Review calls for urgent new laws over use of biometric technology
Report also calls for the creation of a biometrics ethics board and greater scrutiny of data sharing


An independent legal review has concluded that new laws regulating the use of biometric data in the public and private sector are urgently needed.
The report, commissioned by The Ada Lovelace Institute and undertaken by Matthew Ryder QC, aimed to highlight the uncertain level of biometric technology regulation provided by existing laws such as the EU's General Data Protection Regulation (GDPR).
Among the review’s recommendations are a new statutory framework to set out the use of biometric data by private and public organisations for both identification and classification, and the establishment of a national Biometrics Ethics Board. This, it says, is necessary given the rights-intrusive potential of new technologies such as live facial recognition and gait recognition.
Further investigation into the private sector’s use of biometrics, as well as the sharing of information between private and public sector entities, was also highlighted as a matter of importance.
The review gives the example of the use of facial recognition technology at the King’s Cross site in 2019, which was later found to have included a data sharing agreement with the Metropolitan Police and British Transport Police, to “prevent and detect crime in the neighbourhood”, according to the site's owners.
Recommendations in this area include stricter regulation of Live Facial Recognition (LFR) and a complete moratorium on all LFR in both the public and private sector until the new framework is in place.
Additional concern was raised around the use of remote monitoring and video processing to collect biometric data in the private sector, enabled by the rise of remote working throughout the pandemic.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Under current protections provided by GDPR, biometric data is only classified as special category data when it is collected for ‘the purpose of uniquely identifying a natural person'. The Ada Lovelace Institute, in their policy report supplemental to the review, notes that this leaves biometric data used to determine a person’s “gender, race, or emotional state” subject to less stringent legal oversight.
Proposed legislation would cover use of biometric data for identification and classification. It would also require biometric technology earmarked for public use to first undergo a series of impact assessments to determine its potential impact on privacy and equality, as well as scrutinise the necessity and proportionality of the technology.
Public bodies would then have to refer any such technology to a newly proposed Biometric Ethics Board, the creation of which would provide ethical oversight in a public advisory capacity. It was also suggested that the advice of the board should be made publicly available, with public bodies required to publish explanations for any decisions made contrary to this advice within 14 days of any such decision.
Having begun in 2020, the review makes no reference to the proposed Data Reform Bill, which has been specifically highlighted by government ministers as relaxing certain restrictions imposed by GDPR that they dubbed “red tape and pointless paperwork”. These include aims by the government to cut down on the need to seek user consent for the processing of data in certain circumstances.
As part of the review, the Ada Lovelace council convened a Citizens’ Biometrics Council, composed of a diverse group of 50 members of the public asked to learn about and offer views on the use of biometric technology in legislation. A common view in their recommendations was the need for consent and transparency regarding the use of biometric data.

Rory Bathgate is Features and Multimedia Editor at ITPro, overseeing all in-depth content and case studies. He can also be found co-hosting the ITPro Podcast with Jane McCallion, swapping a keyboard for a microphone to discuss the latest learnings with thought leaders from across the tech sector.
In his free time, Rory enjoys photography, video editing, and good science fiction. After graduating from the University of Kent with a BA in English and American Literature, Rory undertook an MA in Eighteenth-Century Studies at King’s College London. He joined ITPro in 2022 as a graduate, following four years in student journalism. You can contact Rory at rory.bathgate@futurenet.com or on LinkedIn.
-
Global cybersecurity spending is set to rise 12% in 2025 – here are the industries ramping up investment
News Global cybersecurity spending is expected to surge this year, fueled by escalating state-sponsored threats and the rise of generative AI, according to new analysis from IDC.
By Ross Kelly Published
-
Google Cloud is leaning on all its strengths to support enterprise AI
Analysis Google Cloud made a big statement at its annual conference last week, staking its claim as the go-to provider for enterprise AI adoption.
By Rory Bathgate Published
-
UK businesses patchy at complying with data privacy rules
News Companies need clear and well-defined data privacy strategies
By Emma Woollacott Published
-
Data privacy professionals are severely underfunded – and it’s only going to get worse
News European data privacy professionals say they're short of cash, short of skilled staff, and stressed
By Emma Woollacott Published
-
Four years on, how's UK GDPR holding up?
News While some SMBs are struggling, most have stepped up to the mark in terms of data governance policies
By Emma Woollacott Published
-
Multicloud data protection and recovery
whitepaper Data is the lifeblood of every modern business, but what happens when your data is gone?
By ITPro Published
-
Intelligent data security and management
whitepaper What will you do when ransomware hits you?
By ITPro Published
-
How to extend zero trust to your cloud workloads
Whitepaper Implement zero trust-based security across your entire ecosystem
By ITPro Published
-
The threat prevention buyer's guide
Whitepaper Find the best advanced and file-based threat protection solution for you
By ITPro Published
-
Why The Matrix offers valuable lessons on data sovereignty for channel partners
Industry Insight Two decades on, there's much that the Matrix series can teach channel partners about data sovereignty
By David Devine Published