Netherlands facial recognition law enforcement Asia

The Dutch Police Line on Facial Recognition Is Policy, Not Law, and That Is Its Weak Point

Dutch police say they never use live facial recognition, only retrospective CATCH matching. The UK fight over Nottinghamshire shows how fragile a policy-only line is.

Dutch CATCH: Retrospective Matching in Numbers People of Internet Research · Netherlands 499 Suspects identified, 2024 From 884 images of sufficient qual… 56% Match rate, 2024 Up from about 20% two years earlie… 48% Oppose high-street scanning Liberty polling cited in the Notti… peopleofinternet.com
Dutch CATCH: Retrospective Matching in… People of Internet Research · Netherlands 499 Suspects identified, 2024 56% Match rate, 2024 48% Oppose high-street scan… peopleofinternet.com

Key Takeaways

On 21 August 2026, EFF, Big Brother Watch, Defend Digital Me, Liberty, Open Rights Group, Race Equality First, Statewatch and Stopwatch wrote to Nottinghamshire Police demanding an immediate halt to its planned rollout of live facial recognition in public spaces. This is a British dispute, not a Dutch one. But it is a useful stress test for the Netherlands, where police say they never use live facial recognition at all.

The case for the Dutch approach

The strongest argument for facial recognition in policing is simple: serious crimes go unsolved, and a face on CCTV is often the only lead. The Dutch answer is a narrow tool. CATCH, run by the police Centre for Biometrics in Zoetermeer, compares images of unidentified suspects against police databases of arrested and convicted people. According to Security Management, it is used for serious offences such as sexual offences, attempted murder, aggravated assault, weapons trafficking, burglary and drug trafficking. Access is limited to experts at the Centre, and a match is only a lead for investigators to corroborate. Dutch police state that live facial recognition "is never applied."

The numbers suggest the tool works. Press coverage reported that CATCH led to 424 identifications in 2023, from 1,693 images submitted. For 2024 the police submitted 2,022 images, and a new algorithm introduced at the end of 2023 raised the match rate on usable images to 56%, with 499 suspects identified from 884 images of sufficient quality. A human expert reviews each result, and nobody is scanned unless they are already the subject of an investigation.

What the Nottinghamshire letter objects to

The coalition's letter, summarised by EFF, raises six concerns. Live recognition scans everyone who walks past a camera, treating them as a suspect by default. It may deter people from seeking medical care, legal advice, union membership or protest. It could be used against low-level offences such as youth anti-social behaviour, with watchlists reportedly including children as young as 11. The groups also cite Liberty-commissioned polling in which 48% oppose scanning faces on high streets when there is no imminent threat.

One point matters most: the objections are about the mode of use, not the algorithm. A comparison against a custody database after a crime is a different act from a biometric scan of every passer-by. Dutch practice sits on the narrower side of that line, and it is the right side.

Where the Dutch line is actually drawn

The line is thinner than it looks. Dutch police say CATCH actions fall under the Police Data Act (Wet politiegegevens), and that every use passes an internal legal-ethical review. Commentators have noted that there is still no dedicated statute for police facial recognition. That is a policy commitment, which a future government or police chief could revise, rather than a statutory rule.

The EU framework sets a floor but not a ceiling. Under the AI Act, real-time remote biometric identification for law enforcement in publicly accessible spaces is a listed prohibited practice, with prohibitions applying since 2 February 2025. The prohibition carries narrow exceptions: searches for missing or trafficked persons, imminent threats to life or terrorist attacks, and suspects of serious crimes. Using them requires a fundamental rights impact assessment, registration, and prior judicial or independent authorisation. Retrospective matching is not banned; it is treated as high-risk, which brings compliance duties rather than a prohibition.

The European Data Protection Board's Guidelines 05/2022, adopted in final form on 17 May 2023, address facial recognition in law enforcement under data protection law. The Netherlands has also shown it will police the market: the Dutch DPA fined Clearview AI €30.5 million in September 2024 for building a biometric database from scraped photos.

A proportionate path

A pro-innovation stance does not require choosing between blanket bans and open-ended deployment. Retrospective, expert-reviewed matching against lawful databases, limited to serious crime, delivers most of the investigative value with a fraction of the chilling effect. The Dutch model is worth defending for that reason.

But defending it means putting it on firmer ground. Three steps would do that:

The Nottinghamshire fight shows what happens when a technology arrives before the rules. Dutch police have so far avoided that outcome, and codifying their own restraint would make it permanent.

Sources & Citations

  1. European Commission: AI Act regulatory framework
  2. EDPB Guidelines 05/2022 on facial recognition in law enforcement
  3. EFF: Civil society groups call on Nottinghamshire Police to halt live facial recognition
  4. Security Management: more faces recognised of unknown suspects (CATCH)
  5. Hunton: Dutch regulator fines Clearview AI €30.5 million