
The Face on the Bus Pass
Download PDFThe National Entitlement Card is Scotland’s bus pass. It is also the largest collection of faces any Scottish public body holds that no biometric regulator watches, and the one office built for the job cannot touch it.
Scotland has something no other part of the UK has: a biometrics regulator whose statutory remit reaches the face. And right now the man who holds the post is asking Parliament for a law that does not yet exist. Police Scotland is pressing ahead toward live facial recognition. It put the question to a public “national conversation” in 2025, resolved to keep going, and expects to bring a business case to its oversight board in 2027.1 The Scottish Biometrics Commissioner has written to ministers to say the technology should not go anywhere near a Scottish street until primary legislation governs it.2 The regulator is telling you, on the record, that he cannot stop the thing he exists to watch.
What he can watch is narrow, and narrow by design. The Scottish Biometrics Commissioner Act 2020 gives him oversight of biometric data held for criminal justice and police purposes by three bodies: Police Scotland, the Scottish Police Authority, and the Police Investigations and Review Commissioner.3 The Code he enforces binds those three and no one else.4 The Commissioner says as much himself, warning of a “Biometric Wild West” in the spaces the law does not reach, objecting in the same breath to police bulk-searching the passport and driving-licence databases for low-level crime.5 A handful of staff, a budget under £700,000, an office built on the stated assumption of no significant expansion.6 It watches one room.
None of this is news. Before the Act was passed, Open Rights Group Scotland and a sitting MSP argued that the Commissioner’s reach should run to biometrics wherever they are found, in education, in health, in retail. The point was made in 2018, and dropped.7 What replaced it is an oversight body for the police, and silence everywhere else. Asked in 2023 whether there were plans to use facial recognition in Scotland’s schools or its public services, the Scottish Government replied that it did not hold the information: school facial recognition, it said, is a matter for local authorities; for the rest, contact the bodies directly.8
That silence is where the largest of these holdings sits, and no one with biometric expertise is watching it. The National Entitlement Card is the bus pass, the young person’s card, the proof of age, the cashless school lunch, the key to a hundred council services. As of June 2026 there are 2,973,029 active cards.9 Every card issued from secondary-school age up carries a photograph. For a child carded through school, the photograph need not be taken for the card at all: one council’s privacy notice describes lifting it from the school’s own records, the SEEMiS system, and reusing it.10 From age eleven a pupil’s school photo becomes a record in the Card Management System, kept, in that notice’s words, “until you advise us you no longer require your card.”11 Indefinitely, then. Thirty-two councils are joint controllers, the Improvement Service processes the applications through the national portal, the programme office sits inside Dundee City Council, and the photograph travels onward into the extract that proves identity across the country’s other public services.12
The scheme’s core privacy assessment dates from July 2020; a supplementary assessment in November 2021 covered new supplier contracts and the under-22 travel scheme, and neither revisits the photograph or the police-sharing arrangements.13 Its oversight, the government confirms, is ordinary data-protection housekeeping: a data protection officer, an annual audit, the auditors of public spending. Nothing biometric, and no specialist regulator anywhere in the chain.14
The law gives two answers to one question: is this photograph biometric data? Under the 2020 Act, a facial photograph capable of identifying a person is biometric data the moment it is held; the definition is broad and the wording is plain.15 Under UK GDPR, the same photograph stays ordinary until software is run across it to identify someone, becoming special-category biometric data only then. The councils hold to the second reading, and treat the card photograph as an ordinary passport snap; the Argyll and Bute school-route notice says in terms that it collects no special category data.16 Yet the scheme’s own front door already crosses the line they draw. Applying through MyAccount, the route the councils use, an applicant verifies identity with Yoti, which does so by facial recognition.17 That is a biometric face-match, run before a card exists, and the duty to account for it is the controller’s, not the applicant’s. Special-category processing at enrolment needs a lawful basis under Article 9, an assessment that weighs it, and a notice that tells the person it is happening. The scheme’s paperwork does none of the three: the recognition appears in no council privacy notice and nowhere in the assessment. That a member of the public picked the verification route discharges nothing; the duty is the controller’s, and the person is never told.
The failure is not that they weighed the risk and got it wrong. It is that they never see a face as the thing to weigh. The scheme’s privacy paperwork is careful where it chooses to look: it fixes that suppliers process the data only within the UK; it sets retention periods for disability records; it asks whether a parent should see a child’s journey history.18 It settles where the data sits and never asks which jurisdiction can compel it, nor whether the photograph is biometric at all. The recognition already running at the front door appears nowhere in it. A stored face is matchable the day it is filed, and the software that reads it is no lawyer.
The usual reassurance is that none of it matters, because the photographs only make bus passes, and any police access is “case by case”.19 We now know how often. Freedom of information responses in June 2026 confirm that police access to the cardholder photograph runs through a standing tri-party data-sharing agreement between the programme office that operates the card, Police Scotland and British Transport Police; the photograph is one of the fields it covers, the gateway is the office’s “implied powers” rather than any statute, and every disclosure is a written request signed off by an officer of inspector rank or above.20 Over three financial years the office granted about 414 of 426 requests, close to 97 per cent, and released nearly four hundred card photographs; it holds no record of any of them being run for facial recognition, identity confirmation rather than gallery matching, and the access log the scheme’s own privacy assessment promises, kept on a council SharePoint, has never been audited: asked, the council answered that no audit records are held.21 A record no one is required to check is not oversight. A last reassurance says the photographs get deleted anyway. One copy does. The online portal deletes its image within sixty days of the application being exported, two years for the Young Scot cards kept for proof-of-age audit; the Card Management System keeps the photograph for as long as you hold a card.22 Deleting the application copy clears the queue, not the gallery.
The deeper answer is that the brake has rarely been the purpose written at the outset. Once built, a capability is pushed to the limit of what it can technically do. Local authorities were handed covert surveillance powers, and one used them to watch a family for three weeks to check which school catchment they lived in; the surveillance tribunal ruled it disproportionate.23 England kept the DNA of people it never convicted until Strasbourg ordered it to stop.24 Police held more than nineteen million custody photographs, over sixteen million of them searchable by face, years after a court ruled the retention of the never-convicted unlawful.25 Number-plate cameras grew from catching stolen cars into tens of millions of reads a day, kept for a year.26 Clearview scraped twenty billion faces off the open web and sold the result to police forces.27 South Wales Police ran live facial recognition in the street until the Court of Appeal ruled its use unlawful.28 The pattern reaches civilian photo databases most directly of all: the passport and driving-licence collections were built to issue documents, and police now search them by face, which is the objection the Commissioner himself raises. Where a limit was set at all, a court or a statute set it, not the purpose written at the outset, and only after the capability had been defended to the last, with the public’s own money. The times it stopped are the times something with teeth was standing in the way.
The demand for faces is not hypothetical. Thirteen police forces in England and Wales now use live facial recognition; the Metropolitan Police scanned more than 1.7 million faces in the first four months of 2026 alone.29 Live systems match against a watchlist, and no one loads millions of bus-pass photos into one. The exposure runs the other way. A standing database of faces is what retrospective search reaches for: one image run against the whole gallery after the fact, which is exactly the bulk-searching of passport and licence photos the Commissioner already warns against. Scotland has deployed none of the live kind, which is the opening, not the all-clear: it could be the first UK nation to govern the technology by primary legislation before it arrives rather than after. But the council database of Scottish faces already exists, and nothing with teeth stands between those faces and whatever use is found for them next. The Information Commissioner is no answer here: a UK-wide generalist, reactive by design, holding the very doctrine that a photograph is not biometric until software is run across it, under no duty to audit this holding and, by and large, waiting for a complaint before it acts. The point is not that a child’s bus-pass photo is being matched against a watchlist today. The point is that no one can tell you it is not, because no one is required to look, and the one body built to look was sent to the wrong room.
The comparison people reach for is the wrong one. The Commissioner’s reviews estimate more than three million images in Police Scotland’s systems, reviewed, audited and reported to Parliament, and record that the true total is unknown even there.30 Those are images, not individuals: repeat shots of a far smaller population, on the order of 380,000 people on the criminal history system. The National Entitlement Card is close to one face per holder, across roughly two million people on the scheme’s own 2020 count.31 Set the police number against a curated criminal-history gallery under active specialist review, and set two million council faces against no specialist review at all. If even the watched holding cannot state its own total, that is the measure of what unwatched looks like everywhere else. And those two million faces are watched by no one with the word biometric in their job title.
None of this is an argument against the card, or against a single key to public services. A small country gains from not making its people prove who they are from scratch at every counter. The argument is against holding millions of facial photographs with no acknowledgement that they are biometric, no limit that names them as such and no one required to check the general limits hold, no independent audit, no specialist regulator with the power to compel change, and no answer to the person whose face it is beyond one that is priced: you may have the record deleted, but only by surrendering the card, and with it the bus pass, the proof of age, the cashless lunch. A capability at this scale has to be acknowledged, constrained, audited, governed, and answerable. This one is none of the five. Move the perimeter; do not empty the vault.
The public is already standing on this ground. People back the targeted use of facial recognition, the search for someone who has committed a crime, and pull back sharply from the blanket kind, the tracking of the population at large; in the three countries surveyed a majority said they did not trust government to use the technology responsibly.32 Govern it and the licence follows; leave it ungoverned and it was never given.
There is a floor for all of this, and it governs use, not storage. Since February 2025 the European Union’s AI Act has banned the untargeted scraping of faces to build recognition databases, and the real-time biometric identification of the public by police outside narrow, authorised cases; the binding obligations for high-risk biometric systems follow, after a deferral adopted by the Parliament and Council in June 2026, in December 2027.33 What Scotland lacks is not a rule about the database sitting still, but any rule about the moment it is used: the Code binds only the police, confers no power to prohibit, and triggers no legal action of its own when breached, which is why the Commissioner is reduced to asking for a law.
The floor is one Scotland says it wants: since 2021 its ministers have held a power, renewable but currently due to lapse in March 2027 unless extended, to keep devolved law in step with the EU’s.34 Meeting the five tests at home would reach the parts of that floor that fall to devolved hands, the governance of Scotland’s own public bodies, with no one aiming for Brussels at all. Scotland cannot adopt the AI Act: data protection, and most of the levers around it, are reserved to Westminster.35 But it can place duties on those bodies over how they use what they hold, the same devolved footing on which it already governs the police. That is alignment by good governance.
Different jurisdictions have chosen different tools, but they share a common principle: population-scale biometric data is governed, audited and answerable, and named in law for what it is. It is established international practice, and Scotland has joined it for the police but not for its civilian holdings. New Zealand looked at the same problem and, in 2025, issued an enforceable code for biometric processing that covers civilian use, under privacy law it already had, with no new statute and no new regulator.36 Australia went further. Having rejected an ungoverned national identity card in the 1980s on civil-liberties grounds, it came back and built the governed version: a voluntary digital identity, independently accredited, regulated by two separate watchdogs, with binding limits on what may be collected and a public register of who is trusted to hold it.37 Estonia, whose entire state runs on a national identity, gives every citizen a log of who has looked at their records.38 Illinois answers a narrower question, but answers it to the person: once a face is scanned into biometric form, the holder is liable to the individual directly, with a right to sue and damages that do not turn on proving harm.39
England and Wales are the cautionary tale. They have no statutory code for civilian biometrics at all, and the government that brought reform forward in 2023 proposed to abolish even the police biometrics watchdog; an independent report warned the change would leave “significant gaps” in oversight.40 Scotland is rightly proud of being the exception. The exception stops at the police-station door, and the faces on the other side of it have less protection in Scotland than a police-held fingerprint does. Run recognition across them and, in Wellington or Tallinn, an enforceable regime answers at once; in Scotland nothing specialist answers at all.
The Act already lets Scottish Ministers add bodies to the Commissioner’s remit by regulation, and a statutory review of his functions is live as this is written, weighing exactly that.4142 But section 2(7) moves the bodies, not the purpose: the remit it extends still reaches only biometric data held for criminal justice and police purposes. Add the councils tomorrow and the bus-pass photographs still escape, because they are held for travel and proof of age, not for policing. The Independent Advisory Group that designed the post drew that line in 2018, confining its recommendation to policing; the review now debates extending it to more criminal-justice bodies, the prison service among them.43 The largest holding of the lot, the council database of Scottish faces, is not in the room.
Reaching it needs the other way in: primary legislation, widening the purpose the Commissioner is allowed to watch, and giving the office the powers and the budget the current Code lacks. Widen the remit of a four-person office that cannot prohibit anything, and you move the boundary while changing nothing behind it. That legislation is the same kind of vehicle the Commissioner is already demanding for live facial recognition, and Parliament will have a biometrics bill open in any case; his ask and this one could ride it together. It need not be the policing Code. New Zealand shows a lighter instrument can carry the weight, a code issued by the existing privacy regulator under existing law. Scotland cannot simply copy that route: data protection is reserved, so its generalist regulator is not Scotland’s to direct, and the one that does hold the remit has sat on the photograph-is-not-biometric doctrine for years without acting. The devolved move is to legislate for its own bodies. Do that, and that part of the European floor arrives as a side effect, for the price of governing your own house.
What that bill has to say is not mysterious, and it tracks the five tests. Name an identifying facial photograph held at population scale as biometric data in statute, so a holding cannot be called ordinary to slip the definition. Fix the purposes it may be put to and bar the rest, so a database gathered for travel and proof of age cannot quietly become a search index. Put a positive duty to audit on a named office, with power to compel disclosure and to open the access logs the scheme already keeps and never checks. And give the person whose face it is a way to answer back: to know the holding exists, to see who has reached into it, and to object without surrendering the card and every service that rides on it. Acknowledged, constrained, audited, governed, answerable, written down as duties rather than named as virtues.
Scotland built the regulator the rest of the UK keeps wishing it had, and aimed it at the one part of the problem already under the brightest light. The unwatched faces are not the ones in police custody, which are watched, reviewed and reported to Parliament. They are the millions of faces in a council database, gathered for a bus pass, lifted in childhood from a school camera, called ordinary by the people who hold them, and watched, in any specialist sense, by no one at all.
airt.scot · July 2026. Free to use, in whole or chopped into little pieces, provided the source is acknowledged. (CC BY 4.0)
Police Scotland and the Scottish Police Authority ran a public “national conversation” on live facial recognition in 2025 (public survey, consult.scotland.police.uk); in August 2025 the force confirmed it would continue to pursue the technology, with a business case not expected before the SPA until 2027. https://www.biometricupdate.com/202602/police-scotland-plans-lfr-business-case-consultation-on-the-way-to-a-decision-spa ↩︎
Scottish Biometrics Commissioner, correspondence with Scottish ministers and the Criminal Justice Committee, 2025-2026, urging primary legislation before any LFR deployment. https://www.biometricupdate.com/202606/scottish-biometrics-commissioner-calls-for-lfr-law-before-police-deployment ↩︎
Scottish Biometrics Commissioner Act 2020 (asp 8), s.2(1). https://www.legislation.gov.uk/asp/2020/8 ↩︎
ibid., s.9(1). A breach of the Code gives rise to no legal action in itself (s.9(3)); the Commissioner may issue a compliance notice (s.23), enforceable on application to the Court of Session (s.27), but cannot himself prohibit a technology, only recommend against it. ↩︎
Scottish Biometrics Commissioner, letter to the Convener of the Criminal Justice Committee, 16 March 2026, urging primary legislation before any LFR deployment (the remit covering only those three bodies is the effect of s.2(1) of the Act); and his December 2025 blueprint to the Home Office warning of a “Biometric Wild West” and against the “bulk washing” of passport and driving-licence images against retrospective facial recognition for low-level or volume crime. https://www.biometricscommissioner.scot/media/lzge5aen/letter-to-convenor-criminal-justice-committee-march-2026.pdf ; https://www.biometricupdate.com/202601/scottish-biometrics-commissioner-lays-out-blueprint-for-regulating-police-use-of-biometrics ↩︎
Scottish Biometrics Commissioner, Strategic Plan 2025-29 (four full-time staff; annual budget around £564,000 to £630,000; “no significant expansion”). https://www.biometricscommissioner.scot/publications/ ↩︎
The Ferret, “Biometrics watchdog will lack powers, say critics,” 23 July 2018. Liam McArthur MSP argued the remit should reach “biometrics wherever they are found, be it in education, health or retail”; Open Rights Group Scotland pressed the same widening of scope in its own terms. https://www.theferret.scot/scottish-biometrics-commissioner-enforcement-powers/ ↩︎
Scottish Government, freedom of information response 202300344043 (received 19 February 2023, responded 17 March 2023): a section 17(1) notice that it holds no information on plans for facial recognition in schools (“a matter for local authorities”) or across public services. The same response confirms that the digital identity service uses facial recognition, and that the MyAccount route used for National Entitlement Card applications offers facial recognition (Yoti) for identity verification (MyAccount users “have the option to use” Yoti). https://www.gov.scot/publications/facial-recognition-within-school-and-public-services-foi-release/ ↩︎
Transport Scotland, freedom of information response 202600516361 (8 June 2026): 2,973,029 active National Entitlement Cards, given as the current total (the response states no earlier snapshot date). A copy of the response is held by the author and available on request. ↩︎
Argyll and Bute Council, “National Entitlement Cards: Privacy Statement” (school photograph taken from the SEEMiS system; Card Management System retention “until you advise us you no longer require your card”; “we will only collect personal data about you which does not include any special categories”). The cardholder extract used to verify identity across public services includes the photograph: getyournec.scot Privacy Notice v5 (13 March 2023). https://www.argyll-bute.gov.uk/education-and-learning/national-entitlement-cards-privacy-statement ; https://getyournec.scot/Privacy_Notice_v5.pdf ↩︎
Argyll and Bute privacy statement, as cited above. ↩︎
getyournec.scot Privacy Notice v5, as cited above. ↩︎
National Entitlement Card Scheme, Data Protection Impact Assessment v2.1 (July 2020); and NEC Scheme Changes Data Protection Impact Assessment (November 2021), covering new supplier contracts and the under-22 free-travel scheme. https://www.nec.scot/sites/default/files/2021-11/NEC%20Data%20Protection%20Impact%20Assessment.pdf ; https://www.nec.scot/sites/default/files/2023-03/DPIA_202111signoffs.pdf ↩︎
Scottish Government, freedom of information response 202500470823 (2 July 2025), addressing the under-22 free-travel entitlement carried on the National Entitlement Card: data governance rests on standard data-protection compliance (a data protection officer, annual audits, Audit Scotland), with no biometric-specialist oversight body in the chain. The same controllers and card systems serve the wider scheme, and no specialist regulator reaches any civilian layer of it. https://www.gov.scot/publications/foi-202500470823/ ↩︎
Scottish Biometrics Commissioner Act 2020, s.34 (definition of biometric data). Contrast UK GDPR, Article 4(14) and Recital 51: a photograph counts as biometric data only when processed by specific technical means for the purpose of uniquely identifying a person. https://www.legislation.gov.uk/asp/2020/8 ; https://www.legislation.gov.uk/eur/2016/679/article/4 ↩︎
Argyll and Bute Council, “National Entitlement Cards: Privacy Statement”, as cited above (“we will only collect personal data … which does not include any special categories”). ↩︎
Scottish Government, FOI response 202300344043, as cited above: the digital identity service uses facial recognition, and MyAccount applicants for a National Entitlement Card “have the option to use Yoti … Yoti uses facial recognition for identity verification.” ↩︎
NEC Scheme Changes DPIA (November 2021), as cited above: the new-contract suppliers “committed to process only within the UK”; the assessment also revises retention for special-category (disability) data and weighs parent or guardian approval and access to a child’s journey history. Neither it nor the v2.1 assessment (July 2020) treats the photograph as biometric data or addresses the facial recognition used at enrolment. ↩︎
National Entitlement Card Scheme, DPIA v2.1 (July 2020), as cited above: police access “takes place on a case by case basis, and each request received from the police is logged”, with police services “not given system access … at any time”. ↩︎
Data Sharing Agreement between the National Entitlement Card Programme Office (Dundee City Council, for all Scottish local authorities), Police Scotland and British Transport Police, version 2.0 (2024), marked OFFICIAL, disclosed under freedom of information response 20260610013. Clause 4.1(a) lists the shareable card fields, including (vii) the photograph. Clause 6.1 states that the programme office relies on “implied powers” to share, citing no express statutory gateway. Clause 5.1 requires a written request signed by an officer of inspector rank or above. Clause 3.1 confines the purposes to serious crime and the protection of vital interests. A copy is held by the author and available on request. ↩︎
Dundee City Council, freedom of information response 20260610013 (30 June 2026). Dundee City Council operates as the National Entitlement Card Programme Office for all 32 Scottish local authorities; requests from Police Scotland and British Transport Police for cardholder data, including the photograph, are governed by a tri-party data-sharing agreement (see below), and each is a written request authorised by an officer of inspector rank or above and assessed manually (“approval is not automated … not determined by a software workflow”). Across 2023/24 to 2025/26, 426 requests were received and 414 granted (about 97 per cent), with 395 photographs provided. The programme office “holds no records of any facial photograph being disclosed for the purposes of facial recognition or automated facial comparison”. Records of requests are held on the council’s SharePoint, and “no audit records are held” in relation to them. A copy of the response is held by the author and available on request. ↩︎
getyournec.scot Privacy Notice v5 (13 March 2023), “How long do we store your data.” Online application data, including the photograph, is deleted sixty days after export to NECPO for most card types, and two years for Young Scot and disabled Young Scot cards retained for PASS proof-of-age audit. This is the application-portal copy only; the Card Management System record is governed separately. https://getyournec.scot/Privacy_Notice_v5.pdf ↩︎
Ms Jenny Paton and others v Poole Borough Council, Investigatory Powers Tribunal (covert directed surveillance February 2008; determination 2010, the use held disproportionate). Local authorities held these powers under RIPA Part II; the Protection of Freedoms Act 2012 later required magistrates’ approval for their use. https://investigatorypowerstribunal.org.uk/judgement/ms-jenny-paton-and-others-vs-poole-borough-council/ ↩︎
S and Marper v United Kingdom (2008) 48 EHRR 50, Application nos 30562/04 and 30566/04, Grand Chamber, 4 December 2008. https://www.bailii.org/eu/cases/ECHR/2008/1581.html ↩︎
R (RMC and FJ) v Commissioner of Police of the Metropolis [2012] EWHC 1681 (Admin); Home Office, Review of the Use and Retention of Custody Images (February 2017). Over 19 million custody images were held on the Police National Database, over 16 million searchable by facial recognition, as at July 2016. https://www.judiciary.uk/wp-content/uploads/JCO/Documents/Judgments/r-rmc-fj-metropolitan-police-commissioner-22062012.pdf ; https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/594463/2017-02-23_Custody_Image_Review.pdf ↩︎
Police.uk reports around 60 million ANPR reads per day with one-year retention; the National ANPR Service Data Protection Impact Assessment v4 (January 2025) cites volumes that can exceed 90 million per day. https://www.police.uk/advice/advice-and-information/rs/road-safety/automatic-number-plate-recognition-anpr/ ↩︎
Information Commissioner’s Office enforcement against Clearview AI (£7.5m penalty, May 2022). A tribunal overturned it on jurisdiction in 2023; the Upper Tribunal restored the Commissioner’s jurisdiction in October 2025 ([2025] UKUT 319 (AAC)), with permission to appeal to the Court of Appeal granted in December 2025. https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/10/uk-upper-tribunal-hands-down-judgment-on-clearview-ai-inc/ ↩︎
R (Bridges) v Chief Constable of South Wales Police [2020] EWCA Civ 1058, 11 August 2020 (South Wales Police’s deployment held unlawful on the framework then in force). https://www.bailii.org/ew/cases/EWCA/Civ/2020/1058.html ↩︎
Of thirteen forces in England and Wales using live facial recognition, the Metropolitan Police scanned more than 1.7 million faces in the first four months of 2026, an increase of about 87% on the same period in 2025; the force’s own figures are due in its annual live facial recognition report, expected around October 2026. https://statewatch.org/news/2026/june/england-police-use-of-facial-recognition-technology-growing-rapidly/ ; https://www.biometricupdate.com/202605/will-scotland-be-the-first-nation-to-pass-primary-legislation-covering-live-frt ↩︎
Scottish Biometrics Commissioner, assurance review SBC/2024/01 (2024), laid before Parliament, estimating Police Scotland held more than three million images across its criminal-history and related systems, noting the true total is unknown, and recording 646,935 images relating to 382,052 people on the Criminal History System. https://www.biometricscommissioner.scot/media/vcfnimt0/sbc-assurance-review-on-images.pdf ↩︎
National Entitlement Card Scheme DPIA v2.1 (July 2020), as cited above: approximately two million individuals hold National Entitlement Card data (a 2020 estimate). ↩︎
Ritchie et al., “Public attitudes towards the use of automatic facial recognition technology in criminal justice systems around the world,” PLoS ONE (2021), https://doi.org/10.1371/journal.pone.0258241. Of 3,124 respondents in the UK, Australia and the USA, about 89% supported police searches for a person who had committed a crime and about 25% supported tracking citizens; across all three countries a majority did not trust government to use the technology responsibly. The recommendation is to set legal boundaries around the use of the technology, not to ban it. ↩︎
Regulation (EU) 2024/1689 (Artificial Intelligence Act), Article 5 prohibitions in force from 2 February 2025. Obligations for the Annex III high-risk category, which includes biometric systems, fell under the Regulation’s general application date of 2 August 2026 (Art 113); the EU ‘digital omnibus’ simplification package, adopted by the Parliament (16 June 2026) and Council (29 June 2026), deferred those obligations to 2 December 2027. https://artificialintelligenceact.eu/article/5/ ; https://www.biometricupdate.com/202605/eu-pushes-ai-act-deadlines-for-high-risk-systems-including-biometrics ↩︎
UK Withdrawal from the European Union (Continuity) (Scotland) Act 2021 (asp 4), s.1 (the “keeping pace” power). The power is time-limited by s.4(1) and, absent an extension under s.4(2), lapses at the end of 28 March 2027. https://www.legislation.gov.uk/asp/2021/4 ↩︎
Scotland Act 1998, Schedule 5, Part II, reservation B2 (data protection). Artificial intelligence is not expressly reserved, but the levers to regulate it, including data protection, consumer protection and product safety, largely are. https://www.legislation.gov.uk/ukpga/1998/46/schedule/5 ↩︎
New Zealand Office of the Privacy Commissioner, Biometric Processing Privacy Code 2025 (in force 3 November 2025), issued under the Privacy Act 2020. https://www.privacy.org.nz/privacy-principles/codes-of-practice/biometric-processing-privacy-code/ ↩︎
Digital ID Act 2024 (Australia), in force 30 November 2024 (voluntary; accredited; regulated by the Digital ID Regulator, the role performed by the Australian Competition and Consumer Commission, and the Office of the Australian Information Commissioner); and the defeat of the “Australia Card” national identity proposal in 1987. https://www.legislation.gov.au/C2024A00025/latest/text ↩︎
Estonia operates a national digital identity under the Identity Documents Act; through the state portal (eesti.ee), any eID holder can log in to review who has accessed their personal data and for what purpose, via the state “data tracker” run by the Information System Authority. https://e-estonia.com/data-tracker-build-citizen-trust/ ↩︎
Illinois Biometric Information Privacy Act 2008 (740 ILCS 14), giving individuals a private right of action and statutory damages without proof of harm (Rosenbach v Six Flags Entertainment Corp, 2019 IL 123186). https://www.aclu-il.org/campaigns-initiatives/biometric-information-privacy-act-bipa/ ↩︎
In England and Wales there is no statutory code for civilian biometric holdings; the Data Protection and Digital Information Bill (2023) proposed to abolish the police Biometrics and Surveillance Camera Commissioner, which an independent report (whose co-author, William Webster, took office as the new Commissioner in November 2025) warned would create “significant gaps” in oversight. The Bill fell with the 2024 general election. Its successor, the Data (Use and Access) Act 2025, kept the Commissioner and the surveillance-camera code rather than abolishing them, but enacted no statutory code for civilian biometrics; the civilian gap the earlier bill described remains. https://assets.publishing.service.gov.uk/media/653f7128e6c968000daa9cae/Changes_to_the_functions_of_the_BSCC.pdf ↩︎
Scottish Biometrics Commissioner Act 2020, s.2(7): the bodies subject to the Code may be added to by regulations made by the Scottish Ministers. The power has not been exercised. SBC Annual Report and Accounts 2023/24. https://www.biometricscommissioner.scot/publications/ ↩︎
Scottish Government, Review of the Functions of the Scottish Biometrics Commissioner (consultation paper, ISBN 9781806437603), the post-legislative review under section 6 of the 2020 Act; responses under consideration, 2026. https://www.gov.scot/isbn/9781806437603 ↩︎
Independent Advisory Group on the Use of Biometric Data in Scotland (2018), which recommended a commissioner for policing and criminal justice and noted that oversight ‘in other areas of Government where they feature, for example, health and education, and the private sector’ would be ‘beyond our Terms of Reference’. https://www.gov.scot/publications/report-independent-advisory-group-use-biometric-data-scotland/ ↩︎