We're back to the complexity of how to craft the law.
Let's say we're within the realm of a serious crime, which, according to our recommendations, would lead to the police being able to use facial recognition. The law cannot know of all individual cases, so there will have to be, as you say, a risk management assessment made by a police force.
What is the conversation with the oversight body, including privacy commissioners? I think it starts with a conversation before the program is put into placeāa privacy impact assessment. How are you going to assess risk in a category of circumstances?
Then, if the police want to develop a program, we say that there should be program-level authorization. The police describe the program, which is, say, the protection of very important people in public spaces. That's the program. There's a discussion between the police and the Privacy Commissioner on that program. That's before the use of the technology. Once the technology is adopted and actually used, oversight should include the authority to investigate complaints and make orders as to the lawfulness of the use of the technology in a given case.
