“1. It is of paramount importance that the law enforcement agencies should take full advantage of the available techniques of modern technology and forensic science. Such real evidence has the inestimable value of cogency and objectivity. It is in large measure not affected by the subjective defects of other testimony. It enables the guilty to be detected and the innocent to be rapidly eliminated from inquiries. Thus, in the 1990s closed circuit television (CCTV) became a crime prevention strategy extensively adopted in British cities and towns. The images recorded facilitate the detection of crime and prosecution of offenders. Making due allowance for the possibility of threats to civil liberties, this phenomenon has had beneficial effects. 2. The use of fingerprint evidence in this country dates from as long ago as 1902. In due course other advances of forensic science followed. But the dramatic breakthrough was the use of DNA techniques since the 1980s. The benefits to the criminal justice system are enormous. For example, recent Home Office statistics show that while the annual detection rate of domestic burglary is only 14%, when DNA is successfully recovered from a crime scene this rises to 48%. It is, of course, true that such evidence is capable of being misused and that courts must be ever watchful to eliminate risks of human error creeping in. But as a matter of policy it is a high priority that police forces should expand the use of such evidence where possible and practicable.”
“The United Kingdom has never had a secret police or internal intelligence agency comparable to those that have existed in some other European countries, the East German Stasi being a wellknown example. There has however been growing concern in recent times about surveillance and the collection and use of personal data by the state. … But such concern on this side of the Channel might be said to have arisen later, and to be less acutely felt, than in many other European countries, where for reasons of history there has been a more vigilant attitude towards state surveillance. That concern and vigilance are reflected in the jurisprudence of the European Court of Human Rights in relation to the collection, storage and use by the state of personal data. The protection offered by the common law in this area has, by comparison, been of a limited nature.”
“Article 8 1. Everyone has the right to respect for his private and family life, his home and his correspondence. 2. There shall be no interference by a public authority with the exercise of this right except such as is in accordance with the law and is necessary in a democratic society in the interests of national security, public safety or the economic well-being of the country, for the prevention of disorder or crime, for the protection of health or morals, or for the protection of the rights and freedoms of others.”
“57. There are a number of elements relevant to a consideration of whether a person's private life is concerned by measures effected outside a person's home or private premises. Since there are occasions when people knowingly or intentionally involve themselves in activities which are or may be recorded or reported in a public manner, a person's reasonable expectation as to privacy may be a significant, although not necessarily conclusive, factor. A person who walks down the street will, inevitably, be visible to any member of the public who is also present. Monitoring by technological means of the same public scene (for example, a security guard viewing through closed-circuit television) is of a similar character. Private-life considerations may arise,however, once any systematic or permanent record comes intoexistence of such material from the public domain …”
“84. … While true, this consideration cannot alter the fact that fingerprints objectively contain unique information about the individual concerned allowing his or her identification with precision in a wide range of circumstances. They are thus capable of affecting his or her private life and retention of this information without the consent of the individual concerned cannot be regarded as neutral or insignificant.”
“18. … The automated capture of facial biometrics, and conversion of those images into biometric data, involves large scale and relatively indiscriminate processing of personal data. If such processing is not subject to appropriate safeguards, such data … could be collected … in a manner amounting to a serious interference with privacy rights.” interference with privacy rights.”
“ 102. … The fact that a power is exercised sparingly has no direct bearing on its legality. A power on which there are insufficient legal constraints does not become legal simply because those who may not have resort to it, exercise self-restraint. It is the potential reach of the power rather than its actual use by which its legality must be judged.”
“303. Given that [the Protection of Freedoms Act] is not generic legislation covering all biometrics used by the police, the use by the police of these second generation biometrics [which the Commissioner defined as including facial image matching] is not currentlygoverned by any specific legislation, other than generaldata protection legislation, and only by regulationsdrawn up by the police themselves such as the Management of Police Information principles (MOPI) drawn up by the College of Policing. It is therefore the case that technical development and deployment isrunning ahead of legislation, which is why the HomeOffice’s promised biometric strategy is urgentlyneeded”
“ [I]t is part of the obligations and duties of a police constable to take all steps which appear to him necessary for keeping the peace, for preventing crime or for protecting property from criminal damage. There is no exhaustive definition of the powers and obligations of the police, but they are at least those, and they would further include the duty to detect crime and to bring an offender to justice.”
“At common law the police have the power to obtain and store information for policing purposes, i.e.broadlyspeaking for the maintenance of public order and theprevention and detection of crime. These powers do not authorise intrusive methods of obtaining information, such as entry onto private property or acts (other than arrest under common law powers) which would constitute an assault. But they were amply sufficient to authorise the obtaining and storage of the kind of public information in question on these appeals.”
“ The lawfulness requirement in the Convention addresses supremely important features of the rule of law. The exercise of power by public officials, as it affects members of the public, must be governed by clear and publicly accessible rules of law. The public must not be vulnerable to interference by public officials acting on any personal whim, caprice, malice, predilection or purpose other than that for which the power was conferred. This is what, in this context, is meant by arbitrariness, which is the antithesis of legality. This is the test which any interference with or derogation from a Convention right must meet if a violation is to be avoided.”
“103. The protection of personal data is of fundamental importance to a person’s enjoyment of his or her right to respect for private and family life, as guaranteed byart. 8 of the Convention . The domestic law must afford appropriate safeguards to prevent any … use of personal data as may be inconsistent with the guarantees of this article. The need for such safeguards is all the greater where the protection of personal dataundergoing automatic processing is concerned, not leastwhen such data are used for police purposes. The domestic law should notably ensure that such data are relevant and not excessive in relation to the purposes for which they are stored. The domestic law must also afford adequate guarantees that retained personal data was efficiently protected from misuse and abuse. The above considerations are especially valid as regards the protection of special categories of more sensitive data and more particularly of DNA information, which contains the person's genetic make-up of great importance to both the person concerned and his or her family. 104. The interests of the data subjects and the community as a whole in protecting the personal data, including fingerprint and DNA information, may be outweighed by the legitimate interest in the prevention of crime. However, the intrinsically private character of this information calls for the Court to exercise careful scrutiny of any State measure authorising its retention and use by the authorities without the consent of the person concerned.”
“data”; “processing”; and “personal data”
“in relation to information or data, means obtaining, recording or holding the information or data or carrying out any operation or set of operations on the information or data, including – (a) organisation, adaptation or alteration of the information or data, (b) retrieval, consultation or use of the information or data, disclosure of the information or data by transmission, dissemination or otherwise making available, or (c) alignment, combination, blocking, erasure, or destruction of the information or data”. “Personal data” is defined as meaning (a) is being processed by means of equipment operating automatically in response to instructions giving for (b) is recorded with the intention that it should be processed “in relation to information or data, means obtaining, recording or holding the information or data or carrying out any operation or set of operations on the information or data, including – (a) organisation, adaptation or alteration of the information or data, (b) retrieval, consultation or use of the information or data, disclosure of the information or data by transmission, dissemination or otherwise making available, or (c) alignment, combination, blocking, erasure, or destruction of the information or data”. (a). from those data, or (b). from those data and other information which is in the possession, of or is likely to come into the procession of, the data controller, and includes any expression of opinion about the individual and any indication of the intentions of the data controller or any other person in respect of the individual.”
“115. We think the case that the BGI constitutes personal data under section 1(1)(a) of the 1998 Act is clearly arguable: it is supported by the terms of the Directive, as explained in the working party’s opinion, and the decision of the Court of Justice in the Lindqvist case (Case C-101/01 )[2004] QB 1014 . The various points made by Mr White in response do not alter our view. The case for the claimants in more detail is this. Ifsection 1 of the 1998 Act is appropriately defined in linewith the provisions and aims of the Directive,identification for the purposes of data protection isabout data that “individuates” the individual, in thesense that they are singled out and distinguished fromall others. It is immaterial that the BGI does not name the user. The BGI singles them out and therefore directly identifies them for the purposes of section 1(1)(a) having regard to the following: (i) BGI information comprises two relevant elements: (a) detailed browsing histories comprising a number of elements such as the website visited, and dates and times when websites are visited; and (b) information derived from use of the “double-click” cookie, which amounts to a unique identifier, enabling the browsing histories to be linked to an individual device/user; and the defendant to recognise when and where the user is online, so advertisements can be targeted at them, based on an analysis of their browsing history. (ii) Taking those two elements together, the BGI enables the defendant to single out users because it tells the defendant (a) the unique ISP address of the device the user is using ie a virtual postal address; (b) what websites the user is visiting; (c) when the user is visiting them; (d) and, if geo-location is possible, the location of the user when they are visiting the website; (e) the browser’s complete browsing history; (f) when the user is online undertaking browser activities. The defendant therefore not only knows the user’s (virtual) address; it knows when the user is at his or her (virtual) home.”
“35 The first data protection principle (1) The first data protection principle is that the processing of personal data for any of the law enforcement purposes must be lawful and fair. (2) The processing of personal data for any of the law enforcement purposes is lawful only if and to the (1) The first data protection principle is that the processing of personal data for any of the law enforcement purposes must be lawful and fair. (2) The processing of personal data for any of the law enforcement purposes is lawful only if and to the extent that it is based on law and either — (a). the data subject has given consent to the 152. processing for that purpose, or (b). the processing is necessary for the performance of a task carried out for that purpose by a competent authority. (3). In addition, where the processing for any of the law enforcement purposes is sensitive processing, the processing is permitted only in the two cases set out in subsections (4) and (5). (4). The first case is where — (a) the data subject has given consent to the processing for the law enforcement purpose as mentioned in subsection (2)(a), and (b) at the time when the processing is carried out, the controller has an appropriate policy document in place (see section 42). (5). The second case is where — (a) the processing is strictly necessary for the law enforcement purpose, (b) the processing meets at least one of the conditions in Schedule 8, and (c) at the time when the processing is carried out, the controller has an appropriate policy document in place (see section 42). (6). The Secretary of State may by regulations amend Schedule 8 (a) by adding conditions; (b) by omitting conditions added by regulations under paragraph (a). (7). Regulations under subsection (6) are subject to the affirmative resolution procedure. (8). In this section, "sensitive processing" means— (a) the processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership; (b) the processing of genetic data, or of biometric data, for the purpose of uniquely identifying an individual; (c) the processing of data concerning health; (d) the processing of data concerning an individual's sex life or sexual orientation.”
“18. The notion of “identifiable” refers not only to the individual’s civil or legal identity as such, but also to what may allow to “individualise” or single out (and thus allow to treat differently) one person from others. This “individualisation” could be done, for instance, by referring to him or her specifically, or to a device or a combination of devices (computer, mobile phone, camera, gaming devices, etc.) on the basis of an identification number, a pseudonym, biometric or genetic data, location data, an IP address, or other identifier. The use of a pseudonym or of any digital identifier/digital identity does not lead to anonymisation of the data as the data subject can still be identifiable or individualised. Pseudonymous data is thus to be considered as personal data and is covered by the provisions of the Convention. The quality of the pseudonymisation techniques applied should be duly taken into account when assessing the appropriateness of safeguards implemented to mitigate the risks to data subjects … 58. Processing of biometric data, that is data resulting from a specific technical processing of data concerning the physical, biological or physiological characteristics of an individual which allows the unique identification or authentication of the individual, is also considered sensitive when it is precisely used to uniquely identify the data subject. 59. The context of the processing of images is relevant to the determination of the sensitive nature of the data. The processing of images will not generally involve processing of sensitive data as the images will only be covered by the definition of biometric data when being processed through a specific technical means which permits the unique identification or authentication of an individual. Furthermore, where processing of images is intended to reveal racial, ethnic or health information (see the following point), such processing will be considered as processing of sensitive data. On the contrary, images processed by a video surveillance system solely for security reasons in a shopping area will not generally be considered as processing of sensitive data.”
“strictly necessary … has to be understood as a call to pay particular attention to the necessity principle in the context of processing special categories of data, as well as to foresee precise and particularly solid justifications for the processing of such data”
“… to the extent that views are expressed on matters requiring assessment or evaluation the court should go no further in its review than to identify whether the essential questions have been conscientiously considered and that any conclusions reached are not irrational. Inessential errors or misjudgements cannot constitute evidence of the breach of the duty.”
“1. The data subject has given his consent to the processing. … 5. The processing is necessary— (a) for the administration of justice, (b) for the exercise of any functions conferred on any person by or under any enactment, (c) for the exercise of any functions of the Crown, a Minister of the Crown or a government department, or (d) for the exercise of any other functions of a public nature exercised in the public interest by any person.” (a) for the administration of justice, (b) for the exercise of any functions conferred on any person by or under any enactment, (c) for the exercise of any functions of the Crown, a Minister of the Crown or a government department, or (d) for the exercise of any other functions of a public nature exercised in the public interest by any person.”
“(a) closed circuit television or automatic number plate recognition systems, (b) any other systems for recording or viewing visual images for surveillance purposes, (c) any systems for storing, receiving, transmitting, processing or checking images or information obtained by systems falling within paragraph (a) or (b), or (d) any other systems associated with, or otherwise connected with,systems falling within paragraph (a), (b) or (c).”
“(1) A relevant authority must have regard to the surveillance cameracode when exercising any functions to which the code relates. (2) A failure on the part of any person to act in accordance with any provision of the surveillance camera code does not of itself make that person liable to criminal or civil proceedings. (3) The surveillance camera code is admissible in evidence in any such proceedings. (4) A court or tribunal may, in particular, take into account a failure by a relevant authority to have regard to the surveillance camera code in determining a question in any such proceedings.”
“34 Overview and general duty of controller (1) This Chapter sets out the six data protection principles as follows— (a) section 35(1)sets out the first data protection principle (requirement that processing be lawful and fair); (b) section 36(1)sets out the second data protection principle (requirement that purposes of processing be specified, explicit and legitimate); (c) section 37sets out the third data protection principle (requirement that personal data be adequate, relevant and not excessive); (d) section 38(1)sets out the fourth data protection principle (requirement that personal data be accurate and kept up to date); (e) section 39(1)sets out the fifth data protection principle (requirement that personal data be kept for no longer than is necessary); (f) section 40sets out the sixth data protection principle (requirement that personal data be processed in a secure manner). (2) In addition— (a) each of sections 35, 36,38 and 39makes provision to supplement the principle to which it relates, and (b) sections 41 and 42make provision about the safeguards that apply in relation to certain types of processing. (3) The controller in relation to personal data is responsible for, and must be able to demonstrate, compliance with this Chapter.”
“…the processing of… biometric data… for the purpose of uniquely identifying an individual.”
“…personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of an individual, which allows or confirms the unique identification of that individual, such as facial images or dactyloscopic data”
“1. Statutory etc purposes This condition is met if the processing- (a) is necessary for the exercise of a function conferred on a person by an enactment or rule of law, and (b) is necessary for reasons of substantial public interest. 2. Administration of justice This condition is met if the processing is necessary for the administration of justice. … 6. Legal claims This condition is met if the processing- (a) is necessary for the purpose of, or in connection with, any legal proceedings (including prospective legal proceedings)…”
“42 Safeguards: sensitive processing (1) This section applies for the purposes of section 35(4) and (5) (which require a controller to have an appropriate policy document in place when carrying out sensitive processing in reliance on… a condition specified in Schedule 8). (2) The controller has an appropriate policy document in place in relation to the sensitive processing if the controller has produced a document which— (a) explains the controller’s procedures for securing compliance with the data protection principles (see section 34(1)) in connection with sensitive processing in reliance on the consent of the data subject or (as the case may be) in reliance on the condition in question, and (b) explains the controller’s policies as regards the retention and erasure of personal data processed in reliance on the consent of the data subject or (as the case may be) in reliance on the condition in question, giving an indication of how long such personal data is likely to be retained. (3) Where personal data is processed on the basis that an appropriate policy document is in place, the controller must during the relevant period— (a) retain the appropriate policy document, (b) review and (if appropriate) update it from time to time, and (c) make it available to the Commissioner, on request, without charge. (4) The record maintained by the controller under section 61(1) and, where the sensitive processing is carried out by a processor on behalf of the controller, the record maintained by the processor under section 61(3) must include the following information— (a) …which condition in Schedule 8 is relied on, (b) how the processing satisfies section 35 (lawfulness of processing), and (c) whether the personal data is retained and erased in accordance with the policies described in subsection (2)(b) and, if it is not, the reasons for not following those policies. (5) In this section, “relevant period”, in relation to sensitive processing …in reliance on a condition specified in Schedule 8, means a period which— (a) begins when the controller starts to carry out the sensitive processing …in reliance on that condition, and (b) ends at the end of the period of 6 months beginning when the controller ceases to carry out the processing.” out sensitive processing in reliance on… a condition specified in Schedule 8). (a) explains the controller’s procedures for securing compliance with the data protection principles (see section 34(1)) in connection with sensitive processing in reliance on the consent of the data subject or (as the case may be) in reliance on the condition in question, and (b) explains the controller’s policies as regards the retention and erasure of personal data processed in reliance on the consent of the data subject or (as the case may be) in reliance on the condition in question, giving an indication of how long such personal data is likely to be retained. (b) review and (if appropriate) update it from time to time, and (c) make it available to the Commissioner, on request, without charge. (a) …which condition in Schedule 8 is relied on, (b) how the processing satisfies section 35 (lawfulness of processing), and (c) whether the personal data is retained and erased in accordance with the policies described in subsection (2)(b) and, if it is not, the reasons for not following those policies. (a) begins when the controller starts to carry out the sensitive processing …in reliance on that condition, and (b) ends at the end of the period of 6 months beginning when the controller ceases to carry out the processing.”
“1. Use of a surveillance camera system must always be for a specified purpose which is in pursuit of a legitimate aim and necessary to meet an identified pressing need. 2. The use of a surveillance camera system must take into account its effect on individuals and their privacy, with regular reviews to ensure its use remains justified. 3. There must be as much transparency in the use of a surveillance camera system as possible, including a published contact point for access to information and complaints. 4. There must be clear responsibility and accountability for all surveillance camera system activities including images and information collected, held and used. 5. Clear rules, policies and procedures must be in place before a surveillance camera system is used, and these must be communicated to all who need to comply with them. 6. No more images and information should be stored than that which is strictly required for the stated purpose of a surveillance camera system, and such images and information should be deleted once their purposes have been discharged. 7. Access to retained images and information should be restricted and there must be clearly defined rules on who can gain access and for what purpose such access is granted; the disclosure of images and information should only take place when it is necessary for such a purpose or for law enforcement purposes. 8. Surveillance camera system operators should consider any approved operational, technical and competency standards relevant to a system and its purpose and work to meet and maintain those standards. 9. Surveillance camera system images and information should be subject to appropriate security measures to safeguard against unauthorised access and use. 10. There should be effective review and audit mechanisms to ensure legal requirements, policies and standards are complied with in practice, and regular reports should be published. 11. When the use of a surveillance camera system is in pursuit of a legitimate aim, and there is a pressing need for its use, it shouldthen be used in the most effective way to support public safety and law enforcement with the aim of processing images and information of evidential value. 12. Any information used to support a surveillance camera system which compares against a reference database for matching purposes should be accurate and kept up to date.”
“1.8 This code has been developed to address concerns over thepotential for abuse or misuse of surveillance by the state in publicplaces.” “2.1 Modern and forever advancing surveillance camera technology provides increasing potential for the gathering and use of images and associated information. These advances vastly increase the ability and capacity to capture, store, share and analyse images and information. This technology can be a valuable tool in the management of public safety and security, in the protection of people and property, in the prevention and investigation of crime, and in bringing crimes to justice. Technological advances can also provide greater opportunity to safeguard privacy. Used appropriately, current and future technology can and will provide a proportionate and effective solution where surveillance is in pursuit of a legitimate aim and meets a pressing need.” “2.2 In general, any increase in the capability of surveillance camera system technology also has the potential to increase the likelihood of intrusion into an individual’s privacy.The Human Rights Act 1998 gives effect in UK law to the rights set out in the European Convention on Human Rights (ECHR). Some of these rights are absolute, whilst others are qualified, meaning that it is permissible for the state to interfere with the right provided that the interference is in pursuit of a legitimate aim and the interference is proportionate. Amongst the qualified rights is a person’s right to respect for their private and family life, home and correspondence, as provided for byArticle 8 of the ECHR .” “2.3 That is not to say that all surveillance camera systems use technology which has a high potential to intrude on the right to respect for private and family life. Yet this code must regulate that potential,now and in the future. In considering the potential to interfere with the right to privacy, it is important to take account of the fact that expectations of privacy are both varying and subjective. In general terms, one of the variables is situational, and in a public place there is a zone of interaction with others which may fall within the scope of private life. An individual can expect to be the subject of surveillance in a public place as CCTV, for example, is a familiar feature in places that the public frequent. An individual can, however, rightly expect surveillance in public places to be both necessary and proportionate, with appropriate safeguards in place.” “2.4 The decision to use any surveillance camera technology must, therefore, be consistent with a legitimate aim and a pressing need. Such a legitimate aim and pressing need must be articulated clearly and documented as the stated purpose for any deployment. The technicaldesign solution for such a deployment should be proportionate to thestated purpose rather than driven by the availability of funding ortechnological innovation. Decisions over the most appropriate technology should always take into account its potential to meet the stated purpose without unnecessary interference with the right to privacy and family life. Furthermore, any deployment should not continue for longer than necessary.” “3.2.3 Any use of facial recognition or other biometric characteristicrecognition systems needs to be clearly justified and proportionate inmeeting the stated purpose, and be suitably validated 4. It should always involve human intervention before decisions are taken that affect an individual adversely. (Footnote 4 The Surveillance Camera Commissioner will be a source of advice on validation of such systems).” “4.8.1 Approved standards may apply to the system functionality, the installation and the operation and maintenance of a surveillance camera system. These are usually focused on typical CCTV installations, however there may be additional standards applicable where the system has specific advanced capability such as ANPR, video analytics or facial recognition systems, or where there is a specific deployment scenario, for example the use of body-worn video recorders.” “4.12.1 Any use of technologies such as ANPR or facial recognitionsystems which may rely on the accuracy of information generated elsewhere such as databases provided by others should not be introduced without regular assessment to ensure the underlying data is fit for purpose.” “4.12.2 A system operator should have a clear policy to determine the inclusion of a vehicle registration number or a known individual’s details on a reference database associated with such technology. A system operator should ensure that reference data is not retained for longer than necessary to fulfil the purpose for which it was originally added to a database.”
“What safeguards are required for sensitive processing? If you are carrying out sensitive processing based on the consent of a data subject, or based on another specific condition in Schedule 8 of the Act, you must have an appropriate policy document in place. The appropriate policy must explain: - your procedures for complying with the data protection principles when relying on a condition from Schedule 8; and - your policy for the retention and erasure of personal data for this specific processing. You must retain this policy from the time you begin sensitive processing until six months after it has ended. You must review and update it where appropriate and make it available to the Information Commissioner upon request without charge.”
“3. Compliance with Data Protection Principles a) ‘lawfulness and fairness’ The lawfulness of South Wales Police processing is derived from its official functions as a UK police service, which includes the investigation and detection of crime and the apprehension of offenders, including acting in obedience to court warrants that require the arrest of defendants who have failed to attend court. b) ‘data minimisation’ South Wales police only processes sensitive personal data when permitted to do so by law. Such personal data is collected for explicit and legitimate purposes such as biometric data during the deployment of Automatic Facial Recognition technology. c) ‘accuracy’ During AFR Locate deployments South Wales Police collects the information necessary to determine whether the individual is on a watchlist. If an intervention is made the process will not prompt data subjects to answer questions and provide information that is not required. Where processing is for research and analysis purposes, wherever possible this is done using anonymised or deidentified data sets. d) ‘storage limitation’ Providing complete and accurate information is required when constructing a watchlist. During AFR Locate deployments watchlists will be constructed on the day of deployment and where the deployments extend beyond 24 hours these will be amended daily. Where permitted by law and when it is reasonable and proportionate to do so, South Wales Police may check this information with other organisations – for example other police and law enforcement services. If a change is reported by a data subject to one service or a part of South Wales Police, whenever possible this is also used to update the AFR application, both to improve accuracy and avoid the data subject having to report the same information multiple times. e) ‘integrity and confidentiality’ South Wales Police has a comprehensive set of retention policies in place which are published online, further information specific to AFR can be found on SWP AFR webpage. All staff handling South Wales Police information are security cleared and required to complete annual training on the importance of security, and how to handle information appropriately. In addition to having security guidance and policies embedded throughout SWP business, SWP also has specialist security, cyber and resilience staff to help ensure that information is protected from risks of accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.” a) ‘lawfulness and fairness’ The lawfulness of South Wales Police processing is derived from its official functions as a UK police service, which includes the investigation and detection of crime and the apprehension of offenders, including acting in obedience to court warrants that require the arrest of defendants who have failed to attend court. b) ‘data minimisation’ South Wales police only processes sensitive personal data when permitted to do so by law. Such personal data is collected for explicit and legitimate purposes such as biometric data during the deployment of Automatic Facial Recognition technology. c) ‘accuracy’ During AFR Locate deployments South Wales Police collects the information necessary to determine whether the individual is on a watchlist. If an intervention is made the process will not prompt data subjects to answer questions and provide information that is not required. Where processing is for research and analysis purposes, wherever possible this is done using anonymised or deidentified data sets. d) ‘storage limitation’ Providing complete and accurate information is required when constructing a watchlist. During AFR Locate deployments watchlists will be constructed on the day of deployment and where the deployments extend beyond 24 hours these will be amended daily. Where permitted by law and when it is reasonable and proportionate to do so, South Wales Police may check this information with other organisations – for example other police and law enforcement services. If a change is reported by a data subject to one service or a part of South Wales Police, whenever possible this is also used to update the AFR application, both to improve accuracy and avoid the data subject having to report the same information multiple times. e) ‘integrity and confidentiality’ South Wales Police has a comprehensive set of retention policies in place which are published online, further information specific to AFR can be found on SWP AFR webpage. All staff handling South Wales Police information are security cleared and required to complete annual training on the importance of security, and how to handle information appropriately. In addition to having security guidance and policies embedded throughout SWP business, SWP also has specialist security, cyber and resilience staff to help ensure that information is protected from risks of accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.”