How to Protect Your Privacy From Facial Recognition in Public
Facial recognition has moved from a futuristic concern to an everyday reality faster than most people noticed. You’ve been scanned at an airport gate, possibly at a concert or sports venue, almost certainly at a border crossing, and — depending on where you live — possibly at a supermarket or on a public street. Most of the time there was no sign, no warning, and no option to opt out.
This guide explains where facial recognition is actually being used, what your rights are in the jurisdictions most Techwey readers come from, and what practical steps are available to reduce your exposure.
Where Facial Recognition Is Actually Being Used Right Now
Airports and border crossings. This is the most widespread deployment in the US, UK, EU, and Australia. The US TSA and CBP use facial recognition at major airports for boarding and customs. The EU’s Entry/Exit System began rolling out biometric border checks across Schengen countries in 2024. In most cases, international travellers cannot meaningfully opt out — the legal basis is your visa and entry documents, not your consent.
Concerts, stadiums, and large events. Ticketmaster introduced facial recognition for entry at thousands of venues in the US and UK. Madison Square Garden’s owner Sphere Entertainment has deployed it across its venues. The NFL uses it for staff credentialing. Some venues use it for age verification at bars inside the facility. Attendance at a private venue typically means you’ve accepted it via terms and conditions most people don’t read.
Retail and hospitality. Walmart, Amazon Fresh stores, and some supermarket chains in the UK use facial recognition for loss prevention — recognising individuals previously flagged for shoplifting. Some casino operators use it for loyalty programme recognition and to identify banned gamblers. A handful of fast-food chains are piloting it for personalised ordering. Unlike airports, most retail deployments operate in a legal grey area and face increasing regulatory scrutiny.
Law enforcement and public surveillance. The UK has the highest density of CCTV cameras in the democratic world, and the Metropolitan Police uses live facial recognition in targeted operations. US police departments in New York, Chicago, and Detroit use it for after-the-fact identification from footage. In China, it is pervasive. In the EU, live biometric surveillance in public spaces is heavily restricted under the AI Act for most use cases.
What Your Legal Rights Are
Rights vary significantly by jurisdiction — and this matters practically.
European Union: The EU AI Act, which came into force in August 2026, prohibits real-time biometric identification in public spaces for most purposes. Exceptions exist for national security and investigating serious crimes. Retailers and private event operators using live facial recognition in public or semi-public spaces face serious legal exposure.
United States: There is no federal law governing facial recognition for private companies. Illinois’ Biometric Information Privacy Act (BIPA) is the strongest state-level protection — it requires written consent before collecting biometric data and gives individuals the right to sue for violations. Texas and Washington have weaker protections. California is considering expanding CCPA to cover biometrics more explicitly. If you’re in Illinois, you have real legal teeth available.
United Kingdom: The ICO (Information Commissioner’s Office) has issued guidance that live facial recognition in retail settings is likely unlawful without explicit consent. The Metropolitan Police’s use in public has been challenged in court with mixed outcomes. Your rights under UK GDPR include the right to object to automated processing — but enforcement is inconsistent.
Australia and Canada: Both have privacy commissioners who have investigated specific deployments. Canada’s Privacy Commissioner found that Clearview AI’s collection of facial data from public sources violated Canadian privacy law. Australia’s Privacy Act is under review with proposed amendments that would specifically cover biometric data.
What You Can Actually Do
Honest answer first: if you use airports, attend large events, or shop at major retailers, you will encounter facial recognition and you cannot fully opt out of every deployment. What you can do is reduce your exposure and exercise the rights that exist where you are.
- At airports: In the US, you can opt out of biometric boarding and request a manual ID check instead. TSA and airline staff are required to accommodate this — you may need to be firm, as the process is not always clearly advertised. At non-US airports, options are more limited.
- At events and venues: Before purchasing tickets, check the venue’s facial recognition policy. Some venues publish it; many don’t. In the EU, a venue operating live facial recognition without clear consent notice may be violating the AI Act — you can file a complaint with your national data protection authority.
- At retail: In the EU, you have the right to object to automated processing under GDPR Article 22. In Illinois, you can sue under BIPA if a retailer collected your biometric data without written consent. In most other US states, you currently have no enforceable rights against private retailers.
- In public spaces: Physical countermeasures exist — glasses with IR LEDs that disrupt camera-based facial recognition, makeup patterns designed to confuse recognition algorithms — but their effectiveness against modern systems is inconsistent and their practicality for everyday use is limited. Wearing a hat and sunglasses reduces recognition accuracy at longer distances but is not a reliable defence against close-range systems.
- Across the board: Opt out of facial recognition features in the apps and services you use voluntarily — Apple Photos, Google Photos, and similar platforms all offer settings to disable facial grouping and recognition. That data doesn’t leave your device by default, but it’s worth reviewing.
The most effective protection available to most people isn’t a technical countermeasure. It’s political: supporting legislation that requires explicit consent for facial recognition in private settings, mandatory disclosure when you’re being scanned, and meaningful penalties for violations. That’s how the landscape changes at scale.
The Bigger Picture
Facial recognition is expanding faster than regulation. The EU AI Act represents the most serious attempt to establish limits, but it has carve-outs for security and law enforcement that critics argue are wide enough to swallow the rule. In the US, the patchwork of state laws means your rights vary dramatically based on where you happen to be standing.
Awareness is the starting point. Knowing where the technology is deployed, what it does with the data it captures, and what rights you have in your jurisdiction is the foundation for making informed decisions about where you go and what you accept. For more on protecting your digital privacy broadly, see our complete digital privacy guide for 2026 and our guide on how to spot AI-generated content online.
Read more tech related articles here.
