About

Using Facial Recognition Without Losing Public Trust

Using Facial Recognition Without Losing Public Trust
Published on 8/18/2026

Facial recognition can solve real problems. It can help secure restricted areas, reduce credential sharing, support fraud prevention and speed up identity checks. It can also make people feel watched, misidentified or powerless if the system is introduced without clear rules.

That tension matters in Jamaica. The Data Protection Act 2020 has made privacy a boardroom issue, not just an IT or legal concern. When an organisation uses a person’s face as an access key or matching tool, it is processing deeply personal information. Public trust depends on whether people believe the use is necessary, fair, secure and limited.

The goal is not to avoid every privacy-sensitive technology. The goal is to prove that facial recognition is being used for a legitimate purpose, with safeguards strong enough for the risk.

Facial recognition is not just another camera

Many organisations treat facial recognition as a simple upgrade to CCTV. That is a mistake. Traditional CCTV records images for later review. Facial recognition extracts or compares facial characteristics so a person can be identified, verified or matched against a database.

That difference changes the trust equation. A password can be reset. A card can be replaced. A face cannot. If biometric templates are exposed, misused or repurposed, the individual may carry that risk for years.

The public also reacts differently to face scanning because it can happen silently. A person can see a turnstile, a receptionist or a security guard. They may not know whether a camera is simply recording video or actively comparing faces. When people discover the technology after the fact, the issue becomes larger than compliance. It becomes a question of honesty.

Start with necessity, not novelty

The first governance question should not be, “Which vendor has the best facial recognition system?” It should be, “What specific problem are we trying to solve, and is facial recognition necessary to solve it?”

A vague purpose such as “improving security” is too broad. A stronger purpose is more specific, such as preventing unauthorised entry to a sensitive server room where card sharing has already been documented. The narrower the purpose, the easier it is to assess necessity, proportionality and public expectations.

Before adopting facial recognition, compare it with less intrusive options. Could the same result be achieved with access cards, PINs, guards, better visitor procedures or multi-factor authentication? If a lower-risk method works reasonably well, facial recognition may be difficult to justify.

Proportionality also depends on where the system is used. A biometric check at the entrance to a restricted laboratory is different from scanning everyone entering a shopping centre. The number of people affected, the sensitivity of the location, the availability of alternatives and the consequences of a false match all affect whether the use is reasonable.

Map the Data Protection Act obligations before launch

Under Jamaica’s Data Protection Act 2020, organisations that determine why and how personal data is processed must handle that data in line with core data protection standards. Facial recognition should be treated as high-risk processing because it involves biometric identification or verification and can affect access, movement, employment or service delivery.

For a Jamaican organisation, compliance planning should address:

  • The lawful basis or statutory authority for using facial recognition

  • The exact purpose for collecting and comparing facial data

  • Whether consent is valid, especially where there is a power imbalance

  • How much data is collected and whether raw images are truly needed

  • How long facial images or templates are retained

  • Who has access to the system and audit logs

  • Whether a third-party vendor processes or hosts the data

  • How individuals can exercise rights, raise concerns or challenge decisions

Employment settings deserve special care because staff may feel they have no genuine choice. If your organisation is considering workplace biometrics, PLMC has a separate guide on biometric data risks employers should consider.

Run a privacy and trust assessment

A facial recognition project should not move from sales demo to live deployment without a documented risk assessment. Many organisations use the language of a Data Protection Impact Assessment, but the exercise should be broader than a legal checklist. It should test whether the use will be understood and accepted by the people affected.

Include legal, IT security, operations, human resources, communications and the business owner. For public-facing deployments, consider whether community consultation or stakeholder engagement is appropriate before launch. The earlier concerns are heard, the easier they are to address without reputational damage.

Trust question

Why it matters

Practical safeguard

What problem is being solved?

Vague purposes invite function creep

Write a narrow purpose statement and approve changes formally

Who will be scanned?

Risk increases as more people are affected

Limit use to defined areas, groups or transactions

What happens if the system is wrong?

False matches can deny access or damage reputation

Require human review before any adverse action

Can people use an alternative?

Choice supports fairness and accessibility

Provide a non-biometric route where feasible

How long is data kept?

Long retention increases breach and misuse risk

Set retention periods and automatic deletion rules

Who can see or export the data?

Access abuse can destroy trust

Use role-based access, logging and regular reviews

This assessment should be revisited when the system changes. A deployment approved for staff access control should not quietly become a customer analytics tool, attendance monitor or law enforcement feed without a fresh assessment and updated transparency.

Accuracy and bias are governance issues

Facial recognition errors are not only technical failures. They can become fairness, discrimination and public confidence issues.

The U.S. National Institute of Standards and Technology has tested face recognition algorithms for years through its Face Recognition Vendor Test. NIST’s work has shown that performance varies significantly by algorithm, use case and demographic factors. This does not mean every system is unreliable. It means organisations should not accept a vendor’s accuracy claim without understanding the testing conditions.

Local conditions matter. Lighting, camera angle, image quality, age range, skin tone diversity, facial coverings, uniforms and environmental factors can all affect performance. A system that performs well in a controlled demonstration may produce different results at a busy entrance, airport queue, hotel lobby or outdoor facility.

Responsible deployment should include local testing before full rollout. Test false match rates and false non-match rates. Document the threshold settings. Decide in advance what level of error is acceptable for the specific use case. Most importantly, do not allow the system alone to make high-impact decisions.

A facial recognition alert should usually be treated as a signal requiring human review, not proof. Security teams and managers must be trained to avoid treating a possible match as a final conclusion.

Transparency should happen before people are scanned

Trust improves when people understand what is happening before they are affected. Notices should be visible, plain and specific. A small sign saying “CCTV in operation” is not enough if the system is performing facial recognition.

A good notice should explain who is operating the system, why facial recognition is used, whether participation is mandatory, what data is stored, how long it is kept, who receives it and how people can ask questions. For employees, this should be backed by an internal policy and training. For customers or visitors, information should be available at the point of entry and through a fuller privacy notice.

Avoid burying key details in a long privacy policy. People should not need legal training to learn whether their face is being scanned. If the deployment affects the public, a short public-facing explanation can prevent rumours and misinformation from filling the gap.

A secure building entrance shows a facial recognition privacy notice, a staffed assistance desk, and signs for alternative identity checks.

Set firm limits against function creep

Function creep is one of the fastest ways to lose public trust. A system introduced for one purpose gradually gets used for another because the data already exists and the technology makes it easy.

For example, facial recognition introduced for high-security access might later be proposed for staff attendance, customer profiling, queue analytics or identifying people on a watchlist. Each new use changes the risk profile. It may also change what individuals were told when their data was collected.

Prevent this with a formal change control process. Any new purpose should require legal review, risk reassessment, senior approval and updated notices. If the new purpose cannot be justified on its own, the fact that the technology is already installed should not make it acceptable.

Data minimisation is also central to trust. Do not collect more facial data than necessary. Do not retain raw images if templates are sufficient. Do not keep templates for people who no longer need access. The same principle applies across privacy programmes, as PLMC explains in its guide on how to spot over-collection before it becomes a problem.

Put strong vendor and cybersecurity controls in place

Many facial recognition systems depend on external vendors, cloud hosting, device manufacturers, software updates and support teams. That creates a supply chain risk. A weak contract or poorly reviewed vendor can undermine even a well-intentioned project.

Before procurement, ask direct questions. Where is the data stored? Is it transferred outside Jamaica? Is the vendor a processor, joint controller or independent controller? Can the vendor use images or templates to train its models? Are subcontractors involved? What happens to the data when the contract ends?

The contract should cover confidentiality, security controls, breach notification, data return or deletion, audit rights, subcontracting and limits on secondary use. If the vendor provides AI-enabled matching, the review should also cover model performance, updates, explainability, testing records and support for human review. PLMC’s guidance on how to review AI tools before staff start using them is useful for building that due diligence process.

Cybersecurity controls should include encryption in transit and at rest, access controls, strong administrator authentication, logging, monitoring, patching and incident response procedures. Because biometric data cannot be changed like a password, breach prevention and containment deserve special attention.

Create a real remedy when something goes wrong

People are more likely to trust facial recognition if they know there is a fair way to challenge errors. This is especially important where the system affects employment, access to premises, delivery of services or potential law enforcement action.

A remedy process should be simple and visible. If someone is denied entry because the system fails to verify them, staff should know how to verify identity another way. If someone is wrongly matched to a watchlist, there should be a documented escalation route, review by a trained person and correction of the record.

Organisations should also track complaints and false matches. Patterns can reveal problems with camera placement, lighting, training, vendor performance or the underlying policy. A system that generates repeated complaints should not be defended simply because it was approved at launch.

Special care for sensitive settings

Some environments carry higher public trust risks than others.

Workplaces need careful handling because employees may feel pressured to agree. Alternatives, consultation and clear limits are essential. Facial recognition should not become a convenient way to monitor staff beyond the stated purpose.

Schools and services involving children require heightened caution. Children may not fully understand biometric processing and parents or guardians may have limited practical choice. Strong necessity should be proven before adopting facial recognition in these settings.

Retail and hospitality deployments can damage reputation quickly if customers feel secretly profiled or wrongly accused. Watchlist matching in customer-facing spaces should be subject to strict governance, strong evidence thresholds and human review.

Public sector and law enforcement uses require the highest level of transparency and accountability. Clear legal authority, public policy, audit trails, oversight and limits on retention are essential because the consequences for individuals can be severe.

A public trust checklist before deployment

Before using facial recognition, leaders should be able to answer these questions without relying on vague assurances:

  • Have we documented a specific, legitimate purpose?

  • Have we tested less intrusive alternatives?

  • Have we completed a privacy and security risk assessment?

  • Have we assessed accuracy and bias in the real operating environment?

  • Have we created a human review process for matches and failures?

  • Have we published clear notices before collection begins?

  • Have we limited retention, access and secondary use?

  • Have we reviewed vendor contracts and data transfer risks?

  • Have we trained staff who will operate or rely on the system?

  • Have we created an accessible complaint and correction process?

If the answer to any of these questions is unclear, the organisation is not ready for full deployment. A pilot with defined limits may be more appropriate than an immediate rollout.

Frequently Asked Questions

Is facial recognition allowed under Jamaica’s Data Protection Act 2020? The Act does not create a blanket ban on facial recognition, but organisations must have a lawful and fair basis for processing personal data, meet data protection standards and apply strong safeguards. Because biometric identification is high-risk, legal and privacy review should happen before deployment.

Can an organisation rely on consent for facial recognition? Sometimes, but consent must be genuine, informed and freely given. In workplaces or essential service settings, people may feel they cannot refuse, so consent may be weak. Organisations should assess whether another lawful basis or statutory authority applies and whether a non-biometric alternative is needed.

What is the biggest public trust risk with facial recognition? The biggest risk is using the technology for purposes people did not expect or understand. Secret deployment, vague notices, false matches, excessive retention and weak remedies can damage trust even if the original security goal was legitimate.

Should facial recognition decisions be fully automated? High-impact decisions should not be left to the system alone. A possible match should normally trigger human review, context checking and a fair opportunity for the person to challenge the result.

How often should a facial recognition system be reviewed? Review should happen before launch, after any pilot, when the purpose changes, when the vendor updates the system and at regular intervals during operation. Complaints, false matches, security incidents and audit findings should also trigger review.

Need help building privacy into facial recognition?

Facial recognition can support security, but only when governance, data protection and public communication are designed into the project from the start. Privacy & Legal Management Consultants Ltd. supports organisations in Jamaica with data protection implementation, risk assessment, privacy awareness and compliance planning.

If your organisation is considering facial recognition or another biometric system, request guidance from Privacy & Legal Management Consultants Ltd. before you launch.