offence associated with the watchlist entry. A person can resemble someone else. The watchlist record itself can be stale, wrong, duplicated, or linked to a status that has already changed.
The watchlist therefore carries more power than the model. The algorithm can compare only against the people selected for it. A narrow list of people wanted by a court for serious violence creates one kind of deployment. A list that includes children associated with low-level anti-social behaviour creates another, even if the same cameras and threshold are used.
That concern sits at the centre of the current dispute. In a 19 August letter to Nottinghamshire Police, EFF and seven UK civil-society organisations cited reporting that children as young as 11 were on an existing list linked to anti-social behaviour. The letter urged the force to stop further live facial recognition use, especially for low-level behaviour involving children. The available material does not establish that the Old Market Square watchlist contained those children. It establishes a question the force should answer before another deployment.
The safest public rule begins before the camera switches on. Each watchlist category should have a written legal basis, a clear operational purpose, a maximum age for the underlying information, an approval route, and a removal test. Children need a distinct and stricter analysis. “Known to police” reaches far beyond “wanted by a court,” and a database should not erase that difference.
Watchlist size matters too. Adding more faces increases the number of comparisons and can increase the chance that some passer-by looks sufficiently similar to somebody on the list. Public reports should show the total entries, entries by legal category, entries involving children, the age of the oldest image, and how many records were removed during pre-deployment review. Those figures reveal whether the operation began with discipline.
Seconds of retention do not erase the moment of comparison
Fast deletion is a real safeguard. If a non-matching template disappears within seconds, it cannot later be searched in the same system, leaked from a long-term archive, or joined to a month of movements. The force should keep that design and prove that it works.
Deletion still happens after capture, template creation, and comparison. A passer-by cannot recover the moment before the software measured the face. That is the civil-liberties point behind the coalition’s objection: the privacy decision occurs at collection and processing, while deletion controls what can happen afterwards.
Consider a person walking to meet a confidential source. The cameras may produce no match and retain no template. If the operation is visible, the source may avoid the square, cancel the meeting, or choose a route that exposes them elsewhere. The effect comes from anticipated comparison rather than stored data. A protester, patient, worshipper, union organiser, or young person may make the same calculation.
The coalition letter says routine facial scanning could discourage people from seeking legal or medical advice, speaking with journalists, attending protests, or expressing parts of their identity. Those are predictions about behaviour, rather than measured outcomes from the Nottingham deployment. They should be tested seriously. A force can survey the affected community, publish complaints, examine whether groups avoid a deployment area, and invite independent researchers to study the effect.
Deletion also has several objects. The live template may vanish while an alert image, officer body-camera recording, notebook entry, stop record, arrest file, system log, or screenshot remains. Some of those records may be necessary to investigate an alert or audit a mistake. Their retention periods should be named separately. “Scans are deleted” cannot stand in for a complete data map.
A useful data map follows five paths. It shows what is created for every passer-by, what is created only after an alert, what reaches the reviewing officer, what enters police records after an engagement, and what is retained for audit. Each item needs an owner, purpose, access list, deletion period, and record of onward sharing. The map should cover test data and backups as well as the live system.
System logs deserve careful treatment. Logs can prove which watchlist was loaded, which threshold was used, who approved the operation, when alerts occurred, and how officers resolved them. Deleting every trace would make accountability impossible. Keeping face images from every passer-by would create the archive the safeguard was meant to avoid. Good audit design records decisions and system state while minimising biometric material from people who did not match.
The public should ask for evidence that deletion runs, rather than an assurance that it exists. An independent test can pass known non-matching faces through a controlled deployment and verify that their templates cannot be retrieved after the stated interval. Auditors can inspect storage, caches, failure queues, diagnostic files, and backups. A deletion control earns trust when it survives a broken network connection, a crashed process, and an operator mistake.
Plain language sets a useful test. “Deleted within seconds” should mean the non-match has no remaining searchable face template anywhere the force or supplier can reach. If technical or legal exceptions exist, name them before deployment.
The regulator found uneven governance across police forces
Nottingham’s first use arrived during a wider expansion. On 18 August 2026, three days before the Old Market Square deployment, the UK Information Commissioner’s Office published results from its work on police facial recognition. The timing gives the local story national context without turning one force into a stand-in for every audit finding.
The ICO said live facial recognition vans had previously been limited to two forces but were spreading to forces with no prior experience of public deployment. It had audited five forces and planned a later audit of the Metropolitan Police Service. Nottinghamshire Police was not named among the five summaries listed in the regulator’s post, so those findings should guide questions rather than be presented as findings against Nottinghamshire.
The regulator found a mixed picture. Audited forces generally identified and documented a lawful basis, limited data in live deployments, and maintained breach-reporting procedures. The ICO also said clear senior oversight, staff responsibilities, records of personal information and sharing, image sources, retention, accuracy, unfairness, and bias needed work. Across the five forces it made 107 recommendations, all accepted or partially accepted.
That number is revealing because the hard part extends beyond model accuracy. A technically accurate comparison can sit inside weak approval, poor records, vague roles, or an unjustifiably broad watchlist. Conversely, strong governance cannot rescue a system that performs badly. Both layers have to hold at once.
The ICO also reported a separate 2025 finding about bias in the algorithm used for retrospective facial searches in the Police National Database. That system and use case differ from Nottingham’s live van. The regulator said the issue could increase incorrect matches for some demographic groups and that mitigations and replacement plans were under way. The lesson is narrower than “all facial recognition is biased”: a force must identify the exact model and version it uses, test that system in its real conditions, and keep checking after software changes.
Accuracy reports should separate true recognition, false alerts, missed subjects, and demographic performance. A single percentage can hide the result that matters. If almost everybody passing the van is absent from the watchlist, even a small false-alert rate can produce avoidable interventions. Tests should use the camera positions, lighting, image quality, crowd movement, and threshold expected in Nottingham deployments.
Human review belongs in those tests. Measure how often officers reject a bad alert and how often they accept one. Record the time they receive for comparison, the information shown on screen, the training completed, and whether they can dismiss an alert without pressure. The final operational system includes the officer, interface, policy, and watchlist as well as the model.
The regulator’s position is clear: public trust depends on strong data-protection governance, and governance across audited forces remains inconsistent. Nottinghamshire can respond by publishing its evidence before the pattern hardens. New operators have the advantage of seeing where earlier programmes needed repair.
The argument over law is really an argument over boundaries
Nottinghamshire Police says the system will be used fairly and proportionately. The civil-society coalition says police should pause until Parliament creates a specific legal framework for live facial recognition. The ICO says the government is considering legislation and that data-protection law should remain the foundation of any new regime, with greater legal specificity capable of improving confidence.
These positions reveal the unresolved boundary. Police rely on existing powers, data-protection duties, equality law, human-rights obligations, and professional guidance. Critics see a patchwork that leaves too much discretion with each force. A dedicated statute could state permitted purposes, approval levels, watchlist categories, treatment of children, notice, audit, reporting, complaint routes, and remedies in one place.
Waiting for Parliament is a policy choice with costs on both sides. A pause delays a tool police believe may locate wanted or missing people. Continuing allows local practice to form before national lawmakers set the limits. Once vans, contracts, staff, and expected arrest numbers exist, later restrictions face institutional resistance. Temporary local rules therefore need expiry dates and formal review.
A deployment authorisation should answer a small set of hard questions. Which named problem is the force trying to solve? Why is face comparison necessary for that problem? Why this place and time? Who qualifies for the watchlist? Who approved the list and threshold? What less intrusive method was considered? What result would show that the deployment helped? What result would stop the programme?
“Crime prevention” is too broad. A time-limited search near a location connected to a named serious offender can be assessed. General deterrence across a shopping district cannot tell the public which people, offences, or evidence justified scanning the crowd. Proportionality needs a defined objective because cost can be judged only against something specific.
Public notice needs the same precision. A sign should say that live facial recognition is operating, identify the force, describe the watchlist categories, explain non-match deletion, provide the deployment period, and give a route to the full policy and complaint process. Notice does not create consent. It gives people enough information to understand a state action and challenge it later.
Advance notice can improve scrutiny but may undermine a tightly targeted operation if it reveals exactly whom police seek. The answer is a recorded exception, rather than silence by default. Publish planned areas and general times when possible. If operational necessity delays notice, require written approval and explain the exception after the risk passes.
Independent approval becomes more important as the purpose broadens. An internal senior officer may be enough for a short search tied to an urgent safeguarding case. A recurring programme that scans a city centre, uses broad categories, or includes children should face outside scrutiny before use. A court, commissioner, elected oversight body, or another genuinely independent reviewer can test necessity without sharing the force’s incentive to deploy equipment it already owns.
Rules also need remedies. A person wrongly approached should be able to learn that an alert occurred, request the relevant records, correct watchlist data, complain to an identified body, and seek review without proving the hidden system failed first. Aggregate transparency cannot replace an individual route when the system causes an intervention.
The Anonymity Playbook returns to one practical question: where does observation cross a trust boundary, and who can connect what they see to a real person? A live face system performs that connection attempt in public space. The answer cannot rest only with the operator standing beside the van.
What Nottinghamshire should publish before the next deployment
The first operation has already happened. The most useful next step is a public record detailed enough to test the police account, the coalition’s concerns, and the regulator’s standards. Officials do not need to reveal the names of wanted people or tactics that would defeat an active search.
Publication should begin with the decision, then follow the system through operation and review. The documents below are separate because each catches a different failure.
-
Publish the deployment authorisation. Name the date, place, duration, operational purpose, approving officer, legal basis, alternatives considered, expected benefit, and stopping condition. Redact details only where disclosure would create a specific operational or safety risk, and explain each redaction category.
-
Describe the watchlist by category. Report the total number of entries, legal basis for each category, number involving children, age range of source images, source of those images, pre-deployment accuracy checks, and removal criteria. State whether people linked only to anti-social behaviour were included in the 21 August deployment.
-
Name the technical system. Publish the supplier, model and version, matching threshold, camera arrangement, independent test results, demographic performance, and any local trial performed in comparable lighting and crowd conditions. Record every configuration change between deployments.
-
Show the full data path. Separate non-match templates, alert images, watchlist images, officer views, audit logs, body-camera footage, stop records, and case files. For each, name retention, access, sharing, deletion, backup treatment, and the evidence used to verify deletion.
-
Report outcomes with denominators. Give estimated faces processed, watchlist size, system alerts, officer-confirmed alerts, rejected alerts, approaches, stops, arrests, safeguarding interventions, complaints, and known missed matches. Explain how each measure was counted and where estimation was necessary.
-
Release the human-review procedure. Show what the officer sees, what comparison is required, which other facts must be checked, how a bad alert is dismissed, and what training and refresher testing reviewers complete. Make clear that an alert remains a lead.
-
Create a route for the person affected. Explain how somebody can ask whether an alert led to an approach, obtain records, challenge mistaken identity or watchlist inclusion, correct data, and complain. Provide response deadlines and identify the independent appeal body.
-
Commission an outside audit. Give the auditor access to configuration, watchlist controls, logs, deletion behaviour, alert outcomes, training records, and complaints. Publish methods and findings, including failed tests and corrective deadlines. Independence requires freedom to report an uncomfortable result.
-
Set a review and expiry date. A pilot should end unless a named body renews it after reading the evidence. The review should compare claimed benefit with false alerts, rights impact, complaints, cost, and less intrusive alternatives. Hardware ownership should never become the renewal test.
These records make disagreement productive. Police can show that a narrow deployment worked as described. Critics can point to a specific category, threshold, retention path, or authorisation that needs change. Residents can judge the programme without choosing between a press release and a protest letter.
Journalists should ask for the documents in machine-readable form where figures are involved. A PDF total is useful once. A table covering each deployment lets outsiders compare places, watchlists, alerts, and outcomes over time. Definitions must stay stable, with corrections recorded rather than silently replacing old numbers.
Technical reviewers can test whether the published metrics support the claims. Lawyers and civil-liberties groups can assess authority and proportionality. Children’s rights specialists can examine watchlist criteria that affect young people. People from communities likely to pass the cameras can describe consequences an office-based review will miss.
If the force cannot publish a watchlist policy without exposing operational names, it can publish the categories and approval tests. If it cannot reveal an exact deployment in advance, it can explain the decision afterwards. Secrecy should attach to the small fact that creates risk, rather than spreading across the whole programme.
What you can do when a face-recognition van appears
Most people cannot prevent a camera from seeing a face while crossing an open square. Clothing or gestures intended to defeat recognition may draw attention, conflict with local rules, or fail unpredictably. The durable work is documentation, collective oversight, and a complaint path that reaches the system owner.
Start by reading the signs without blocking officers or other pedestrians. Record the force, date, time, location, stated purpose, and link or contact shown. From a lawful public position, note the van markings and the boundaries of the camera area. Do not photograph members of the public in a way that creates another unnecessary face database.
If an officer approaches after an alert, stay focused on the interaction. Ask whether live facial recognition generated the approach and which process records that fact. Note the officer’s identifying information where local rules allow. If the match is wrong, say so plainly and avoid trying to prove the entire technology debate on the pavement.
Write down what happened as soon as you can. Time, place, words used, documents requested, length of the stop, witnesses, and any explanation of the match will matter later. Preserve original files and avoid posting a stranger’s face while seeking attention for the incident.
Then request the policy and deployment record. Ask the force for the authorisation, watchlist categories, outcome report, data-protection impact assessment, equality assessment, supplier and version, retention schedule, and complaint route. A journalist or community group can submit the same questions across deployments and compare answers.
Parents and youth advocates should ask directly whether children can enter watchlists, for which legal statuses, at what minimum age, who approves inclusion, how parents or guardians are notified where appropriate, and when records expire. A child sought because they are missing presents a different purpose from a child associated with low-level disorder. Policy should preserve that distinction.
A person facing a credible source-protection or targeted-surveillance risk needs a location plan as well as a complaint plan. Check deployment notices before a sensitive meeting when that information is available. Choose routes and meeting places based on the adversary and consequence. Assume that avoiding one marked van cannot remove the wider network of cameras, phones, payment records, transport logs, and witnesses around a city.
That limit matters. Personal evasion cannot carry a public-law problem. If ordinary movement requires every resident to become an expert in camera angles, the policy has failed before the software runs. Democratic controls should narrow where and why scanning happens so daily life does not depend on defeating it.
A marked van still needs a visible boundary
Nottinghamshire Police made several choices that deserve to remain: a marked vehicle, signs, officer review, and rapid deletion of non-matches. Those measures reduce secrecy, automation error, and long-term collection. They give the public something concrete to verify.
The first deployment also exposes what those safeguards cannot decide. They cannot choose a proportionate watchlist, establish whether children belong on it, define a sufficiently serious purpose, prove deletion across every copy, or create an independent remedy after a wrong alert. Governance has to do that work.
The ICO’s August findings show why publication should come early. Five audited forces accepted or partly accepted 107 recommendations across oversight, records, image handling, accuracy, fairness, and staff responsibility. Nottinghamshire can use that evidence before local habits harden around the van.
A face can be converted, compared, and discarded in seconds. The authority for doing it must be slower to create, harder to stretch, and visible enough to challenge. Publish the purpose. Publish the watchlist rules. Publish the data path and results. Put an expiry date on the permission.
You cannot make a public square invisible. You can make surveillance answer to the people who cross it.
If this kind of plain-English privacy analysis helps, the newsletter sends one email per month. The signup is on this site.
Sources
- West Bridgford Wire: Facial recognition cameras deployed in Nottingham city centre for first time, accessed 2026-08-24
- BBC News: Facial recognition vans to be deployed by Nottinghamshire Police, accessed 2026-08-24
- Electronic Frontier Foundation: EFF and Civil Society Groups Call on Nottinghamshire Police to Halt Live Face Recognition, accessed 2026-08-24
- Civil-society coalition: Letter to Nottinghamshire Police on live facial recognition, accessed 2026-08-24
- Information Commissioner’s Office: Facial recognition in policing, earning public trust through strong data protection governance, accessed 2026-08-24