Facial Recognition Technology: Where Is It Legal?

Photo of author
Author: Alex
Published:
Updated:
Abstract face silhouette with scan grid lines, shield, and gavel icons — facial recognition legal issues

Direct Answer: The legality of facial recognition depends entirely on where you are. The EU has banned real-time facial recognition in public spaces under the AI Act (2024). In the United States, there is no federal law but 16-plus cities have banned it and 15 states restrict police use. The UK currently has no dedicated facial recognition legislation at all, and police there scan millions of faces each year under a patchwork of guidelines.

Facial recognition legal issues affect anyone who walks past a security camera, shops at a grocery store, or attends a public event. The technology can identify you in seconds, but the laws governing it vary wildly depending on which country, state, or city you happen to be standing in. Your legal protections depend almost entirely on geography and understanding those differences starts with knowing what rights you have when police want your data.

The Short Version

  • The EU’s AI Act (2024) bans real-time biometric surveillance in public spaces, with narrow law enforcement exceptions. Fines can reach €35 million or 7% of global revenue.
  • The United States has no federal facial recognition law. Protections come from a growing but uneven patchwork of city bans and state restrictions.
  • The UK has no facial recognition legislation. Police scanned over 7 million faces in 2025 alone, and the government is consulting on expanding not restricting the technology.
  • Illinois is the only US state where individuals can sue companies directly for scanning their face without consent, under the Biometric Information Privacy Act (BIPA, 2008).

What Facial Recognition Legal Issues Actually Look Like Under the Law

The rules break down into three categories: government (police) use, commercial (retail and private sector) use, and the question of consent. Each jurisdiction handles these differently.

In the European Union

The EU AI Act (Regulation 2024/1689), which took effect on August 1, 2024, is the strongest facial recognition law in the world on paper. Its prohibited-practices provisions became enforceable on February 2, 2025.

Under Article 5, the AI Act bans three things outright: real-time biometric identification in public spaces by law enforcement, scraping faces from the internet or CCTV to build recognition databases, and using biometric data to categorize people by race, religion, or sexual orientation.

The ban is not absolute. Law enforcement can still use real-time facial recognition in three narrow situations: searching for victims of abduction or trafficking, preventing imminent threats like terrorist attacks, and locating suspects of serious crimes punishable by at least four years in prison. Each use requires judicial or administrative authorization.

Companies that violate these rules face fines of up to €35 million or 7% of global annual revenue, whichever is higher. Enforcement remains a challenge Clearview AI owes more than €100 million in European fines across five jurisdictions and, as of mid-2026, has paid nothing.

In the United States

There is no federal law governing facial recognition. Every bill introduced since 2019 including Senator Ed Markey’s ICE Out of Our Faces Act (February 2026) has stalled in committee without a floor vote.

Protection depends on where you live:

City bans. At least 16 US cities have banned government use of facial recognition entirely. San Francisco led the way in 2019, followed by Boston, Oakland, Portland (Oregon), Minneapolis, and others. Milwaukee became the latest in February 2026.

State restrictions. Fifteen states have some form of restriction on police use. Seven states including Colorado, Maryland, Maine, Virginia, and Montana prohibit police from using a facial recognition match as the sole basis for an arrest. Several states now require officers to tell defendants when facial recognition was used in their case.

Illinois BIPA. The Biometric Information Privacy Act (740 ILCS 14), passed in 2008, is the only US law that lets individuals sue private companies for collecting face scans without written consent. BIPA produced Facebook’s $650 million settlement in 2021. In most other states, companies can scan your face without telling you and without legal consequence.

In the United Kingdom

The UK has no legislation specifically governing facial recognition. A 2020 Court of Appeal ruling (R (Bridges) v. South Wales Police) found police use of facial recognition unlawful on multiple grounds including a failure to assess racial bias but police continued using the technology afterward.

By 2025, UK police had scanned over 7 million faces using live facial recognition, and the Metropolitan Police alone scanned more than 1.7 million faces in the first half of 2026, an 87% increase over the same period in 2025. The UK’s first permanent facial recognition cameras went live in Croydon, South London, in October 2025.

In December 2025, the Home Office launched a consultation not on restricting facial recognition, but on expanding it to all 43 police forces. The proposed framework includes building a national face database from passport and driving license photos. As of July 2026, the Home Secretary has acknowledged that dedicated legislation is still being developed, with legal scholars estimating it is at least three years away.

World map highlighting EU, US, and UK facial recognition legal issues with icons showing ban, patchwork, and surveillance

Real-World Examples

Wrongful arrests in the US. As of early 2026, at least 13 criminal cases have been dismissed after facial recognition matched the wrong person. Nearly every victim was Black. A NIST study found that many systems misidentify darker-skinned faces at rates 10 to 100 times higher than white faces.

In August 2025, the NYPD arrested Trevis Williams based on a facial recognition match. Williams was eight inches shorter and 70 pounds lighter than the actual suspect. Cell phone data confirmed he was miles away at the time.

Retail scanning. In January 2026, Wegmans confirmed it uses facial recognition in some stores. In most US states, this is perfectly legal no notice or consent required. Only in Illinois can customers take legal action under BIPA.

Police workarounds. A 2024 investigation found that police in ban cities including San Francisco and Austin were asking neighboring jurisdictions to run facial recognition searches for them. Boston anticipated this loophole: its ban specifically prohibits officers from requesting other agencies to run searches on their behalf.

What People in This Situation Typically Do

  1. Check local laws. Facial recognition rules vary by city and state. Resources like EPIC.org and the ACLU maintain up-to-date trackers of facial recognition bans and restrictions by jurisdiction.
  2. File a public records request. In many US jurisdictions, residents can submit a Freedom of Information request asking whether local police use facial recognition, which vendor they contract with, and how many times the technology has been used.
  3. Report commercial scanning. In Illinois, individuals who believe a company scanned their face without consent can contact a BIPA attorney. In the EU, complaints can go to the relevant national data protection authority (DPA).
  4. Contact elected representatives. City-level bans in the US have consistently been driven by public pressure. Residents who want facial recognition restrictions in their area typically start by contacting their city council members or state legislators.
  5. Exercise data rights where available. Under GDPR in the EU, individuals can request what biometric data a company holds and demand deletion. Under BIPA in Illinois, individuals can request that biometric data be destroyed once the original collection purpose is fulfilled.

Tools That Can Help

There are no affiliate recommendations for this article. For practical privacy tools related to data broker removal and biometric data protection, see our data broker opt-out guide.

Related Articles

Frequently Asked Questions

Which US cities have banned facial recognition?

At least 16 US cities have banned government use of facial recognition, including San Francisco (2019), Boston, Oakland, Portland (Oregon), Minneapolis, and Milwaukee (2026). Enforcement has been inconsistent some departments have asked neighboring agencies to run searches on their behalf.

Can police use facial recognition to identify suspects?

It depends on location. In the EU, real-time police facial recognition in public spaces is generally banned under the AI Act, with narrow exceptions. In the UK, police use it widely with no specific legislation. In the US, at least seven states prohibit police from using a facial recognition match as the sole basis for an arrest.

Is facial recognition banned in the EU?

Real-time facial recognition by law enforcement in public spaces is banned under the EU AI Act (2024), which became enforceable in February 2025. However, the ban has exceptions for terrorism, missing persons, and serious crimes. Private-sector uses of facial recognition are not outright banned but remain subject to strict GDPR consent and data protection rules.

Can stores use facial recognition on customers?

In most of the United States, yes and they do not need to tell you or ask permission. Illinois is the major exception: under BIPA, stores must get written consent before scanning your face, and individuals can sue for violations. In the EU, commercial facial recognition generally requires explicit consent under GDPR. In the UK, there is currently no law specifically addressing retail facial recognition.

The question of facial recognition legal issues is far from settled new laws continue to pass at the city and state level in the US, enforcement of the EU AI Act is ramping up, and the UK is still debating whether to write its first dedicated legislation. The protections available to any person today depend almost entirely on where they happen to be standing.

This article is for educational purposes only and does not constitute legal advice. Laws vary by jurisdiction and change frequently. For advice specific to your situation, consult a qualified attorney.

Sources & Further Reading

Pinterest graphic about facial recognition legal issues with scan grid face icon, shield, and gavel on navy background

Written by Alex

Alex is the editorial pen name of Mohammed Ez-Zayady, a law student based in Morocco and the founder of Jovonk. The content is provided for educational purposes and does not constitute legal advice.