Prohibited Practices That Rule Out Certain Policing Uses

Understanding Prohibited Practices
Police forces must understand that certain uses of biometric and analytics tools are categorically prohibited by law and policy. These restrictions apply regardless of technological sophistication or potential benefits. Managers must ensure their teams recognise these boundaries clearly. The prohibition extends beyond simple misuse to include any approach that violates fundamental rights or legal frameworks.
Prohibited practices typically involve surveillance or data processing that breaches privacy rights, creates unlawful discrimination, or operates outside established legal parameters. These restrictions apply to all staff levels, from frontline officers to senior management. The consequences of violating these rules extend beyond individual disciplinary action to organisational liability and public trust erosion.
Unlawful Surveillance and Monitoring
Unlawful surveillance practices represent one of the most significant categories of prohibited activities. These include continuous monitoring of individuals or groups without proper legal basis or judicial authorisation. For example, using facial recognition technology to track individuals in public spaces without specific court approval or operational necessity violates data protection principles.
- Monitoring individuals based solely on their membership of protected groups
- Creating databases of individuals merely for being present in certain locations
- Using analytics tools to predict criminal behaviour based on demographic characteristics
- Conducting surveillance of political activists or journalists
Specific examples of unlawful surveillance include deploying automatic number plate recognition systems to monitor the movements of individuals who have not been identified as suspects. Similarly, using biometric data to identify people in public spaces without reasonable suspicion or specific legal authority breaches privacy rights. These practices cannot be justified by operational efficiency or crime prevention goals.
Discriminatory Use of Analytics
Discriminatory practices through analytics tools occur when algorithms or data processing systems produce outcomes that disproportionately affect protected characteristics. These prohibited uses include any approach that reinforces existing biases or creates new forms of unfair treatment. The prohibition applies to both direct discrimination and indirect discrimination through seemingly neutral processes.
Examples of discriminatory analytics use include employing risk assessment tools that weight factors such as postcode, employment status, or educational background in ways that disadvantage particular groups. These approaches cannot be justified through statistical correlation or predictive models. The law requires that any data processing must not result in unlawful discrimination against protected characteristics including race, gender, religion, or sexual orientation.
- Using predictive policing models that disproportionately target ethnic minorities
- Applying risk scoring systems that penalise individuals based on socioeconomic factors
- Creating profiling systems that rely on protected characteristics
- Automating decisions that would otherwise require human discretion
Managers must ensure that any analytics tool deployment undergoes thorough assessment for discriminatory impact. This includes examining whether the tool’s outcomes create unfair treatment or reinforce existing inequalities. The prohibition exists regardless of whether these outcomes are intentional or accidental.
Other prohibited practices include using biometric data for purposes beyond those originally authorised. This includes sharing data with third parties without proper legal basis or failing to implement appropriate data protection measures. The prohibition also covers using these tools to monitor or control individuals who have not been identified as suspects or subjects of investigation.
Organisations must maintain clear records of all biometric and analytics tool usage. This documentation must demonstrate compliance with legal requirements and demonstrate that prohibited practices have not occurred. Regular audits and staff training ensure that these boundaries remain clear and respected. The prohibition applies to all staff members, including those who develop, implement, or use these technologies.
Any attempt to circumvent these restrictions through technical workarounds or procedural modifications remains prohibited. The law requires that these boundaries be respected through proper legal processes, not through creative interpretation of rules. Managers must ensure that their teams understand these limitations clearly and maintain appropriate oversight of all activities involving these technologies.
