Live facial recognition (LFR) has moved from a contested police trial to a routine feature of mid-market UK retail. Facewatch, the most widely deployed private LFR provider in Britain, reportedly issued 516,739 automated alerts in 2025, more than double its 2024 total, with Sainsbury’s, Tesco and Asda among the chains accelerating roll-out. Over the same period, the Metropolitan Police recorded 962 arrests directly attributed to live facial recognition, with more than a quarter linked to offences involving violence against women and girls.

That trajectory has brought regulation into sharper focus. The Home Office’s ten-week consultation on a new legal framework for police use of biometrics and facial recognition closed in February 2026, with ministers signalling that primary legislation, not merely revised guidance, is now on the table. The consultation deals with the policing side of the question, but its outcome will shape the legal climate in which private deployment continues to grow. This is what UK retail operators need to know before the next regulatory cycle.

What the consultation actually covers

The consultation, run by the Home Office between December 2025 and February 2026, asked Parliament and the public to weigh in on when, how and under what safeguards facial recognition should be used by law enforcement. According to gov.uk, the stated aim is to consolidate what the government has described as a “patchwork” of existing laws – spanning common-law police powers, the Data Protection Act 2018, the UK GDPR, the Human Rights Act and the Equality Act – into a single, clearer framework.

Public support, on the Home Office’s own survey, sits at roughly two in three for police use of the technology. The same survey identified concerns about misidentification and the absence of an explicit statutory basis. The consultation does not directly govern private retail use, but the eventual legislation is widely expected to set a tone – and arguably a benchmark – for what private sector deployment is expected to look like.

The retail picture in numbers

Private LFR in retail is regulated under the Data Protection Act 2018 and the UK GDPR. The Information Commissioner’s Office is the primary supervisory authority, although civil liberties groups including Big Brother Watch and Liberty have publicly criticised what they describe as a slow pace of regulatory intervention. The growth figures reported across 2025 and early 2026 illustrate the scale:

  • Reportedly 516,739 Facewatch alerts in 2025, against around half that number in 2024.
  • A record 14,885 alerts in the single week ending Christmas Eve 2025.
  • Sainsbury’s expanded from two trial stores in late 2025 to a reported seven sites by early 2026, with B&M, Home Bargains, Sports Direct, Farmfoods and Spar among other named users.
  • The Pegasus Partnership, a £6 million public-private initiative backed by 15 major retailers, has been reported to have secured 148 arrests in its first year by funnelling private camera data into Police National Database searches.

Alongside that growth, Retail Gazette reported in May 2026 that some shoppers wrongly identified by LFR systems had struggled to understand why they were approached, how their data was held, or how to challenge a decision. Civil-liberties research has separately suggested that error rates remain higher for black and Asian customers than for white customers, replicating well-documented technical biases in facial recognition models.

When LFR is appropriate – and when it isn’t

From a security-operations perspective, LFR is a high-impact tool with a narrow legitimate use case. It is most defensible where (a) there is a documented record of repeat offending against a specific store or estate, (b) the watchlist is built only from individuals already convicted or formally banned, (c) data retention is short and auditable, and (d) staff are trained to engage with anyone identified as a match calmly, in private, and without public accusation.

It is far harder to defend where the watchlist contains unverified internal entries, where retention drifts beyond what a Data Protection Impact Assessment supports, or where match alerts trigger public confrontation. Those are the scenarios most likely to produce both ICO scrutiny and reputational damage.

What this means for UK retailers

Three practical takeaways for retail operators while the legal framework remains in flux:

  • Document everything. A current Data Protection Impact Assessment, a documented lawful basis, and a defined retention policy are the minimum a retailer should expect to defend if the ICO or a customer raises a complaint.
  • Train guards on the engagement step. An LFR alert is intelligence, not evidence. Front-line officers should be drilled in approaching a matched customer discreetly, verifying identity through dialogue, and stepping back politely if the match is wrong.
  • Plan for a tighter regime. Whatever shape the new legislation takes, expect tighter documentation requirements, mandatory transparency at the point of deployment, and clearer redress for misidentified customers. Building those into operations now is cheaper than retrofitting them later.

LFR is not going away. The question for retailers is not whether to use it, but whether the rest of the security programme – trained officers, well-defined intervention protocols, audited cameras and stock-loss procedures – is robust enough to make the technology a genuine force-multiplier rather than a liability.

Need a security review?

Our team works with retailers across London and the UK to design integrated security programmes that combine SIA-licensed manned guarding, CCTV operations, and incident-response protocols. If your store or estate is considering LFR, or already running it and wants a second opinion on the operational and compliance picture, we can help.

Call 020 3700 0967, email info@secureonsitesecurity.co.uk, or use our contact form. You can also read more about our retail security and corporate security services.

Loading...
Share This