Alessandro Del Ninno
News
Data Protection Authority: favourable opinion on the draft legislative decree on facial recognition and AI in policing. Mass biometric data collection and databases created through web scraping are prohibited.
INFORMATION TECHNOLOGY
28/07/2026

The Data Protection Authority has issued a favourable opinion, subject to conditions, on the draft legislative decree governing the use of artificial intelligence systems by the police, including the use of real-time remote biometric identification and retrospective facial recognition.

Opinion No. 531 of 14 July 2026 concerns Government Bill No. 418, adopted in implementation of the delegated powers contained in Law No. 132 of 23 September 2025. The draft still has to complete its legislative process and does not, therefore, constitute the final text of the national legislation.

The draft allows the police to use real-time remote biometric identification systems in public places or places open to the public only in the exceptional circumstances permitted by the AI Act: the prevention of specific threats, the search for missing persons or victims of certain offences, and, in the context of criminal investigations, the targeted search for persons who have been specifically identified or are identifiable.

Such use must be authorised by a judicial authority, relate to a specific event, be limited to a defined geographical area and a specified period, and be based on a comparison database appropriate to the specific purpose pursued. In urgent cases, a fast-track procedure is provided for, subject to subsequent validation. Failure to comply with the conditions and time limits renders the results inadmissible and, in principle, requires the deletion of the data collected.

One of the Authority’s main concerns relates to the quality and composition of the biometric databases used for comparison.

According to the Data Protection Authority, the decree must set out specific requirements to reduce the risk of false positives, identification errors and discriminatory results. It must also be clarified whether the database must be created specifically for each operation or whether it may be of a permanent nature.

Even in the latter case, the comparison set must contain only data relevant to the individual authorised search and must not be progressively expanded by accumulating data used in previous operations. Security measures, retention periods, deletion procedures and safeguards against the indiscriminate expansion of the database must also be regulated.

The Data Protection Authority also calls for strict limitations to be placed on exceptions to the obligation to erase unlawfully collected data. A generic reference to the possibility of retaining such data on the basis of a different legal ground would, in fact, risk undermining the safeguards provided for in Legislative Decree No. 51/2018 for processing carried out for police purposes.

Of particular significance is the Authority’s position on retrospective facial recognition applied to images collected via CCTV.

The draft appeared to permit the prior processing and storage of biometric data of all persons accessing places or events subject to public order and security requirements, such as stadiums, concerts, demonstrations, stations or major events.

In the Authority’s view, such automated and blanket collection is not compatible with the AI Act. Retrospective facial recognition may only be used for targeted ex post searches concerning individuals suspected of or convicted of a criminal offence.

The conversion of images into biometric models should therefore not take place automatically at the time of recording. Processing should only be carried out on recordings that have already been captured, when a specific operational need linked to a criminal offence has arisen.

The draft legislation already prohibits, for certain preventive police activities, the use of biometric databases populated through non-targeted scraping techniques or created in breach of data protection legislation.

The Data Protection Authority calls for this same prohibition to be expressly included in the new Article 359-ter of the Code of Criminal Procedure, which is intended to regulate remote biometric identification in the context of investigations.

Consequently, databases of facial images created by indiscriminately collecting photographs from websites, social media or other online sources, or databases formed through unlawful processing, may not be used, even for investigative purposes.

The Data Protection Authority also calls for the reference in the draft to mere ‘qualified human review’ to be replaced with the broader concept of human oversight, as used in Article 14 of the AI Act. The person in charge must not merely formally verify the result, but must be able to understand how the system works, critically assess the output and prevent or halt its use when necessary.

In research and experimentation projects, the Authority proposes to prohibit not only the sharing but also the use of sensitive operational data, favouring synthetic data or real data that has been masked or pseudonymised. The privacy roles of the public and private entities involved must also be clarified.

Finally, the Data Protection Authority must be involved in the operation of regulatory sandboxes whenever experimentation involves the processing of personal data. In addition to the impact assessment on fundamental rights provided for by the AI Act, the specific data protection impact assessment required by Legislative Decree No. 51/2018 must also be carried out.