airt. Independent policy analysis
Cover of The Face on the Bus Pass

The Face on the Bus Pass

10 July 2026
Download PDF

The National Entitlement Card is Scotland’s bus pass. It is also the largest collection of faces any Scottish public body holds that no biometric regulator watches, and the one office built for the job cannot touch it.

Scotland has something no other part of the UK has: a biometrics regulator whose statutory remit reaches the face. The man who holds the post is asking Parliament for a law that does not yet exist. Police Scotland is pressing ahead toward live facial recognition. It put the question to a public “national conversation” in 2025, resolved to keep going, with a business case not expected before its oversight board until 2027 at the earliest.1 The Scottish Biometrics Commissioner has written to ministers to say the technology should not go anywhere near a Scottish street until primary legislation governs it.2 The regulator is telling you, on the record, that he cannot stop the thing he exists to watch.

What he can watch is narrow, and narrow by design. The Scottish Biometrics Commissioner Act 2020 gives him oversight of biometric data held for criminal justice and police purposes by three bodies: Police Scotland, the Scottish Police Authority, and the Police Investigations and Review Commissioner.3 The Code he enforces binds those three and no one else.4 The Commissioner says as much himself, warning of a “Biometric Wild West” in the spaces the law does not reach, objecting elsewhere in the same submission to police bulk-searching the passport and driving-licence databases for low-level crime.5 A handful of staff, a budget under £700,000, an office built on the stated assumption of no significant expansion.6 It watches one room.

Before the Act was passed, Open Rights Group Scotland and a sitting MSP argued that the Commissioner’s reach should run to biometrics wherever they are found, in education, in health, in retail. The point was made in 2018, and dropped; the private-sector half of it was arguably never Holyrood’s to grant, the public-sector half was, and both went down together.7 What replaced it is an oversight body for the police, and silence everywhere else. Asked in 2023 whether there were plans to use facial recognition in Scotland’s schools or its public services, the Scottish Government replied that it did not hold the information: school facial recognition, it said, is a matter for local authorities; for the rest, contact the bodies directly.8

That silence is where the largest of these holdings sits, and no one with biometric expertise is watching it. The National Entitlement Card is the bus pass, the young person’s card, the proof of age, the cashless school lunch, the key to a hundred council services. As of June 2026 there are 2,973,029 active cards.9 Every card issued from secondary-school age up carries a photograph. For a child carded through school, the photograph need not be taken for the card at all: one council’s privacy notice describes lifting it from the school’s own records, the SEEMiS system, and reusing it.10 From age eleven a pupil’s school photo becomes a record in the Card Management System, kept, in that notice’s words, “until you advise us you no longer require your card.”11 Indefinitely, then. Thirty-two councils are joint controllers, the Improvement Service processes the applications through the national portal, the programme office sits inside Dundee City Council, and the photograph travels onward into the extract that proves identity across the country’s other public services.12

The scheme’s core privacy assessment dates from July 2020; a supplementary assessment in November 2021 covered new supplier contracts and the under-22 travel scheme, and neither revisits the photograph or the police-sharing arrangements.13 Its oversight, the government confirms, is ordinary data-protection housekeeping: a data protection officer, an annual audit, the auditors of public spending. Nothing biometric, and no specialist regulator anywhere in the chain.14

The law gives two answers to one question: is this photograph biometric data? Under the 2020 Act, a facial photograph capable of identifying a person is biometric data the moment it is held; the definition is broad and the wording is plain.15 Under UK GDPR, the same photograph stays ordinary until software is run across it to identify someone, becoming special-category biometric data only then. The councils hold to the second reading, and treat the card photograph as an ordinary passport snap; the Argyll and Bute school-route notice says in terms that it collects no special category data.16 The scheme’s own assessment, listing the reasons a DPIA was required at all, gives first that the scheme “processes special category data on a large scale”.17

The scheme’s own front door already crosses the line they draw. Applying through MyAccount, the route the councils use, an applicant can choose to verify identity with Yoti, which does so by facial recognition.18 That is a biometric face-match, run before a card exists, and the duty to account for it is the controller’s, not the applicant’s. Special-category processing at enrolment needs a lawful basis under Article 9, an assessment that weighs it, and a notice that tells the person it is happening. Only the third is done. The application service’s own notice describes the biometric face match, and names an Article 9 condition exactly once in twenty-five pages, for the documents a disabled-card applicant submits as proof. It names none for the face. The scheme’s assessment does not weigh the match either, and the council privacy statement quoted earlier, which says it collects no special-category data at all, says nothing about it.1920 That a member of the public picked the verification route discharges nothing; the duty is the controller’s. Ending it needs no new statute. Enforcement of Article 9 belongs to the reserved regulator, which by and large waits to be asked, but the ministers and councils that run the scheme control the enrolment design, the notices and the assessment today, and could account for the match tomorrow.

The failure is not that they weighed the risk and got it wrong. It is that they never see a face as the thing to weigh. The scheme’s privacy paperwork is careful where it chooses to look: it fixes that suppliers process the data only within the UK; it moves to set retention periods for disability records; it asks whether a parent should see a child’s journey history.21 It settles where the data sits and never asks which jurisdiction can compel it, nor whether the photograph is biometric at all. The recognition already running at the front door appears nowhere in it. A stored face is matchable the day it is filed, and the software that reads it is no lawyer.

The usual reassurance is that none of it matters, because the photographs only make bus passes, and any police access is “case by case”.22 We now know how often. Freedom of information responses in June 2026 confirm that police access to the cardholder photograph runs through a standing tri-party data-sharing agreement between the programme office that operates the card, Police Scotland and British Transport Police; the photograph is one of the fields it covers, the gateway is the office’s “implied powers” rather than any statute, and every disclosure is a written request signed off by an officer of inspector rank or above.23 Over three financial years the office granted 414 of 426 requests, close to 97 per cent, and released nearly four hundred card photographs; it holds no record of any of them being run for facial recognition, and the access log the scheme’s own privacy assessment promises, kept on a council SharePoint, has never been audited: asked, the council answered that no audit records are held.24 A record no one is required to check is not oversight.

A last reassurance says the photographs get deleted anyway. One copy does. The online portal deletes its image within sixty days of the application being exported, two years for the Young Scot cards kept for proof-of-age audit; the Card Management System keeps the photograph for as long as you hold a card.25 Deleting the application copy clears the queue, not the gallery.

Ask each keeper of the boundary in turn, and every answer is a nil return. The Scottish Biometrics Commissioner confirms on his own record that he has never been consulted about expanding the card, prepares no guidance on multi-purpose identity cards because they are not policing, and is “not involved in the NEC scheme” at all.26 Police Scotland states that it does not use facial matching on photographs held under the scheme, and has made no requests for them for that purpose; the same response denies holding any agreement with a council, the Improvement Service or the programme office for access to the photographs at all, and six days later the programme office disclosed the standing agreement that names the force as a party.27 And the Improvement Service, the body that operates the card and the address to which every deflection points, sits outside freedom of information law altogether: fourteen years on the government’s candidate list, and by its own mid-2025 workplan the research had yet to commence.28 Individually, each answer reassures. Read together, they are the finding: no consultation, no guidance, no matching on anyone’s record, and an operator outside freedom of information. The absence is symmetrical across the regulator, the police and the statute book, and a boundary no one can inspect from any side is not a boundary. It is a hope.

The brake has rarely been the purpose written at the outset. Once built, a capability is pushed to the limit of what it can technically do. Local authorities were handed covert surveillance powers, and one used them to watch a family for three weeks to check which school catchment they lived in; the surveillance tribunal ruled it disproportionate.29 England and Wales kept the DNA of people they never convicted until Strasbourg held it a breach of private life.30 Police held more than nineteen million custody photographs, over sixteen million of them searchable by face, years after a court ruled the retention of the never-convicted unlawful.31 Number-plate cameras grew from catching stolen cars into tens of millions of reads a day, kept for a year.32 Clearview scraped over twenty billion images off the open web and sold access to police and security agencies abroad.33 South Wales Police ran live facial recognition in the street until the Court of Appeal held its use was not in accordance with the law. They paused for three years, then resumed in 2023 once an independent study answered the equality-duty ground: nothing in the judgment, the force said, fundamentally undermined the use of the technology.34 The pattern reaches civilian photo databases most directly of all: the passport and driving-licence collections were built to issue documents, and police now search them by face, which is the objection the Commissioner himself raises. Where a limit was set at all, a court or a statute set it, not the purpose written at the outset, and only after the capability had been defended to the last, with the public’s own money. The times it stopped are the times something with teeth was standing in the way, and the record grades the teeth: a ruling ignored for years, a judgment that held for three, a deletion that came only when Parliament legislated.

At least twelve police forces in England and Wales now use live facial recognition; the Metropolitan Police scanned more than 1.7 million faces in the first four months of 2026 alone.35 And the demand has reached Scotland’s own inspectorate: in August 2026 the Chief Inspector of Constabulary called for facial recognition to be explored for keeping banned fans out of football grounds, framing the question as not whether to adopt the technology but how fast.36 Live systems match against a watchlist, and no one loads millions of bus-pass photos into one. The exposure runs the other way. A standing database of faces is what retrospective search reaches for: one image run against the whole gallery after the fact, which is exactly the bulk-searching of passport and licence photos the Commissioner already warns against. Scotland has deployed none of the live kind, which is the opening, not the all-clear: it could be the first UK nation to govern the technology by primary legislation before it arrives rather than after.

Scotland has done the equivalent once. When Strasbourg struck down the English DNA regime, it used the Scottish statute as the measure: samples from the unconvicted kept only for adults charged with violent or sexual offences, for three years, extendable only by a sheriff. The Court called that position “of particular significance”, and named England, Wales and Northern Ireland as the only jurisdictions in the Council of Europe permitting indefinite retention of anyone suspected of anything. The same judgment attaches a duty to going first: “any State claiming a pioneer role in the development of new technologies bears special responsibility for striking the right balance in this regard.”37 Holyrood wrote the narrower rule; Strasbourg used it to condemn the wider one.

The gallery would search badly, the fallback runs: a school photograph taken at eleven, aged out of likeness, lit however the assembly hall was lit. Grant it. A holding is not governed by its own poor quality. Every renewal swaps an old face for a current one, so the gallery improves by ordinary administration, and nobody is required to notice when a collection too ragged to search becomes one that searches cleanly. Incapacity decays. A limit has to be written down.

But the council database of Scottish faces already exists, and nothing with teeth stands between those faces and the decision to hand them over. The Commissioner’s writ starts only once police acquire; the gallery, and the choice to disclose from it, answer to no one. He watches the destination; no one watches the tap. Acquisition for policing is inside the remit, so of the two ends of a transfer, only the Police Scotland end is governed: the gallery escapes because it is held for the wrong purpose, the disclosure decision escapes because a council is not one of the three bodies, British Transport Police, the sharing agreement’s other force, is not one of the three either, and a 97 per cent grant rate is a fact about the discloser, whom nobody oversees. The fix has to stand at the tap: govern the discloser, and every requester is covered at source.

The Information Commissioner is no answer here: a UK-wide generalist, reactive by design, holding the very doctrine that a photograph is not biometric until software is run across it, under no duty to audit this holding and, by and large, waiting for a complaint before it acts.

The reasoning is older than the Commissioner. In 1995 the Strasbourg Commission held that retaining photographs taken at a public demonstration did not touch private life, because they “had not been entered in a data-processing system” and the authorities “had taken no steps to identify the persons photographed by means of data processing”.38 The card gallery is a data-processing system whose purpose is identifying people. Neither thing the Commission relied on is true of it.

The point is not that a child’s bus-pass photo is being matched against a watchlist today. The point is that no one can tell you it is not, because no one is required to look, and the one body built to look was sent to the wrong room.

The comparison is with Police Scotland’s own holdings. The Commissioner’s own assurance review estimates more than three million images in Police Scotland’s systems, reviewed, audited and reported to Parliament, and record that the true total is unknown even there.39 Those are images, not individuals: repeat shots of a far smaller population, on the order of 380,000 people on the criminal history system. The National Entitlement Card is close to one face per holder, across roughly two million people on the scheme’s own 2020 count.40 Set the police number against a curated criminal-history gallery under active specialist review, and set two million council faces against no specialist review at all. And those two million faces are watched by no one with the word biometric in their job title.

The other objection asks why the bus pass, when the passport and driving-licence galleries are larger and hold the faces of most adults in the country. Because those galleries are reserved: Holyrood cannot legislate for them, which is why the Commissioner is reduced to writing to the Home Office about their bulk searching, though the Scottish end of that practice, Police Scotland’s own requests, already sits inside his Code’s reach.41 The National Entitlement Card is the population-scale civilian holding Scotland can govern. The settlement answers the question: the card is the one gallery whose keys are in Edinburgh.

None of this is an argument against the card, or against a single key to public services. A small country gains from not making its people prove who they are from scratch at every counter. The argument is against holding millions of facial photographs with no acknowledgement that they are biometric, no limit that names them as such and no one required to check the general limits hold, no audit that has ever opened the access log, no specialist regulator with the power to compel change, and no answer to the person whose face it is beyond one that is priced: you may have the record deleted, but only by surrendering the card, and with it the bus pass, the proof of age, the cashless lunch. A capability at this scale has to be acknowledged, constrained, audited, watched, and answerable. Move the perimeter; do not empty the vault.

In a survey run across the UK, Australia and the United States over the turn of 2019 into 2020, people backed the targeted use of facial recognition, the search for someone who has committed a crime, and pulled back sharply from the blanket kind, the tracking of the population at large; in all three countries a majority said they did not trust government to use the technology responsibly.42 Govern it and the licence follows; leave it ungoverned and it was never given.

There is a floor for all of this, and it governs use, not storage. Since February 2025 the European Union’s AI Act has banned the untargeted scraping of faces to build recognition databases, and the real-time biometric identification of the public by police outside narrow, authorised cases; the binding obligations for high-risk biometric systems follow, after a deferral adopted by the Parliament and Council in June 2026, in December 2027.43 What Scotland lacks is not a rule about the database sitting still, but any rule about the moment it is used: the Code binds only the police, confers no power to prohibit, and triggers no legal action of its own when breached, which is why the Commissioner is reduced to asking for a law.

The floor is one Scotland says it wants: since 2021 its ministers have held a power, renewable but currently due to lapse in March 2027 unless extended, to keep devolved law in step with the EU’s.44 Meeting the five tests at home would reach the parts of that floor that fall to devolved hands, the governance of Scotland’s own public bodies, with no one aiming for Brussels at all. Scotland cannot adopt the AI Act: data protection, and most of the levers around it, are reserved to Westminster.45 But it can place duties on those bodies over how they use what they hold, the same devolved footing on which it already governs the police. That is alignment by good governance.

Different jurisdictions have chosen different tools, but they share a common principle: population-scale biometric data is governed, audited and answerable, and named in law for what it is. It is established international practice, and Scotland has joined it for the police but not for its civilian holdings. New Zealand looked at the nearest problem and, in 2025, issued an enforceable code for biometric processing that covers civilian use, under privacy law it already had, with no new statute and no new regulator. Its trigger is purpose: a face held for matching is biometric information before any software runs, an ordinary photograph is not, and once covered the code’s rules follow the information into storage.46 Australia went further. Having rejected an ungoverned national identity card in the 1980s on civil-liberties grounds, it came back and built the governed version: a voluntary digital identity, independently accredited, regulated by two separate watchdogs, with binding limits on what may be collected and a public register of who is trusted to hold it.47 Estonia, whose entire state runs on a national identity, gives citizens a log of who has looked at their records; it covers 15 of more than 300 state systems so far, and the justice ministry is legislating to make it mandatory for nearly all of them, which is its own verdict on partial coverage.48 Illinois answers a narrower question, but answers it to the person: once a face is scanned into biometric form, the holder is liable to the individual directly, with a right to sue and damages that do not turn on proving harm.49 Nearly every regime, the newest included, bites when software runs, and Illinois writes photographs out of its very definition of a biometric identifier. The stored holding is the blind spot everywhere, not a Scottish oversight. That is what makes the Scottish position unusual in the other direction: the 2020 Act already defines an identifying photograph as biometric the day it is filed. Scotland is not behind the world on this question. It is one short statute away from being ahead of it.

England and Wales are the cautionary tale. They have no statutory code for civilian biometrics at all, and the government that brought reform forward in 2023 proposed to abolish even the police biometrics watchdog; an independent report warned the change would leave “significant gaps” in oversight.50 Scotland is proud of being the exception. The exception stops at the police-station door, and the faces on the other side of it have less protection in Scotland than a police-held fingerprint does. Run recognition across them and, in Wellington or Tallinn, an enforceable regime answers at once; in Scotland nothing specialist answers at all.

The United Kingdom has just run the experiment in public. A mandatory digital identity card, announced in 2025, drew nearly three million signatures against it, the second-largest petition on record; the new Prime Minister cancelled it within days of taking office, in July 2026, and announced that the £1.8 billion saved would go to energy bills. Read the small print and the saving is stranger than the scheme: the figure was a fiscal watchdog’s estimate for a programme with no budget line, disowned by the department’s own permanent secretary within days of publication, and never replaced.51 What did not stop is the machinery underneath: GOV.UK One Login and its wallet carried on, with a £280 million procurement naming “Digital ID” in its scope published three weeks before the cancellation and a tender expected in September.52 The card was the argument; the gallery was never on the ballot. Scotland should recognise the shape. It never announced a card at all. It issued one, nearly three million times, called it a bus pass, and the faces went in without a single petition.

The Act already lets Scottish Ministers add bodies to the Commissioner’s remit by regulation, and a statutory review of his functions is live as this is written, weighing exactly that.5354 But section 2(7) moves the bodies, not the purpose: the remit it extends still reaches only biometric data held for criminal justice and police purposes. Add the councils tomorrow and the bus-pass photographs still escape, because they are held for travel and proof of age, not for policing. The line is the statute’s, not the designers’: the Independent Advisory Group’s 2018 recommendation asked for a Commissioner keeping ‘all biometric data’ held by the police, the SPA and other public bodies under review, and the Act narrowed that to criminal justice and policing.55 The review now debates extending the remit to more criminal-justice bodies, the prison service among them.56 The response from his counterpart for England and Wales presses it to go further: to the prison service, to every body using biometrics for law enforcement and safeguarding, to the surveillance cameras councils operate. The photographs those same councils hold appear nowhere in it.57 The largest holding of the lot, the council database of Scottish faces, is not in the room.

The advisers’ case for the narrow scope: police biometrics are taken under compulsion, much of the holding from people never convicted of anything, and they are used in decisions that deprive people of liberty; a card photograph is handed over for a bus pass. Aiming the new office at the sharpest harm first is a defensible order of operations, and the Group itself did not close the wider question: it recorded that oversight elsewhere in government was beyond its terms of reference, and that consideration could be given to extending the role.58 The record since is the answer. The volunteered photograph is volunteered for travel, not for a standing tri-party sharing agreement the person is never told about; the child’s photograph is not volunteered at all, but lifted from a school system under a notice that says nothing about either; and the compulsion the advisers feared at the police station reappears at the counter, priced: surrender the card, and the bus with it, or stay in the gallery. Eight years on, the sharpest harm is governed and the largest holding is not. The order of operations was right. Stopping after step one was not.

The constitutional objection: data protection is reserved to Westminster; policing is devolved. A regulator whose remit is defined by the purpose the data serves sits on the devolved side of that line. Define the remit by the data instead, biometric wherever it is held and whatever it is held for, and the office starts to look like a data-protection regulator wearing a Scottish badge, which Holyrood cannot create. Read that way, section 2(1)’s purpose lock is not a drafting timidity but a competence boundary, and it would explain both why the Act was drawn so tight and why the live review reaches for the add-a-body power rather than the wider purpose. The answer is the one the Act itself relies on: Holyrood cannot regulate data protection, but it can place duties on its own public bodies about the conduct of their own functions, the footing the police Code already stands on. A bill written as governance of Scottish public bodies, what they must acknowledge, what they must audit, whom they must answer, is devolved housekeeping, not data-protection law. The drafting has to be done with the reservation open on the desk, and someone will test it. That is a reason to draft carefully, not a reason to leave two million faces unwatched.

Audit the log, correct the notices, rewrite the assessment, put the sharing on an express footing, and leave the architecture alone. But each of those fixes already had an owner. The impact assessment existed, and never asked whether the photograph is biometric. The access log existed, and nobody opened it. The privacy notices existed, and told no one about the sharing agreement. The agreement itself existed, and rested on implied powers. These are not lapses a better housekeeper would have caught; they are what a holding produces when no one is required to look, and a correction made under attention lasts as long as the attention. Fix all four tomorrow and the machinery that produced them stands untouched. That is why the tests say watched, and not merely fixed.

The route in is primary legislation: widening the purpose the Commissioner is allowed to watch, and giving the office the powers and the budget the current Code lacks. Widen the remit of a four-person office that cannot prohibit anything, and you move the boundary while changing nothing behind it. That legislation is the same kind of vehicle the Commissioner is already demanding for live facial recognition. The government’s answer so far is that legislating now would be premature, the police business case being two years away, which is exactly the drift the Commissioner is warning about: the moment to write the law is before the deployment is on the desk.59 When that bill comes, his ask and this one could ride it together. It need not be the policing Code. New Zealand shows how light the instrument can be, a code issued by the existing privacy regulator under existing law, though a Scottish version would have to do what the Wellington code does not and reach the holding itself. Scotland cannot copy the route in any case: data protection is reserved, so its generalist regulator is not Scotland’s to direct, and the one that does hold the remit has sat on the photograph-is-not-biometric doctrine for years without acting. The devolved move is to legislate for its own bodies. Do that, and that part of the European floor arrives as a side effect, for the price of governing your own house.

The bill tracks the five tests. Name an identifying facial photograph held at population scale as biometric data for the purposes of every duty the bill creates, the move the 2020 Act’s own definition already makes, so that within Scotland’s governance of its own bodies a holding cannot be called ordinary to slip the definition. What the photograph is called under UK data-protection law stays Westminster’s; the bill does not need it. Fix the purposes it may be put to, as a rule of each body’s own conduct, and bar the rest, so a database gathered for travel and proof of age cannot quietly become a search index. Constrained is the thinnest of the five today: the sharing agreement does confine police requests to serious crime and vital interests, but a limit the parties wrote for themselves on implied powers is a limit the same parties can rewrite, and the version disclosed carries a duration clause that ran out in September 2024, with 135 requests processed in the financial year after that date; constraint that counts is enforced from outside.60 Put a positive duty to audit on a named office, with power to compel disclosure and to open the access logs the scheme already keeps and never checks. And put the person whose face it is back in the room, by duty on the holder: a duty to tell people the holding exists, a duty to show them who has reached into it, and a duty to hear an objection without pricing it at the card and every service that rides on it. Acknowledged, constrained, audited, watched, answerable, written down as duties rather than named as virtues.

Scotland built the regulator the rest of the UK keeps wishing it had, and aimed it at the one part of the problem already under the brightest light. The unwatched faces are not the ones in police custody, which are watched, reviewed and reported to Parliament. They are the millions of faces in a council database, gathered for a bus pass, lifted in childhood from a school camera, called ordinary by the people who hold them, and watched, in any specialist sense, by no one at all.

airt.scot · July 2026, revised August 2026. Free to use, in whole or chopped into little pieces, provided the source is acknowledged. (CC BY 4.0)


  1. Police Scotland and the Scottish Police Authority ran a public “national conversation” on live facial recognition in 2025 (public survey, consult.scotland.police.uk); in August 2025 the force confirmed it would continue to pursue the technology, with a business case not expected before the SPA until 2027. https://www.biometricupdate.com/202602/police-scotland-plans-lfr-business-case-consultation-on-the-way-to-a-decision-spa ↩︎

  2. Scottish Biometrics Commissioner, letter to the Cabinet Secretary for Justice and Home Affairs, 27 May 2026: writing “formally to offer my support to the resolution adopted at the last SNP Conference proposing that LFR should not be implemented in Scotland without passing through primary legislation at the Scottish Parliament”, and asking ministers to consider primary legislation creating a statutory basis and enabling framework for limited and proportionate police use. https://www.biometricscommissioner.scot/media/wy0fcyhf/letter-to-neil-gray-msp-cabinet-secretary-for-justice.pdf ↩︎

  3. Scottish Biometrics Commissioner Act 2020 (asp 8), s.2(1). https://www.legislation.gov.uk/asp/2020/8 ↩︎

  4. ibid., s.9(1). A breach of the Code gives rise to no legal action in itself (s.9(3)); the Commissioner may issue a compliance notice (s.23), enforceable on application to the Court of Session (s.27), but cannot himself prohibit a technology, only recommend against it. ↩︎

  5. Scottish Biometrics Commissioner, letter to the Convener of the Criminal Justice Committee, 16 March 2026, pressing the case for primary legislation as the ‘gold standard’ for LFR (the remit covering only those three bodies is the effect of s.2(1) of the Act); and his December 2025 blueprint to the Home Office warning of a “Biometric Wild West” and against the “bulk washing” of passport and driving-licence images against retrospective facial recognition for low-level or volume crime. https://www.biometricscommissioner.scot/media/lzge5aen/letter-to-convenor-criminal-justice-committee-march-2026.pdf ; https://www.biometricupdate.com/202601/scottish-biometrics-commissioner-lays-out-blueprint-for-regulating-police-use-of-biometrics ↩︎

  6. Scottish Biometrics Commissioner, Strategic Plan 2025-29: a total staff of 4 FTE including the officeholder, an office allocated its budget on the policy assumption that there would be “no significant expansion” of its functions, and a 2026/27 total budget of £630,110. That figure includes £65,000 for a two-year Forensics secondment from SPA Forensic Services running to September 2027; the office’s core budget for the year, the £562,000 reported elsewhere, is the same number without it. https://www.biometricscommissioner.scot/publications/ ↩︎

  7. The Ferret, “Biometrics watchdog will lack powers, say critics,” 23 July 2018. Liam McArthur MSP argued the remit should reach “biometrics wherever they are found, be it in education, health or retail”; Open Rights Group Scotland pressed the same widening of scope in its own terms. https://www.theferret.scot/scottish-biometrics-commissioner-enforcement-powers/ ↩︎

  8. Scottish Government, freedom of information response 202300344043 (received 19 February 2023, responded 17 March 2023): a section 17(1) notice that it holds no information on plans for facial recognition in schools (“a matter for local authorities”) or across public services. The same response confirms that the digital identity service uses facial recognition, and that the MyAccount route used for National Entitlement Card applications offers facial recognition (Yoti) for identity verification (MyAccount users “have the option to use” Yoti). https://www.gov.scot/publications/facial-recognition-within-school-and-public-services-foi-release/ ↩︎

  9. Transport Scotland, freedom of information response 202600516361 (8 June 2026): 2,973,029 active National Entitlement Cards, given as the current total (the response states no earlier snapshot date). A copy of the response is held by the author and available on request. ↩︎

  10. Argyll and Bute Council, “National Entitlement Cards: Privacy Statement” (school photograph taken from the SEEMiS system; Card Management System retention “until you advise us you no longer require your card”; “we will only collect personal data about you which does not include any special categories”). The cardholder extract used to verify identity across public services includes the photograph: getyournec.scot Privacy Notice v5 (13 March 2023). https://www.argyll-bute.gov.uk/education-and-learning/national-entitlement-cards-privacy-statement ; https://getyournec.scot/Privacy_Notice_v5.pdf ↩︎

  11. Argyll and Bute privacy statement, as cited above. ↩︎

  12. getyournec.scot Privacy Notice v5, as cited above. ↩︎

  13. National Entitlement Card Scheme, Data Protection Impact Assessment v2.1 (July 2020); and NEC Scheme Changes Data Protection Impact Assessment (November 2021), covering new supplier contracts and the under-22 free-travel scheme. The second link below is the November 2021 assessment in full, despite its filename; the first serves the July 2020 assessment, despite its path. https://www.nec.scot/sites/default/files/2021-11/NEC%20Data%20Protection%20Impact%20Assessment.pdf ; https://www.nec.scot/sites/default/files/2023-03/DPIA_202111signoffs.pdf ↩︎

  14. Scottish Government, freedom of information response 202500470823 (2 July 2025), addressing the under-22 free-travel entitlement carried on the National Entitlement Card: data governance rests on standard data-protection compliance (a data protection officer, annual audits, Audit Scotland), with no biometric-specialist oversight body in the chain. The same controllers and card systems serve the wider scheme, and no specialist regulator reaches any civilian layer of it. https://www.gov.scot/publications/foi-202500470823/ ↩︎

  15. Scottish Biometrics Commissioner Act 2020, s.34 (definition of biometric data). Contrast UK GDPR, Article 4(14) and Recital 51: a photograph counts as biometric data only when processed by specific technical means for the purpose of uniquely identifying a person. https://www.legislation.gov.uk/asp/2020/8 ; https://www.legislation.gov.uk/eur/2016/679/article/4 ↩︎

  16. Argyll and Bute Council, “National Entitlement Cards: Privacy Statement”, as cited above (“we will only collect personal data … which does not include any special categories”). ↩︎

  17. NEC Scheme Data Protection Impact Assessment v2.1 (July 2020), as cited above: the screening list of the reasons a DPIA was required at all, of which the first is that the scheme “processes special category data on a large scale”. ↩︎

  18. Scottish Government, FOI response 202300344043, as cited above: the digital identity service uses facial recognition, and MyAccount applicants for a National Entitlement Card “have the option to use Yoti … Yoti uses facial recognition for identity verification.” ↩︎

  19. getyournec.scot Privacy Notice v5, as cited above: the biometric face match, and the notice’s single Article 9 condition, explicit consent, recorded for the proof-of-disability document a disabled-card applicant submits. ↩︎

  20. Argyll and Bute Council, “National Entitlement Cards: Privacy Statement”, as cited above. The passage stating what is collected names the NEC application form, the school photograph from SEEMiS, and no special categories; the face match appears nowhere in the notice. ↩︎

  21. NEC Scheme Changes DPIA (November 2021), as cited above: the new-contract suppliers “committed to process only within the UK”; the assessment also proposes retention periods targeting special-category (disability) data (“Introduce retention periods targeting special categories of data”) and weighs parent or guardian approval and access to a child’s journey history. Neither it nor the v2.1 assessment (July 2020) treats the photograph as biometric data or addresses the facial recognition used at enrolment. ↩︎

  22. National Entitlement Card Scheme, DPIA v2.1 (July 2020), as cited above: police access “takes place on a case by case basis, and each request received from the police is logged”, with police services “not given system access … at any time”. ↩︎

  23. Data Sharing Agreement between the National Entitlement Card Programme Office (Dundee City Council, for all Scottish local authorities), Police Scotland and British Transport Police, version 2.0 (2024), marked OFFICIAL, disclosed under freedom of information response 20260610013. Clause 4.1(a) lists the shareable card fields, including (vii) the photograph. Clause 6.1 states that the programme office relies on “implied powers” to share, citing no express statutory gateway. Clause 5.1 requires a written request signed by an officer of inspector rank or above. Clause 3.1 confines the purposes to serious crime and the protection of vital interests. Clause 12.1 states the Agreement continues ‘until September 2024’; the review clause beside it provides for review ’not less than every 5 years’. The office disclosed this version in June 2026 as the governing instrument, and its own figures record 135 requests in 2025/26. Whether a renewal exists was not asked; on the face of the disclosed document, the duration had run out. A copy is held by the author and available on request. ↩︎

  24. Dundee City Council, freedom of information response 20260610013 (30 June 2026). Dundee City Council operates as the National Entitlement Card Programme Office for all 32 Scottish local authorities; requests from Police Scotland and British Transport Police for cardholder data, including the photograph, are governed by a tri-party data-sharing agreement (see below), and each is a written request authorised by an officer of inspector rank or above and assessed manually (“approval is not automated … not determined by a software workflow”). Across 2023/24 to 2025/26, 426 requests were received and 414 granted (about 97 per cent), with 395 photographs provided. The programme office “holds no records of any facial photograph being disclosed for the purposes of facial recognition or automated facial comparison”. Records of requests are held on the council’s SharePoint, and “no audit records are held” in relation to them. A copy of the response is held by the author and available on request. ↩︎

  25. getyournec.scot Privacy Notice v5 (13 March 2023), “How long do we store your data.” Online application data, including the photograph, is deleted sixty days after export to NECPO for most card types, and two years for Young Scot and disabled Young Scot cards retained for PASS proof-of-age audit. This is the application-portal copy only; the Card Management System record is governed separately. https://getyournec.scot/Privacy_Notice_v5.pdf ↩︎

  26. Scottish Biometrics Commissioner, FOI response FOI/011 (25 June 2026), answering in substance: not consulted by the Scottish Government, the Improvement Service or any local authority on any proposal to expand the card’s functionality; no guidance prepared on multi-purpose identity or entitlement cards (the Commissioner ‘does not prepare guidance on any matter that does not pertain to the use of biometric data or technologies for policing and criminal justice purposes and is not involved in the NEC scheme’). The request’s third head, whether the Commissioner has assessed any biometric implications of the scheme, is not answered in the response at all. A copy is held by the author and available on request. ↩︎

  27. Police Scotland, freedom of information response 26-1705 (24 June 2026): three heads answered section 17 not held, with declaratory statements that the force ‘does not use any form of facial matching technology on photographs held under the National Entitlement Card scheme or otherwise held by a Scottish local authority’ and has made no requests for NEC facial photographs ‘for use in facial matching’ in the last three financial years. Both statements are present-custody and purpose-qualified in the response’s own words; they say nothing about photographs once they leave the scheme’s custody. The response’s second head denies holding ‘any agreement, protocol, memorandum of understanding or other arrangement’ with a local authority, the Improvement Service or the programme office for access to, or facial searching of, the photographs; the tri-party data-sharing agreement disclosed under freedom of information response 20260610013 six days later names Police Scotland as a party. The force may have read the question as reaching facial-searching arrangements only; the question, and its answer, both say ‘access to’. A copy is held by the author and available on request. ↩︎

  28. Scottish Government, FOI release 202500481032 (responded 17 September 2025, published 2 December 2025) and its released documents. The file index records “Section 5 - re Improvement Service”, created 20 July 2011; respondents raised the body again in the 2019 consultation; a 2021 policy paper was “minded to explore” section 4 designation with section 5 as fallback; a November 2021 official’s email states “Neither of these bodies are currently subject to the Scottish legislation”; the internal record notes the 2021-22 draft policy paper “has not been progressed since”; and the mid-2025 workplan entry reads “Research work on Improvement Service, Forensic Network and Research Data Scotland yet to commence”. https://www.gov.scot/publications/foi-202500481032/ ↩︎

  29. Ms Jenny Paton and others v Poole Borough Council, Investigatory Powers Tribunal (covert directed surveillance February 2008; determination 2010, the use held disproportionate). Local authorities held these powers under RIPA Part II; the Protection of Freedoms Act 2012 later required magistrates’ approval for their use. https://investigatorypowerstribunal.org.uk/judgement/ms-jenny-paton-and-others-vs-poole-borough-council/ ↩︎

  30. S and Marper v United Kingdom (2008) 48 EHRR 50, Application nos 30562/04 and 30566/04, Grand Chamber, 4 December 2008. The Court was “struck by the blanket and indiscriminate nature of the power of retention in England and Wales” (para 119) and held the retention of fingerprints, cellular samples and DNA profiles of persons suspected but not convicted a violation of Article 8 (paras 125 to 126). Scotland’s narrower regime is the comparator the judgment uses. Destruction of the material followed from the Protection of Freedoms Act 2012, not from the judgment itself. https://hudoc.echr.coe.int/eng?i=001-90051 ↩︎

  31. R (RMC and FJ) v Commissioner of Police of the Metropolis [2012] EWHC 1681 (Admin); Home Office, Review of the Use and Retention of Custody Images (February 2017). Over 19 million custody images were held on the Police National Database, over 16 million searchable by facial recognition, as at July 2016. https://www.judiciary.uk/wp-content/uploads/JCO/Documents/Judgments/r-rmc-fj-metropolitan-police-commissioner-22062012.pdf ; https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/594463/2017-02-23_Custody_Image_Review.pdf ↩︎

  32. Police.uk reports around 60 million ANPR reads per day with one-year retention. https://www.police.uk/advice/advice-and-information/rs/road-safety/automatic-number-plate-recognition-anpr/ ↩︎

  33. Clearview AI Inc v Information Commissioner [2025] UKUT 319 (AAC), paras 40 and 146: the database was estimated in October 2022 at “over 20 billion images”, growing by 75 million a day, and “all of Clearview’s current clients carry out criminal law enforcement and/or national security functions”, none of them in the United Kingdom. The Upper Tribunal preserved the First-tier Tribunal’s findings only subject to its own para 287, which holds that the clients finding “lacks specificity” and that the primary findings behind it “are inadequate to support such a conclusion”. The Commissioner’s monetary penalty of £7,552,800 and enforcement notice are dated 18 May 2022; a tribunal overturned them on jurisdiction in 2023 and the Upper Tribunal restored the Commissioner’s jurisdiction in October 2025. The 2022 penalty notice is no longer published on the Commissioner’s site. https://ico.org.uk/media2/mc5bjzsg/ua-2024-001563-gia.pdf ; https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/10/uk-upper-tribunal-hands-down-judgment-on-clearview-ai-inc/ ↩︎

  34. R (Bridges) v Chief Constable of South Wales Police [2020] EWCA Civ 1058, 11 August 2020: the Court declared the force’s use of live facial recognition “not in accordance with the law for the purposes of Article 8(2)”, allowing the appeal on three of five grounds, one of them the Public Sector Equality Duty. South Wales Police announced the resumption of deployments on 5 April 2023 following the National Physical Laboratory’s equitability study, the Chief Constable saying “There was nothing in the Court of Appeal judgment that fundamentally undermined the use of facial recognition to protect the public”. https://caselaw.nationalarchives.gov.uk/ewca/civ/2020/1058 ; https://www.south-wales.police.uk/news/south-wales/news/2023/ebr-apr/commitment-facial-recognition-technology-reaffirmed-report-tech-does-not-breach-equality-requirements/ ↩︎

  35. Sources differ on the number of forces in England and Wales using live facial recognition: Statewatch counts twelve, Biometric Update thirteen. The Metropolitan Police scanned more than 1.7 million faces in the first four months of 2026; the force’s own figures are due in its annual live facial recognition report, expected around October 2026. https://statewatch.org/news/2026/june/england-police-use-of-facial-recognition-technology-growing-rapidly/ ; https://www.biometricupdate.com/202605/will-scotland-be-the-first-nation-to-pass-primary-legislation-covering-live-frt ↩︎

  36. HM Chief Inspector of Constabulary in Scotland (Craig Naylor), annual report for 2025-26 (August 2026): banning orders backed by “modern technologies such as facial recognition” should be “explored and enacted” against football disorder; “the challenge is not whether to adopt these technologies, but how quickly they can do so safely, ethically and effectively.” Police Scotland does not currently use live facial recognition. https://emergencyservicestimes.com/2026/08/21/police-scotland-urged-to-consider-live-facial-recognition-to-tackle-football-disorder/ ↩︎

  37. S and Marper v United Kingdom, as cited above, paras 109, 110 and 112. The Scottish regime the Court describes at para 36 allows retention of the DNA of unconvicted persons only for adults charged with violent or sexual offences, for three years, extendable by a further two with a sheriff’s consent. https://hudoc.echr.coe.int/eng?i=001-90051 ↩︎

  38. Friedl v Austria (1995), as the Grand Chamber describes it in S and Marper at para 82: the Commission “attached special weight to the fact that the photographs concerned had not been entered in a data-processing system and that the authorities had taken no steps to identify the persons photographed by means of data processing”. Cited through the Grand Chamber’s account rather than the Commission’s own decision. https://hudoc.echr.coe.int/eng?i=001-90051 ↩︎

  39. Scottish Biometrics Commissioner, assurance review SBC/2024/01 (2024), laid before Parliament, estimating Police Scotland held more than three million images across its criminal-history and related systems, noting the true total is unknown, and recording 646,935 images relating to 382,052 people on the Criminal History System. https://www.biometricscommissioner.scot/media/vcfnimt0/sbc-assurance-review-on-images.pdf ↩︎

  40. National Entitlement Card Scheme DPIA v2.1 (July 2020), as cited above: approximately two million individuals hold National Entitlement Card data (a 2020 estimate). ↩︎

  41. Scottish Biometrics Commissioner, response to the Home Office consultation, December 2025, as cited above: law enforcement should have no “routine” access to UK passport or driving licence images, and there should be no “bulk washing” of those images against retrospective police facial recognition for low level or volume crime. ↩︎

  42. Ritchie et al., “Public attitudes towards the use of automatic facial recognition technology in criminal justice systems around the world,” PLoS ONE (2021), https://doi.org/10.1371/journal.pone.0258241. Fieldwork ran from 28 December 2019 to 29 January 2020. Of 3,124 respondents in the UK, Australia and the USA, about 89% supported police searches for a person who had committed a crime and about 25% supported tracking citizens; across all three countries a majority did not trust government to use the technology responsibly. The recommendation is to set legal boundaries around the use of the technology, not to ban it. ↩︎

  43. Regulation (EU) 2024/1689 (Artificial Intelligence Act), Article 5 prohibitions in force from 2 February 2025. Obligations for the Annex III high-risk category, which includes biometric systems, fell under the Regulation’s general application date of 2 August 2026 (Art 113). Regulation (EU) 2026/1744 of 8 July 2026, the EU ‘digital omnibus’ on AI, published in the Official Journal on 24 July 2026, amends Article 113 so that those obligations apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I. It followed the European Parliament’s position of 16 June 2026 and the Council’s decision of 29 June 2026. https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ%3AL_202601744 ; https://artificialintelligenceact.eu/article/5/ ↩︎

  44. UK Withdrawal from the European Union (Continuity) (Scotland) Act 2021 (asp 4), s.1 (the “keeping pace” power). The power is time-limited by s.4(1) and, absent an extension under s.4(2), lapses at the end of 28 March 2027. https://www.legislation.gov.uk/asp/2021/4 ↩︎

  45. Scotland Act 1998, Schedule 5, Part II, reservation B2 (data protection). Artificial intelligence is not expressly reserved, but the levers to regulate it, including data protection, consumer protection and product safety, largely are. https://www.legislation.gov.uk/ukpga/1998/46/schedule/5 ↩︎

  46. New Zealand Office of the Privacy Commissioner, Biometric Processing Privacy Code 2025 (in force 3 November 2025), issued under the Privacy Act 2020. https://www.privacy.org.nz/privacy-principles/codes-of-practice/biometric-processing-privacy-code/ ↩︎

  47. Digital ID Act 2024 (Australia), in force 30 November 2024 (voluntary; accredited; regulated by the Digital ID Regulator, the role performed by the Australian Competition and Consumer Commission, and the Office of the Australian Information Commissioner); and the defeat of the “Australia Card” national identity proposal in 1987. https://www.legislation.gov.au/C2024A00025/latest/text ↩︎

  48. Estonia operates a national digital identity under the Identity Documents Act; through the state portal (eesti.ee), an eID holder can review which institution has queried their personal data, when and for what purpose, via the state “data tracker” run by the Information System Authority. Coverage, per the Ministry of Justice as reported by ERR (December 2025): integration is voluntary and reaches 15 of more than 300 information systems, with a legislative proposal to make it mandatory for nearly all public databases holding personal data. https://e-estonia.com/data-tracker-build-citizen-trust/ ; https://news.err.ee/1609886842/estonia-planning-to-make-data-tracker-mandatory-for-all-public-databases ↩︎

  49. Illinois Biometric Information Privacy Act 2008 (740 ILCS 14), giving individuals a private right of action and statutory damages without proof of harm (Rosenbach v Six Flags Entertainment Corp, 2019 IL 123186: “a person need not have sustained actual damage beyond violation of his or her rights under the Act in order to bring an action under it”; the private right of action is the Act’s only enforcement mechanism. Rosenbach itself concerned a thumbprint; the Act’s definition covers scans of face geometry). https://www.illinoiscourts.gov/Resources/f71510f1-fb2a-43d8-ba14-292c8009dfd9/123186.pdf ; https://www.aclu-il.org/campaigns-initiatives/biometric-information-privacy-act-bipa/ ↩︎

  50. In England and Wales there is no statutory code for civilian biometric holdings; the Data Protection and Digital Information Bill (2023) proposed to abolish the police Biometrics and Surveillance Camera Commissioner, which an independent report (whose co-author, William Webster, took office as the new Commissioner in November 2025) warned would create “significant gaps” in oversight. The Bill fell with the 2024 general election. Its successor, the Data (Use and Access) Act 2025, kept the Commissioner and the surveillance-camera code rather than abolishing them, but enacted no statutory code for civilian biometrics; the civilian gap survives every version. https://assets.publishing.service.gov.uk/media/653f7128e6c968000daa9cae/Changes_to_the_functions_of_the_BSCC.pdf ↩︎

  51. The mandatory UK digital identity scheme announced September 2025 was cancelled by Prime Minister Andy Burnham in July 2026, the stated £1.8 billion three-year saving redirected to household energy bills (Chancellor John Healey: “breathing room on bills … this winter”). The figure’s provenance undercuts the framing: it is the Office for Budget Responsibility’s November 2025 estimate (£1.3 billion capital, £0.5 billion operating) for a programme “for which no specific funding has been identified”, to be met “through existing DEL budgets” with “no specific savings … yet … identified”; and DSIT’s permanent secretary rejected it on 3 December 2025 (“not a figure that we recognize”), offering no alternative before or since. The parliamentary petition closed on 9 January 2026 at 2,984,191 signatures, the second-largest on record; the mandatory element had already been dropped before the cancellation. https://techcrunch.com/2026/07/21/uk-government-scraps-plans-for-digital-id-cards-after-millions-of-brits-opposed/ ; https://www.biometricupdate.com/202511/first-official-cost-estimate-for-uk-govt-digital-id-plan-1-8b-over-3-years ; https://www.theregister.com/2025/12/09/uk_digital_id_costs/ ↩︎

  52. DSIT/GDS Preliminary Market Engagement notice 2026/S 000-061316 (30 June 2026): £280m ex VAT for GOV.UK One Login and credentials, scope naming “Wallet and verifiable credentials, including Digital ID”, tender notice expected 16 September 2026, published three weeks before the cancellation and not withdrawn with it; trade reporting confirms the wallet and verifiable credentials work continuing. Whether “Digital ID” survives in the tender’s scope will be visible when the notice publishes. https://www.biometricupdate.com/202607/the-uk-national-digital-id-is-dead-long-live-the-uk-digital-id ↩︎

  53. Scottish Biometrics Commissioner Act 2020, s.2(7): the bodies subject to the Code may be added to by regulations made by the Scottish Ministers. The power has not been exercised. SBC Annual Report and Accounts 2023/24. https://www.biometricscommissioner.scot/publications/ ↩︎

  54. Scottish Government, Review of the Functions of the Scottish Biometrics Commissioner (consultation paper, ISBN 9781806437603), the post-legislative review under section 6 of the 2020 Act; responses under consideration, 2026. https://www.gov.scot/isbn/9781806437603 ↩︎

  55. Independent Advisory Group on the Use of Biometric Data in Scotland (2018), Recommendation 8: the Commissioner ‘should keep under review the acquisition, retention, use and disposal of all biometric data by the police, SPA and other public bodies’. The Group’s own terms of reference stopped at policing: oversight ‘in other areas of Government where they feature, for example, health and education, and the private sector’ would be ‘beyond our Terms of Reference’; its paragraph 9.14 adds that ‘Consideration can be given as to whether the role of the Scottish Biometrics Commissioner should be extended to these.’ https://www.gov.scot/publications/report-independent-advisory-group-use-biometric-data-scotland/ ↩︎

  56. Scottish Government, Review of the Functions of the Scottish Biometrics Commissioner, consultation paper (16pp), as cited above: consideration “should be given to extending the list of bodies” to “other organisations who acquire and manage biometric data that could be used for policing and criminal justice purposes in Scotland such as the Scottish Prison Service”. The paper marks these as points “offered to prompt your thinking” which “do not necessarily reflect the SG’s position”. ↩︎

  57. Biometrics and Surveillance Camera Commissioner for England and Wales (Professor William Webster), response to the Review of the Functions of the Scottish Biometrics Commissioner (May 2026, published 3 June 2026): proposes extension to the Scottish Prison Service, consideration of “all bodies using biometric data for law enforcement, public safety and safeguarding purposes”, and “public space surveillance camera systems, included those operated by local authorities”. The National Entitlement Card appears nowhere in it. https://www.gov.uk/government/publications/scottish-biometrics-commissioner-consultation-response/scottish-biometrics-commissioner-review-of-functions-consultation-response-accessible ↩︎

  58. Independent Advisory Group (2018), as cited above, on the limits of its own remit: there “may be scope” for the Commissioner overseeing biometrics “in other areas of Government where they feature, for example, health and education, and the private sector, although any such extension is beyond our Terms of Reference”; paragraph 9.14 adds that “Consideration can be given as to whether the role of the Scottish Biometrics Commissioner should be extended to these”. ↩︎

  59. Neil Gray MSP, Cabinet Secretary for Justice and Home Affairs, response of 16 June 2026: committing to primary legislation now would be “premature”, Police Scotland being around two years from a viable business case; the Scottish Government “stands ready to work with” the Commissioner and will assess any Westminster draft legislation for its implications for Scotland. https://www.computerweekly.com/news/366644481/Scottish-minister-clarifies-police-facial-recognition-approach ↩︎

  60. Data Sharing Agreement, as cited above: clause 3.1 confines the purposes to serious crime and the protection of vital interests, and clause 12.1 continues the Agreement “until September 2024”. ↩︎