Digital Marketing, Spam & Privacy
Facial recognition and privacy: assessment checklist
Practical guidance on facial recognition and privacy: assessment checklist, with a February 2026 explanation, business checklist and evidence questions.
What changed in February 2026
The ART set aside one APP 3 conclusion on the facts but affirmed governance and notice breaches. The guidance decision is authoritative within the Tribunal framework, not a court precedent or broad approval of facial recognition.
What businesses should do now
For biometric systems, document necessity and proportionality, complete privacy impact work, provide effective notice and maintain governance even where an exception may support collection.
- Map the live data flow, including temporary systems, pixels, vendors and onward disclosures.
- Confirm necessity, authority, notice, consent and purpose for each material use or disclosure.
- Reconcile intended privacy settings with live states across downstream systems.
- Apply access, configuration, monitoring, deletion and incident controls to non-production environments.
- Retest after changes to websites, vendors, migrations, permissions or data fields.
Evidence to retain
- Current data maps, system inventories and supplier responsibilities.
- Privacy assessments, notices, consent records and decision logs.
- Access reviews, configuration evidence, monitoring records and verified deletion.
- Incident chronology, assessment decisions, notifications and remediation evidence.
Turn the issue into a controlled decision
- Record the affected product, claim, customer journey, system, supplier or business process.
- Separate current requirements from proposals, priorities, allegations, warnings and matter-specific outcomes.
- Assign an owner, action date and evidence location for every material gap.
- Set review triggers for legal changes, new facts, supplier changes, incidents, complaints and campaign variations.
- Escalate when the available facts or evidence do not support the proposed decision.
Questions to ask
Focus on the decision and the evidence.
- 01
What personal information is actually collected, inferred, used, disclosed and retained?
- 02
Do privacy conclusions match the exact dataset, system, purpose and time period?
- 03
What evidence shows that the control works across suppliers and downstream systems?
Primary sources
Check the controlling material.
Recommended training
Watchdog PRO Certificate: Privacy Officer
Build practical privacy controls for digital marketing, tracking, consent and customer data.
- Map information, systems, purposes and data flows
- Review collection, use, disclosure and retention
- Conduct practical privacy impact assessments
Practical support
Apply the guidance to your facts.
Identify the exact product, claim, customer journey, supplier, legal entity or process involved. Preserve the information that supports the current position, record unresolved facts, assign an owner and confirm the point at which specialist review is required.
Tell us how this issue affects your organisation and receive a tailored recommendation for the most useful next step.
Important information
Check the current position.
This resource is general information, not legal advice. Laws, official guidance and proposals can change. Do not rely on a title or summary alone to decide whether a requirement applies to a particular entity, product or activity.
